Showing posts with label SAP Security. Show all posts
Showing posts with label SAP Security. Show all posts

Thursday, 13 October 2011

Move roles from one client to another in SAP


Transporting User Roles between Clients (Transport System Method)

When a modification is made to a role in the 100 client, the roles must be transported to the 800 client.  One role, several roles, or all roles can be done if needed.  They can all be added to the same transport change request.  After the roles have been moved to other clients, you will need to log on to each of those clients and do a user comparison.  You will also need to do a text comparison in client 100 of the appropriate SAP system.

1.               Log on to client 100 of the appropriate SAP system.
2.               Go to transaction PFCG.
3.               On the Role maintenance screen, type in the Role name of the first role to be transported.  Click the Truck picture-icon.
4.               You will see an Information popup.  Click the green √ picture-icon.
5.               In the Choose objects popup, unclick the □s beside User assignment and Personalization.  If you want to transport the users along with the role, profiles, and authorizations, you can √ the □ to the left of User assignment.  Click the green √ picture-icon.
6.               On the Prompt for Customizing request popup, click the blank page picture-icon to create a new change request.  On the Create Request popup, fill in the Short description and click the Save picture-icon.  You will be returned to the Prompt for Customizing request popup which contains the generated change request number for this system change. Click the green √ to continue.
7.               You will see a Data entered in change request message in the status bar at the bottom of the screen.  Now enter the name of the next role to be transported and click the Truck picture-icon.
8.               You will see an Information popup.  Click the green √ picture-icon.
9.               In the Choose objects popup, unclick the □s beside User assignment and Personalization. If you want to transport the users along with the role, profiles, and authorizations, you can √ the □ to the left of User assignment. Click the green √ picture-icon.
10.           On the Prompt for Customizing request popup, continue to use the same transport you created in step 6.  Click the green √ to continue.
11.           Continue to perform steps 7 through 10 until all the roles you need to transport have been attached to the transport change request.
12.           The generated transport can now be released and transported into the clients needing the modified roles.
13.           You may now leave the PFCG transaction.

Modify a user role in SAP



1.               Log on to client needing the role change.
2.               Go to transaction PFCG.
3.               On the Role Maintenance screen, either type in the role name to be changed or select it from a dropdown.  Press Enter to confirm that the role is found.
4.               Click the Change Role little yellow pencil button role button or press F6.
5.               Click the Authorizations tab and then the Change Authorization Data button.
6.               On the Change Role: Authorizations screen, expand and change the authorizations you need to adjust.  When finished click first the Save button and then the Generate button – looks like a little red and white beachball.
7.               Back out to the Change Roles screen and click the User tab.  Click on User Comparison and then Complete Comparison.  Once the comparision is done, click Save one more time and you are done!

Grant a transaction to a user in SAP


Granting Transaction Access to a User via Role

1.    Log on to the applicable SAP instance and client.
2.    Go to transaction SU01.
3.    On the User Maintenance: Initial Screen screen, fill in the User ID for the user you want to change, either by typing it in or choosing it from the drop down.  Click the little yellow pencil Change button.
4.    On the Maintain User screen, click on the Roles tab.  Fill in the new role in the first available Role field.  Press ENTER to confirm that the role exists.  Click the Save button.
5.    Make sure to use transaction PFCG to run a user comparion to rebuilt the role-to-user connections.
6.    You may now leave the PFCG transaction.

create a user role in SAP




The easiest way to create a new user role is to copy an already existing user role, either one of your own or one of the ones provided to you in the installation of SAP.  So let’s assume that you have none of your own and use one of the SAP role templates provided.  It might assist you with picking one of these roles if you have someone dump the appropriate information into a spreadsheet containing the Role Name, Role Description, Transactions contained in the Role, and the Transaction description.  The SQL query would be something like this:

