cancel
Showing results for 
Search instead for 
Did you mean: 

Query related to User authorization

Former Member
0 Kudos

Dear All,

I have query that, suppose i a user is having authorization of standard profile; eg. SAP_ALL & SAP_NEW.

then can we restrict the critical or the sensitive eg. BASIS T-code which can be created problem by the Functional Consultant; without removing these profiles. Is it possible, if yes how to do.

I have limitation user creation. I cannot create diferent user for all functional consultant and assign then the desired T-code or profile.

This is my company requriement.

Please suggest me.

Thanks n Regards.

Bhaskar

Accepted Solutions (0)

Answers (3)

Answers (3)

Former Member
0 Kudos

No Mate ! Its not possible.It's better to make New Role or profile for your FI user with list of T-codes which FI consultant required only..

Regards,

Rohit

Former Member
0 Kudos

Dear Rohit,

but i cannot create seperate user and role for all functional consultant...because they limitation in user liciense.

Thanks n regards

Bhaskar

Former Member
0 Kudos

Hi Bhaskar,

I am not telling you to create new user i m only saying to create new roles or profile ..for creating new roles and profiles you need not any license.After creating new roles with specific FI user needs you can assign this new role to user and delete the old one and one more thing Which you can do here is create new profile by copying the SAP_ALL profile and then delete the basis and other rights or transaction from this copied profile and then assign it to user.

Regards,

Rohit

Former Member
0 Kudos

Hi,

SAP_ALL : This profile grants practically unrestricted access to the entire system

(including applications), including, above all, access to application

development tools.

it is not possible to restrict when you assign sap_all profile it's override all authorization in other authorization profile,

it's better to create a appropriate role for functional consultant

regards,

kaushal

Former Member
0 Kudos

Hi,

SAP authorisation concept is based on GRANTING RIGHTS not revoking.

So - you can't revoke any rights from user having SAP_ALL profile.

Regards,

Wojtek