Transcription of How to Define Authorizations
1 How To GuideSAP Business OneDocument Version: 2019-10-30 PUBLICHow to Define AuthorizationsApplicable Release: SAP Business One and SAP Business One ,version for SAP HANA2 PUBLIC 2019 SAP SE. All rights to Define AuthorizationsTypographic ConventionsTypographic ConventionsType StyleDescriptionExampleWords or characters quoted from the screen. These include field names, screen titles,pushbuttons labels, menu names, menu paths, and menu cross-references to other words or names of system objects. These include report names, program names,transaction codes, table names, and key concepts of a programming language when theyare surrounded by body text, for example, SELECT and on the screen. This includes file and directory names and their paths, messages,names of variables and parameters, source text, and names of installation, upgrade anddatabase user entry.
2 These are words or characters that you enter in the system exactly asthey appear in the documentation.<Example>Variable user entry. Angle brackets indicate that you replace these words and characterswith appropriate entries to make entries in the on the keyboard, for example,F2 to Define AuthorizationsDocument HistoryPUBLIC 2019 SAP SE. All rights UDFs were added to theDetermination Criteria - Inventory window The screenshot of windowDetermination Criteria- Inventory wasupdated in section Screenshot and information were updated in section Updates and corrections from Chapter 2 to Chapter 20 Added steps for setting up Authorizations for system queries4 Error! Reference source not 2019 SAP SE. All rights to Define AuthorizationsTable of ContentsTable of Contents1 Introduction .. 62 Authorizations Window .. for Users .. for User Groups.
3 authorization Profiles from One User to Another .. 9 How to Define AuthorizationsTable of ContentsPUBLIC 2019 SAP SE. All rights Authorizations .. 114 Customization Tool Authorizations .. 195 Administration Module Authorizations .. 216 Financials Module Authorizations .. 487 Opportunities Module Authorizations .. 628 Sales A/R Module Authorizations .. 649 Purchasing A/P Module 7410 Business Partners Module Authorizations .. 7911 Banking Module Authorizations ..8512 Inventory Module Authorizations .. 9213 Resources Module Authorizations .. 10614 Production Module Authorizations .. 10715 MRP Module Authorizations .. 11016 Service Module Authorizations .. 11117 Human Resources Module Authorizations .. 11518 Project Management Module 11719 Reports Module Authorizations ..11820 Cockpit & Widget Authorizations .. 12521 User Authorizations .. 12822 System Queries Authorizations .
4 1296 PUBLIC 2019 SAP SE. All rights to Define AuthorizationsIntroduction1 IntroductionThis document provides information about the authorization settings in theAuthorizations window in SAPB usiness One. For more information about the authorization function, see the online help for SAP Business theAuthorizations window, you can determine the required Authorizations for the users and user groups in can also grant Authorizations for creating, updating, and deleting documents in theData OwnershipAuthorizations window. Only a user defined asSuperuser (Administration Setup General Users Setup)can access theAuthorizationssubmenu and grant Authorizations for other user defined asSuperuser has full authorization to all SAP Business One modules and functions and it is notpossible to modify the Authorizations for this a module, when different components have different Authorizations , the module authorization is displayedasVarious Authorizations .
5 For example, in theSales module, if you haveFull authorization for the sales quotation,butNo authorization for the sales order,Sales is displayed asVarious document relates to aProfessional User license. Other license types have a fixed set of to Define AuthorizationsAuthorizations WindowPUBLIC 2019 SAP SE. All rights WindowThe main pane of theAuthorizations window contains a list of modules and functions. To expand its content, clicknext to a module or a function column to the right of the function names displays the authorization type granted for the module, window,function, or action. NoteIn theAuthorizations window, the functions appear in a hierarchical structure. The Expand icon ( ) in arow indicates that the function contains additional functions at a lower level. The Authorizations set at thehigher level apply to all its lower level functions.
