Symptom
- The error "Restriction Type HRYTYPE_HRYID_OH is not valid for business role" occurs when attempting to remove the business catalog SAP_FIN_BC_GL_AUDIT_PC from a business role and saving changes.
- The error "Restriction Type HRYTYPE_HRYID_DV is not valid for business role" occurs when attempting to remove the business catalog SAP_FIN_BC_GL_AUDIT_PC from a business role and saving changes.
Environment
SAP S/4HANA Cloud Public Edition
Reproducing the Issue
- Open the Maintain Business Roles app.
- Open the affected business role.
- Remove the business catalog SAP_FIN_BC_GL_AUDIT_PC.
- Save the role.
- Observe the error as "Restriction Type HRYTYPE_HRYID_XX is not valid for business role"
Cause
A hierarchy restriction combination (HRYTYPE_HRYID_OH and HRYTYPE_HRYID_DV) in the role requires intermediate IAM apps to be present. When these IAM apps are not directly assigned to the business role, the validation fails during save.
Resolution
A permanent fix is currently under development and is planned for delivery with Hotfix Collection 03 (HFC03) for SAP S/4HANA Cloud Public Edition 2608.
As a workaround, assign F3161_03_TRAN as well directly to the business role (the "Filter assigned IAM Apps" needs to be deactivated in the value help for adding IAM Apps).
Steps to follow :
- Add the "F3516_03_TRAN" IAM app directly to the business role.
- Add the "F3161_03_TRAN" IAM app directly to the business role.
- Remove the "SAP_FIN_BC_GL_AUDIT_PC" business catalog from the business role.
- Save the business role.
The business role should now be saved successfully.
Keywords
HRYTYPE_HRYID_DV, HRYTYPE_HRYID_OH, restriction type not valid, business role, remove catalog, SAP_FIN_BC_GL_AUDIT_PC, IAM app, F3516_03_TRAN, F3161_03_TRAN, maintain business roles, identity and access management, authorization, hierarchy restriction, error message , KBA , BC-SRV-APS-IAM , Identity and Access Management , Known Error
SAP Knowledge Base Article - Public