https://raw.githubusercontent.com/ajmaradiaga/feeds/main/scmt/topics/NW-ABAP-User-Administration-and-Authorization-qa.xmlSAP Community - NW ABAP User Administration and Authorization2026-02-28T00:11:25.954548+00:00python-feedgenNW ABAP User Administration and Authorization Q&A in SAP Communityhttps://community.sap.com/t5/technology-q-a/issue-with-screen-enhancement-pbo-in-sap-as03-asset-master-on-premise-2020/qaq-p/14121973Issue with Screen Enhancement PBO in SAP AS03 (Asset Master) - On-Premise 2020 vs. 20232025-06-08T06:41:02.963000+02:00rogerz_19https://community.sap.com/t5/user/viewprofilepage/user-id/1680009<P>Dear Team/Colleagues,</P><P>I am encountering an issue with a screen enhancement implemented for the Asset Master Data (transactions AS01, AS02, AS03) in our SAP on-premise 2020 system.</P><P>I followed the steps outlined in the SAP Community blog post: <A class="" href="https://community.sap.com/t5/application-development-and-automation-blog-posts/adding-z-fields-to-asset-master-screen-aist0002-t-codes-as01-as02-as03/ba-p/13208878" target="_blank">https://community.sap.com/t5/application-development-and-automation-blog-posts/adding-z-fields-to-asset-master-screen-aist0002-t-codes-as01-as02-as03/ba-p/13208878</A> to add custom Z-fields.</P><P>The problem is that the <STRONG>Process Before Output (PBO)</STRONG> module of my custom subscreen is not being triggered in our SAP on-premise 2020 release. As a result, I am unable to disable fields in AS03, and any validations or Listbox functionalities defined in the PBO are not working.</P><P>Interestingly, I've observed that the PBO <EM>is</EM> being triggered correctly for the same enhancement in an SAP on-premise 2023 release system.</P><P>Could you please help me understand why this behaviour differs between the two releases and what I might have missed or need to adjust for our 2020 environment?</P><P>Thank you</P>2025-06-08T06:41:02.963000+02:00https://community.sap.com/t5/technology-q-a/restricting-bnk-moni-t-code/qaq-p/14177550Restricting BNK_MONI T-code2025-08-11T14:58:25.019000+02:00Quadirhttps://community.sap.com/t5/user/viewprofilepage/user-id/121394<P>Hi,</P><P>Any idea how can we restrict BNK_MONI T-code on the basis on company code since even after restricting, users are able to run for all company code?</P><P> </P><P>Thanks,</P><P>Syed Imam</P>2025-08-11T14:58:25.019000+02:00https://community.sap.com/t5/supply-chain-management-q-a/can-you-tell-me-what-authoirzation-is-missing-for-this-su53-screenshot/qaq-p/14206092Can you tell me what authoirzation is missing for this SU53 screenshot2025-09-03T15:14:20.812000+02:00Apoorva_Bhargavahttps://community.sap.com/t5/user/viewprofilepage/user-id/2218031<P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Apoorva_Bhargava_0-1756905317567.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/308612i7EAEE3039BBCDC72/image-size/large?v=v2&px=999" role="button" title="Apoorva_Bhargava_0-1756905317567.png" alt="Apoorva_Bhargava_0-1756905317567.png" /></span></P><P> </P><P> </P>2025-09-03T15:14:20.812000+02:00https://community.sap.com/t5/technology-q-a/usgrpt-table-text-field-translation/qaq-p/14206310USGRPT table TEXT field translation2025-09-03T17:39:06.080000+02:00Raquel1810https://community.sap.com/t5/user/viewprofilepage/user-id/2204186<P>I was trying to translate