Question:
I know that this has been asked and answered quite a lot, But any tips/help would be appreciated.
I am trying to set up an auth grp for a gl account
1.I have added the Auth grp value to one accout
2.I have added Auth grp val to Auth obj in table TBRG
F_BKPF_BES and F_SKA_BES
3.I have checked SU24 for trans FB03 and added F_SKA_BES, F_BKPF_BES was already there.
4.Created a role with just FB03 and made F_BKPF_BES and F_SKA_BES have auth grp value created earlier.
I hoped this would work but obviuosly I'm missing something.
I can still see everything not just that 1 account.
If auth grp is blank in all other accounts
1.I should see only the auth grp I have selected??
or
2.I will still see everything because all accounts must now have a value in auth grp????
I'm a bit confused
Answer:
Ok I think I have found the answer.
You have to make auth group a mandatory field so it gets populated, as leaving it blank seems to be a wild card and then all accounts show up when using FB03.
Answer:
yes, if auth group is blank it will pass the check regardless. If you are going to use auth groups, best put them on all the accounts