Symptom
A Business User has been restricted to access certain objects, for example a Sales Order. However, the Business User can access restricted Sales Order via the Enterprise Search. The restrictions are working as expected per the work center view level.
Environment
SAP Cloud for Customer
Reproducing the Issue
- Ask the affected Business User to log in to the system.
- Go to the Sales workcenter.
- Go to the Sales Order view.
- Search for the Sales Order ABC (ABC represents the sales order ID) which the Business User should have no access.
- The Business User will not see the restricted Sales Order in the Overview Worklist (OWL).
- Click on the Enterprise Search and search for the same restricted Sales Order again.
- The restricted Sales Order will be shown as a result.
- Business user is now able to click on the link to open the Sales Order to which he should has no access.
Cause
The Business User is having access to the Sales Order ABC from sales organization 123 (123 represents the sales organization ID). From OWL, only My Sales Order is configured and that query shows only the Sales Order created by the Business User. Hence, the Sales Order ABC is not appearing. But in Enterprise Search, which every Sales Order from sales organization 123 that the Business User have access, everything will appear.
Resolution
In the current system version, Enterprise Search has the same restriction as the business object and it's not possible to add more restrictions there.
See Also
KBA 2594061 - Access Restriction Not Working For Enterprise Search
Keywords
Enterprise Search, Sales Orders, Sales, Business User, Access Restriction , KBA , LOD-LE-CQP-CO , Lean Sales Orders , How To