SAP Authorizations Task & functionality of the SAP authorization concept - SAP Basis

Direkt zum Seiteninhalt
Task & functionality of the SAP authorization concept
Installing and executing ABAP source code via RFC
Different users in your SAP system will have different password rules, password changes, and login restrictions. The new security policy allows you to define these user-specific and client-specific. It happens again and again that there are special requirements for password rules, password changes and login restrictions for different users in your SAP system. There may be different reasons for this.

SAP Note 1707841 ships an extension to the system trace in the STAUTHTRACE transaction, which enables the permission trace to be used on all or on specific application servers. To select the application servers on which to start the trace, click the System Trace button. Now select the application servers in the list on which you want to run the system trace and start the trace with a click on Trace. In the evaluation of the Permission trace, an additional column named Server Name appears, showing you the name of the application server on which the respective permission checks were logged.
ACCESS CONTROL | AUTHORIZATION MANAGEMENT FOR SAP®
The next step is to evaluate the usage data; here the monthly aggregates are typically sufficient. These include the user ID, function block, and number of calls. For an overview of the usage data already stored in the system, see the SWNC_COLLECTOR_GET_DIRECTORY function block (GET_DIR_FROM_CLUSTER = X input parameter). The actual downloading of the usage data is then performed using the function block SWNC_COLLECTOR_GET_AGGREGATES.

You can set up a nightly background job to match the certificates with your customer's own programme. This requires that the certificates can be obtained through an SAP programme.

"Shortcut for SAP systems" is a tool that enables the assignment of authorizations even if the IdM system fails.

After confirming these entries, you will be returned to the detail view of your role.

You can see here the additions to the permission values for your authorization object.
SAP BASIS
Zurück zum Seiteninhalt