Showing posts with label SAP User Administration. Show all posts
Showing posts with label SAP User Administration. Show all posts

Thursday, 13 October 2011

Modify a user role in SAP




1.               Log on to client needing the role change.
2.               Go to transaction PFCG.
3.               On the Role Maintenance screen, either type in the role name to be changed or select it from a dropdown.  Press Enter to confirm that the role is found.
4.               Click the Change Role little yellow pencil button role button or press F6.
5.               Click the Authorizations tab and then the Change Authorization Data button.
6.               On the Change Role: Authorizations screen, expand and change the authorizations you need to adjust.  When finished click first the Save button and then the Generate button – looks like a little red and white beachball.
7.               Back out to the Change Roles screen and click the User tab.  Click on User Comparison and then Complete Comparison.  Once the comparision is done, click Save one more time and you are done!

Grant a transaction to a user in SAP




*** Since SAP R/3 4.5, this is not the standard for user authorizations.
***


Granting Transaction Access to a User via Role

1.    Log on to the applicable SAP instance and client.
2.    Go to transaction SU01.
3.    On the User Maintenance: Initial Screen screen, fill in the User ID for the user you want to change, either by typing it in or choosing it from the drop down.  Click the little yellow pencil Change button.
4.    On the Maintain User screen, click on the Roles tab.  Fill in the new role in the first available Role field.  Press ENTER to confirm that the role exists.  Click the Save button.
5.    Make sure to use transaction PFCG to run a user comparion to rebuilt the role-to-user connections.
6.    You may now leave the PFCG transaction.




*** Since SAP R/3 4.5, this is not the standard for user authorizations.
***


Revoking Authorizations from a User via Role

Use the same procedure as Adding Authorization Objects and/or Authorizations to a
Role


 Revoking Transaction Access from a User via Profile

*** Remember that profiles are NOT the standard way to implement SAP security. ***


Delete a user role in SAP




1.               Log on to client needing the role deletion.
2.               Go to transaction PFCG.
3.               On the Role Maintenance screen, either type in the role name to be changed or select it from a dropdown.  Press Enter to confirm that the role is found.
4.               Click the Role Delete button or Shift+F2.
5.               On the Delete Role popup, confirm that you wish to delete the deletion.  If you get an Information popup, confirm it also.
6.               Your deletion will return a successful message in the bottom status bar.