the field TEXT from this table but it doesn't appear on the tab " go to -> translate" like others object do. So the thing is, I went to se63 transaction and tried to use the object types DOMA and DTEL but I didn't get the results I was looking for. Please, someone had the same problem as me and can bring some light to the issue? thanks in advanced. </P>2025-09-03T17:39:06.080000+02:00https://community.sap.com/t5/technology-q-a/population-of-field-techdesc-in-table-usr21/qaq-p/14210494Population of field TECHDESC in table USR212025-09-08T10:04:50.835000+02:00SAPSupporthttps://community.sap.com/t5/user/viewprofilepage/user-id/121003<P>Since recent upgrade to SAP S/4HANA, we have noticed that some workflows are checking for a value in field TECHDESC in table USR21.</P><P>In table USR21 field TECHDESC, we have records that are populated with First Name & Last Name, and we have blank records in that field also.</P><P>We would like to know what is the data flow path / update mechanism, for the field TECHDESC to get populated with a value? Is there a link to HR infotype to obtain the person's first name & last name?</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B>2025-09-08T10:04:50.835000+02:00https://community.sap.com/t5/technology-q-a/can-an-s-user-id-to-access-cloud-resources-for-s-4hana-be-assigned-to-an/qaq-p/14215177Can an S-User ID, to access Cloud Resources for S/4HANA, be assigned to an @army.mil email account?2025-09-11T23:53:17.163000+02:00Kyle_Burkehttps://community.sap.com/t5/user/viewprofilepage/user-id/2234529<P>In support of a US Army Green Field S/4HANA Private Cloud Edition implementation, there are several developers and technical team members (users) with <a href="https://community.sap.com/t5/user/viewprofilepage/user-id/1786002">@Army</a>.mil e-mail accounts. <BR />Can an S-User ID be initiated and assigned to these users, or must they register with a .com e-mail account?</P>2025-09-11T23:53:17.163000+02:00https://community.sap.com/t5/enterprise-resource-planning-q-a/table-tobj-list-of-authorization-ehp8/qaq-p/14216050Table TOBJ list of authorization EHP82025-09-12T20:26:35.954000+02:00manthana99c17https://community.sap.com/t5/user/viewprofilepage/user-id/823346<P>Hi Expert,</P><P>I have list authorization of table TOBJ for object class SD after upgrade to EHP8. </P><P>Anyway to know that this is new authorization object after upgrade to EHP8?</P><P>And do i need to assign this new authorization object to user role one by one.</P><P> </P><P>Thanks in advance.</P>2025-09-12T20:26:35.954000+02:00https://community.sap.com/t5/enterprise-resource-planning-q-a/can-we-rerun-su25-step-2a-2b-2c/qaq-p/14216628can we rerun SU25 step 2a,2b,2c2025-09-14T11:18:33.518000+02:00manthana99c17https://community.sap.com/t5/user/viewprofilepage/user-id/823346<P>Hi expert</P><P> </P><P>after upgrade to EHP8, can we rerun Su25 2a,2b,2c as many times as we needed?</P><P>this is just comparison. isn't it? no harm if more business users work together?</P><P>if we would like to see only new authorization object after upgrade which step to do pls?</P><P> </P><P><SPAN><a href="https://community.sap.com/t5/user/viewprofilepage/user-id/390279">@olgavlachova</a></SPAN></P><P>Pls advise.