0% found this document useful (0 votes)
334 views2 pages

Backend Roles For SAP BPC & Managing User F..

Backend Roles
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
334 views2 pages

Backend Roles For SAP BPC & Managing User F..

Backend Roles
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 2

13/05/2015

BackendRolesforSAPBPC&ManagingUserf...|SCN

GettingStarted Newsletters

Hi,Guest

LogOn

JoinUs

Products

Services&Support

AboutSCN

Downloads

Industries

Training&Education

Partnership

DeveloperCenter

Activity

LinesofBusiness

UniversityAlliances

Events&Webinars

Innovation

Browse

BackendRolesforSAPBPC&Managing
UserfromBackendSystem

Store

SearchtheCommunity

Communications

Actions

Version1

createdbyHarikrishnanKMohananonJan22,20149:04AM,lastmodifiedbyHarikrishnanKMohananonJan22,20149:19AM

Share

14

Tweet

Like

SAPBusinessPlanningandConsolidationispartofSAPNetWeaverandhasadifferentauthorizationconceptfrom
SAPR/3orECC.IthasbothfrontendandbackendviewsandusesUserTeams,TaskProfiles&DataAccessProfiles
insteadofUserGroups,Transactions&Roles.

WheneverykindofUserAdministrationisdoneinthefrontendBPC(UserAddition,TaskProfile&DataAccessProfile
creation),wecannotcreateanewusertotheBPCfrontendsystem,butaddauserwhoispresentintheECCbackend
system.Thatmeans,theusershouldbecreatedfirstinthebackendandthenonlyhe/shebeavailabletoaddinthe
frontendsystem.

Also, for the user to access BPC frontend from Web Login, two mandatory roles should be assigned to the users
accountinthebackend!(Giveninbelowtable).

Intheabovetwocontexts,whenauseraccountshouldbecreatedandassignedwithtwomandatoryroles,wecan
avoidtheuseoffrontendsystemforgivingaccesstoauser(atleastforthefirsttime,aswealreadyneedtoeditthe
userfromSU01),byaddingallthenecessaryrolesinonego!Howitisdone?

Usually,whenwecreateanEnvironment,UserTeam,DataAccessProfileandTaskProfilefromBPCfrontend,aroleis
createdinthebackendsystemautomatically.Foradministratinguserfromthebackend,whatwehavetodoisidentify
theseautomaticallycreatedroles.Forthis,wehavesometableswhichmaintainthesedata.

FromSE16,accessthefollowingtablestogetthedata:

i. Environment:TofindouttherolerelatedtoeachEnvironment,gototableUJE_USER_AGR.Here,youcansee
the environment name under APPSET_ID and the corresponding role under USER_AGR. The role will be
startingwithZBPC_##UXXXXXX.Udenotesenvironment.
ii. UserTeam:TofindouttherolerelatedtoeachUserTeam,gototableUJE_TEAM_AGR.Here,youcanseeall
theteamscreatedinalltheenvironmentsavailableinthesystem(youcanfiltertheenvironmentfromthefirst
pageifrequired),andtherolecorrespondingtoeachteamsandteamleaders.Therolewillbesimilartothe
above,ieZBPC_##TXXXXXXfor team and ZBPC_##LXXXXXX for team leader. T denotes User Team and L
denotesTeamleader.
iii. TaskProfile&DataAccessProfile:TofindouttherolerelatedtoeachTaskProfileandDataAccessProfile,go
to table UJE_PROFILE_AGR. Here, you can see the Profile Name under PROFILE_ID, PROFILE_CLASS
contains the type of profile (MBR for Data Access Profile & TSK for Task Profile), and the corresponding role
name under PROFILE_AGR. The role will be like ZBPC_##MXXXXXX for Data Access Profile and
ZBPC_##PXXXXXX. Here M denotes Data Access Profile (referred to as Member Access Profile in earlier
versions)andPdenotesTaskProfile.
Now,letuslookintotherolenamingconventionhere:
ZBPC_:Commonforallroles.
##:ItistheAPPSET(Environment)Prefix,whichisspecifictoeachenvironment.Thiscanbefoundoutfrom
thetableUJA_APPSET_INFO.
U/T/L/M/P:DenotesEnvironment,Team,TeamLeader,DataAccessProfileandTaskProfilerespectively.
XXXXXX:Thisisthenumber.(ThisnumberwillbeinsequenceforEnvironment,Team,etc.)

Theserolescanbefoundoutfromtheabovetablesandaddedtotheuserssothatthefrontendadministrationcanbe
avoided.Sointheendauserwhowantstologinthroughweb,whoisassignedwithaDataAccessProfileandTask
ProfileandaUserTeaminanenvironmentwill(should)havethefollowingrolesassignedtohisprofile.

/POA/BUI_FLEX_CLIENT

RoleforWeblogin

/POA/BUI_UM_USER

RoleforWeblogin

ZBPC_CMU000002

EnvironmentRole

ZBPC_CMT000027

UserTeamRole

ZBPC_CMP000009

TaskProfileRole

ZBPC_CMM000014

DataAccessProfileRole

http://scn.sap.com/docs/DOC51460

1/2

13/05/2015

BackendRolesforSAPBPC&ManagingUserf...|SCN

Note:IfwehaveaddedaTaskProfile&aDataAccessProfileoaUserTeamfromfrontend,andaddedonlytheUser
Teamroleinthebackendforauser,theuserwillnothaveaccesstotheTaskProfileandDataAccessProfile.These
tworolesshouldbeaddedexplicitly!

Hopeithelps!

4261Views

AverageUserRating
(1rating)

Share

14

Tweet

2 Like

4Comments
JidhinBalanJan22,201411:36AM

Thanksforthedocument!Verymuchuseful!
Like(0)

PadeepMoluguFeb18,20146:37AM

Verywelldocumentedinformation...
Like(0)

HarikrishnanKMohananFeb21,20149:22AM(inresponsetoPadeepMolugu)

ThanksPadeepforfindingsometimetoreadthis.!
Like(0)

RidwansyahRidwansyahApr21,201411:31AM

Clearexplanation.ThanksHari
Like(0)

SiteIndex
Privacy

ContactUs
TermsofUse

http://scn.sap.com/docs/DOC51460

SAPHelpPortal
LegalDisclosure

Copyright

FollowSCN

2/2

You might also like

pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy