You are on page 1of 146

IBM Global Technology Services

SAP BASIS TRAINING


User and Authorization

10/10/2006
IBM China
GuoLei, AMS, guol@cn.ibm.com

Integrating for Client Success

IBM Global Technology Services

Copyright IBM Corporation 2006

IBM Global Technology Services

R3

Copyright IBM Corporation 2006

IBM Global Technology Services

Copyright IBM Corporation 2006

IBM Global Technology Services

Copyright IBM Corporation 2006

IBM Global Technology Services

Copyright IBM Corporation 2006

IBM Global Technology Services

SPEX SAP R/3 Project

Version 1.0

Authorization Concept

SAP .

Copyright IBM Corporation 2006

IBM Global Technology Services

SPEX SAP R/3 Project

Version 1.0

Authorization Concept

SAP

Copyright IBM Corporation 2006

IBM Global Technology Services

Copyright IBM Corporation 2006

IBM Global Technology Services

Authorization Concept 2

Prof
Activit ile 1
y Grou

p1

Pro
Activi file 2
ty Gro
up 2

Profile
3
Manu
al

User Master Record

Profile(s)

Data Bank

Authorization(s)

Field Values

SAP AG 1999
Copyright IBM Corporation 2006

IBM Global Technology Services

Copyright IBM Corporation 2006

IBM Global Technology Services

SPEX SAP R/3 Project

Version 1.0

Authorization Concept

SM35

XK05

SE38

XK04

FF_5

MB53

FEBP

MB24

F-04

Copyright IBM Corporation 2006

IBM Global Technology Services

SPEX SAP R/3 Project

Version 1.0

Authorization Concept

IDs

:
John Doe
:

WO

TCODE1
TCODE2
TCODE3
TCODE4
TCODE5
TCODE
6
TCODE
7
TCODE
8
TCODE
9

Mary Jones
:

TCODE1
TCODE2
TCODE3
TCODE10
TCODE11
TCODE12
TCODE13
TCODE14
TCODE15

Copyright IBM Corporation 2006

IBM Global Technology Services

SPEX SAP R/3 Project

Version 1.0

Authorization Concept

Copyright IBM Corporation 2006

IBM Global Technology Services

SPEX SAP R/3 Project

Version 1.0

Authorization Concept

Copyright IBM Corporation 2006

IBM Global Technology Services

SPEX SAP R/3 Project

Version 1.0

Authorization Concept

Copyright IBM Corporation 2006

IBM Global Technology Services

SPEX SAP R/3 Project

Version 1.0

Authorization Concept

SAP .

Copyright IBM Corporation 2006

IBM Global Technology Services

SPEX SAP R/3 Project

Version 1.0

Authorization Concept

!
()

Copyright IBM Corporation 2006

IBM Global Technology Services

Authorization Objects

Authorization

Object
class

Authorization object

Financial
Accounting

Object: Customer
company code
Company Code
Activity

Customer company code:


Authorization A
0001-0009
display, change

Customer company code:


Authorization B
*
display

SAP AG 1999
Copyright IBM Corporation 2006

IBM Global Technology Services

SPEX SAP R/3 Project

Version 1.0

Authorization Concept

: MIRO
.

Copyright IBM Corporation 2006

IBM Global Technology Services

SPEX SAP R/3 Project

Version 1.0

Authorization Concept

Copyright IBM Corporation 2006

IBM Global Technology Services

SPEX SAP R/3 Project

Version 1.0

Authorization Concept

1
2
Copyright IBM Corporation 2006

IBM Global Technology Services

SPEX SAP R/3 Project

Version 1.0

Authorization Concept

:
-

Copyright IBM Corporation 2006

IBM Global Technology Services

SPEX SAP R/3 Project

Version 1.0

Authorization Concept

Object parameters determine the specific permissions


a user can perform in a transaction.
:

This user can perform


WHAT ACTIVITIES to
WHICH ACCOUNT
TYPES?

Copyright IBM Corporation 2006

IBM Global Technology Services

SPEX SAP R/3 Project

Version 1.0

Authorization Concept

!!!


!!!

Copyright IBM Corporation 2006

IBM Global Technology Services

Copyright IBM Corporation 2006

IBM Global Technology Services

Copyright IBM Corporation 2006

IBM Global Technology Services

1.
2./Template Role/
3.
4.
5.

Copyright IBM Corporation 2006

IBM Global Technology Services

1.
2.SAP

Copyright IBM Corporation 2006

IBM Global Technology Services

,
1.DEBUG,,
,
2.

3.I.T.useruserleader
useruser
I.T.

Copyright IBM Corporation 2006

IBM Global Technology Services

SAP
SAP User account
-Address
-Logon data
-Group
............

