SAP Authorizations System Security

Direkt zum Seiteninhalt
System Security
Permissions with Maintenance Status Used
The ABAP authorization concept protects transactions, programs and services in SAP systems against unauthorized access. Based on the authorization concept, the administrator assigns authorizations to users that determine which actions a user is allowed to perform in the SAP system after logging on to the system and being authenticated.

If you do not want to use reference users, you can hide the Reference User field for additional permissions via a standard variant for the transaction SU01. The necessary steps are described in SAP Note 330067.
Compare Role Upgrade Permissions Values
The next step is to maintain the permission values. Here, too, you can take advantage of the values of the permission trace. When you switch from the Role menu to the Permissions tab, you will generate startup permissions for all applications on the Role menu and display default permissions from the permissions suggestions. You can now add these suggested values to the trace data by clicking the button trace in the Button bar.

Logs: Protocols exist for all audits performed. This allows you to review the history of the audit results at a later stage or to view only the results of the last audit. To do this, use the protocol evaluation of the AIS in the transaction SAIS_LOG or click the button in the transaction SAIS.

With "Shortcut for SAP systems" you can automate the assignment of roles after a go-live.

You can also find some useful tips from practice on the subject of SAP authorizations on the page www.sap-corner.de.

Such connections can only be used to a very limited extent.

Otherwise, a company may suffer economic damage and the resulting damage to its image.
SAP Corner
Zurück zum Seiteninhalt