02-11-2008 5:52 PM
Hi,
I need to add:
1. A profile to a role ??? Sounds OK ?
2. I want to add an Object --NOT MANUALLY - to a role (tried SU24?? failed !)
3. since this role doesnot have t codes -- how do I keep the Menu tab green (any ideas othe rthan ZTCODE?)
Whole I dea is to create a communication /system user with a role as I can transport it ..
Thanks
02-11-2008 6:26 PM
>
> Hi,
>
>
> I need to add:
>
> 1. A profile to a role ??? Sounds OK ?
> 2. I want to add an Object --NOT MANUALLY - to a role (tried SU24?? failed !)
> 3. since this role doesnot have t codes -- how do I keep the Menu tab green (any ideas othe rthan ZTCODE?)
>
> Whole I dea is to create a communication /system user with a role as I can transport it ..
>
> Thanks
Hi George,
If I am thinking through your situation correctly, you have a user which needs only object level access?
In this case I would create a role and manually add in the objects which are required and document what the objects are used for in the role text field. As long as you document it, I can't see there being a problem if no S_TCODE auths are required.
If you need the menu tab to be populated then something like SU53 or SU3 in there can't do much harm and prevents need to create & transport a custom t-code.
02-11-2008 6:26 PM
>
> Hi,
>
>
> I need to add:
>
> 1. A profile to a role ??? Sounds OK ?
> 2. I want to add an Object --NOT MANUALLY - to a role (tried SU24?? failed !)
> 3. since this role doesnot have t codes -- how do I keep the Menu tab green (any ideas othe rthan ZTCODE?)
>
> Whole I dea is to create a communication /system user with a role as I can transport it ..
>
> Thanks
Hi George,
If I am thinking through your situation correctly, you have a user which needs only object level access?
In this case I would create a role and manually add in the objects which are required and document what the objects are used for in the role text field. As long as you document it, I can't see there being a problem if no S_TCODE auths are required.
If you need the menu tab to be populated then something like SU53 or SU3 in there can't do much harm and prevents need to create & transport a custom t-code.
02-11-2008 6:36 PM
Yes..All i wanted that the user have an object level access...I wanted do away with manual addition..now I will do it manually .OK I will add an SU53 too.
So the take home is ...Object levels .system /communication user ...add manually the Auth objects ?
02-12-2008 5:51 PM
>
> So the take home is ...Object levels .system /communication user ...add manually the Auth objects ?
You can also maintain authorization objects and values to fields against an RFC enabled "Function module" or types of "Services" in SU24. You can then add these to the role menu in PFCG and it will add those objects and prposed field values for you. That way you do not have to create a role free of object S_TCODE by adding the objects manually.
I thought you knew that, because I vaguely remember having discussed it with you before?
Cheers,
Julius
02-12-2008 6:28 PM
>
> You can also maintain authorization objects and values to fields against an RFC enabled "Function module" or types of "Services" in SU24. You can then add these to the role menu in PFCG and it will add those objects and prposed field values for you. That way you do not have to create a role free of object S_TCODE by adding the objects manually.
good point, I forgot about that option.
02-12-2008 7:05 PM
02-12-2008 8:21 PM