SAP Authorizations Using eCATT to maintain roles - SAP Basis

Direkt zum Seiteninhalt
Using eCATT to maintain roles
Define S_RFC permissions using usage data
Two equal permissions that meet the first maintenance status condition are also combined when all the values of the two permissions differ in one field or when a permission with all its fields is included in the other. However, if there are open permission fields in a permission, they will not be combined unless all permission fields in the permission values are the same.

Trace after missing permissions: Run the System Trace for Permissions (ST01 or STAUTHTRACE transaction) to record permission checks that you want to include in the role (see Tip 31, "Optimise Trace Evaluation"). Applications are logged through the Launch Permissions checks.
Basic administration
To maintain suggestion values, use the transaction SU24. Here you can view and customise suggestion values for all types of applications, such as SAP GUI transactions, RFC building blocks, or Web Dynpro applications. One way to maintain suggestion values is to use the system trace, which is linked to the transaction SU24 after inserting the support package named in SAP Note 1631929 and the correction instructions. This means that from the transaction SU24 you start the system trace, collect trace data and use this data directly during maintenance.

Transaction SE63 allows you to translate a variety of text in the SAP system. You can find the relevant texts for the eligibility roles via the menu path: Translation > ABAP Objects > Short Texts In the pop-up window Object Type Selection that appears, select the S3 ABAP Texts node and select the ACGR Roles sub-point.

The possibility of assigning authorizations during the go-live can be additionally secured by using "Shortcut for SAP systems".

The transactions and reports included in the SAP_AUDITOR_TAX collection role have been expanded to include additional checks that define the audit period.

In the SAP system, passwords are locked when the maximum number of allowed password login errors is reached.
SAP BASIS
Zurück zum Seiteninhalt