6 To set each lower level function individually, click toexpand the hierarchy and set the Authorizations for the specific open theAuthorizations window, proceed as follows:From the SAP Business OneMain Menu, chooseAdministration System Initialization Authorizations General can Define the Authorizations for either an individual user, or a group of users withAuthorization group for UsersTo Define Authorizations for a user, select the user on theUsers tab on the left side of the window,8 PUBLIC 2019 SAP SE. All rights to Define AuthorizationsAuthorizations WindowDefining authorization Profiles for a Certain UserIn theAuthorization column, select one of the following options for the corresponding subject displayed in theSubject column: Full authorization : grant full Authorizations to the user for the subject Read-Only: the user can display all data of the subject but cannot make any changes to it No authorization : the user is unable to display or change any data of the subjectEffective authorization for a UserThis column displays the resultant authorization that the current user has over the subject.
7 It is the highest level ofauthorization that is applied to the user considering the authorization defined for it and the user group or groups itbelongs to. ExampleUser U0001 is assigned to User group A and User group B. For a particular permission subject:oU0001 authorization = Read-OnlyoUser group A authorization = FulloUser group B authorization = No AuthorizationAs a result, the effective authorization = Full NoteThe Authorizations at the window level have the highest priority over those at the field, tab or other sub-levels. When a specific window is inaccessible to a user, the user cannot access any elements of thewindow, unless the user has the authorization of an authorized user and can provide credentials of theauthorized user inthe Permission override window that pops for User GroupsTo Define Authorizations for a user group , select a user group on theGroups tab on the left side of the window,How to Define AuthorizationsAuthorizations WindowPUBLIC 2019 SAP SE.
8 All rights authorization Profiles for a User GroupIn theAuthorization column, select one of the following options for the corresponding subject displayed in theSubject column: Full authorization : grant full Authorizations to all users in the group for the subject Read-Only: all users in the group can display all data of the subject but cannot make any changes to it No authorization : all users in the group are unable to display or change any data of the authorization Profiles from One User to AnotherAfter defining the general Authorizations for a certain use, you can copy his or her authorization profile to that the users are already defined in the company. NoteFor more about defining users see the online helpProcedureTo copy Authorizations to multiple theAuthorizations window, on the left side, select a user who has the Authorizations that you want to 2019 SAP SE.
9 All rights to Define AuthorizationsAuthorizations Window NoteTo check the Authorizations for specific users, select a user and in theAuthorization column, thepermissions for the selected user are and drop the user name onto the name of the user to whom you want to copy the theSystem Message window, choose theUpdate button, then choose theOK second user now has the same Authorizations as the following behavior applies when changing Authorizations in SAP Business One: When you change the authorization of a parent article, for example, fromNo authorization toFullAuthorization, the change is applied automatically to all the child Authorizations below it. If you change the parent article toRead Only, and one or more of the child Authorizations do not include theRead Only option, this child authorization is set with the valueNo authorization . When you change an authorization that has a parent article, and that parent article represents an applicationwindow (for example, the authorization for theBusiness Partner Master Data window underBusiness Partnersin the Authorizations tree), the parent article is not influenced and retains the same authorization it hadbefore the child authorization was changed.
10 When you change an authorization that has a parent article, and that parent article represents a menu entry inSAP Business One, but with no application window (for example,Setup, underAdministration in theAuthorizations tree) the following behavior applies:oIf after the change of the child authorization , the values of the child Authorizations below the specificparent article vary (for example, one child authorization is set toNo authorization and the other is set toFull authorization ), the parent article is set with the valueVarious after the change of the child authorization , all of the child Authorizations of a specific parent article areset to the same value, the parent article is set to that value as to Define AuthorizationsGeneral AuthorizationsPUBLIC 2019 SAP SE. All rights AuthorizationsThe following modules and functions Define theGeneral Authorizations :Field NameDescriptionGeneral Full authorization Users can enter allGeneralfunctions andmake required changes or new settings.