SAP Knowledge Base Article - Public

3637336 - Access Restrictions for Accounts is not Working As Expected

Symptom

You have restricted read/write access on certain company(account) for Accounts for the user, but the user can still access to Account which he/she has no access rights.

Environment

SAP Business ByDesign

Reproducing the Issue

  1. Go to Application and User Management work center-> Business Users view.
  2. Select the user and Edit Access Rights.
  3. Navigate to Access Restrictions tab.
  4. Access is restricted for Account work center view on certain company(account).
  5. Login system with the user ID.
  6. The user can access to company(account) which he/she has no access.

Cause

This behavior is due to the access restriction being set with Access Context 1010 – Employee. It is important to note that Access Context 1010 enforces restrictions based solely on the Employee Responsible field. Even if organizational or company assignments exist, they are not considered in this access context. Hence if there is no Employee Responsible is maintained for the company(account), the system treats these records as unrestricted for users with access context 1010, allowing the users to access them.

Resolution

You need to maintain the Employee Responsible for the company(account).

See Also

Account Restriction is not Working for Employee

Keywords

BPM Accounts, Account Restrictions, Employee Responsible , KBA , SRD-CC-IAM , Identity & Access Management , SRD-CRM-ACC , Account Management , Problem

Product

SAP Business ByDesign 2505