Quantcast
Channel: SCN: Message List
Viewing all articles
Browse latest Browse all 8902

Structural Authorization - Restrict Single Object

$
0
0

Hello,

Our company does not currently utilize structural authorizations across HR but we're exploring use of this functionality as a means to restrict user access to workflow agent responsibility setup via OOCU_RESP.  Standard security setup for this transaction does not provide the ability to restrict against a specific rule number.

 

My question is how to best configure this area to restrict access to a specific rule (object type AC) while not impacting other areas of HR access for the user.  Effectively I want the user to have all access provided under the delivered 'ALL' profile except when it pertains to object type AC which is restricted.

 

I have configured the profile as follows:

SeqPlan VersionObj TypeObj IDMaint
101AC90000001X
2**RYX
3**USX

 

Under this setting, assigned users are only able to modify rule 90000001 in OOCU_RESP - attempts against other rules are restricted as expected.  How can I enable access for all other object types?  A brute force approach would be to repeat rows 2/3 for all other object types in the system but this does not seem practical.  What would be the best way to meet the objective?  I am a longtime SAP consultant in many areas but have not done anything in HR so this area is new to me.  Appreciate thoughts from the HR gurus out there.

Regards,

Adam


Viewing all articles
Browse latest Browse all 8902

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>