SlideShare ist ein Scribd-Unternehmen logo
1 von 13
Authorization Concept
        The authorizations for users are created using roles and profiles. The administrator
creates the roles, and the system supports him or her in creating the associated authorizations.




                                                                       Authorization
       B Object Class             Authorization Object                       A
                                                                   Create, Change,Display
                                      User Master                          SUPER
                                    Maintenance: User
                                         Groups                               B
          Basis Admin                   Activity                           Display
                                      User Group                           Finance



                                 Fig 1.1 Authorization Concepts

          Authorization objects allow complex checks that involve multiple conditions that allow
a user to perform an action. An authorization is always associated with exactly one authorization
object and contains the value for the fields for the authorization objects.

          An authorization is a permission to perform a certain action in the SAP System. The
action is defined on the basis of the values for the individual fields of an authorization object.
When a user logs on to a client of an SAP system, his or her authorizations are loaded in the user
context. The user context is in the user buffer( in the main memory) of the application Server.

         When the user calls a transaction, the system checks whether the use has an
authorization in the user context that allows him/her to call the selected transaction.
Authorization checks use the authorizations in the user context.

All the authorizations are permissions. There are no authorizations for prohibiting. Everything
that is not explicitly allowed is forbidden.

The user gets the necessary authorization through Roles. The role also contains the
authorizations users need to access the transactions, reports, web-based applications and so on,
contained in the menu.

The details of user administration is specified in my other BOK “User Administration in SAP
R3 System”.

How to Create a new Role
There are 2 ways, for creation of new roles

   •    Copy an existing role (SAP pre-defined role).
   •    Creating a new role, based up on the business requirements.

Copy an existing role

You can use the user role examples just as they are delivered with the SAP System.

Prerequisites

Check the suitability of the roles delivered by SAP before you create your own roles. If you want
to modify them, all you need to do is copy the SAP template (Roles provided by SAP). And
modify that newly created one.

Procedure

The copying a existing role is described below.


Using this icon (Copy Role).        .

To create a single role:

   1. Choose the pushbutton Create role or the transaction PFCG in the initial transaction SAP
        Easy Access. You go to the role maintenance.
   2. Choose the pushbutton Copy role.
   3. Now select the appropriate role, delivered by SAP in the source role and specify the user
        defined role as the target role
   4. Now choose the pushbutton “copy all/ copy selectively.”
   5. Now new role has been created successfully. Now we can edit the new role by pressing
        the pushbutton “change role”.
   6.   And based on the requirements deselect/remove unnecessary authorizations from that
        SAP.
7. Now we can assign this new role to the user.

This reduces the risk of giving all the authorizations to a user.
For example, consider a business scenario where we want to create a role for a particular user,
who works in sales department.

Creating a new role

Based up on the business requirements we have to create roles, which are not provided by SAP.

Here in the above scenario, we have to assign only that particular role with which he will be
able to create, change and view the Sales Order.

Procedure

The creation of a single role is described below.

To create a single role:

   1. Choose the pushbutton Create role or the transaction PFCG in the initial transaction SAP
      Easy Access. You go to the role maintenance.
2. Specify a name for the role.

       The roles delivered by SAP have the prefix 'SAP_'. Do not use the SAP namespace for
       your user roles.

   3. To distinguish between the names of User defined roles and SAP predefined roles, we
      will prefix the role with ‘Z_’ or ‘Y_’.




   4. Choose Create Role.

   5. Enter a meaningful role description text. You can describe the activities in the role in
      detail. And save the role.

You may use an existing role as a reference.
Assign transactions, programs and/or web addresses to the role in the Menu tab.
6. The user menu which you create here is called automatically when the user to whom this
   role is assigned logs on to the SAP System.
7. You can create the authorizations for the transactions in the role menu structure in the
      authorizations tab.




To get the profile name for this particular role, press the pushbutton “propose profile names”.
SAP will supply with a profile name.

And press the pushbutton ‘Change Authorization Data’ for maintaining authorization data and
generating profiles.




  Profile generator
Specify the company code, division, sales organization distribution channel etc, press Save
button.

If we don’t specify any organization code, we will see the red color dot against each
Authorization Object. To avoid this, its better to specify the company code and the rest.




                                                                 Authorization object



                                                                                        Activity



                                                                               User group



                                                                    Tasks



For each role, there will be some Authorization objects, User group, Activity and Tasks, which I
had specified in fig 1.1.

