Show TOC

PD: Creating authorization profiles

Description

This new function facilitates the administration of authority structures. This depends on the company organizational structure and the existence of the relevant positions (object type S).

There are two new infotypes for this new functionality: (1016 - standard profiles and 1017 - PD profiles). These can be appended to

A program then collects the information from the infotypes in the structure (bottom up) i.e. task --> job --> position --> organizational unit and automatically completes the table 'user authorizations'.

Changes in procedure

1. Description of infotype 1016 - standard profiles

You can append existing SAP R/3 authorization profiles to objects with this infotype. It is possible to assign several profiles to an object.
The profiles linked with org.units, jobs, positions or tasks are
automatically applied to all employees who work for the org.unit, who
perform the job, position or task.
It is also possible to append more than one authority profile to an
object, with the different profiles valid at different points of time.
This can be useful for an organizational unit that employs seasonal staff, for instance.

2. Description of infotype 1017 PD Profiles

In addition to the SAP authorization profiles, PD customers need the structural authority profiles from table "definition of authorization profiles". The PD profiles infotype allows you to create and maintain profiles that pertain specifically to PD. You must maintain this
infotype if you want to work with PD. However, you must also use the
standard profiles infotype to enter basic authority privileges.
A PD profile contains a list of authorizations, and the list is
unlimited. The profiles define what PD users can see and what actions
PD users can undertake when working with organizational plans.

3. Procedure

Decide which object types or objects should have which authorizations.

There are several possible ways to append profiles: