cancel
Showing results for 
Search instead for 
Did you mean: 

Access to All transactions but Display mode only

Former Member
0 Kudos

Hi Team,

Currently we are working on 4.6c and we have a requirementthe end users needs to have accessto all the transactions in Display mode only..

I tried to create a new role with full authorizations and then change the ACTVT filed but there are 613objects which is a very tedious task to change to 03 -display mode..

Could you please provide me your suggestions what the best could be done..

Regds,

Satyanarayana .

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

assign role SAP_ALL_DISPLAY to your users

Former Member
0 Kudos

I have done that but when we try to execute transactions like SU01 - it is giving you rae not authorized..

One important thing is that when I have tried to create a user and assign the role asp_all_display it is giving a message that Some Activity groups are locked..

Regds,

Satyanarayana N.

Former Member
0 Kudos

Hi Sataya,

You can only crreate the roles starting with z*

there is no role with sap_all_display,

I think it is a profile you can directly assign this profile to all the users you want or else you can create a role for this profile.

Reward points if helpfull.

Regards,

Vamshi.

Former Member
0 Kudos

Hi Satyanarayana,

make profile by name Z_SAP_ALL_DISPLAY... add auth SAP_ALL_DISPLAY... but in this some transactions like su01 su10 you wont get.. that you need to apply manually one by one... No alternative for it!!!

Thanks & Rgds,

Vishal Ranadive

Former Member
0 Kudos

Hi,

Still it is the same problem..

When I copy the SAP_ALL_DISPLAY to some Z_sap_all_display.. and assign this to some user and when I save it is giving the message that

SOME ACTIVITY GROUPS WERE NOT ASSIGNED BECAUSE THEY ARE LOCKED

And unable to execute any transaction..

Pls help..

Regds,

Satyanarayana N

Former Member
0 Kudos

Hi Sataya,

I dont think you can create a different profile.You can try assigning this profile to a particular user id. First create a role with z_* and then while generating the authourization profile it iwll ask you to choose a profile then you can choose the profile from it.

Reward points if helpfull.

Regards,

Vamshi.

Former Member
0 Kudos

I think Vamsi is right,

upto 4.6 Activity groups groups menace Profiles... Satya please check whether any profile is lock....

Former Member
0 Kudos

Hi,

I have copied the role and assigned to the user but still it is giving as you are not authorized for any transaction I execte..

Regds,

Satyanarayana N.

Former Member
0 Kudos

have you done user comparison?? and all objects are activated ????

Former Member
0 Kudos

Yes..I have done the user comparision and all the objects are activated..

Former Member
0 Kudos

Hello Vamshi,

SAP_ALL_DISPLAY does exist in release 4.6 C.

Hello Satya,

If hyou would have checked the description of SAP_ALL_DISPLAY you would notice it is : Display authorizations for all modules (except BC, CA, HR). So it won't have basis component in it. This translates to no access for SU01 through this role. Infact no access to S* transactions!!

To solve the issue create a new role, assign SU01 to it and give activity 03 in all the activities for the user. Assign the role to the user and check.

Regards.

Ruchit.

Former Member
0 Kudos

Hi Ruchit,

Thanks for your reply..

But Iam unable to access any transaction apart from s*...

what could be the reason..

I have done the user comparision also and everything is in green...

Regds,

SatyanarayaNA..

Former Member
0 Kudos

Ruchit,

Would like to know the best way to create a role where end users can have access to all the transactions in display mode...only..

Former Member
0 Kudos

Hello Satya,

For the transactions you are unable to access please do SU53 and then check if the correpsonding authorization is missing in SAP_ALL_DISPLAY.

Also coming to your second question: Would like to know the best way to create a role where end users can have access to all the transactions in display mode...only..

Basically this is not an easy excercise. However you can insert with in a role full authorizations by using the option: EDIT>INSERT AUTHORIZATIONS>FULL AUTHORIZATIONS: For this go to authorization tab of the role in change mode. After you have inserted this you need to go to every authorization object and then adjust the values so as to ensure that only display activites are coming. Mind you we are talking about several authorization objects so it is a tedious activity.

Regards.

Ruchit.