SAP Authorizations Maintain proposed values using trace evaluations - SAP Stuff

Direkt zum Seiteninhalt
Maintain proposed values using trace evaluations
Search for user and password locks
However, the authorization trace is not active by default, but must be explicitly activated via the profile parameter "auth/authorization_trace". In transaction RZ11 you can easily and quickly check if the parameter is already set. The profile parameter is set in transaction RZ10. By default, the profile parameter is active in SAP systems (profile parameter transport/systemtype = SAP) and inactive in customer systems (profile parameter transport/systemtype = CUSTOMER).

If you want to allow users to access only individual table rows, you can use the S_TABU_LIN authorization object, which allows access to specific rows of a table for defined organisational criteria. A prerequisite for this type of permission is that the tables have columns with such organisational values, such as the work, country, accounting area, etc. You must now configure these organisational values in the system as organisational criteria that represent business areas; serve as a bridge between the organisational columns in the tables and the permission field in the authorization object. Since the organisational criteria are found in several tables, this eligibility check need not be bound to specific tables and can be defined across tables.
Authorizations
The next step is to maintain the permission values. Here, too, you can take advantage of the values of the permission trace. When you switch from the Role menu to the Permissions tab, you will generate startup permissions for all applications on the Role menu and display default permissions from the permissions suggestions. You can now add these suggested values to the trace data by clicking the button trace in the Button bar.

With "Shortcut for SAP systems" you can automate the assignment of roles after a go-live.

You can also find some useful tips from practice on the subject of SAP authorizations on the page "www.sap-corner.de".

This information should be part of the naming convention, as these roles differ only in their organisational but not in their functional form.

SAP Stuff
Zurück zum Seiteninhalt