13.12.10

SAP Note 13128 - General info on authorizations in Project System

Symptom:

You want to restrict user authorizations for the Project System or parts thereof.


Solution
This note refers to Release 2.2A and after. Apart from system
enhancements, especially object-related authorizations, it also applies
to Release 2.1
A knowledge of the general concept of authorization is assumed.

Object-related authorizations
-----------------------------
Authorization objects referring directly to application objects in the
Project System, such as project definitions or networks, can be found
in the Project System object class in authorization maintenance. These
generally refer to particular values for the object, such as the
controlling area, and an activity, such as time scheduling. For
further details, read the online documentation for the authorization
objects.

The authorization profile C_PS_ALL contains all the authorizations
for these authorization objects.

Authorizations for particular functions
---------------------------------------
As well as the object-related authorizations, you also need particular
authorizations for functions, which are used in other applications.
From Release 2.2B, the authorization objects for these functions are
also contained in the C_PS_ALL profile. The overview below shows
which authorization objects are checked in the respective areas.

General checks
Object class: Production planning
Object C_AFKO_ATY CIM: Typ zum PPS-Auftrag
For network processing, you need authorization
for order category 20.
Object C_AFKO_AWK CIM: Plan for order type in order
Object class: Production planning
Object C_ARPL_WRK CIM: Work center plant

Classification and summarization
Object class: Class system
Object C_TCLA_BKA Authorization for class types
--- Important ---
Every user who has authorization to change
WBS elements (activity 02) must also have
authorization for class type 014 (project
summarization).
Further objects Familiarize yourself in authorization
maintenance with the authorization objects for
the class system. It is particularly important
to have the appropriate authorizations if you
want to process user-defined attributes for
summarization purposes.

Assignment of customer order/material to the WBS
Object class: Sales and distribution
Object V_VBAK_VKO Sales document: authorization for sales
organization
Object V_VBAK_AAT Sales document: authorization for sales
document types

Cost planning
Object class: Controlling
Object K_CSKB_PLA CO: Cost element planning

Actual data entry:
Object class: Controlling
Object K_VRGNG CO: Activities, actual posting, and
plan/actual allocation

Information system
Object class: Cross-application authorization objects
For the cost information system, you need the
authorizations for the Report Writer

Object class: Production planning
Object C_KAPA_PLA CIM: Capacity planning
For the resource information system, you need
the authorizations for activity 16 (Execute)

Customizing
Object class Basis - Administration
Object S_NUMBER Number range maintenance
The following are provided for maintenance in
Customizing

Application object Number range object
------------------- -------------------
Network AUFTRAG
Library network ROUTING_0
Planning/budget BP_BELEG
Settlement CO_ABRECHN

The following numbers should be changeable only
in exceptional circumstances (resetting data,
repairs:

Application object Number range object
------------------- -------------------
Project definition PROJ
WBS element PRPS
PS texts PSTX

Object S_TABU_DIS Table maintenance (using standard tools such as
SM31)
The tables or view in Customizing are
summarized via an assignment table (TDDAT)
into maintenance authorization groups. This
maintenance authorization group is entered in
authorization maintenance as "Authorization
group".

You require the following values for Project
System customizing: , BCSV, BS, CA, CC, CP, CS, FC22, KC, KCA, KCB, KKA, KKB1, KKB2, KKK, MC, MCMD, SC, VC

For time units (authorization group SS), you
should restrict the change authorization to a
very few people. We recommend that you only
allow PS customizing to be displayed.

Note: In releases 2.2A-2.2H and 3.00 - 3.0D, the
profile C_PS_ALL, delivered by SAP, sill
contains the authorization for authorization
group PC. This is not required for
customizing. Remove this value from the
authorizations C_PS_CUST and C_PS_SHOW for
authorization group S_TABU_DIS.

Key word: PS authorization

No comments:

Post a Comment