Hi Pradeep,
To create a display only role, First go to transaction PFCG and go to authorization tab.
Here save your role and click on change authorization data.
Choose the SAP_ALL template profile, and then click on Adopt reference .
In this way, all authorizations entered in the SAP_ALL profile are used to fill up the role.
A pop up will emerge with quote " Insert all authorizations?"
click on yes. An information message will appear saying that "authorizations added with complete authorization".
By doing this, you can ensure that all authorization objects that are entered in the
SAP_ALL profile are covered by the role that you are creating.
Next, ensure that this role lets the user access the system in display mode only.
Be sure that in all authorization objects with the ACTVT field, the values chosen
are in display. (In table TACT the ACTVT field for display is 03).
For this, click on the binoculars icon, and then find all authorization objects with the
ACTVT field.
Look for all authorization object fields with the ACTVT field, and set them in display mode by entering the previously listed values.
provide points ,if useful. ![]()
Best Regards,
Somya