</P>2025-09-14T11:18:33.518000+02:00https://community.sap.com/t5/supply-chain-management-q-a/role-authorization-pfcg/qaq-p/14220327ROLE AUTHORIZATION PFCG2025-09-17T17:34:11.718000+02:00SERGIO_SURROCAhttps://community.sap.com/t5/user/viewprofilepage/user-id/2255077<P><SPAN>Good afternoon, </SPAN></P><P><SPAN>Let's see if someone can help me with this role issue because it's not easy at all. </SPAN></P><P><SPAN>I've been working with SAP for a while but I can't seem to find the solution. Let me explain: </SPAN></P><P><SPAN>1) I have a user (USER1) with several assigned roles. This user does not have authorization to access Tx SE16. </SPAN></P><P><SPAN>2) I have a role created by me (ROL1) that allows access to SE16 and contains the following: - Authorization object S_TCODE - TCD SE16 - Authorization object S_TABU_NAM - ACTVT 03, TABLE ZXX1.</SPAN></P><P><SPAN>3) I have another empty user (USER2). If I assign the role created by me (ROL1), it works perfectly, and the user has access to SE16 for table ZXX1. If, for example, I try to access table ZXX2, it doesn't let me because there is no authorization. So far, everything is fine. </SPAN></P><P><SPAN>Now comes the strange part:</SPAN></P><P><SPAN>4) If I assign my role (ROL1) to user USER1, who has several roles assigned but does not have access to SE16, the user can access SE16 (correct because ROL1 allows it), but in addition to being able to access ZXX1, they can also access ZXX2 and all tables in the system. </SPAN></P><P><SPAN>Why can they access all tables if they only have access to ZXX1? </SPAN></P><P><SPAN>How can I configure it so that USER1 can only access certain tables? </SPAN></P><P><SPAN>Thank you in advance for your help.</SPAN></P>2025-09-17T17:34:11.718000+02:00https://community.sap.com/t5/enterprise-resource-planning-q-a/how-to-restrict-the-ledger-to-only-2l-and-ys/qaq-p/14228051How to restrict the Ledger to only 2L and YS2025-09-25T16:28:19.971000+02:00Quadirhttps://community.sap.com/t5/user/viewprofilepage/user-id/121394<P>Hi,</P><P>I have restricted the ledger to 2L (Statutory Ledger) & YS(Tax Ledger). However user is still able to post on 0L (IFRS Ledger). Screenshot attached. Does anyone have any idea how to restrict on this ?</P><P>just to add-- this is an <STRONG>Security</STRONG>/<STRONG>authorization issue</STRONG> and not functional.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Quadir_0-1758810319696.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/319944iAD75C1ACDA48D5F6/image-size/medium?v=v2&px=400" role="button" title="Quadir_0-1758810319696.png" alt="Quadir_0-1758810319696.png" /></span></P><P> </P>2025-09-25T16:28:19.971000+02:00https://community.sap.com/t5/technology-q-a/inquiry-regarding-removal-of-tcd-su01-from-authorization-object-s-tcode/qaq-p/14240133Inquiry Regarding Removal of TCD: SU01 from Authorization Object S_TCODE2025-10-10T10:13:02.716000+02:00SAPSupporthttps://community.sap.com/t5/user/viewprofilepage/user-id/121003<P>Dear SAP Support Personnel,</P><P> </P><P>I would like to remove TCD: SU01 from the Authorization Object: S_TCODE for a specific role.<BR />However, since the object containing TCD: SU01 is part of the standard configuration, it cannot be deleted directly.<BR />I would appreciate your guidance on the following two points:</P><P> </P><P>1.When Authorization Object: S_TCODE is standard, is removing the SU01 node from<BR />PFCG > Menu > Hierarchy > Role Menu the only way to delete the transaction?