Auth object F_KNA1_GRP: how to avoid to display specific Account group
Hi Gurus,my aim is to avoid specific users to display customers with specific account group (XD03 transaction)..In order to do this I've implemented Auth object F_KNA1_GRP specifying ACVT = 3...
View ArticleRe: Auth object F_KNA1_GRP: how to avoid to display specific Account group
Moved from SAP ERP Sales and Distribution (SAP SD) to Security
View Articledetailed authority-check for TA KA03, KAH3
Hi, validating the authority in KA03 or KAH3 is very simple. The user need the for example the authority object K_CSKA_SET with the correct activity (ACTVT) and the correct chart of account (KTOPL)....
View ArticleIssue in BI office for analysis
Hi All, I have a issue in BI office for analysis when user is running airport report it shows up no authorization maintained all necessary authorization objects in Rsecadmin t-code. I have a question...
View ArticleRe: SAP Tables accesses by a tcode
Hi All,Probably the easiest way which works often is for you to use the display transaction to display the data, then place your cursor on the field displaying the data, and then hit F1.Can you please...
View ArticleRe: Security retrofit strategy and best practices
Hi all, I have faced some problems using Retrofit for security roles, however it was fixed by some SAP Notes. Until now, for all my roles changes I retrofited, they were all categorized as Manual...
View ArticleRe: Auth object F_KNA1_GRP: how to avoid to display specific Account group
hi angelo, F_KNA1_GRP is a standard assignment/check to XD03. what have extra you done in SU24, also could you clarify ' A_FBD(CLI) ' RegardsPlaban
View ArticleRe: Auth object F_KNA1_GRP: how to avoid to display specific Account group
Dear Plaban,with SU24 I've check all the auth check assigned to XD03 verifying that within F_KNA1_GRP the linjked specific account group.With PFCG I've checked role A_FBD(CLI) in particular...
View ArticleRestricing IDOCs for IT user
Dear All, I want to restrict IT user form viewing FICO IDOCS Can some body help me in finding a good solution I am stuck in my analysis since many days I tried to restricting users via Message type....
View ArticleSAP HR Payroll edit by supplier?
Security experts - Is it not an SoD Violation if the IT supplier/support team edits the Payroll of the customer. The SAP HR support team (Outsourced supplier) should not edit the Payrolls of customer's...
View ArticleRe: Is this possible: SNC connection from SAP GUI to SAP Router, and ...
Hi Guys Is the scenario: SAP GUI -- (SNC conn) -- saprouter1 -- (non SNC conn) -- SAP System Possible now? ThanksJP
View ArticleRe: Is this possible: SNC connection from SAP GUI to SAP Router, and ...
No, that is not possible. SNC is used by SAP router at network layer and SNC is used by SAP GUI and NW ABAP for application/user authentication. You can do the following though: SAP GUI...
View ArticleRe: Is this possible: SNC connection from SAP GUI to SAP Router, and ...
Thank, for the response We successfully connect from outside our domain (internet) from GUI via router to backend system. Q: is there a way to secure this without SSO or third party software? And as...
View ArticleRe: Auth object F_KNA1_GRP: how to avoid to display specific Account group
i cannot understand A_FBD(CLI). is it a custom role, that you have created. Could you provide trace, for XD03
View ArticleRe: Auth object F_KNA1_GRP: how to avoid to display specific Account group
Hi, Sometimes it`s not possible to make restriction based on account groups. Thanks.
View ArticleRe: Auth object F_KNA1_GRP: how to avoid to display specific Account group
Hi Angelo, Few questions to understand your situation 1.Have you made check as 'Yes' for authorization object F_KNA1_GRP for t-code XD03 in t-code SU24?2.Have you created a custom role 'A_FBD(CLI)'...
View ArticleRe: Auth object F_KNA1_GRP: how to avoid to display specific Account group
Hi Plaban, I suppose A_FDB (CLI) i s a custom role created by our tech department.Since It hasn't a Z* ad first letter I was thinking it was standard... Below the trace (SU53 XD03): it's seems that...
View ArticleRe: Auth object F_KNA1_GRP: how to avoid to display specific Account group
HI Pradeep,1)yes. 2)yes 3)yes. 4)Below the trace: Many thanks for your support Angelo
View ArticleRe: Auth object F_KNA1_GRP: how to avoid to display specific Account group
Hi Angelo, I have found few problems with your implementation. 1.In your PFCG role why activity 01,02 is provided when it was only display '03' activity.so please remove activity 01 & 02(Create or...
View ArticleRe: Auth object F_KNA1_GRP: how to avoid to display specific Account group
Hi Pradeep,first of all many thanks for your support. 1)I've just corrected 2)Even if I try to tarce XD03 the result is that the system gives the message: 0 records found. Many thanksAngelo
View Article