Showing posts with label CUA. Show all posts
Showing posts with label CUA. Show all posts

How do we know if CUA is used in a system

You can quickly run transaction SU01 and see if the "Systems" tab is available. If it
is, CUA has been configured. Also, run transaction SCUA to see if there are distribution
models defined. You can also run transaction SCUL to view logs that might have been
generated by the use of CUA.

What is Central System

Central User Administration (CUA) system. You administer users for all systems of the Central User Administration and their authorizations in the central system. With active Central User Administration, you can only create and delete users in the central system and not in the connected child systems. You can also lock and unlock users, assign roles to users, and so onfrom the central system, in accordance with the settings that you have chosen in transaction SCUM for the distribution of the data.

How to check if CUA is used

1) How do we know if Central User Administration (CUA) is used in a system?
You can quickly run transaction SU01 and see if the "Systems" tab is available. If it is then CUA has been configured. Well there is another way to see whether CUA is used. Run transaction code SCUA to see if there are any distribution models defined. Run transaction code SCUL to see to view logs that are generated by CUA & if you have logged into a child system, then goto transaction code SU01 and see, there will be no CREATE activity.


2) How to find derived roles under the master roles

1) Goto transaction SE16
2) Enter the table name : agr_define
3) Enter the master role in the second role field ( this field is in the second row) and execute
4) Then you will see the derived roles based on the master roles

CUA - Central User Admin - Issues and Learning

Question: Hi all

Anyone would like to share any major issues or learning or even any undocumented features for implementing CUA. One of our client is likely to be taking a decision for implementing CUA involving about 20+ systems.

Any inputs be much appreciated.

Thanks
_________________
SAPFAN

Answer:
If you start by reading the OSS notes at service.sap.com related to CUA you will be busy for a while and maybe reconsider.

Answer:
While some use CUA to contorl EVERYTHING and beleive all is fine, CUA was NOT built to do what you want. Its design was to manage WORKPLACE and ONE production client. CUA was to be configured on the Workplace system and control it and the production client. The product is NOT robust enough to meet stringent qualtity contorls nor has enough reconcilliation report to assist in its problems.

Answer:
I am not a big fan of CUA, but I strongly disagree with what John Jarboe has said in the previous post. I believe that it can be used to manage multiple production systems. In fact using it from Solution Manager across R/3, CRM, BW EBP can be ok. I wouldn't use it to manage test and development systems. It is too much trouble.

The problem with the CUA concept is that SAP has been branching out. EBP and CRM security have some novelties that are not well handled by CUA. BW also has some issues that CUA does not deal with well. And then what about personaliztion etc.? or HR integration?

Unfortunately user administration is a bit of a hodge-podge. Perhaps someday SAP will address the little mess they have created.

Answer:
I did not indicate it coulld NOT be used for multiple production system/client, just that it is not robust enough to do so, as your post indicates

cua configuration

Create Logical systems to all clients.
Attach Logical system to clients.

Central system: DEVCLNT000

Child system: DEVCLNT001

3. Create user CUA_DEV_001 in devclnt001 system with roles , Z_SAP_BC_USR_CUA_SETUP_CLIENT and

Z_SAP_BC_USR_CUA_CLIENT.

4. Create user CUA_DEV in devclnt000 system with roles Z_SAP_BC_USR_CUA_SETUP_CENTRAL, Z_SAP_BC_USR_CUA_CEN-

TRAL, and Z_SAP_BC_USR_CUA_CENTRAL_BDIST.

Create RFC’s to child systems from central and central to child

5. Now logon to central system and execute tcode scua to configure cua.

Enter the name of the distribution model: CUA

Press create

Enter ALL Child system RFC’s

Save your entries now result screen will appear

If you expand the nodes for

the individual systems, you normally see the following messages for

each system: .ALE distribution model was saved,. .Central User

Administration activated,. and .Text comparison was started.. If

problem messages are displayed here, follow the procedure in SAP

Note 333441:

Setting the Parameters for Field Distribution

Enter Tcode SCUM in central system following screen will appear

Now maintain your filed distribution and save it.

You can use transaction SUCOMP to administer company address data.

You can use transaction SCUG in the central system to perform the

synchronization activities between the central system and the child

systems by selecting your child system on the initial screen of transaction

SCUG and then choosing Synchronize Company Addresses in the Central

System

To be able to transfer users from a child system to the central system, or to

distribute them from the central system to a child system, the user group to

which the user is assigned must exist in all systems in which the user exists.

After you have synchronized the company addresses, you can transfer the

users from the newly connected child systems to central administration.

This is done, as with the synchronization of the company addresses, using

transaction SCUG in the central system. To do this, on the initial screen of

transaction SCUG, select your child system and choose the Copy Users to

the Central System button.