</P><P> </P><P>2.After removing the node and updating the profile, several authorization objects were added or suggested in the Authorization Data.<BR />Could you please advise on a simple method to compare the authorizations before and after the profile update?</P><P> </P><P>Thanks and best regards,<BR />A.</P><P> </P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B>2025-10-10T10:13:02.716000+02:00https://community.sap.com/t5/technology-q-a/probleme-su01-berechtigungen/qaq-p/14244584Probleme SU01 Berechtigungen2025-10-15T11:49:03.798000+02:00sap_beginner_96https://community.sap.com/t5/user/viewprofilepage/user-id/2259972<P> </P><P>Hallo zusammen,</P><P>folgende Situation:</P><P>Die Techniker in meinem Team sollen die SU01 nutzen können. Sie sollen dabei 03 Aktivität haben und in bestimmten Fällen, z. B. für die Erstellung eines RFC Users, dürfen sie die 02 Aktivität haben.</P><P>Nun habe ich zum Test eine Rolle erstellt, die im Menü nur die Transaktion SU01 hat. Die dabei generierten Berechtigungen habe ich zum Testen erstmal alle auf Aktivität 03 gesetzt und bestimmte Berechtigungen wie z. B. für HR gelöscht/deaktiviert. Außerdem habe ich in der Berechtigung S_USER_GRP ausschließlich die User Gruppe für RFC User hinzugefügt.</P><P>Als ich die Rolle testen wollte, hatte ich dennoch vollen Zugriff auf die SU01 und konnte auch jede andere Usergruppe bearbeiten. Die Transaktion SU01 zeigt mir innerhalb der Transaktion in einer Message-Box eine rote Error-Meldung an, dass mir die nötigen Berechtigungen fehlen, um Änderungen durchzuführen, jedoch kann ich es trotzdem machen.</P><P>Bisherige Tests:</P><P>– Ich habe meinem User alle Rollen nehmen lassen und nur diese Rolle für SU01 hinzufügen lassen. Ergebnis bleibt, dass ich bearbeiten kann.</P><P>– Mein User hat kein extra Profil oder SAP_ALL etc., nur das Profil, welches aus der Rolle für SU01 generiert wird.</P><P>-In der SU53 werden mir auch, korrekt, meine fehlenden Aktivität wie die 02 in der Berechtigung S_USER_GRP angezeigt. Wie oben beschrieben kann ich dennoch bearbeiten.</P><P>-In der SUIM habe ich über die komplexe Berechtigungsobjektsuche die Berechtigung S_USER_GRP mit der Aktivität 02 gesucht und das System hat mir die Rolle angezeigt, die ich erstellt habe und die ausschließlich die Aktivität 03 hat.</P><P>Technische Details: Mein System ist ein BW System mit der Installierten Version SAP BW/4HANA 2021 SP/FP 08 03/2024</P><P>Ich hoffe nun das jemand von euch mir dabei helfen kann.</P><P> </P><P> </P>2025-10-15T11:49:03.798000+02:00https://community.sap.com/t5/technology-q-a/copy-users-and-production-profiles-to-quality/qaq-p/14245202Copy users and production profiles to quality2025-10-15T23:31:16.207000+02:00javierm_9230https://community.sap.com/t5/user/viewprofilepage/user-id/837753<P>Good morning, could you please advise me on the possible options for copying users and profiles from production to quality? I need to have the users and profiles certified in both environments.</P>2025-10-15T23:31:16.207000+02:00https://community.sap.com/t5/technology-q-a/stauthtrace/qaq-p/14256743STAUTHTRACE2025-10-30T07:01:19.807000+01:00SreeCharanhttps://community.sap.com/t5/user/viewprofilepage/user-id/1689317<P>what does access filtering column in STAUTHTRACE result means? And how is it useful?