Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

Copy/Merge only 3 Auth. Objects from old role to new corresponding role

Former Member
0 Kudos

Hi,

I want to Copy/Merge only 3 Auth. Objects from old role to new corresponding role.

There are around 30-40 Auth. Objects in the old role. I want to pick only 3 Auth. Objects form the old role & copy/merge it in the new role with the exact same Auth. Object values.

Please suggest. <removed_by_moderator>

Thanks & Regards,

Sameer

Edited by: Julius Bussche on Jul 15, 2008 6:42 AM

18 REPLIES 18

jurjen_heeck
Active Contributor
0 Kudos

What is the scale of your problem? 10 roles? 50? 100?

Once we know that we kan help you find the appropriate solution.

Jurjen

Please do not advertise with 'giving points', it is as bad as asking for them. Thank you.

0 Kudos

Hi,

The no. of roles are not yet fixed..The requirement may come for a fewer roles or a whole lot of 30-40 of them.

<removed_by_moderator>

Thanks & Regards,

Sameer

Edited by: Julius Bussche on Jul 15, 2008 6:41 AM

Bernhard_SAP
Employee
Employee
0 Kudos

Hi,

either you copy the complete role and set the unwanted objects to 'inactive' to avoid re-inserting at the next merge.

Or you create a new role without menu and

a)insert the authroizations you want manually (menu->edit->insert authorizations->from profile. Still you will have to delete the authorizations that you don't need manually.

b)insert the 3-4 objects you need manually and maintain the values manually

A selective insertion/copy is not available in standard.....

I suggest, not to update agr_1250,agr_1251 manually for your new role.

b.rgds, Bernhard

0 Kudos

Hi Bernhard,

I am aware of all these possible options.

I simply want to Copy/Merge only 3 Auth. Objects from old role to new corresponding role. Don't want the rest of the Auth. Objects.

There must be some solution to it. Please suggest.

Thanks & Regards,

Sameer

0 Kudos

Sameer,

I find the way you demand solutions on a short term slightly offensive. This is a forum were people help each other on a voluntairy basis.

Anyhow, here goes: By downloading roles, manipulating the download and re-uploading you can delete unwanted objects/values. This is almost as dangerous as dangerous as editing tables directly so you should do this on a sandbox system/client and check the results thoroughly before bringing it to your 'real' landscape.

1 : Copy your roles to their new names

2 : Download the copies to your pc using "mass download"in PFCG. Best use UTF-8 as the download parameter.

3: Open the download file with a text editor and remove all lines starting with AGR_1250, AGR_1251 and AGR_1252 that have no relationship to the objects you want to keep.

4: Save the edited file and upload again into PFCG (mind the UTF-8 parameter)

5: Regenerate the profiles.

As you can see this will not be a real shortcut to manually changeing the roles in PFCG, especially when the number of roles to edit doesn't exceed 50. Also the risks are a lot higher than setting yourself to only a day of work in PFCG.

Jurjen

0 Kudos

Jurjen,

I guess it only you who feels me demanding.

It is a practise and a formal way to write please suggest etc...

Sameer

0 Kudos

Sameer,

I was not referring to the "please suggest" itself but to:

> There must be some solution to it. Please suggest.

and also to the -now removed- line in your second post in this thread.

Hopefully the solutions brought in the thread can help you out as I do not have any other ideas. Mass change tools for role/profile details are on a lot of peoples wishlist.

Jurjen

0 Kudos

Jurjen,

I was suggesting for some alternatives...not demanding..FYI

Your suggestion did not help though.

Sameer

0 Kudos

Hi Sameer,

I agree with Jurjen. See the description of the forum at the top of the page:

> Strategic SAP product security issues and questions in the areas of secure user access, such as Single Sign-On and Identity Management, secure collaboration, such as message security (encryption) and trust management as well as infrastructure security questions that span more than one SAP NetWeaver component, should be posted here.

No where does it mention nor imply a "24x7 urgent support unit".

Mostly we discuss things here and exchange views, and some challenging support-type questions are interesting for us as well as we learn from them, but there is no urgency and it is voluntary.

If you disagree or would like to have a different Service Level, then either open a customer note via the SAP Service Marketplace and mark it "Urgent" (in othe words your production system is down) or go directly to finding yourself a good consultant.

Now... let me look at your question, and if I find it interesting, I will also answer.

Cheers,

Julius

0 Kudos

Julius,

I disagree to what Jurjen has to say.

ASAP I had written in a generalised way. I never expected 24*7 support. If it was that critical I would have never come to SDN. I would have logged in a Critical Ticket in SAP Service Marketplace. Simple as that.

Sameer

0 Kudos

Hi,

The problem is solved.

Sameer

0 Kudos

Hi Sameer,

In that case there seems to be a solution for what to do, and also what not to do.

Take care,

Julius

0 Kudos

Julius,

That's what..In that case one has to understand the importance of the problem and help and not write why you have written this & that.

Sameer

0 Kudos

would you care to elaborate on what you did in order to solve this issue?

0 Kudos

No Dimitri.

It was a simple thing and people for no reason complicate matters like this thread

0 Kudos

What on earth makes you believe that anyone else on this planet should help you ASAP, when you won't even share with Dimitri a "simple solution" after waiting patiently for a week?

0 Kudos

Julius,

I never expected ASAP solution from anyone.

It is upto me to write.

Former Member
0 Kudos

Hello,

There is one option.

you want to merge/copy the limited objects from old to new role... right?

1. copy the old role

2. edit the copied role

3. when u r in the "authorization data" screen, u will find the menu option "utilities". under this, u will find the "merge authorizations".

this will only merge the different entries maintained for the same object. and will work only on "standard" objects. objects "maintained" and "manually" inserted will not be merged.

4. before this delete/inactivate the unwanted objects.

Let me know if i did not understand your requirement ...

If not please could you elaborate on your idea of "copy/merge" ...

Regards,

Srihari