However, all the authorization values must be manually checked and adjusted if required in
accordance with the actual requirements and authorities.




                                                                   Profile generator
Once we see all the authorization object are green, then we can generate the profile for this
particular role by pressing that ‘generate’ pushbutton .

With this we have successfully created a role.

Advanced Concepts

If you want to call the transactions in a role in another system, enter the RFC destination of the
other system in the Target system field.




You should only use RFC destinations which were created using the Trusted System concept to
guarantee that the same user is used in the target system. This is only necessary if you want to
navigate via the Easy Access Menu in the SAPgui.

If you use the Workplace Web Browser, you can use any destination containing a logical system
with the same name.

If the Target system field is empty, the transactions are called in the system in which the user is
logged on.

You can also specify a variable which refers to an RFC destination. Variables are assigned to the
RFC destinations in the transaction SM30_SSM_RFC.

To distribute the role into a particular target system, specify the target system (its Release must
be 4.6C) and choose Distribute. This function is most useful when you use the Workplace.
You can create the user menu:

   o   from the SAP menu

       You can copy complete menu branches from the SAP menu by clicking on the
       cross in front of it in the user menu. Expand the menu branch if you want to put
       lower-level nodes or individual transactions/programs in the user menu.

   o   from a role

       this function copies a defined role menu structure in the same system into the
       current role. You can also copy the menu structure of a role delivered by SAP.
       Click on the menu branches and copy them.

   o   from an area menu

       You can copy area menus (SAP Standard and your own) into a role menu. Choose
       an area menu from the list of menus and copy the transactions you want.




   o   Import from file

   o   Transaction

       You can put a transaction code in the user menu directly.
o   Program

               This function puts programs, transaction variants or queries in the user menu.
               They need not be given a transaction code.

               ABAP Report

               Choose a report and a variant. You can skip the selection screen.




           o   Others

               By choosing the other button, you can add Internet Address or Links or Files.
               When integrating files, you must use the storage paths instead of URLs. You can
               also specify BW Web Reports, and links to external mail systems and Knowledge
               Warehouse.

   7. Save your entries.

Result

You have created a role. Role maintenance automatically creates the authorizations that are
associated with the transactions specified in the menu tree. However, all the authorization values
must be manually checked and adjusted if required in accordance with the actual
requirements and authorities.

Weitere ähnliche Inhalte

Was ist angesagt?

SAP Security & GRC Framework
SAP Security & GRC FrameworkSAP Security & GRC Framework
SAP Security & GRC Framework
Harish Sharma
 
sap security interview_questions
sap security interview_questionssap security interview_questions
sap security interview_questions
sumitmsn2
 
081712 isaca-atl-auditing sap-grc
081712 isaca-atl-auditing sap-grc081712 isaca-atl-auditing sap-grc
081712 isaca-atl-auditing sap-grc
hkodali
 
Sap security-administration
Sap security-administrationSap security-administration
Sap security-administration
nanda nanda
 
1000 solved questions
1000 solved questions1000 solved questions
1000 solved questions
Kranthi Kumar
 
Workflow Part1 1
Workflow Part1 1Workflow Part1 1
Workflow Part1 1
evil66_in
 

Was ist angesagt? (20)

SAP Security & GRC Framework
SAP Security & GRC FrameworkSAP Security & GRC Framework
SAP Security & GRC Framework
 
sap security interview_questions
sap security interview_questionssap security interview_questions
sap security interview_questions
 
165373293 sap-security-q
165373293 sap-security-q165373293 sap-security-q
165373293 sap-security-q
 
Sap GRC Basic Information | GRC 12 online training
Sap GRC Basic Information | GRC 12 online trainingSap GRC Basic Information | GRC 12 online training
Sap GRC Basic Information | GRC 12 online training
 
Introduction on sap security
Introduction on sap securityIntroduction on sap security
Introduction on sap security
 
Day5 R3 Basis Security
Day5 R3 Basis   SecurityDay5 R3 Basis   Security
Day5 R3 Basis Security
 
SAP SECURITY GRC
SAP SECURITY GRCSAP SECURITY GRC
SAP SECURITY GRC
 
SU01 - Background and Instruction
SU01  - Background and InstructionSU01  - Background and Instruction
SU01 - Background and Instruction
 
