SAP Authorizations Checking at Program Level with AUTHORITY-CHECK - SAP Basis

Direkt zum Seiteninhalt
Checking at Program Level with AUTHORITY-CHECK
Displaying sensitive data
What roles does my user have (SU01)? We start with a simple question: which roles are actually assigned to your SAP user? With the transaction SU01 you can view your (or other) SAP user. Among a lot of other information, you can find the assigned single and composite roles on the "Roles" tab.

The SAP standard offers various ways to record and play on a massive scale. These tools are generally available for all operations in the SAP system, not just for role maintenance. Therefore, they are also more complex to operate, in order to be able to cover as flexibly as possible all possible application scenarios. eCATT is also no exception, so many users are still afraid to use it. But we can tell you from experience: After the second or third time, the creation of the test scripts is so quick that you'll wonder why you haven't always done it this way.
Understanding SAP HANA Permissions Tests
Small companies would theoretically benefit from an authorization tool. However, in many cases the tools are too costly, so the cost-benefit ratio is usually not given.

The object S_PROGRAM checks since SAP Release 2.x for the field TRDIR-SECU i.e. the authorization group of the program. As of Release 7.40, you can optionally switch on a check for the object S_PROGNAM. For more information, see note 2272827 for further instructions. The check on S_PROGNAM MUST first be activated in the customer system. Note, however, that they CORRECTLY authorize S_PROGNAM before doing so, otherwise NOBODY except emergency users will be able to start any report or report transaction after the SACF scenario is activated.

With "Shortcut for SAP systems" you can automate the assignment of roles after a go-live.

This applies not only to communication between the user interface and the application server, but also to communication between different SAP systems via Remote Function Call (RFC).

The time factor for determining, organizing and implementing the necessary components should not be underestimated.
SAP BASIS
Zurück zum Seiteninhalt