Vous êtes sur la page 1sur 3

Assigning users to a role The users that you include in this list are authorized to execute the transactions

in the role using the corresponding authorizations. These users can also display the transactions in their SAP Easy Access Menu. You can include user IDs in the list as follows:

By multiple selection from a selection list You can include several users at the same time, for example, all users in a particular user group or all users in the SAP System. To do this, first choose "Selection" and then additional value selection pushbuttons.

Using Organization Management (see below)

The user names are automatically entered in the second column next to the user ID. In the two additional columns, you can specify a validity period for the assignment. You can delete the user IDs and insert an additional one in front of a selected user ID. Status display on the tab o The status display on the tab indicates whether or not users are already assigned to the role. If the display is red, no users are assigned. If it is green, at least one user is assigned to the group. If the display is yellow, this means that although users have been assigned to the role, the user master record comparison is not current. If the role is a composite role, the status display only indicates whether users are assigned to the role.

Time-dependency of user assignment and authorizations o If you are also using the role to generate authorization profiles, then you should note that the generated profile is not entered in the user master record until the user master records have been compared. When you specify the users for the role, the system enters by default the current date as the start date of the user assignment, and 12.31.9999 as the end date. If you want to restrict the start and end dates of the assignment, for example, if you want to define a temporary substitute for a user, the system automatically ma es the changes to the user. This automatic adjustment of the user's authorizations is executed using report PFCG_TIME_DEPENDENCY. In this case, you should schedule report PFCG_TIME_DEPENDENCY daily, for example, early in the morning, to run in the bac ground (in transaction SA38, for example). This compares the user master records for all roles and updates the authorizations for the user master records. The system removes

By a single entry or by ma ing a selection from the possible entries list.

authorization profiles for invalid user assignments from the user master record, and enters authorization profiles from valid user assignments to a role. When you use Organization Management (often called Org. Management or HR-Org. in the documentation), note that: o If you use organization management, you can also assign users to the role indirectly, that is, using jobs or positions. You can assign the users by choosing Org. Management on this tab. The user assignments you ma e are labeled as indirect user assignments, as long as they were not made directly between users and roles. On the user display, these indirect assignments are displayed with a gray bac ground and highlighted in color. You can display details on indirect user assignments by choosing Org. Management. You can also create direct user assignments using Organization Management. These are then exactly the same as assignments you maintain on the tab. Using Organization Management is also based on the scheduling of report PFCG_TIME_DEPENDENCY. This report updates all indirect user assignments. This means that it inserts into the role all indirectly assigned users who are now valid due to the assignment period, and removes all indirectly assigned users that have become invalid. It then compares the user master records for all roles. The status display of Org. Management (green or red) indicates whether or not you have to update the indirect user assignments. If the display is red, the indirectly assigned users are not displayed completely on the tab. In this case, you need to compare them using Org. Management. If you periodically schedule report PFCG_TIME_DEPENDENCY, the system compares the roles automatically. The indirectly assigned users are also updated automatically when you compare the user master records manually. If you are not using indirect assignment of users to roles, you can ignore the status display for Org. Management. The system only displays this pushbutton if you have defined an active plan variant in the current client, the prerequisite fir using Organization Management. If you have not defined this active plan variant, you cannot see Org. Management . Otherwise, you should choose "Full view" at the start of the transaction.

When using composite roles, note: o Users assigned to a composite role are grayed out (cannot be changed) in the included roles. Users should only be changed in the composite role. If a user master comparison of the composite role is performed, this affects all roles included in the composite role.

Comparing user master records o The user master record comparison that is run automatically by

report PFCG_TIME_DEPENDENCY can also be executed manually for a single role. To do this, choose Compare users on the Users tab. The status display on this pushbutton indicates whether or not you need to execute the comparison again.

This compares the authorization profiles with the user master records, that is, profiles that are no longer current are removed from the user master records, and the current profiles are entered.

Additional information about comparing user master records: You can also compare the user master records automatically when you save the role. To do this, choose Utilities -> Settings and choose the option to compare the user master records automatically when you save the role. If you select the option to compare the user master records automatically when saving, this may increase the time required to save.

If you ma e changes to the users assigned to the role or generate a corresponding authorization profile, then you need to compare the user master records again.

Vous aimerez peut-être aussi