Creating new users and roles in sap guide
Creating new users and roles in sap guideCreating new users and roles in sap guide
Creating new users and roles in sap guide
 
081712 isaca-atl-auditing sap-grc
081712 isaca-atl-auditing sap-grc081712 isaca-atl-auditing sap-grc
081712 isaca-atl-auditing sap-grc
 
Authorisations in SAP: best practices
Authorisations in SAP: best practicesAuthorisations in SAP: best practices
Authorisations in SAP: best practices
 
SAP BI 7 security concepts
SAP BI 7 security conceptsSAP BI 7 security concepts
SAP BI 7 security concepts
 
Sap security-administration
Sap security-administrationSap security-administration
Sap security-administration
 
SAP Risk Management
SAP Risk ManagementSAP Risk Management
SAP Risk Management
 
Iia los angeles sap security presentation
Iia  los angeles  sap security presentation Iia  los angeles  sap security presentation
Iia los angeles sap security presentation
 
Derived master roles Configuration screenshots in SAP Security
Derived master roles Configuration screenshots in SAP Security Derived master roles Configuration screenshots in SAP Security
Derived master roles Configuration screenshots in SAP Security
 
1000 solved questions
1000 solved questions1000 solved questions
1000 solved questions
 
Sap grc-access-control-solution
Sap grc-access-control-solutionSap grc-access-control-solution
Sap grc-access-control-solution
 
Sap basis made easy
Sap basis made easySap basis made easy
Sap basis made easy
 
Workflow Part1 1
Workflow Part1 1Workflow Part1 1
Workflow Part1 1
 

Andere mochten auch

Andere mochten auch (20)

SAP Basis Training Material | www.sapdocs.info
SAP Basis Training Material | www.sapdocs.infoSAP Basis Training Material | www.sapdocs.info
SAP Basis Training Material | www.sapdocs.info
 
SAP Configuration Guide for Functional Modules (Based on IDES)
SAP Configuration Guide for Functional Modules (Based on IDES)SAP Configuration Guide for Functional Modules (Based on IDES)
SAP Configuration Guide for Functional Modules (Based on IDES)
 
SAP FICO BBP Sample Document PDF NEW!
SAP FICO BBP Sample Document PDF NEW!SAP FICO BBP Sample Document PDF NEW!
SAP FICO BBP Sample Document PDF NEW!
 
SAP FI AP: End User Guide for Beginners
SAP FI AP: End User Guide for BeginnersSAP FI AP: End User Guide for Beginners
SAP FI AP: End User Guide for Beginners
 
SAP MM Configuration - Real Project Documentation
SAP MM Configuration - Real Project DocumentationSAP MM Configuration - Real Project Documentation
SAP MM Configuration - Real Project Documentation
 
LSMW Tutorial (Spanish Espanol)
LSMW Tutorial (Spanish Espanol)LSMW Tutorial (Spanish Espanol)
LSMW Tutorial (Spanish Espanol)
 
SAP FI Asset Accounting: End User Guide for Beginners
SAP FI Asset Accounting: End User Guide for BeginnersSAP FI Asset Accounting: End User Guide for Beginners
SAP FI Asset Accounting: End User Guide for Beginners
 
SAP PM Master Data Training Guide
SAP PM Master Data Training GuideSAP PM Master Data Training Guide
SAP PM Master Data Training Guide
 
SAP FI AR: End User Guide for Beginners
SAP FI AR: End User Guide for BeginnersSAP FI AR: End User Guide for Beginners
SAP FI AR: End User Guide for Beginners
 
SAP PP MRP Guide for Beginners
SAP PP MRP Guide for BeginnersSAP PP MRP Guide for Beginners
SAP PP MRP Guide for Beginners
 
SAP SD Certification (C_TSCM62_66) Preparation Training Notes
SAP SD Certification (C_TSCM62_66) Preparation Training NotesSAP SD Certification (C_TSCM62_66) Preparation Training Notes
SAP SD Certification (C_TSCM62_66) Preparation Training Notes
 
Variant Configuration in SAP PP: Beginner's Guide
Variant Configuration in SAP PP: Beginner's GuideVariant Configuration in SAP PP: Beginner's Guide
Variant Configuration in SAP PP: Beginner's Guide
 
