SAP Knowledge Base Article - Public

3698467 - Write restriction for Account Type S does not work

Symptom

  • When maintaining a write restriction for account types A (Assets), D (Customers), K (Suppliers) and/or M (Material) users still have authorizations to post to S (G/L Accounts).
  • The write restriction for account type S (G/L Accounts) does not work. 
  • Error message F5 084 (You have no authorization for posting to &1) is not prompted for account type S (G/L Accounts).

"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."  

Environment

SAP S/4HANA Cloud Public Edition 

Reproducing the Issue

  1. Maintain Business Roles.
  2. Create a copy or similar role to the SAP_BR_GL_ACCOUNTANT role.
  3. Maintain Restrictions.
  4. Write restriction for "Account Type".
  5. Maintain a restriction for either A (Assets), D (Customers), K (Suppliers) and/or M (Material).
  6. Save the role and assign this to a user.
  7. The user has the possibility to post and revers to "Account Type" S (G/L Accounts) despite this restriction object not being maintained for write.

Cause

Account Type = S (G/L Account) is special because all S-lines are included basically in every accounting document. If the posting or reversal of a document containing A, D, K or M would check also write access for Account Type = S, then the write access to Account Type = S must be always granted.

The corresponding or offsetting items to A, D, K or M account type involve S account type.  

For example;

In Journal Entry 100000165 the D (Customer) Line Items 000002, 000003, 000004.

The Offsetting Account is S (G/L Accounts) Line Item 000001.  

If there was an S restriction the posting to these D account types would not work due to the offsetting account. 

 

Resolution

The main purpose of the Account Type S (G/L Accounts) is for read restrictions. If A, K, D or M is maintained the users will have the possibility to write to S.  It does not make sense to have a write restriction on S as all postings will involve such accounts.  The system in this case is working as designed.

See Also

Maintain Business Users

Keywords

IAM, Access, posting, KOART, AUTHORITY_ACCOUNT_TYPE, F5084, F5 084, Authorization, Authorisation, Authority, restrict, access,  , KBA , FI-FIO-GL-2CL , Fiori UI for General Ledger Accounting (Public Cloud) , BC-SRV-APS-IAM , Identity and Access Management , FI-GL-GL-A-2CL , Posting/Clearing (Public Cloud) , FI-FIO-AR-TRA-2CL , Transaction Apps: Public Cloud , FI-FIO-AP-2CL , Fiori UI for Accounts Payable (Public Cloud) , Problem

Product

SAP S/4HANA Cloud Public Edition all versions