</P>2025-10-30T07:01:19.807000+01:00https://community.sap.com/t5/technology-q-a/ias-ips-sap-security/qaq-p/14263101IAS-IPS (SAP Security)2025-11-07T15:28:51.630000+01:00Agrawal_Himanshuhttps://community.sap.com/t5/user/viewprofilepage/user-id/494787<P><STRONG>IAS & IPS</STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG>Content :</STRONG></P><OL><LI>SAP Identity Authentication Service (IAS)</LI><LI>SAP Identity Provisioning Service (IPS)</LI><LI>Real World Scenario</LI></OL><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG>SAP Identity Authentication Service (IAS)</STRONG></P><P>IAS is SAP’s cloud-based authentication service.</P><P>Its core job is to make sure “the right user logs in securely to the right SAP application.”</P><P>Think of IAS as the gatekeeper.</P><P> </P><P><STRONG><SPAN></SPAN></STRONG><STRONG>What IAS Does </STRONG></P><OL><LI><STRONG>Authenticates Users (Login / Sign-in)</STRONG></LI></OL><P>IAS verifies user identity when they try to log in to:</P><UL><LI>SAP BTP</LI><LI>SAP SuccessFactors</LI><LI>SAP Ariba</LI><LI>SAP Analytics Cloud</LI><LI>SAP S/4HANA Cloud</LI><LI>Any custom application connected to IAS</LI></UL><P>It checks:</P><UL><LI>Username + Password</LI><LI>Multi-Factor Authentication (OTP, SMS, Email, Authenticator App)</LI><LI>Certificates</LI><LI>Biometrics (via device IdP)</LI></UL><P><SPAN> </SPAN></P><OL><LI><STRONG>Single Sign-On (SSO)</STRONG></LI></OL><P>IAS supports:</P><UL><LI>SAML 2.0</LI><LI>OAuth 2.0</LI><LI>OpenID Connect (OIDC)</LI></UL><P>So your users log in once and access all SAP apps without logging in again.</P><P><SPAN> </SPAN></P><OL><LI><STRONG>Acts as an Identity Provider (IdP)</STRONG></LI></OL><UL><LI>IAS can serve as</LI></UL><P>Primary IdP</P><UL><LI>IAS handles authentication directly</LI></UL><P>Proxy IdP</P><UL><LI>IAS redirects authentication to:</LI></UL><OL><LI>Microsoft Azure AD</LI><LI>ADFS</LI><LI>Okta</LI><LI>Ping Identity</LI><LI>Any SAML-based IdP</LI></OL><P>IAS becomes the bridge between SAP systems and corporate identity providers.</P><P><SPAN> </SPAN></P><OL><LI><STRONG>Conditional Authentication Policies</STRONG></LI></OL><P>IAS can decide:</P><UL><LI>Who can log in</LI><LI>From where</LI><LI>Under what conditions</LI></UL><P>Examples:</P><UL><LI>Allow MFA only when user logs in from outside office</LI><LI>Block login from certain countries</LI><LI>Force password reset for risky accounts</LI><LI>Apply SSO only for trusted devices</LI></UL><P><SPAN> </SPAN></P><OL><LI><STRONG>User Store (Identity Directory)</STRONG></LI></OL><P>IAS stores user accounts, including:</P><UL><LI>Username</LI><LI>Email</LI><LI>First Name / Last Name</LI><LI>Groups</LI><LI>Password (if local authentication)</LI></UL><P>Note : BUT IAS does NOT create users automatically — IPS usually does provisioning.</P><P><SPAN> </SPAN></P><OL><LI><STRONG>Authorization Pre-Processing (via Groups → Mappings)</STRONG></LI></OL><P>IAS can assign groups, and these groups can be mapped in target apps (like SAP BTP) to give role collections.</P><UL><LI>IAS Group = “FinanceUsers”</LI></UL><P>→ Mapped to</P><UL><LI>BTP Role Collection = “Finance App Access”</LI></UL><P>But IAS itself does NOT assign app roles.</P><P>Note : IAS group can only be mapped to BTP role collections, not to PFCG Role etc.