ABAP Basico para Consultores Funcionales
ABAP Basico para Consultores FuncionalesABAP Basico para Consultores Funcionales
ABAP Basico para Consultores Funcionales
 
SAP FI AP: Configuration & End User Guide
SAP FI AP: Configuration & End User GuideSAP FI AP: Configuration & End User Guide
SAP FI AP: Configuration & End User Guide
 
SAP FI-AP TCODES & MENU PATHS
SAP FI-AP TCODES & MENU PATHSSAP FI-AP TCODES & MENU PATHS
SAP FI-AP TCODES & MENU PATHS
 
SAP PM Training Manual - www.sapdocs.info
SAP PM Training Manual - www.sapdocs.infoSAP PM Training Manual - www.sapdocs.info
SAP PM Training Manual - www.sapdocs.info
 
SAP FI-AR TCODES & MENU PATHS
SAP FI-AR TCODES & MENU PATHSSAP FI-AR TCODES & MENU PATHS
SAP FI-AR TCODES & MENU PATHS
 
SAP HR Time Management User Guide | www.sapdocs.info
SAP HR Time Management User Guide | www.sapdocs.infoSAP HR Time Management User Guide | www.sapdocs.info
SAP HR Time Management User Guide | www.sapdocs.info
 
SAP PP End User Document - www.sapdocs.info
SAP PP End User Document - www.sapdocs.infoSAP PP End User Document - www.sapdocs.info
SAP PP End User Document - www.sapdocs.info
 
Variant Configurition in SAP: Beginners Guide | www.sapdocs.info
Variant Configurition in SAP: Beginners Guide | www.sapdocs.infoVariant Configurition in SAP: Beginners Guide | www.sapdocs.info
Variant Configurition in SAP: Beginners Guide | www.sapdocs.info
 

Ähnlich wie Authorisation Concept In SAP | http://sapdocs.info

Cis407 a ilab 6 web application development devry university
Cis407 a ilab 6 web application development devry universityCis407 a ilab 6 web application development devry university
Cis407 a ilab 6 web application development devry university
lhkslkdh89009
 
10 necto administration_ready
10 necto administration_ready10 necto administration_ready
10 necto administration_ready
www.panorama.com
 

Ähnlich wie Authorisation Concept In SAP | http://sapdocs.info (20)

Anypoint access management - Roles
Anypoint access management - RolesAnypoint access management - Roles
Anypoint access management - Roles
 
359555069 aae-control room-usermanual
359555069 aae-control room-usermanual359555069 aae-control room-usermanual
359555069 aae-control room-usermanual
 
Users and roles sitefinity guide
Users and roles  sitefinity guideUsers and roles  sitefinity guide
Users and roles sitefinity guide
 
SAP_HANA_SECURITY_overview_online_Resear.docx
SAP_HANA_SECURITY_overview_online_Resear.docxSAP_HANA_SECURITY_overview_online_Resear.docx
SAP_HANA_SECURITY_overview_online_Resear.docx
 
24 - Panorama Necto 14 administration - visualization & data discovery solution
24  - Panorama Necto 14 administration - visualization & data discovery solution24  - Panorama Necto 14 administration - visualization & data discovery solution
24 - Panorama Necto 14 administration - visualization & data discovery solution
 
Winter24-Welly Release Overview - Stephen Stanley.pdf
Winter24-Welly Release Overview - Stephen Stanley.pdfWinter24-Welly Release Overview - Stephen Stanley.pdf
Winter24-Welly Release Overview - Stephen Stanley.pdf
 
Automation Hub Best Practices - Large Scale Rollouts.pdf
Automation Hub Best Practices - Large Scale Rollouts.pdfAutomation Hub Best Practices - Large Scale Rollouts.pdf
Automation Hub Best Practices - Large Scale Rollouts.pdf
 
ORACLE FUSION FINANCIAL CLOUD FEATURES - CREATING IMPLEMENTATION USERS
ORACLE FUSION FINANCIAL CLOUD FEATURES - CREATING IMPLEMENTATION USERSORACLE FUSION FINANCIAL CLOUD FEATURES - CREATING IMPLEMENTATION USERS
ORACLE FUSION FINANCIAL CLOUD FEATURES - CREATING IMPLEMENTATION USERS
 
