Symptom
- When maintaining a write restriction for account types A (Assets), D (Customers), K (Suppliers) and/or M (Material) users still have authorizations to post to S (G/L Accounts).
- The write restriction for account type S (G/L Accounts) does not work.
- Error message F5 084 (You have no authorization for posting to &1) is not prompted for account type S (G/L Accounts).
"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."
Environment
SAP S/4HANA Cloud Public Edition
Reproducing the Issue
- Maintain Business Roles.
- Create a copy or similar role to the SAP_BR_GL_ACCOUNTANT role.
- Maintain Restrictions.
- Write restriction for "Account Type".
- Maintain a restriction for either A (Assets), D (Customers), K (Suppliers) and/or M (Material).
- Save the role and assign this to a user.
- The user has the possibility to post and revers to "Account Type" S (G/L Accounts) despite this restriction object not being maintained for write.
Cause
Account Type = S (G/L Account) is special because all S-lines are included basically in every accounting document. If the posting or reversal of a document containing A, D, K or M would check also write access for Account Type = S, then the write access to Account Type = S must be always granted.
The corresponding or offsetting items to A, D, K or M account type involve S account type.
For example;
In Journal Entry 100000165 the D (Customer) Line Items 000002, 000003, 000004.
The Offsetting Account is S (G/L Accounts) Line Item 000001.
If there was an S restriction the posting to these D account types would not work due to the offsetting account.
Resolution
The main purpose of the Account Type S (G/L Accounts) is for read restrictions. If A, K, D or M is maintained the users will have the possibility to write to S. It does not make sense to have a write restriction on S as all postings will involve such accounts. The system in this case is working as designed.
See Also
Keywords
IAM, Access, posting, KOART, AUTHORITY_ACCOUNT_TYPE, F5084, F5 084, Authorization, Authorisation, Authority, restrict, access, , KBA , FI-FIO-GL-2CL , Fiori UI for General Ledger Accounting (Public Cloud) , BC-SRV-APS-IAM , Identity and Access Management , FI-GL-GL-A-2CL , Posting/Clearing (Public Cloud) , FI-FIO-AR-TRA-2CL , Transaction Apps: Public Cloud , FI-FIO-AP-2CL , Fiori UI for Accounts Payable (Public Cloud) , Problem
SAP Knowledge Base Article - Public