Authorization Management: at The Customer Site
Authorization Management: at The Customer Site
Authorization Management: at The Customer Site
PUBLIC
Authorization Management at the Customer Site
At the customer site, tables USOBX_C and USOBT_C control the behavior of Role Maintenance.
After a new installation, these tables are empty, and must be filled with values before Role
Maintenance is used for the first time.
Authorization Business
Development User
Management
ABAP
Workbench
SU25 1 Logs on to the SAP
system
Creates application containing
1 AUTHORITY-CHECK Navigates using
1 Copies options in the role
2 Test application authorization data menu
Accesses applications
SU22 SU24 for which the role
contains authorizations
Creates authorization
3 proposals
2 Adjusts authorization
Determines necessary checks
and enters default values
defaults to customer‘s
needs
PFCG PFCG
USOBX_C
USOBT_C
Composite Role
Role
Transaction 1 SU24
Transaction 2 USOBX_C
Report 0815
USOBT_C
User
SU25
SU22
USOBX
USOBT
SAP Customer
Defaults SU25 Values
(Step 2A – 2D)
USOBX 2A: Compares the new tables USOBX and USOBX_C
USOBT with USOBX_C and USOBT_C
Authorization proposals are then refined/adjusted for this specific customer system
ABAP
SU25 1 Logs on to the SAP system
Workbench
Navigates using options in the
1 Creates application containing role menu
AUTHORITY-CHECK
1 Copies authorization data Accesses applications for
which the role contains
2 Test application authorizations
SU22 SU24
Creates authorization
3 proposals 2 Adjusts authorization defaults
Determines necessary checks to customer‘s needs
and enters default values
PFCG PFCG
SU24
Customer Values USOBX_C USOBT_C
Proposal Status
For each application type:
Which checks No
exist?
Which checks Yes, Without Values
are performed?
What is entered in Yes
Role Maintenance?
What does Role
Maintenance propose?
Objects & Field Values
At the customer site, the administrator creates roles that meet the needs of the customer
ABAP
SU25 1 Logs on to the SAP system
Workbench
Navigates using options in
1 Creates application the role menu
containing AUTHORITY-
CHECK 1 Copies authorization Accesses applications for
2 Test application data which the role contains
authorizations
SU22 SU24
Creates authorization
3 proposals 2 Adjusts authorization
Determines necessary checks defaults to customer‘s
and enters default values needs
PFCG PFCG
Work Center
Description:
- Activity 1 Role
- Activity 2
- ...
Determine activities
Assign users
Maintained Maintenance
Maintenance
Connection between this object
entry and the role menu exists
Standard
Role 2
Role 5
Role 1 Role 3 Role 4 Role 6 Role 7
Composite Composite
Role A Role B
Composite Role
Role 1
Role 1 Menu
Read Menu
Purchasing
Purchase Order
Delivery
Material Price
Purchasing
PRs
Purchase Order
Delivery Full menu can be changed!
Role 2 Menu Material Price (entries can be
Inventory restructured
Inventory and deleted)
Count
Count
Role 2 PRs
Material Price
Project-IMG
Customizing-
Role
Business users log on to the SAP system and access applications for which they have
authorizations
ABAP
SU25 1 Logs on to the SAP
Workbench
system
1 Creates application
Navigates using options
containing AUTHORITY-
1 Copies in the role menu
CHECK
2 Test application authorization data Accesses applications
for which the role
contains authorizations
SU22 SU24
Creates authorization
proposals Adjusts authorization
3 Determines necessary 2
defaults to customer‘s
checks and enters needs
default values
PFCG
PFCG
Start Transaction
Check for S_TCODE ME21N
ME21N
Program
Check for Values (program) in
M_BEST_EKO
Partner logo