02-17-2016 10:35 AM
Hi all,
I am in a great dilemma. Kindly help me.
Here in our production environment we got one requirement. I have to restrict the account group in XK01(Vendor creation) for some department only. I done the same but it is not getting restricted. Kindly check the steps i have done.
I have to assign the account groups IMPS&INDS to the t.code XK01. I given both the account groups in the Authorization object F_LFA1_GRP
After that i selected both account groups, save, and generated the role
Then i checked in SUIM, but the restriction is not working. After that i again checked the same. I got the following screen. I found that the selected account groups didn't restricted.
Can anybody help me in the situation as the users is waiting for me..
Regards
Praveen
02-18-2016 11:41 AM
02-17-2016 12:39 PM
Hi Praveen,
Please check the below points
1. Check whether the same role has object F_LFA1_GRP two times ?
2. Is the profile has been generated after updating the account groups IMPS&INDS values ?
02-17-2016 1:23 PM
don't worry about the unchecked entries in the F4 help - they are not relevant to the authorization. Only the maintained values are relevant. And they are still there (IMPS, INDS).
But you need to check, if the object is really checked in xk01 to delimit the access you require.
Your friend is ST01, resp. stauthtrace....
b.rgds, Bernhard
02-18-2016 11:41 AM