Implement Authorization in your Apps with Microsoft identity platform-June 2020
Implement Authorization in your Apps with Microsoft identity platform-June 2020Implement Authorization in your Apps with Microsoft identity platform-June 2020
Implement Authorization in your Apps with Microsoft identity platform-June 2020
 
Sap basis and_security_administration
Sap basis and_security_administrationSap basis and_security_administration
Sap basis and_security_administration
 
BMS-PPT-7viyvv.pptx
BMS-PPT-7viyvv.pptxBMS-PPT-7viyvv.pptx
BMS-PPT-7viyvv.pptx
 
Cis407 a ilab 6 web application development devry university
Cis407 a ilab 6 web application development devry universityCis407 a ilab 6 web application development devry university
Cis407 a ilab 6 web application development devry university
 
Abap proxies
Abap proxiesAbap proxies
Abap proxies
 
Oracle_Procurement_Cloud_Release_8_Whats_New
Oracle_Procurement_Cloud_Release_8_Whats_NewOracle_Procurement_Cloud_Release_8_Whats_New
Oracle_Procurement_Cloud_Release_8_Whats_New
 
10 necto administration_ready
10 necto administration_ready10 necto administration_ready
10 necto administration_ready
 
Workflow for XPages
Workflow for XPagesWorkflow for XPages
Workflow for XPages
 
Blog Management System
Blog Management SystemBlog Management System
Blog Management System
 
Anypoint access management
Anypoint access management Anypoint access management
Anypoint access management
 
Roles
RolesRoles
Roles
 
Whitepaper: Continuous Compliance in SAP Environments - Happiest Minds
Whitepaper: Continuous Compliance in SAP Environments - Happiest MindsWhitepaper: Continuous Compliance in SAP Environments - Happiest Minds
Whitepaper: Continuous Compliance in SAP Environments - Happiest Minds
 

Mehr von sapdocs. info

Mehr von sapdocs. info (12)

SAP ECC 6.0 PM Configuration Manual - www.sapdocs.info
SAP ECC 6.0 PM Configuration Manual - www.sapdocs.infoSAP ECC 6.0 PM Configuration Manual - www.sapdocs.info
SAP ECC 6.0 PM Configuration Manual - www.sapdocs.info
 
SAP CO Configuration Guide - Exclusive Document
SAP CO Configuration Guide - Exclusive DocumentSAP CO Configuration Guide - Exclusive Document
SAP CO Configuration Guide - Exclusive Document
 
ABAP for Beginners - www.sapdocs.info
ABAP for Beginners - www.sapdocs.infoABAP for Beginners - www.sapdocs.info
ABAP for Beginners - www.sapdocs.info
 
Exclusive SAP Basis Training Book | www.sapdocs.info
Exclusive SAP Basis Training Book | www.sapdocs.infoExclusive SAP Basis Training Book | www.sapdocs.info
Exclusive SAP Basis Training Book | www.sapdocs.info
 
SAP Plant Maintenance Training Material | www.sapdocs.info
SAP Plant Maintenance Training Material | www.sapdocs.infoSAP Plant Maintenance Training Material | www.sapdocs.info
SAP Plant Maintenance Training Material | www.sapdocs.info
 
SAP FICO General Ledger EndUser Training | www.sapdocs.info
SAP FICO General Ledger EndUser Training | www.sapdocs.infoSAP FICO General Ledger EndUser Training | www.sapdocs.info
SAP FICO General Ledger EndUser Training | www.sapdocs.info
 
HR ABAP Technical Overview | http://sapdocs.info/
HR ABAP Technical Overview | http://sapdocs.info/HR ABAP Technical Overview | http://sapdocs.info/
HR ABAP Technical Overview | http://sapdocs.info/
 
SAP Accounts Reveivable Introduction | http://sapdocs.info
SAP Accounts Reveivable Introduction | http://sapdocs.infoSAP Accounts Reveivable Introduction | http://sapdocs.info
SAP Accounts Reveivable Introduction | http://sapdocs.info
 
SAP Accounts Reveivable Functions | http://sapdocs.info
SAP Accounts Reveivable Functions | http://sapdocs.infoSAP Accounts Reveivable Functions | http://sapdocs.info
SAP Accounts Reveivable Functions | http://sapdocs.info
 
SAP Accounts Reveivable Financial Transaction | http://sapdocs.info
SAP Accounts Reveivable Financial Transaction | http://sapdocs.infoSAP Accounts Reveivable Financial Transaction | http://sapdocs.info
SAP Accounts Reveivable Financial Transaction | http://sapdocs.info
 
