SAP Authorizations Introduction & Best Practices

Direkt zum Seiteninhalt
Introduction & Best Practices
Set up permission to access Web Dynpro applications using S_START
Then run step 2c. Here too, there are new features. You will be shown a selection of the roles to match again. However, you have the possibility to perform a simulation of the mixing process via the button Mix. This allows you to see which permissions would be changed in the roles without actually doing so. For more information, see Tip 44, "Compare Role Upgrade Permissions".

The goal of an authorization concept is to provide each user with the appropriate authorizations in the system individually for their tasks according to a previously defined rule. For this purpose, an authorization concept must be defined as the foundation for efficient authorization assignment. In this way, each employee is given system access through the role-specific assignment of authorizations according to his or her tasks. On the one hand, this protects sensitive information and, on the other, prevents damage caused by incorrect use of data.
Reset Manually Maintained Organisation Levels to Roles
Depending on the transaction invoked, the application can be more granular checked by this additional permission check. Therefore, transactions that are called with additional parameters might require more than one authorization object and must be protected programmatically. The following listing shows an example of a permission check that ensures that the logged-in user has the permission to start the SU24 transaction.

Add missing modification flags in SU24 data: This function complements the modification flag for entries that have changed since the last execution of step 2a in the transaction SU25, i.e., where there is a difference to the SAP data from the transaction SU22. The flag is thus set retrospectively, so that no customer data is accidentally overwritten with step 2a due to missing modification flags.

"Shortcut for SAP systems" is a tool that enables the assignment of authorizations even if the IdM system fails.

Some useful tips about SAP basis can be found on www.sap-corner.de.


Value in Central - This column contains the central user type from the ZBV that is stored for the respective subsidiary system to the user.

The freeware Scribble Papers is a "note box" in which all kinds of data can be stored. It takes in typed texts as well as graphics and entire documents. The data is then organised in folders and pages.


When you call the report, in the source and target release selections, type in the appropriate fields, and the role is created for that release difference.
Zurück zum Seiteninhalt