SELECT AGR_TEXTS.AGR_NAME, AGR_TEXTS.TEXT, AGR_TCODES.TCODE, TSTCT.TTEXT
   FROM AGR_TEXTS, AGR_TCODES, TSTCT
WHERE AGR_TEXTS.MANDT = '000' AND
   AGR_TEXTS.SPRAS = 'E' AND
   AGR_TEXTS.LINE = 0 AND
   AGR_TCODES.MANDT = '000' AND
   AGR_TCODES.AGR_NAME = AGR_TEXTS.AGR_NAME AND
   TSTCT.SPRSL = 'E' AND
   TSTCT.TCODE = AGR_TCODES.TCODE
ORDER BY AGR_TEXTS.AGR_NAME, AGR_TCODES.TCODE;

This query should be changed based on the details of your SAP instance.  Identify the roles(s) to be used as the source for your role copy.

1.               Log on to client needing the role.
2.               Go to transaction PFCG.
3.               On the Role Maintenance screen, either type in the role name to be copied or select it from a dropdown.  Press Enter to confirm that the role exists.
4.               Click the Copy role button or press Shift+F11.
5.               One the Query popup box, fill in the to role field with the name to be given the new role.  Come up with a standard that everyone follows so the base original role is designated in some way so you don’t forget where you got the original.  The name must begin with Z or Y. Most people will add a Z- in the first two characters of the role name.  If you want to only select specific roles from a Composite role, you would click the Copy selectively button, otherwise click the Copy all button.

6.               Once the role has been copied, you will be taken back to the original PFCG screen where you will see the name of your new role.  Change you Role description and save the new role before working with it any further 



1.               Log on to client needing the role change.
2.               Go to transaction PFCG.
3.               On the Role Maintenance screen, either type in the role name to be changed or select it from a dropdown.  Press Enter to confirm that the role is found.
4.               Click the Change Role little yellow pencil button role button or press F6.
5.               Click the Authorizations tab and then the Change Authorization Data button.
6.               On the Change Role: Authorizations screen, expand and change the authorizations you need to adjust.  When finished click first the Save button and then the Generate button – looks like a little red and white beachball.
7.               Back out to the Change Roles screen and click the User tab.  Click on User Comparison and then Complete Comparison.  Once the comparision is done, click Save one more time and you are done!

Copy an existing role to a new role in SAP




The easiest way to create a new user role is to copy an already existing user role, either one of your own or one of the ones provided to you in the installation of SAP.  So let’s assume that you have none of your own and use one of the SAP role templates provided.  It might assist you with picking one of these roles if you have someone dump the appropriate information into a spreadsheet containing the Role Name, Role Description, Transactions contained in the Role, and the Transaction description.  The SQL query would be something like this:

SELECT AGR_TEXTS.AGR_NAME, AGR_TEXTS.TEXT, AGR_TCODES.TCODE, TSTCT.TTEXT
   FROM AGR_TEXTS, AGR_TCODES, TSTCT
WHERE AGR_TEXTS.MANDT = '000' AND
   AGR_TEXTS.SPRAS = 'E' AND
   AGR_TEXTS.LINE = 0 AND
   AGR_TCODES.MANDT = '000' AND
   AGR_TCODES.AGR_NAME = AGR_TEXTS.AGR_NAME AND
   TSTCT.SPRSL = 'E' AND
   TSTCT.TCODE = AGR_TCODES.TCODE
ORDER BY AGR_TEXTS.AGR_NAME, AGR_TCODES.TCODE;

This query should be changed based on the details of your SAP instance.  Identify the roles(s) to be used as the source for your role copy.

