Quantcast
Channel: SCN : Discussion List - Security
Viewing all articles
Browse latest Browse all 2353

Field values for Authorization object assignment

$
0
0

Dear Experts,

 

I am trying to understand how SAP behaves when there are conflicting field values are provided when accessing a T.Code.

 

For instance, i am trying to evaluate users having access to T.Code VA01 (Create Sales order).

 

As i understand, BOTH the below authorization objects are required to access VA01.

a) V_VBAK_AAT - Sales Document: Authorization for Sales Document Types

b) V_VBAK_VKO - Sales Document: Authorization for Sales Areas

 

I have a scenario, where the first aurhorization object (V_VBAK_AAT) has been given ACTVT value of 01 (Create), but the second authorization object V_VBAK_VKO has been given ACTVT value of 03 (Display)

 

In the above scenario, would be user be able to create sales order through VA01 ? 

 

My understanding is, since the user has "Create" access to Sales document type, but only "Display" access to sales area, the user would NOT be able to create a sales order.

 

Kindly advise.

 

Thanks !

Uday


Viewing all articles
Browse latest Browse all 2353

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>