Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

Profile Only !

Former Member
0 Kudos

Hi,

I need to add:

1. A profile to a role ??? Sounds OK ?

2. I want to add an Object --NOT MANUALLY - to a role (tried SU24?? failed !)

3. since this role doesnot have t codes -- how do I keep the Menu tab green (any ideas othe rthan ZTCODE?)

Whole I dea is to create a communication /system user with a role as I can transport it ..

Thanks

1 ACCEPTED SOLUTION

Former Member
0 Kudos

>

> Hi,

>

>

> I need to add:

>

> 1. A profile to a role ??? Sounds OK ?

> 2. I want to add an Object --NOT MANUALLY - to a role (tried SU24?? failed !)

> 3. since this role doesnot have t codes -- how do I keep the Menu tab green (any ideas othe rthan ZTCODE?)

>

> Whole I dea is to create a communication /system user with a role as I can transport it ..

>

> Thanks

Hi George,

If I am thinking through your situation correctly, you have a user which needs only object level access?

In this case I would create a role and manually add in the objects which are required and document what the objects are used for in the role text field. As long as you document it, I can't see there being a problem if no S_TCODE auths are required.

If you need the menu tab to be populated then something like SU53 or SU3 in there can't do much harm and prevents need to create & transport a custom t-code.

6 REPLIES 6

Former Member
0 Kudos

>

> Hi,

>

>

> I need to add:

>

> 1. A profile to a role ??? Sounds OK ?

> 2. I want to add an Object --NOT MANUALLY - to a role (tried SU24?? failed !)

> 3. since this role doesnot have t codes -- how do I keep the Menu tab green (any ideas othe rthan ZTCODE?)

>

> Whole I dea is to create a communication /system user with a role as I can transport it ..

>

> Thanks

Hi George,

If I am thinking through your situation correctly, you have a user which needs only object level access?

In this case I would create a role and manually add in the objects which are required and document what the objects are used for in the role text field. As long as you document it, I can't see there being a problem if no S_TCODE auths are required.

If you need the menu tab to be populated then something like SU53 or SU3 in there can't do much harm and prevents need to create & transport a custom t-code.

0 Kudos

Yes..All i wanted that the user have an object level access...I wanted do away with manual addition..now I will do it manually .OK I will add an SU53 too.

So the take home is ...Object levels .system /communication user ...add manually the Auth objects ?

0 Kudos

>

> So the take home is ...Object levels .system /communication user ...add manually the Auth objects ?

You can also maintain authorization objects and values to fields against an RFC enabled "Function module" or types of "Services" in SU24. You can then add these to the role menu in PFCG and it will add those objects and prposed field values for you. That way you do not have to create a role free of object S_TCODE by adding the objects manually.

I thought you knew that, because I vaguely remember having discussed it with you before?

Cheers,

Julius

0 Kudos

>

> You can also maintain authorization objects and values to fields against an RFC enabled "Function module" or types of "Services" in SU24. You can then add these to the role menu in PFCG and it will add those objects and prposed field values for you. That way you do not have to create a role free of object S_TCODE by adding the objects manually.

good point, I forgot about that option.

0 Kudos

Thanks Juluis , Alex.....

Great insights

0 Kudos

Actually, I heard a rumour that Alex was writing an SDN blog on this...