SAP Accounts Reveivable Customer Master | http://sapdocs.info
SAP Accounts Reveivable Customer Master | http://sapdocs.infoSAP Accounts Reveivable Customer Master | http://sapdocs.info
SAP Accounts Reveivable Customer Master | http://sapdocs.info
 
SAP Accounts Reveivable SAP Documents | http://sapdocs.info
SAP Accounts Reveivable SAP Documents | http://sapdocs.infoSAP Accounts Reveivable SAP Documents | http://sapdocs.info
SAP Accounts Reveivable SAP Documents | http://sapdocs.info
 

Kürzlich hochgeladen

Salient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functionsSalient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functions
KarakKing
 
The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptx
heathfieldcps1
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdf
QucHHunhnh
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdf
ciinovamais
 
Spellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please PractiseSpellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please Practise
AnaAcapella
 

Kürzlich hochgeladen (20)

SKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptx
SKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptxSKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptx
SKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptx
 
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
 
Kodo Millet PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
Kodo Millet  PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...Kodo Millet  PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
Kodo Millet PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptx
 
Salient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functionsSalient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functions
 
Mixin Classes in Odoo 17 How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17  How to Extend Models Using Mixin ClassesMixin Classes in Odoo 17  How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17 How to Extend Models Using Mixin Classes
 
The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptx
 
Towards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxTowards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptx
 
Understanding Accommodations and Modifications
Understanding  Accommodations and ModificationsUnderstanding  Accommodations and Modifications
Understanding Accommodations and Modifications
 
Spatium Project Simulation student brief
Spatium Project Simulation student briefSpatium Project Simulation student brief
Spatium Project Simulation student brief
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdf
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POS
 
Graduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - EnglishGraduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - English
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdf
 
How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17
 
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
 
Spellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please PractiseSpellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please Practise
 
Unit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxUnit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptx
 
SOC 101 Demonstration of Learning Presentation
SOC 101 Demonstration of Learning PresentationSOC 101 Demonstration of Learning Presentation
SOC 101 Demonstration of Learning Presentation
 
Making communications land - Are they received and understood as intended? we...
Making communications land - Are they received and understood as intended? we...Making communications land - Are they received and understood as intended? we...
Making communications land - Are they received and understood as intended? we...
 

