Showing posts with label Security Parameters. Show all posts
Showing posts with label Security Parameters. Show all posts

Some of our users are not able to execute some transaction codes, even though the required roles are granted. How to troubleshoot?

Follow the below mentioned steps to identify the root cause:

  • Check if there is a user comparison issue. (The role name will be suffixed with Red light, instead of green)
  • Check the object S_TCODE existence in the authorization object of that particular profile.
  • Check SU56 to know the objects/values available for the user.

If there is an issue with the 1st mentioned point, simply go to Profile Generator and perform a user comparison, which will adjust the user master record. If the issue is with 2nd, you need to regenerate the profile.

Incase, if you find that some of the objects are not loaded properly in SU56, you need to identify the # of profiles assigned and ensure that they are below 312, as you can’t assign more than 312 profiles to a SAP User ID.

If the issue happens even with very few profiles, verify the Number of authorizations in User Buffers value in the Instance profile. The value for Auth/auth_number_in_userbuffer parameter can be increased.

The size of the buffer must always exceed the maximum number of authorizations as authorization checks are made only against those in the buffer.

The default value is 800, but this can be set to a value which is between 1–2000.

Other references: OSS notes 84209 and 75908

I am unable to login to SAP using SAP* user ID in the newly created client. What is the problem?

This issue happens if the login/no_automatic_user_sapstar parameter value is set to “1” in the Instance profile.

Change the value to “0” to enable SAP* login.

Prior to version 4.0 this parameter was login/no_automatic_user_sap*.

How to restrict the users from opening more SAP sessions?

rdisp/max_alt_modes parameter should be added in the Instance profile. The default value of this parameter is 6 and restriction should be done based on the performance of the system, number of users etc.

How do you change the default SAP GUI client number in the initial screen?

login/system_client parameter should be added in the Instance profile. The default value is 000.You need to make the change, save the instance profile and activate it.

How to restrict users from logging in to SAP from multiple systems?

login/disable_multi_gui_login parameter should be added in the Instance profile and the value should be set to 1. By default it is set to 0, which will allows logging in from multiple systems.

This parameter is set to 1 in most of the Production environments. You can see the current settings in RZ11.

