Question: Hi Guys,
I am trying to implement APO security. (APO v. 3.1)
In R/3 the method we used to design roles was:
1. Listed down the organizational entities we would want to control
eg: company code, Business Area, profit centers, purchase org., plants etc
2. Build up roles restricting the values for these entities
3. Assign these roles to the users.
But in APO, we have only one organizational entity - Plan Version and we want to control many other values too. If we are to restrict the transaction access by location, planning book, resource etc for eg. a tcode say /sapapo/sdp94. The authorization objects that are validated against do not have a default status of check/maintain in SU24. I would have to manually change the status to check/maintain - Also then i would have to give default values for the fields of those objects. This would mean i am deviating from SAP standard way of doing things...
My question is : If i want to restrict access in demand planning module by say resource, planning book and location - Is the above said way the right way to carry on?
How is Security usually done in APO?
Regards,
VS
Answer:
There is no standard in Su24. It is a configuration table and is up to the customer to make it work the way they need it, NOT rely on SAP as they have access granted to object no end user should have. In the Add-on modules like APO the SU24 entries are abisimal at best and require your intervention.
note that moving the entry from 'C' to 'CM' means nothing as far as control goes. It is the move from 'N' to 'CM' that cause SAP to start failing the check if the user is not authorized.
Answer:
Thanks John, Your opinion is appreciated - It is good for me to start with. I was under the impression that changes done in SU24 meant deviation from the standard way of doing things..
Any idea what needs to be done during an upgrade - Would changes be overwritten by SAP Standard then.
VS.
Answer:
SU25 is your upgrade transaction for SU24, but before the upgrade use su25 to create a transport of SU24 and export it. then if you use SU25 incorrectly then you can recover by imporitng the file back into the system
Indians Earn 25000 Monthly.Easy Form Filling Jobs
Monday, November 19, 2007
APO Security issue
APO Security
Question: Hi,
does anybody has an overview of which authorization objects are checked against which APO transaction? The standard SU24 for APO is maintained really poor.
Thanks a lot for all help!
Answer:
As with most Add-ons or industry solutions the SU24 AND the authorization checks themselves are lacking and not robust. You will find that many of the tcodes are controlled ONLY by S_TCODE and nothing more. To hasten your answer use ST01 and mark atuhorization trace and use the analysis report to configure SU24.
APO Security
Question: Hi,
does anybody has an overview of which authorization objects are checked against which APO transaction? The standard SU24 for APO is maintained really poor.
Thanks a lot for all help!
Answer:
As with most Add-ons or industry solutions the SU24 AND the authorization checks themselves are lacking and not robust. You will find that many of the tcodes are controlled ONLY by S_TCODE and nothing more. To hasten your answer use ST01 and mark atuhorization trace and use the analysis report to configure SU24.
APO authorization problem
Question: Hello,
Anyone familiar with APO authorizations? I am trying to limit to display only in the product master with tcode /SAPAPO/MAT1. According to the person testing he has create, change, delete access but I only have an 03 and 08 as the activity value. Go figure
The other thing is in the planning book screen, certain buttons are missing when using tcode /SAPAPO/SDP94. I can not see the "selection window" nor the "display dependant objects" buttons. I traced a user that has it and added the access but still do not see the buttons.
Any help on either of the two issues above will be most appreciated.
Thanks in advance.
Answer:
For your /SAPAPO/SDP94 issue, you need to maintain C_APO_FUN to have C_SELCTION, C_SELE and C_SELORG on field APO_FUNC and the name of the planning area on APO_PAREA.
For the /SAPAPO/MAT1 issue, ensure you have only 03 on C_APO_PROD.
Good Luck.
Answer:
Thanks for the help. However in the /SAPAPO/MAT1 issue, I definately do have only 03 in the C_APO_PROD auth. Still he says he's able to do more.
Is this a situation were you may enter the screen and it looks like it's in "change" mode but when you actually try to do something it tells you that you are not authorized.
Also, is there an authorization book on APO. That would help.
Answer:
Hi am having a imilar issue. if i don't attach C_SELCTION to C_APO_FUN , the user is not able to see the selection window Icon or do any selection. But if i attach the C_SELCTION to C_APO_FUN, user is able to make changes fields like "confirm requirements " .
Can anyone help me to district it to Display only !
