120 likes | 221 Views
Users & Authorization. Users must be setup and roles assigned to user master records before you can use the SAP System. A user can only log on to the system if he or she has a user master record. A user menu and authorizations are also assigned to the user master record via one or more roles. .
E N D
Users & Authorization • Users must be setup and roles assigned to user master records before you can use the SAP System. • A user can only log on to the system if he or she has a user master record. A user menu and authorizations are also assigned to the user master record via one or more roles.
Dispatcher B V ... D Users in the R/3 Environment Operating System OS User Present. Server R/3 User Operating System OS User Application Server Admin. User Database Server Operating System OS User Database Server DB User
The User Master Record All user data required for R/3 System access is stored in the user master record in eight categories
Authorization Concept User master record User master record Profile Profile Authorization for Task A Authorization for Task B Action Action Transaction permitted? Authorizations assigned? Objects needing protection Vendor Material Company code Plant
Authorization Check SAP GUI Dynpro User Context Authority Check No OK? Message Yes Processing
Authorization Objects Authorization Customer company code: Authorization A Authorization object Object class 0001-0009 Object: Customer company code Financial Accounting display, change Company Code Activity Customer company code: Authorization B * display
User Master Maintenance:Authorizations (S_USER_AUT) 01 Create 02 Change 03 Display 06 Delete 07 Activate 08 Display change documents 22 Assign authorization profiles 24 Archive ACTIVITY AUTH Limited name space for the assignment of authorization names OBJECT Authorization objects User Administration Authorizations Object Fields Value Meaning
Central User Administration With central user administration, the creation and maintenance of all user master data is performed in a single R/3 System QAS System Client 100 Client 200 Client 100 Client 200 Client 300 PRD System Client 100 DEV System