disable_multi_gui_login

SAP Programs

SAP Program

Program Description
AGR_ACTIVITY_GROUPS_TRANSLATE Translate role texts
AGR_CHECK_ALL_ACTIVITY_GROUPS Old roles check report
AGR_CHECK_ALL_AGRS Find All Accounts Without Path to Root
AGR_CHECK_ALL_AGRS_2 Too Many Transaction Codes in the Menu or D_TCODE - Diff. Analys
AGR_CHECK_ALL_AGRS_3 check for Duplicates in the Role Profile Assignment
AGR_CHECK_ALL_AGRS_4 - Duplicates in the Role Profile Assignment -> Single Cleanup
AGR_CHECK_ALL_AGRS_5 - Duplicates in the Role Profile Assignment -> Single Cleanup
AGR_CHECK_AUTHS_DUPLICATES Checking Duplicate Authorizations in Profiles
AGR_CHECK_AUTHS_DUPLICATES_31 Checking Duplicate Authorizations in Profiles
AGR_CONVERT_GENERATED_PROFILE Convert Profiles for a Role into Manual Profiles
AGR_DELETE_ALL_ACTIVITY_GROUPS Mass deletion of roles (Internal Use Only)
AGR_GET_TPRPROF_TEXTS_IN_AGR TPRPROF-Compare texts in the new tables
AGR_MASS_STAR_0_PROBLEM Clean Up Authorization Tables
AGR_MIGRATE_SSM_USR Conversion of old roles to the new maintenance transaction
AGR_REGENERATE_SAP_ALL Regenerate SAP_ALL Profile in all Clients
AGR_RESET_ORG_LEVELS Reset Manual Status and Contents of Organizational Levels
AGR_STAR_0_PROBLEM Clean Up Problem with *0 in the Profile Generator
AGR_XPRA Conversion of old roles to the new maintenance transaction
AGR_XPRA_ALL_CLIENTS Conversion of old roles to the new maintenance transaction
AGR_XPRA_MENUS_REPAIR Repair roles after migration
AGR_XPRA_MENUS_TRANSFER Menu Migration: Including role, save entire tree
AGR_XPRA_REGENERATE_REPAIR_1 Program AGR_XPRA_REGENERATE_REPAIR_1
AGR_XPRA_REGENERATE_REPAIR_2 Program AGR_XPRA_REGENERATE_REPAIR_2
AGR_XPRA_REGENERATE_SAP_ALL Regenerate SAP_ALL Profile in all Clients
AGR_XPRA_REGENERATE_SAP_NEW Generate SAP_NEW Profile in All Clients
PFCG_ADD_MINIAPP Program PFCG_ADD_MINIAPP
PFCG_AGRS_WITH_MANUAL_S_TCODE List All Roles with Manual S_TCODE Authorization
PFCG_MASS_DOWNLOAD Bulk role download
PFCG_MASS_IMPORT Bulk rolle import
PFCG_MASS_TRANSPORT Transport of roles
PFCG_MASS_USER_ASSIGNMENT Mass Assignment of Users to Roles
PFCG_ORGFIELD_CREATE Profile Generator: Create New Organizational Level Field
PFCG_ORGFIELD_DELETE Profile Generator: Delete New Organizational Level Field
PFCG_ORGFIELD_UPGRADE Profile Generator: Modification After Upgrade for New Org Level Fields
PFCG_REGENERATE_ACT_GROUPS Generate Role Authorization Profiles
PFCG_REGENERATE_ALL_ACT_GROUPS Generate all role authorization profiles
PFCG_SET_PROFILE_NAMERANGE Set Number Range for Profile Name Proposal
PFCG_TIME_DEPENDENCY Role time-dependency scheduling report
RDDIMPDP Dispatcher for Transport Programs Within SAP System
RSPARAM Parameters
RSSCD100_PFCG Display Change Documents for Role Administration
RSUSADRCK1 User Maintenace - error in address admin (oss note 94104)
RSUSDISTRIBUTE_ALL_COMP Company address distribution
RSUSLAND Report RSUSLAND Central User Administration country definition
RSUSLAND_FRM
RSUSLAND_PAI
RSUSLAND_PBO
RSUSR_S_USER_SAS Activate Authorization Object S_USER_SAS
RSUSR_S_USER_SAS_01 Complete Authorization Data for S_USER_SAS in Roles
RSUSR_S_USER_SAS_02 Convert Authorization Defaults
RSUSR_SYSINFO_PROFILE Report cross-system information/profile
RSUSR_SYSINFO_ROLE Report cross-system information/role
RSUSR_SYSINFO_ZBV Report cross-system information/CUM
RSUSR000 Current Active Users
RSUSR001 Infosystem authorizations
RSUSR002 Users by complex selection criteria
RSUSR002_ADDRESS Users by address data
RSUSR003 Check the Passwords of Users SAP* and DDIC in All Clients
RSUSR004 Restrict User Values to the Following Simple Profiles and Auth. Objs.
RSUSR005 List of Users With Critical Authorizations
RSUSR006 List of Users with Incorrect Logons
RSUSR007 List Users Whose Address Data is Incomplete
RSUSR008 By Critical Combinations of Authorizations at Transaction Start
RSUSR009 List of Users With Critical Authorizations
RSUSR010 Executable Transactions (All Selection Options)
RSUSR011
RSUSR012 Search authorizations, profiles and users with specified object values
RSUSR020 Profiles by complex selection criteria
RSUSR030 Authorizations by Complex Selection Criteria
RSUSR040 Authorization Objects by Complex Selection Criteria
RSUSR050 Comparisons
RSUSR060 Where-used lists
RSUSR060OBJ Where-Used List for Authorization Object in Programs and Transactions
RSUSR061 Enter Authorization Fields
RSUSR070 Roles by complex selection criteria
RSUSR100 Change documents for users
RSUSR101 Change documents for profiles
RSUSR102 Change documents for authorizations
RSUSR200 List of Users According to Logon Date and Password Change
RSUSR300 Set External Security Name for All Users
RSUSR301
RSUSR302
RSUSR304 Reload Table TSTCA From Table TSTCA_C
RSUSR400 Test Environment Authorization Checks (SAP Systems Only)
RSUSR401 Report to give all SAPCPIC users profile S_A.CPIC
RSUSR402 Download user data for CA manager from Secude
RSUSR403 Assign Profile S_A.CPIC to User SAPCPIC in Current Client
RSUSR404 Conversion Program for Authorizations of Basis Development Environment
RSUSR405 Reset all user buffers in all clients (uncritical)
RSUSR406 Automatically Generate Profile SAP_ALL
RSUSR406_OLD Automatically Generate Profile SAP_ALL
RSUSR408 XPRA: Conversion of USOBX-OKFLAG, USOBX-MODIFIED for upgrade tool SU26
RSUSR409 Transfer all translated titles to generated transaction codes
RSUSR421 Clean-up report: TSTC-CINFO if no check in TSTCA
RSUSR500 User Administration: Compare Users in Central System
RSUSR500D Display GUM open changes
RSUSR998 Call Reporting Tree Info System
RSUSRCOM
RSUSRDIR
RSUSREXT Enter External Identification in Table View VUSREXTID (From Rel. 4.5)
RSUSREXTID Enter External Identification in Table View VUSREXTID (From Rel. 4.5)
RSUSRLOG Log Display for Central User Administration
RSUSRSCUC CUA: Synchronization of Company Addresses
RSUSRSCUC_F01 CUA tree processing
RSUSRSCUC_F02 List of companies processing
RSUSRSCUC_F03 Comparison list of company addresses
RSUSRSCUC_F04 Company address processing
RSUSRSCUC_F05 Distribution within CUA
RSUSRSCUC_O01 PBO module for screen 0100
RSUSRSUIM User Information System
RSUSX001 XPRA: Assign company addresses (BC01) to an object
RSUSX01TOP

SAP Security Parameters

Parameter ID
auth/authorization_trace
auth/auth_number_in_userbuffer
auth/check/calltransaction
auth/new_buffering
auth/no_check_in_some_cases
auth/object_disabling_active
auth/rfc_authority_check
auth/system_access_check_off
auth/tcodes_not_checked
auth/test_mode
auth/trfc_no_authority_check
bdc/bdel_auth_check
login/disable_password_logon
login/display_country_logon_info
login/ext_security
login/failed_user_auto_unlock
login/fails_to_session_end
login/fails_to_user_lock
login/min_password_lng
login/multi_login_users
login/no_automatic_user_sapstar
login/password_change_for_SSO
login/password_charset
login/password_expiration_time
login/password_logon_usergroup
login/password_max_new_valid
login/password_max_reset_valid
login/system_client
login/ticket_expiration_time
login/update_logon_timestamp
rspo/auth/pagelimit