Authorisation Concept In SAP | http://sapdocs.info

  • 1. Authorization Concept The authorizations for users are created using roles and profiles. The administrator creates the roles, and the system supports him or her in creating the associated authorizations. Authorization B Object Class Authorization Object A Create, Change,Display User Master SUPER Maintenance: User Groups B Basis Admin Activity Display User Group Finance Fig 1.1 Authorization Concepts Authorization objects allow complex checks that involve multiple conditions that allow a user to perform an action. An authorization is always associated with exactly one authorization object and contains the value for the fields for the authorization objects. An authorization is a permission to perform a certain action in the SAP System. The action is defined on the basis of the values for the individual fields of an authorization object. When a user logs on to a client of an SAP system, his or her authorizations are loaded in the user context. The user context is in the user buffer( in the main memory) of the application Server. When the user calls a transaction, the system checks whether the use has an authorization in the user context that allows him/her to call the selected transaction. Authorization checks use the authorizations in the user context. All the authorizations are permissions. There are no authorizations for prohibiting. Everything that is not explicitly allowed is forbidden. The user gets the necessary authorization through Roles. The role also contains the authorizations users need to access the transactions, reports, web-based applications and so on, contained in the menu. The details of user administration is specified in my other BOK “User Administration in SAP R3 System”. How to Create a new Role
  • 2. There are 2 ways, for creation of new roles • Copy an existing role (SAP pre-defined role). • Creating a new role, based up on the business requirements. Copy an existing role You can use the user role examples just as they are delivered with the SAP System. Prerequisites Check the suitability of the roles delivered by SAP before you create your own roles. If you want to modify them, all you need to do is copy the SAP template (Roles provided by SAP). And modify that newly created one. Procedure The copying a existing role is described below. Using this icon (Copy Role). . To create a single role: 1. Choose the pushbutton Create role or the transaction PFCG in the initial transaction SAP Easy Access. You go to the role maintenance. 2. Choose the pushbutton Copy role. 3. Now select the appropriate role, delivered by SAP in the source role and specify the user defined role as the target role 4. Now choose the pushbutton “copy all/ copy selectively.” 5. Now new role has been created successfully. Now we can edit the new role by pressing the pushbutton “change role”. 6. And based on the requirements deselect/remove unnecessary authorizations from that SAP.
  • 3. 7. Now we can assign this new role to the user. This reduces the risk of giving all the authorizations to a user.
  • 4. For example, consider a business scenario where we want to create a role for a particular user, who works in sales department. Creating a new role Based up on the business requirements we have to create roles, which are not provided by SAP. Here in the above scenario, we have to assign only that particular role with which he will be able to create, change and view the Sales Order. Procedure The creation of a single role is described below. To create a single role: 1. Choose the pushbutton Create role or the transaction PFCG in the initial transaction SAP Easy Access. You go to the role maintenance.
  • 5. 2. Specify a name for the role. The roles delivered by SAP have the prefix 'SAP_'. Do not use the SAP namespace for your user roles. 3. To distinguish between the names of User defined roles and SAP predefined roles, we will prefix the role with ‘Z_’ or ‘Y_’. 4. Choose Create Role. 5. Enter a meaningful role description text. You can describe the activities in the role in detail. And save the role. You may use an existing role as a reference.
  • 6. Assign transactions, programs and/or web addresses to the role in the Menu tab.
  • 7. 6. The user menu which you create here is called automatically when the user to whom this role is assigned logs on to the SAP System.
  • 8. 7. You can create the authorizations for the transactions in the role menu structure in the authorizations tab. To get the profile name for this particular role, press the pushbutton “propose profile names”. SAP will supply with a profile name. And press the pushbutton ‘Change Authorization Data’ for maintaining authorization data and generating profiles. Profile generator
  • 9. Specify the company code, division, sales organization distribution channel etc, press Save button. If we don’t specify any organization code, we will see the red color dot against each Authorization Object. To avoid this, its better to specify the company code and the rest. Authorization object Activity User group Tasks For each role, there will be some Authorization objects, User group, Activity and Tasks, which I had specified in fig 1.1. However, all the authorization values must be manually checked and adjusted if required in accordance with the actual requirements and authorities. Profile generator
  • 10. Once we see all the authorization object are green, then we can generate the profile for this particular role by pressing that ‘generate’ pushbutton . With this we have successfully created a role. Advanced Concepts If you want to call the transactions in a role in another system, enter the RFC destination of the other system in the Target system field. You should only use RFC destinations which were created using the Trusted System concept to guarantee that the same user is used in the target system. This is only necessary if you want to navigate via the Easy Access Menu in the SAPgui. If you use the Workplace Web Browser, you can use any destination containing a logical system with the same name. If the Target system field is empty, the transactions are called in the system in which the user is logged on. You can also specify a variable which refers to an RFC destination. Variables are assigned to the RFC destinations in the transaction SM30_SSM_RFC. To distribute the role into a particular target system, specify the target system (its Release must be 4.6C) and choose Distribute. This function is most useful when you use the Workplace.
  • 11. You can create the user menu: o from the SAP menu You can copy complete menu branches from the SAP menu by clicking on the cross in front of it in the user menu. Expand the menu branch if you want to put lower-level nodes or individual transactions/programs in the user menu. o from a role this function copies a defined role menu structure in the same system into the current role. You can also copy the menu structure of a role delivered by SAP. Click on the menu branches and copy them. o from an area menu You can copy area menus (SAP Standard and your own) into a role menu. Choose an area menu from the list of menus and copy the transactions you want. o Import from file o Transaction You can put a transaction code in the user menu directly.
  • 12. o Program This function puts programs, transaction variants or queries in the user menu. They need not be given a transaction code. ABAP Report Choose a report and a variant. You can skip the selection screen. o Others By choosing the other button, you can add Internet Address or Links or Files. When integrating files, you must use the storage paths instead of URLs. You can also specify BW Web Reports, and links to external mail systems and Knowledge Warehouse. 7. Save your entries. Result You have created a role. Role maintenance automatically creates the authorizations that are associated with the transactions specified in the menu tree. However, all the authorization values
  • 13. must be manually checked and adjusted if required in accordance with the actual requirements and authorities.