Symptom
A business user without write access to the Supplier Master Data work center (BPM_SUPPLIERS) is able to modify Supplier master data fields (e.g., email address in the General tab) successfully. No error is raised, even though access restrictions are defined as "No Access" for the user.
Environment
SAP Business ByDesign.
Reproducing the Issue
Making a change and saving in Supplier master data:
- Go to the Business Partner Data or Supplier Base work center.
- Go to the Suppliers view.
- Find the Supplier ID and click Edit -> General.
- Make a change to the E-Mail field.
- Click Save.
System saved the change successfully (no error message raised).
Checking access rights for User:
- Go to the Application and User Management work center.
- Go to the User and Access Management -> Business Users view.
- Find the User ID ABC (ABC is the User ID).
- Click Edit -> Access Rights.
- Open the Access Restrictions tab.
- Find the Work Center View ID BPM_SUPPLIERS.
Notice that Write Access is defined as No Access, so expectation is that system wouldn't have allowed a change in Payment Terms for Supplier DEF, but raised an error message instead.
Cause
The user was not assigned to any valid Organizational Management unit. Because of this missing assignment, the system could not apply access restrictions properly.
Resolution
Ensure that the user is assigned to the correct Organizational Management unit in the system. After updating the Organizational assignment, verify access control behavior by attempting to edit Supplier master data.
Keywords
User Access, Supplier Master Data, BPM_SUPPLIERS, Write Access, No Access, Business User, Access Restrictions, Organizational Management, Access Control, Unauthorized Edit, Supplier Base. , KBA , SRD-CC-IAM , Identity & Access Management , Problem
SAP Knowledge Base Article - Public