We deployed our custom Fiori contract management apps via embedded deployment last week on S/4HANA 1809. Everything looked fine initially, but now users are getting blank screens when trying to access the apps through their custom launchpad roles.
The strange part is that when I assign standard SAP roles (like SAP_BR_PURCHASER), the same apps load perfectly. Our custom roles have been carefully configured with the required business catalogs, but something seems to be missing. I’ve checked the catalog assignments multiple times and they appear correct.
I also noticed that some OData services show as registered in /IWFND/MAINT_SERVICE but don’t have the green activation status. Could this be related? The error console in browser just shows “Failed to load application” without detailed logs.
This is blocking 40+ contract managers from their daily work. Has anyone encountered similar issues with custom roles after embedded app deployment?
Any app-specific technical catalogs shown in working standard roles
Compare your custom role with SAP_BR_PURCHASER in /UI2/FLPD_CUST to identify gaps.
3. Grant S_SERVICE Authorizations:
This is the critical missing piece. In PFCG:
Edit your custom role
Go to Authorizations tab
Manually add authorization object S_SERVICE
Add all OData service technical names found in SU53:
ZCONT_MGT_SRV
ZCONTRACT_APPR_SRV
Any other services your apps consume
Set TADIR_TYPE = IWSG (Service Group)
Generate the role and assign to users
4. Clear Launchpad Cache:
After all changes:
Run /UI2/FLP_CLEAR_CACHE
Have users clear browser cache
Log out and back in to refresh role authorizations
Why Standard Roles Work:
Standard SAP roles like SAP_BR_PURCHASER are pre-delivered with complete authorization sets including S_SERVICE objects for all related OData services. When you build custom roles, you must explicitly replicate these authorizations - catalog assignment alone is insufficient.
The root cause is that embedded Fiori apps require three layers:
UI layer (catalogs) - you had this
Service layer (OData activation) - partially missing
All three must be configured for custom roles. Test with one user first before rolling out to all 40 contract managers.
This draft is based on general SAP S/4HANA knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.
Check your catalog-to-role mapping in PFCG. Custom roles often miss the technical catalogs that contain the OData service groups. Even if business catalogs are assigned, you need the underlying technical catalogs for service access. Run transaction /UI2/FLPD_CUST and verify catalog assignments for your custom role versus the working standard role.
Thanks Anna. I compared both roles in /UI2/FLPD_CUST and found that standard roles have additional technical catalogs like SAP_TC_CONT_MGT_OD that weren’t in our custom role. I added those catalogs but apps still won’t load. The OData services in /IWFND/MAINT_SERVICE still show yellow status instead of green. Do I need to manually activate each service?
Tested this on S/4HANA 2021 embedded deployment — activating ZCONT_MGT_SRV via /IWFND/MAINT_SERVICE with LOCAL alias and enabling ICF nodes under /sap/opu/odata/sap/ resolved our Fiori contract app loading failures immediately.
Yellow status in /IWFND/MAINT_SERVICE means services are registered but not fully activated. You need to activate them properly. Go to /IWFND/MAINT_SERVICE, select each OData service for your contract apps, click ‘Activate and Maintain Services’, then choose ‘Add Service’. Make sure the system alias points to LOCAL or your correct backend system. After activation, the status should turn green. Also check ICF services are active in SICF for path /sap/opu/odata/.
I’ve seen this exact scenario. The issue is usually authorization objects missing in custom roles. Standard SAP roles come pre-configured with S_SERVICE authorizations for OData services. Your custom roles need explicit authorization for each OData service used by the contract apps. Check authorization object S_SERVICE in SU53 after a failed app load attempt. You’ll likely see missing service names that need to be added to your custom role in PFCG under the authorizations tab.
Lisa, you’re right! I ran SU53 after attempting to load the app and found missing S_SERVICE authorizations for services like ZCONT_MGT_SRV and ZCONTRACT_APPR_SRV. I thought catalog assignment would handle this automatically. So I need to manually add these service authorizations to the custom role?
Catalog assignment doesn’t automatically grant OData service authorizations - that’s a common misconception. You need both the catalog for UI definition AND explicit S_SERVICE authorization for backend access. When you add technical catalogs, they bring the app tiles but not the service execution rights. This is actually good security design since it separates UI access from data access permissions.