1.               Log on to client needing the role.
2.               Go to transaction PFCG.
3.               On the Role Maintenance screen, either type in the role name to be copied or select it from a dropdown.  Press Enter to confirm that the role exists.
4.               Click the Copy role button or press Shift+F11.
5.               One the Query popup box, fill in the to role field with the name to be given the new role.  Come up with a standard that everyone follows so the base original role is designated in some way so you don’t forget where you got the original.  The name must begin with Z or Y. Most people will add a Z- in the first two characters of the role name.  If you want to only select specific roles from a Composite role, you would click the Copy selectively button, otherwise click the Copy all button.
6.               Once the role has been copied, you will be taken back to the original PFCG screen where you will see the name of your new role.  Change you Role description and save the new role before working with it any further

Attach a user to a role in SAP




1.               Log on to the appropriate SAP system and the client where the user needs the role. Go to transaction SU01.
2.               On the User Maintenance: Initial Screen screen, type in the user’s name and press Enter to confirm that the user exists.
3.               Click the Change button or press Shift+F6.
4.               On the Maintain User screen, click on the Roles tab.  Fill in the name(s) in the field(s) provided, and when done press Enter.
5.               Click the Save button.
6.               Go to transaction PFCG, and on the Role Maintenance screen, type in the name of the role to which the users where added and press Enter to confirm exist of the role.
7.               Click the Change role little yellow pencil button. 
8.               On the Change Roles screen, click the User tab.  Click on User Comparison and then Complete Comparison.  Once the comparision is done, click Save one more time and you are done!

Attach a role to a user in SAP




1.               Log on to the appropriate SAP system and the client where the user needs the role. Go to transaction SU01.
2.               On the User Maintenance: Initial Screen screen, type in the user’s name and press Enter to confirm that the user exists.
3.               Click the Change button or press Shift+F6.
4.               On the Maintain User screen, click on the Roles tab.  Fill in the name(s) in the field(s) provided, and when done press Enter.
5.               Click the Save button.
6.               Go to transaction PFCG, and on the Role Maintenance screen, type in the name of the role to which the users where added and press Enter to confirm exist of the role.
7.               Click the Change role little yellow pencil button. 
8.               On the Change Roles screen, click the User tab.  Click on User Comparison and then Complete Comparison.  Once the comparision is done, click Save one more time and you are done!





Making user changes one-at-a-time can be extremely time consuming not to mention boring.  SAP has provided mass change transaction to help eleviate the tediousness of making many user changes.  It should be noted, however, that the mass change transaction is limited as to the changes that can be made.  For example, you cannot change the password for multiple users.  Also note that it is best to make one type of mass change at a time.  For example, you need to add a new role to and delete an existing role from 20 users.  The best method to achieve this would be to first do a mass change to add the new role.  Save the changed users.  Then delete the existing role from the same 20 users. 

1.               Log on to the appropriate SAP system and the client where the user changes are to take place.
2.               Go to transaction SU10.
3.               On the User Maintenance: Mass Changes Initial Screen screen, you need to select whether you will select users based on Address Data or Authorization Data and click the appropriate button.  If you click Address Data, you can find users with any combination of First name, Last name, User ID, Company, City, Building, Room, Extension, Department, and Cost Center.  If you opt to use Authorization Data, you can specify a combination of Groups, Reference User, Authorizations, Athorization Objects, and many other fields.  For either method, fill in the fields you want to search on in the Users by Complex Selection Criteria screen, and click the Execute button.
4.               On the Users by Complex Selection Criteria screen, you can click “on” the users to be changed, or click the Select All button.  Once all the users you want to change have been selected, click the Transfer button.
5.               Back on the Maintenance: Mass Changes Initial Screen screen, you can select all the users on the screen again by clicking the Select All button or change your mind and make any last minute corrections.  Once you have all the users selected that you want to change, click User → Change.
6.               On the Mass User Changes screen, scroll through the tabs, changing data and clicking the Add or Remove button for each correction.  Please note, each SU10 batch run must use all Adds or all Removes but never a mixture.  Do all Adds in one run and then all Removes in another. Once all your changes have been made, click the Save button.
7.               On the Mass changes popup, you will see how many users you are about to change.  To make the changes, click on Yes. 
8.               On the Log Display screen, you will see a log of the changes you made.  Expand the list to see the transactional details.
9.               You may now leave the SU10 transaction.