cancel
Showing results for 
Search instead for 
Did you mean: 

Limiting the Report Layout access other than Authorization Object S_ALV_LAYO

Former Member
0 Kudos

Dear Experts,

We have an issue of Layout Access limit to Users coz unwittingly these are being deleted.

(Example: IW39 à after F8 à Settings à Layout.)

The Authorization object S_ALV_LAYO which limits the access, has been defined in the multiple Roles, where every User been assigned with these Roles across Three Continents.

Instead of hampering the existing Streamlined Roles, looking for other Options since if it may give odd behaviour after modifying the Roles then all the Users across the continents will be effected.

It will be grateful if we get other options to limit the Layout access instead of controlling through Authorization Object.

Thank you & Have a Great Day!

Accepted Solutions (0)

Answers (3)

Answers (3)

Joerg_S
Participant
0 Kudos

Hi Jithendar,

in SU24 SAP has set S_ALV_LAYO (ACTVT=23) as "Default" for many transactions. So if you create or change a role in PFCG the object will be added to the profile during generation automatically. We changed the setting in SU24, so now the S_ALV_LAYO has been "erased" from all roles after generation of the profiles.

To limit access for user on changing default ALV-Layouts this is one step possible.

You could also have a look to a newly delivered object from SAP: S_ALV_LAYR
Here you have more option to limit access for the users (ACTVT + PROGRAMM)

regards

Jörg

MTerence
Active Contributor
0 Kudos

Hi Jithendar,

We had a similar issue with our client. We created a Z object similar to S_ALV_LAYO, where there is no access to set Default Layout. User will be forced to check the User Layout and save.

Access to S_ALV_LAYO was provided to limited roles and remaining roles will hold the Z object.

Regards

Terence

Former Member
0 Kudos

Thank you Sebastian & Terence,

The Global Roles has maintained with Authorization Object (S_LAYO_ALV) and these are been assigned to Every User coz all Users should access these reports.

So now every User has maintained with the Authorization Object to access.

Now we are trying to Control the Access to limited Users through without hampering the well maintained/streamlined  Roles, since if any adverse effects on the modified roles may impact to all the Users across the continents.

Looking for other options.

Thanks, I appreciate your time and efforts on this.

MTerence
Active Contributor
0 Kudos

Hi Jithendar,

We had the similar issue, since we have multiple countries involved.

We took the list of roles which needs access to change layout, we retained the access to these roles.

Remaining roles, we removed the object and assigned the custom object.

Yes, you are correct, this is very sensitive, but i dont see any options remaining. You can also contact SAP by raising the OSS note, whether there is any option to restrict.

Thanks

Terence

sebastian_lenartowicz
Active Contributor
0 Kudos

Greetings Jithendar,

I understand that your issue is with the uses changing the global (or even the default global) Layouts. But if you take the authorization in S_ALV_LAYO, they are still able to edit and save the user-specific settings.

So why reinvent the wheel? Grant S_LAYO_ALV to Super User & IT Support roles only