</P><P><SPAN> </SPAN></P><OL><LI><STRONG>Branding & Custom Login Pages</STRONG></LI></OL><P>IAS allows full customization of login screens:</P><UL><LI>Company logo</LI><LI>Color theme</LI><LI>Background</LI><LI>Messages</LI><LI>Terms & conditions</LI></UL><P><SPAN> </SPAN></P><OL><LI><STRONG>Security Enforcement</STRONG></LI></OL><P>IAS applies:</P><UL><LI>Password policies</LI><LI>MFA rules</LI><LI>Account lockout rules</LI><LI>Device trust</LI><LI>Risk-based authentication</LI></UL><P> </P><P><STRONG><SPAN></SPAN></STRONG><STRONG>What IAS Does NOT Do</STRONG></P><UL><LI>IAS does NOT create users(IPS or external IdP does)</LI><LI>IAS group does NOT assign roles in S/4, SAC, Ariba, etc.</LI><LI>IAS does NOT do provisioning(IPS does)</LI><LI>IAS does NOT perform GRC / SoD checks(IAG does)</LI></UL><P> </P><P> </P><P> </P><P> </P><P> </P><P> </P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG> </STRONG></P><P><STRONG>SAP</STRONG><STRONG> Identity Provisioning Service (IPS)</STRONG></P><P>IPS is SAP’s central user provisioning and synchronization service.</P><P>It moves users from one system to another, ensuring that user accounts, attributes, and group/role assignments stay consistent across:</P><UL><LI>SAP BTP</LI><LI>IAS (Identity Authentication Service)</LI><LI>SAP S/4HANA Cloud</LI><LI>SAP Ariba</LI><LI>SAP SuccessFactors</LI><LI>SAP Analytics Cloud</LI><LI>Azure AD, Okta, Ping, etc.</LI></UL><P><STRONG>Think of IPS as the “delivery service” for user accounts.</STRONG></P><P> </P><P><STRONG><SPAN></SPAN></STRONG><STRONG>What IPS Does </STRONG></P><OL><LI><STRONG>Creates Users in Target Systems</STRONG></LI></OL><P>IPS automatically provisions users into multiple systems.</P><P>Example:<BR />SuccessFactors → IPS → IAS → BTP → S/4HANA</P><P>IPS can create user accounts in:</P><UL><LI>IAS</LI><LI>SAP BTP</LI><LI>S/4HANA Cloud</LI><LI>SAP Ariba</LI><LI>SAP Concur</LI><LI>SAP Analytics Cloud (via SCIM)</LI></UL><P> </P><OL><LI><STRONG>Updates User Attributes</STRONG></LI></OL><P>If an employee changes department, email, manager, etc., IPS updates the data in all connected systems.</P><P>Example:<BR />SuccessFactors updates → IPS sync → IAS/BTP/S4/Ariba update</P><P> </P><OL><LI><STRONG>Deletes / Deactivates Users</STRONG></LI></OL><P>When an employee leaves the company, IPS can mark them inactive or delete their user account.</P><P> </P><OL><LI><STRONG>Maps and Transforms Attributes</STRONG></LI></OL><P>IPS allows:</P><UL><LI>Attribute mapping</LI><LI>Attribute transformation</LI><LI>Conditional provisioning</LI></UL><P>Example:<BR />IF user.department = "Finance" → assign group “FIN_USERS”</P><P> </P><OL><LI><STRONG>Assigns Groups / Roles (but not everywhere)</STRONG></LI></OL><P>IPS can assign:</P><UL><LI>IAS Groups</LI><LI>BTP Role Collections</LI><LI>S/4HANA Business Roles</LI><LI>SAP Ariba groups</LI><LI>SAC roles (via SCIM)</LI></UL><P>But <EM>only</EM> where system supports it.</P><P> </P><OL><LI><STRONG>Connects to Many Identity Sources</STRONG></LI></OL><P>IPS can read users from:</P><UL><LI>Azure AD</LI><LI>SuccessFactors</LI><LI>IAS</LI><LI>LDAP</LI><LI>Okta</LI><LI>On-premise systems (via Cloud Connector)</LI></UL><P><STRONG>What IPS does NOT do</STRONG></P><UL><LI><SPAN>IPS does NOT Authenticate Users (</SPAN>IAS does)</LI></UL><P> </P><P><STRONG>Real World Scenario</STRONG></P><P><STRONG> </STRONG></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Agrawal_Himanshu_0-1762525679968.