cancel
Showing results for 
Search instead for 
Did you mean: 

SAP Authorization Objects Concept

Former Member
0 Kudos

Hello Consultants,

I am somewhat confused between authorizations in SAP...

I have a simple scenario.

1. I have a Tcode: PBA7. The program underneath is RPAPRT09.

2. I have created a Z Role and attached this role to my tcode PBA7.

3. I have attached two users: A and B, to this role.

Now, A and B will be able to access this tcode from their R/3.

There is an option in the attributes of the program and the tcode for authorization groups.

I don't understand how does that authorization group give further restrictions.

Recently, an Audit in our company conveyed that our programs are exposed and not secure and we have been advised to give auth groups to programs.

Please let me know how does this work?

I have observed a few standard SAP programs and they are not attached with any such auth groups. eg. PBA7.

Thanking in anticipation.

Rahul.

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

Hi Rahul

Sometimes if user get access to se38 they execute the program without TCode and therefore

to overcome scenario like this all the program and grouped together and given an authorization group.

In your roles user can be rectricted to specific Auth group.

Thanks

RAjdeep

Former Member
0 Kudos

Hi,

Thank you very much for your response.

I do understand the scenario that you are trying to state. That even applies to the usage of the consultants who may have the access to SE38.

I now understand the usage of auth groups, but why do we need to mention the auth groups both at program and transaction level?

Thanks,

Rahul.

Former Member
0 Kudos

Hi Rahul

As you mentioned its just for securing the system

so that no one can misuse it , even if they get access for tcode like se38 or SA38

Thanks

Rajdeep