Bind with

SAP

Assign to

Role template
-Description
-Menu
-Authorizations

Authorization profile
-Object class
-Authorization object
-Authorizations
..
Copyright IBM Corporation 2006

IBM Global Technology Services

SAP

User accountUSER ID
RoleUSERSAP
S/OUSER
(Role)
sap4.0
user(!!)
single role composite role

Copyright IBM Corporation 2006

IBM Global Technology Services

SAP
Profile: sap4.0Role
sap4.6csap

Template Role:Rolesingle role.


(sapDerive
Role(sapadjust)

Copyright IBM Corporation 2006

IBM Global Technology Services

SAP
USER
USER

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
Role:
G+Template Role()assignuser id
-

G+
G+-1

Template Role
Template Role

Z+User Role,assignuser id
-

Z+User ID+
:Template Role
Z+User ID+-1:Template Role
Z+User ID+Exception
:Role,

Y+Basis Role,assignuser id
-

Y+

:Basis Role

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
/Rolename
AR

A/R
CO-AR
G+CO-AR
G+CO-AR-1
Y+CO-AR

Template Role
Template Role
Basis Role

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
Template Role

G +-1
G + CO CO

Template Role

G+-1
G + CO CO 1

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

User RoleuserRole.
-

Z+USER ID
W+ USER ID

Z+PSC1-ACT01+CO-CO

Basis Role
Role.
-

Y+
Y + CO CO

Copyright IBM Corporation 2006

IBM Global Technology Services

.Role
1.Template Role
G
2.User Role:
Z
3.Basis Role:
Y

Copyright IBM Corporation 2006

IBM Global Technology Services

.USER ID
USER IDID
PSC1-ENG01PSC1PP
PPI.T.

Copyright IBM Corporation 2006

IBM Global Technology Services

.
userMIS
user,IDI.T.
I.T.

I.T.

Copyright IBM Corporation 2006

IBM Global Technology Services

User ID, Role, Profile


sap4.6ProfileRole
RoleProfileUser
IDRole

Copyright IBM Corporation 2006

IBM Global Technology Services

USER ID
T CODE SU01

User ID

Copyright IBM Corporation 2006

IBM Global Technology Services

USER ID

Copyright IBM Corporation 2006

IBM Global Technology Services

USER ID

MIS
MISUser
ID

Copyright IBM Corporation 2006

IBM Global Technology Services

USER ID

Copyright IBM Corporation 2006

IBM Global Technology Services

USER ID

save
USER ID
USER IDID
(Assign) USER

Assign
Assign Role
Role
Copyright IBM Corporation 2006

IBM Global Technology Services

Role
RoleT CODE PFCG
1.;
RoleZ+USERID+EXCEPTION

2.;
Z+USERID+

3.COPY
Z+USERID+-1

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
FORTEST, VA01YF30

PFCG

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Role name

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Role name

Role
save

Role
menu
Copyright IBM Corporation 2006

IBM Global Technology Services

Role
MenuUSER MENU

TEXT

T code
SAPMenuT code
RoleCopy Menu

Copyright IBM Corporation 2006

IBM Global Technology Services

Role


EXCEPTION(Standark)
(Add On)
User
MIS

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

USER

user

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

SAPT CODE
SAP
T CODET CODE
T code

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

T CODE(T CODE

T code

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

SAP

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
T codeObject

OBJECT
OBJECT
OBJECT

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
ObjectT code
T codeuser

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Org.level.
sap

Org.level
Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Org.Level

Object
value

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Org.LevelObject value
ObjectObject

Copyright IBM Corporation 2006

IBM Global Technology Services

Role


Object
*(star)*All AuthorizationObject

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
T code
T codeObject

Y-AUTH-PRT

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Object.
T codeT
codeuser

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
Authorization

USER,Assign USER ID Role

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

USER COMPARE
Complete
compare
COMPARE
Assign
FORTEST
VA01YF30

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
,Role RoleMenu,
AuthorizationOrg.level) Role,Role
Role Role 1

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
Role.
FORTEST, APAP
Template Role G+CO-AP
CreateRole

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Template Role,Enter.

YES

YES

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Template
Role,
Authorization

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Profile

1.Org.level
X,Org.level
2.SAVEProfile

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
3.Edit
Copy data,

Object

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Org.level
Org.levelObject
I.T.

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Org.level)
AssignUSER ID,

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Role

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

APTemplate Role G+CO-AP1

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

PFCGTemplate Role
COPY
Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Role

-1Rolemenu

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Org.level

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Role,
AssignUSER IDRole

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

-1Template Role Role,
Org.levelObject
-1Object

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

1.Merge
2./T Code
3.Role
4.Adjust

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

RoleT Code/
MenuMenuAuthorization
User
Authorization

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

RoleProfile
Profile
ProfileMenuProfile

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
ProfileObject

Profile
Object
RoleMenuObject
MergeItem

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Profile

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleMerge
RoleT CodeObject
Value
MergeObjectValue
Item

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleMerge

Object,Object,Value

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleMerge

UtilitiesMerge

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleMerge

ObjectActivityGroup
AcitivityGroup
MergeObjectItem
ItemMerge

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleMerge
RoleMergeRoleObject Menu
AuthorizationUser

T Code : FSS0

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleMerge

ProfileObject

FSS0Object
(RoleT
CodeObject)

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleMerge

ProfileObject

Object
Merge.

