Symptom
A user with display-only access can create mappings in the app "Map FS Items with G/L Accounts" without revision.
The read-only catalog SAP_FIN_BC_CCON_READ_PC is assigned.
Created mapping identifiers are not shown in the overview list, but appear in the Mapping ID value help and in the assignment app.
No error message is displayed.
Environment
SAP S/4HANA Cloud Public Edition
Reproducing the Issue
- Ensure a user has display-only access with catalog SAP_FIN_BC_CCON_READ_PC.
- Log on with that user.
- Open the app Map FS Items with G/L Accounts.
- Choose Create Mapping, enter an ID and description, and untick With Revision.
- Save and observe that the mapping ID is created without a revision and appears in the Mapping ID value help.
Cause
An authorization check issue allowed display-only users to create mapping identifiers without a revision in the app.
Resolution
- A correction has been implemented by development and is planned for delivery with HFC05 for SAP S/4HANA Cloud Public Edition.
- Until the correction is available, verify that the affected user truly has display-only access by assigning only catalog SAP_FIN_BC_CCON_READ_PC for this scope.
- Ensure the user uses IAM app F3333_03_TRAN and that F3333_TRAN is not assigned.
- Clear the browser cache and retest in a private/incognito window.
- Note: No immediate hotfix is provided because creating a revision (the business-relevant action) is correctly blocked; a mapping ID without a revision cannot be used.
See Also
Keywords
map fs items with g/l accounts, display only, read only, create mapping without revision, mapping id created, value help, authorization check, sap_fin_bc_ccon_read_pc, group reporting, data preparation, f3333_03_tran, f3333_tran, s4hana cloud, fs item mapping, assign fs item mapping , KBA , FIN-CS-MD-2CL , Master Data (Public Cloud) , Known Error
SAP Knowledge Base Article - Public