SAP Knowledge Base Article - Public

3444717 - User Able to Change Data In Supplier Master Data Even With No Write Access to Work Center View ID BPM_SUPPLIERSFIN

Symptom

User ID ABC was able to change and save data in Supplier Master Data for Supplier ID DEF (for example, Payment Terms in Purchasing tab) even with Write Access defined as No Access to Work Center View ID BPM_SUPPLIERSFIN.

ABC stands for the User ID.

DEF stands for the Supplier ID.

Environment

SAP Business ByDesign

Reproducing the Issue

A) Making a change and saving in supplier master data:

  1. Go to the Supplier Base work center.
  2. Go to the Suppliers view.
  3. Find Supplier ID DEF and click Edit -> Purchasing.
  4. Make a change to the Payment Terms.
  5. Click Save.

System saved the change successfully (no error message raised).

B) Checking access rights for User:

  1. Go to the Application and User Management work center.
  2. Go to the User and Access Management -> Business Users view.
  3. Find User ID ABC.
  4. Click Edit -> Access Rights.
  5. Open Access Restrictions tab.
  6. Find Work Center View ID BPM_SUPPLIERSFIN.
  7. Notice that Write Access is defined as No Access, so your expectation is that system wouldn't have allowed a change in Payment Terms for Supplier DEF, but raised an error message instead.

Cause

The write access to the Supplier Master Data is determined not only by Work Center View ID BPM_SUPPLIERSFIN, but for the following additional Work Center View IDs (considering they are all Assigned to User in tab Work Center and View Assignment):

BPM_SUPPLIERS

BPM_SUPPLIERSCENTRAL

FIN_SUPPLIERACCOUNTS

Resolution

Only by defining Write Access as No Access for the four Work Center View IDs below the system will deny the edition/saving of changes in supplier master data, by throwing the errors:

"You are not authorized to change the data"

"Save could not be executed"

BPM_SUPPLIERSFIN

BPM_SUPPLIERS

BPM_SUPPLIERSCENTRAL

FIN_SUPPLIERACCOUNTS

Keywords

BPM_SUPPLIERSFIN; BPM_SUPPLIERS; BPM_SUPPLIERSCENTRAL; FIN_SUPPLIERACCOUNTS; IAM; write access; no access; supplier master data , KBA , SRD-CC-IAM , Identity & Access Management , How To

Product

SAP Business ByDesign all versions