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleMerge
Item
ObjectT Code

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleT Code
T Code
MenuRole

AuthorizationRole

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleT Code

MenuRoleS_TCODEObject
ObjectRoleT CodeMenu

Object

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleT Code

MenuT CodeProfile
ObjectT CodeT Code
MenuT Code
T Code

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleRole
Role ARole BInsert
Role BObjectRole A

Profile

Role
BProfile
Name

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleRole
ObjectRole B
Role A
Role B

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleAdjust
AdjustRole
RoleRoleCopy Data
RoleObject Value
RoleObject ValueRoleAdjust

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleAdjust

DisplayTemplate RoleProfileGenerate
derived roles
ChangeTemplate RoleAdjustTemplate Role

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleAdjust
Copy Data Adjust

Copy Data

Adjust

Role

Role

Role
RoleRole

Client
RoleRole

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
1.Request Num
2.Release
3.Transport

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleRequest Num

Role

PFCG
Role

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleRequest Num

Single Role

Role

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleRequest Num

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleRequest Num

Role

client
AssignUser ID

Client
Compare

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleRequest Num
Release
Request Num

Request

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleRequest Num

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleRequest Num

Request Num, C00KT00K


.

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleRequest Num
RoleRequest Num

Key Role

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleRelease
Release T Code SE10

Request Num

Modifiable

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleRelease

Request Num,
Header
Item

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleRelease
Release ItemNumHeader
Num
ItemNum

Release HeaderNum
HeaderNum

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Basis
Unix
YATP
QASYATPQA
Request NumReleaseNumber

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

Request NumServer

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
Role Request NumRelease
SE10,Num

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
ReleaseNumber
Number

Copyright IBM Corporation 2006

IBM Global Technology Services

Role

PFCGRole
Profile

Role

Copyright IBM Corporation 2006

IBM Global Technology Services

Role
Role

1.RoleRequest Num
2.Role
3.Release;(Role
4.

Copyright IBM Corporation 2006

IBM Global Technology Services

User IDSU01

Copyright IBM Corporation 2006

IBM Global Technology Services

RoleZW

Role

USER

Copyright IBM Corporation 2006

IBM Global Technology Services

Debug/

1.SU53

2.SUIM

Copyright IBM Corporation 2006

IBM Global Technology Services

Debug/SU53

/NSU53

Copyright IBM Corporation 2006

IBM Global Technology Services

Debug/SU53

Copyright IBM Corporation 2006

IBM Global Technology Services

Debug/SU53


SU53

Copyright IBM Corporation 2006

IBM Global Technology Services

Debug/SUIM
SUIMInformation

T CodeT CodeRole

Copyright IBM Corporation 2006

IBM Global Technology Services

Debug/SUIM

Copyright IBM Corporation 2006

IBM Global Technology Services

Debug/SUIM

T CodeT codeRole
RoleMenuProfile

Copyright IBM Corporation 2006

IBM Global Technology Services

SD
SDS/O Billing BlockYS08

Copyright IBM Corporation 2006

IBM Global Technology Services

1.ObjectStandard/Manually/Maintained/Changed
2.Object Value VS Org.level

Copyright IBM Corporation 2006

IBM Global Technology Services

Object

Copyright IBM Corporation 2006

IBM Global Technology Services

Object
ProfileObject

NEW OLD
NEWObjectItemValue, Profile SaveOLD
OLD ObjectItem

Copyright IBM Corporation 2006

IBM Global Technology Services

Object

Standard
MaintainedValueItem
ChangedValueItem

Copyright IBM Corporation 2006

IBM Global Technology Services

Object Value VS Org.level


Object ValueOrg.levelAdjustRole
Role

1.Adjust
Org.levelRoleAdjustRoleRoleAdjustRole

Object.ValueRole

Copyright IBM Corporation 2006

IBM Global Technology Services

Object Value VS Org.level


2.ValueOrg.level
ObjectItemValueOrg.level
$Org.level
Org.levelObjectOrg.level
Object$

Copyright IBM Corporation 2006

IBM Global Technology Services

Object Value VS Org.level


RoleObject ValueRoleAdjust
RoleObject ValueOrg.level
Object ValueRoleAdjustRoleObject Value
RoleRoleObject Value
RoleValue$XXXX)Role
Org.level

Copyright IBM Corporation 2006

IBM Global Technology Services

Object Value VS Org.level


3.OrgValue

ValueNULL()
$Key

ObjectObject

Copyright IBM Corporation 2006

IBM Global Technology Services

Q&A

Copyright IBM Corporation 2006

You might also like