cancel
Showing results for 
Search instead for 
Did you mean: 

can I use object S_USER_GRP other than I_IWERK to segregate plant users' authorization

former_member588416
Discoverer
0 Kudos

In my company, we only have PLM system, MM module is not implemented.

I am working on authorization now, considering to put plant code value in ' user group' filed through SU01, insert S_USER_GRP in roles to differential plant authorization.

I know it will work for sure. However SAP Security gurus, I will need your opinion. Is there any risk behind?

Thank you!

Accepted Solutions (1)

Accepted Solutions (1)

alessandr0
Active Contributor
0 Kudos

Hi Iola,

just keep in mind that authorizing S_USER_GRP might open up acess in the user master transactions like SU01, etc. if users get access to it. I am not an PLM expert, but you might instead consider a custom authoriztion object.

Regards, Alessandro

Answers (1)

Answers (1)

former_member588416
Discoverer
0 Kudos

Hi Alessandro,

Thank you very much for the reply. I think you are right. Did a test, S_USER_GRP is only for user master maintenance. Need a custom authorization object... yes...

Thanks,

Iola