Show TOC

Creating Authorization RolesLocate this document in the navigation structure

Use

You can create a new authorization role in the SAP system with the Create/Convert Role function.

Prerequisites

To monitor and maintain the data transferred from the portal to the SAP system you need role administration authorization (see Authorizations ).

Procedure

To create a new authorization role:

  1. Start transaction WP3R.

    The initial screen for role administration, Follow-Up Processes for Portal Roles , appears.

  2. On the initial screen, select Maintain Authorization Roles and run the program.

    A report is displayed containing all portal roles and the authorization roles associated with them. Roles transferred from the portal are highlighted in blue. The warning icon allows you to identify that there are no authorization roles for these roles.

    Caution

    If a role is highlighted in red, it has been deleted in the portal.

  3. To find out which services there are for a role, expand the structure of the relevant role, select a logical system, and choose Start of the navigation path Goto Next navigation step Service list End of the navigation path or Service List.

    If SAP Enterprise Portal has transferred services that are not supported in the current system, these are displayed in a separate section of the service list and ignored when the services are transferred to the authorization role.

  4. To close the window with the service list, choose Continue .

  5. Click the logical system and choose Start of the navigation path Authorization role Next navigation step Create/Convert End of the navigation path or choose Create/Convert icon next to the logical system.

    The system asks for the name of the new role. If you enter a name for which there is no role to date, the system creates a new one. You can also create more than one authorization role per logical system, depending on how many authorization versions you require.

    If you enter the name of an existing role, the system informs you that you can convert this role to an authorization role. The conversion can only take place if you enter the name of a root single role (not a derived role or a composite role).

    Caution

    When converting an existing role to an authorization role, the system assumes that the structure of the role is defined forthwith through the enterprise portal and role assignment is only assigned through the enterprise portal. During conversion, a dialog box points out the consequences.

    The services of the portal role are immediately transferred to the menu structure of the new role. You can also use the Create/Convert function for authorization roles. It can be used to create derived authorization roles.

    Note

    A warning is given if no authorization roles were yet created for the services of a portal role for a logical system.