Hi Ramji
Not too sure on this, but once the user gets the error, check the authorization log (SU53) immediately after that. See if there are any failed auths.
Apart from that, you can just raise an OSS ticket because this is a standard workflow.
regards,
Modak