Using transaction PFCG (Profile Generator)
About this task
Perform
the following steps:
- Write a name, for example ZTWS, in Role Name.
- Click Create Role and write a description for the role, such as "Role for the TWS user."
- Save the role.
- Select Authorizations.
- Click Change Authorization Data.
- In the pop-up, select Templates.
- Manually add the following authorization
objects:
Object Description S_ADMI_FCD System authorizations S_APPL_LOG Application logs S_BTCH_ADM Background processing: Background administrator S_BTCH_JOB Background processing: Operations on background jobs S_BTCH_NAM Background processing: Background user name S_PROGRAM ABAP: Program run checks S_DEVELOP ABAP Workbench: full authorization to modify objects of type PROG S_LOG_COM Authorization to run external commands S_RFC Authorization check for RFC access S_RZL_ADM CCMS: System Administration S_SPO_ACT Spool: Actions S_SPO_DEV Spool: Device authorizations S_XMI_LOG Internal access authorizations for XMI log S_XMI_PROD Authorization for external management interfaces (XMI) - Fill in the values
according to the following scheme:
Object Description S_ADMI_FCD System authorizations - System administration function: Full authorization
S_APPL_LOG Activity: Display - Application log Object name: Full authorization
- Application log subobject: Full authorization
S_BTCH_ADM Background processing: Background administrator - Background administrator ID: Full authorization
S_BTCH_JOB Background processing: Operations on background jobs - Job operations: Full authorization
- Summary of jobs for a group: Full authorization
S_BTCH_NAM Background processing: Background user name - Background user name for authorization check: Full authorization
S_PROGRAM ABAP: Program run checks - User action ABAP/4 program: Full authorization
- Authorization group ABAP/4 program: Full authorization
S_RFC Authorization check for RFC access - Activity: Full authorization
- Name of RFC to be protected: Full authorization
- Type of RFC object to be protected: Full authorization
S_RZL_ADM Activity: Full authorization S_SPO_ACT Spool: Actions - Authorization field for spool actions: Full authorization
- Value for authorization check: Full authorization
S_SPO_DEV Spool: Device authorizations - Spool - Long device names: Full authorization
S_XMI_LOG Internal access authorizations for XMI log - Access method for XMI log: Full authorization
S_XMI_PROD Authorization for external management interfaces (XMI) - XMI logging - Company name: ABC*
- XMI logging - Program name: MAESTRO*
- Interface ID: Full authorization
- Save the authorizations.
- Generate a profile. Use the same name that you wrote in Role Name.
- Exit the authorization management panel and select User.
- Add the HCL Workload Automation user to the role.
- Save the role.