Showing posts with label BI Authorizations. Show all posts
Showing posts with label BI Authorizations. Show all posts

Tables required for SAP Security consultants

To work on daily issues S&A team need tables names related to  authorizations to fix the authorization issues.

BW Related Tables :

RSECHIE                        Status of Authorization Hierarchies
RSECHIEVIEW                    Hierarchy Authorizations Join for All ACT
RSECLOG                        Storage for Authorizations Logs xml
RSECLOG_CL                     Analysis Authorizations BI: Logging Active
RSECTXT                        Authorization Texts
RSECUSERAUTH                   BI AS Authorizations: Assignment of User Auth
RSECUSERAUTH_CL                BI AS Authorizations: Assignment of User Auth(change log)
RSECVAL                        Authorization Value Status
RSECVAL_CL                     Authorization Value Change (Change Log)
RSECVAL_CL_VIEW                View for Versioning
RSECVALVIEW                    Join of USERAUTH, RSECVAL and RSECBIAU: AlRSECVAL_CL                     Authorization Value Change (Change Log)
RSECVAL_CL_VIEW                View for Versioning
RSECVALVIEW                    Join of USERAUTH, RSECVAL and RSECBIAU: All ACT & A-Versions

ECC tables for all security consultant:

USR* Tables:


USR01 User master record (runtime data)
USR02 Logon Data (Kernel-Side Use)
USR03 User address data
USR04 User master authorizations
USR05 User Master Parameter ID
USR06 Additional Data per User
USR06SYS System-Specific User Classification (Licen
USR07 Object/values of last authorization check
USR08 Table for user menu entries
USR09 Entries for user menus (work areas)
USR10 User master authorization profiles
USR11 User Master Texts for Profiles (USR10)
USR12 User Master Authorization Values
USR13 Short Texts for Authorizations
USR14 Surchargeable Language Versions per User
USR15 External User Name (Replaced By Table USRA
USR16 Values for Variables for User Authorizatio
USR20 Date of last user master reorganization
USR21 Assign user name address key
USR40 Table for illegal passwords
USR41 User master: Additional data
USRVAR Variants for Critical Authorizations

 Email id for users:

ADR6 E-Mail Addresses (Business Address Service

 AGR* tables  related to Roles.


AGR_1251 Authorization data for the activity group
AGR_1252 Organizational elements for authorizations
AGR_USERS Assignment of roles to users
AGR_TCODES Assignment of roles to Tcodes
AGR_AGRS Roles in Composite Roles
AGR_DEFINE Role definition/Single and derived roles

Developer Key table:

DEVACCESS Table for development user/DEV keys

Transport Request :


E070                            Change & Transport System: Header of Requests/Tasks
E071                         System: Object Entries of Requests/Tasks

 















Trouble shooting in SAP BW/BI Security

Here we will discuss some access issues in SAP.

In SAP , most of the issues will be assigned to security team as the users will think because of  less authorizations they facing issue while performing activity.

immediately users contact security team to provide access

to help users and reduce tickets in security team, we should guide users properly.

inform to user to provide SU53.

Mass user comparison and Mass Profile Generation in SAP Security

In SAP , most of the authorization issues arise because of incomplete profile generation or user comparison.

To accomplish this issue SAP BASIS/ SECURITY consultants should schedule a background job "PFCG_TIME_DEPENDENCY" to run (hourly/day)

and we can perform this activity manually for Mass users /Mass Roles by using T-codes PFUD / SUPC to update User Master record immediately.

Transaction codes required for SAP SECURITY CONSULTANT

To work in SAP as a Security Consultant , require below T-codes .
First will discuss what SAP S&A team will work in SAP System.
1)user Administration
2)Role Administration
3)Trouble shooting
4)Trace
5)Find out Users information
6)Users related information using Tables
7)Roles related information using Tables.
8)Transport request status
Find below for Transaction codes

User Administration or User set up or User ID creation in SAP Security

To log in to SAP, each user needs User account or ID to be existing in the system. Then only functional or developer can develop the objects in systems.
To get the access to SAP, requester should contact Security & Authorizations team.
S&A team will take necessary actions (approvals) from respective team and then they will set up the user.
Users must be assigned to relevant roles to their user master records before user can use the SAP System.
A user can only log on to the system if he or she has a user master record.
To set up users T-code is SU01.
To set up user below information is required.
·         Last name , password & user type