SAP Knowledge Base Article - Public

1409766 - Journal Entry Voucher: User can post to a Company for which he's not allowed to post to

Symptom

A user is assigned to "General Ledger - Journal Entry Vouchers" Work Center View with restriction to a specific company e.q. 'MC10000' but still he is able to post to other companies.

Reproducing the Issue

  • Go to Application and User Management Work Center
  • Navigate to the Business User View
  • Assign the Workcenter View "General Ledger - Journal Entry Voucher"
  • Assign either one of the following Workcenter Views:
    • Case 1: Work Center "Fixed Assets" either view "Postings" or "Masterdata" also with no instance restriction (at least less restrictive than Work Center "General Ledger")
    • Case 2: Work Center View "General Ledger - Recurring Journal Entry Vouchers"
  • Restrict to one Company
  • Try posting a business document (e.g. Journal Entry Voucher) to a different Company than the business user is restricted to.
  • The business user is able to post although he should not be.

Cause

Coming from the additionally assigned Work Center Views "Fixed Asset" or View "General Ledger - Recurring Journal Entry Vouchers" a policy is created that gives a user the authorization in the "General Ledger" Work Center in general to post in all Companies he is allowed to post to in the additionally added Work Center Views. This policy is needed to allow the reversal of Journal Entry Vouchers created by the business users.

Resolution

There's no fix available. The workaround is: Restrictions in "General Ledger" Work Center and Work Center "Fixed Assets" and/or Work Center View "General Ledger - Recurring Journal Entry Voucher" have to be identical.

Keywords

KBA , SRD-MD-PRD-PRD , Product , Product Enhancement

Product

SAP BUSINESS BYDESIGN 1705 ; SAP BUSINESS BYDESIGN 1708 ; SAP Business ByDesign 1711