Answer:
Check out OSS Note:
Authorizations in APO demand planning - Note 400434
APO Alert Monitor
Question: Within our APO system, they want to split access to data in different countries. In the Alert Monitor, /SAPAPO/AMON1 you can see data for different product and locations. Also the Alert Monitor can be called from other transactions in APO.
The only authority check that I'm aware of for the Alert Monitor is C_APO_AMON and this doesn't permit me to split data.
Is there any way to ensure this kind of split? Or does the system do this automatically?
Thanks
Answer:
duplicate posting locked.
please never double-click inside a browser (such as Netscape or Internet explorer)
Snowy
_________________
SapFans Moderator
APO Alert Monitor
Question: Within our APO system, they want to split access to data in different countries. In the Alert Monitor, /SAPAPO/AMON1 you can see data for different product and locations. Also the Alert Monitor can be called from other transactions in APO.
The only authority check that I'm aware of for the Alert Monitor is C_APO_AMON and this doesn't permit me to split data.
Is there any way to ensure this kind of split? Or does the system do this automatically?
Thanks
Answer:
duplicate posting locked.
please never double-click inside a browser (such as Netscape or Internet explorer)
Snowy
_________________
SapFans Moderator
NetWeaver ‘04–SAP Web AS for ORACLE certified
APO - tcode /SAPAPO/MC62 - Maintain Characteristic Values
Question: Hi
Has anyone been able to restrict this transaction to planning area? The authorisation object with planning area is referenced, however the planning area field is not checked.
Has anyone else experienced this and if so have you found a solution to restricting to planning area or master planning object structure?
Thanks
Answer:
Hi
Has anyone been able to restrict this transaction to planning area? The authorisation object with planning area is referenced, however the planning area field is not checked.
Has anyone else experienced this and if so have you found a solution to restricting to planning area or master planning object structure?
Thanks
Yu can ask an ABAPer to check coding and see if these authorizations objects are checked.
Snowy
_________________
SapFans Moderator
NetWeaver ‘04–SAP Web AS for ORACLE certified
Search: /forums/search.php
SAP Notes: http://service.sap.com/notes
SAP Help: http://help.sap.com
Basic Rules: /forums/viewtopic.php?t=222759
Answer:
Hi,
I have the same problem.
It seems like the field APO_FUNC is checked, but not APO_PAREA.
Anyone that found a solution for this?
APO - second role causes authorization problems
Question: Hello all,
the following effect occurs on my APO system:
User A has assigned a role to do customer plannings, everything works. After that the user gets an additional role for PPDS or SCPT. Now, the customer planning doesn't work anymore?
More authorizations - less rights?
This effect is indenpendent of user A, I tried it with several ones. Always the same.
What can I do?
The users need access to both transactions!
Thanks for your help!
Answer:
may be user comparision issue.
if u get a solution for this problem please post it here.
thanks
Answer:
Hello,
it's not a problem of user comparison.
Answer:
Have you run a trace ?
_________________
Best Regards
Bazza
Answer:
Sometimes SAP performs an auth check to determine screens dynpros or the path which the runtime environment should be generated from.
In some special cases of the above, adding authorizations will give you a more restricted path followed (or it would appear to be so) as a result.
Try logging on with less auths (or none what-so-ever) and see what you get.
Contrary to popular belief, more auths (or SAP_ALL) does not contain more (or all) authorizations for the system.
Tarr
Answer:
No APO experience so look at this as a generalization thta may have some applicability.
If you had a role with an authorization with P_PERNR with value of I and another role with an authorization with the value of E and then assigned the roles together something the user could have done earlier will quit working. This is because these authorizations are mutually exclusive and the system is smart enough to recognize this. You may need to study the values of authorizations in your roles (and the help text) to see if APO delivers an object like P_PERNR.
ps if it does please share.
APO - Locking Planning Area
Question: Hello all,
I have a strange requirement from the project team:
We have a planning area which we do not want the users using during a certain point in time during the day. We do not want the users to be locked. We do not want the users to log out.
Is there a way to lock a planning area without user's logging out?
Planning area (APO_PAREA) is protected by the following authorization objects:
C_APO_FUN
C_APO_SEL2
C_APO_SEL3
C_APO_IOBJ
C_APO_CPY
System specifications:
SAP SCM 4.0
Kernel: 620
Thanks,
Sam
Answer:
SAP Security is not time dependent based on the hour. You can add and remove access based on the from-to date on the user master record but you cannot control it on an hourly basis without a lot of custom programming.
Sounds like you need to rethink your process.