You can configure objects in the Objects by Class tab at the field and value level, or authorization level. You can add objects to a role, but you can only delete an authorization within the object.
When you select Object by Class tab, you can perform the actions listed in the following table:
Object By Class Button |
Function |
---|---|
Save |
Saves the role and moves to the next phase of the role creation. |
Back to Role Definition |
Reverts to the previous phase of the role creation. |
Org. Levels |
Displays the organizational level fields in the role. |
Add Object |
Opens a search screen where you can search for one or more objects. When you select Continue, you return to the Authorization Data screen where you can then update the fields within the authorization object. |
Use this feature to leverage advanced role authorization maintenance features in PFCG. This feature enables both functional and technical teams to work together in role management. To run PFCG, you need proper authorization in the back end ABAP system.
Consider the following when you manage roles in PFCG:
You can manage authorization data in PFCG.
You must save the data to synchronize changes to Enterprise Role Management.
Menu and authorizations data are synchronized, but description and user data should not be synchronized
After you save the data in PFCG, choose Synchronize Authorization Data to synchronize the data with Enterprise Role Management.
Choose the Objects by Class tab and then expand each class.
Expand each object to its field level to:
Note the authorizations that are fully configured
Add authorizations to objects
Add values to authorizations
Copy and edit authorization values
Delete authorization values
View and add notes to authorizations
Icon or Term |
Description |
---|---|
Green Stoplight icon |
The green light indicates that every field in the authorization has a value. |
Yellow Stoplight icon |
The yellow light indicates that there is at least one empty field in the authorization. |
Red Stoplight icon |
The red light indicates that there is no value in the Org. Level field, or that the existing value is not representative of an appropriate value. |
Copy icon |
Copy the authorization. When you copy an authorization, the system copies all fields and values that belong to that authorization. The copied authorization values appear below the original. The two values have different authorization ID numbers. |
Add icon |
Add an authorization value. To add a value to the authorization, click this icon. Add the new value in the field that appears. |
Delete icon |
Delete an authorization value. To delete a specific value, select the checkbox next to the value. Choose the Delete icon. |
Shiny Lightbulb icon |
Authorization is enabled. Select this icon to disable the authorization. |
Dead Lightbulb icon |
Authorization is disabled. When an authorization is disabled, the role ignores the value. Choose this icon to enable the authorization. |
Information icon |
Select this icon to add, view, or change information about the authorization. |
Standard |
The authorization contains default values. The transaction code automatically pulls in the values. |
Maintained |
The authorization contains user-modified values. |
Manually |
The authorization contains values manually added by the user. |