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/337345i7963E03C37F79A89/image-size/medium/is-moderation-mode/true?v=v2&px=400" role="button" title="Agrawal_Himanshu_0-1762525679968.png" alt="Agrawal_Himanshu_0-1762525679968.png" /></span></P><P> </P><P><STRONG><BR /><BR /></STRONG></P><P><STRONG>Company:</STRONG></P><P>A global manufacturing company using:</P><UL><LI>SAP SuccessFactors (HR system of record)</LI><LI>SAP BTP (custom apps, Integration Suite)</LI><LI>SAP S/4HANA Cloud (ERP)</LI><LI>SAP Ariba (Procurement)</LI><LI>SAP IAS (Authentication)</LI><LI>SAP IPS (Provisioning)</LI><LI>SAP IAG (Access Governance)</LI></UL><P><STRONG>Scenario 1: A New Employee Joins the Company</STRONG></P><P><STRONG>Step 1 — Employee is Hired in SuccessFactors</STRONG></P><P>HR creates a new employee: Rohan Sharma with below details</P><UL><LI>Department: Finance</LI><LI>Location: India</LI><LI>Manager: Priya Singh</LI><LI>Job: Accounts Payable Analyst</LI></UL><P>SuccessFactors stores all HR attributes.</P><P><STRONG>S</STRONG><STRONG>tep 2 — IPS Reads Rohan’s Data from SuccessFactors</STRONG></P><P>IPS acts as the "provisioning engine."</P><P>Flow: SuccessFactors → IPS → IAS</P><P>IPS automatically:</P><UL><LI>Reads new user</LI><LI>Maps attributes</LI><LI>Creates user in IAS</LI><LI>Assigns IAS group “Finance_Employees”</LI><LI>Pushes email, username, and department</LI></UL><P><STRONG>Step 3 — IAS Creates User Entry + Prepares Authentication</STRONG></P><P>IAS now has user:</P><UL><LI>Username: rohan.sharma</LI><LI>Email: rohan.sharma@company.com</LI><LI>Group: Finance_Employees</LI><LI>Status: Active</LI></UL><P><EM>IAS does NOT assign roles.</EM></P><P>IAS only sets up login policies:</P><UL><LI>MFA required</LI><LI>Corporate SSO allowed</LI><LI>Conditional rule: India region → allow password login</LI></UL><P><STRONG>Step 4 — IAG Triggers Access Request Workflow</STRONG></P><P>Rohan needs access to:</P><UL><LI>SAP BTP Finance App</LI><LI>S/4HANA Finance Business Roles</LI><LI>Ariba Buyer Role</LI></UL><P>In large companies, users cannot get access automatically,they must request access via IAG.</P><P>Flow:</P><OL><LI>Rohan goes to IAG Access Request Portal</LI><LI>Selects: "Finance Analyst Access Package"</LI><LI>Request goes to Manager (Priya Singh)</LI><LI>IAG performs SoD checks <SPAN></SPAN> No conflicting roles <SPAN></SPAN> No risk</LI><LI>Manager approves</LI></OL><P><STRONG>Step 5 — IAG Sends Provisioning Action to IPS</STRONG></P><P>After approval:</P><P>IAG → IPS → Target Systems</P><P>IPS now provisions the approved roles</P><UL><LI>In SAP BTP: Assigns BTP Role Collection:</LI></UL><P>Finance_Analyst_RoleCollection</P><P> </P><UL><LI>In S/4HANA Cloud: Assigns Business Roles:</LI></UL><P>AP_STANDARD</P><P>FIN_POSTING</P><P>FIN_DISPLAY</P><P> </P><UL><LI>In SAP Ariba: Assigns Ariba group:</LI></UL><P>Buyer_Professional</P><P><STRONG> </STRONG></P><P><STRONG>Step 6 — Rohan Logs In to SAP Systems</STRONG></P><P>Rohan logs in to:</P><P>SAP BTP App</P><UL><LI>IAS checks login</LI><LI>IAS → BTP trusts IAS</LI><LI>BTP picks up role collection assigned via IPS</LI></UL><P>S/4HANA Cloud</P><UL><LI>Login route:</LI><LI>Browser → IAS → S/4</LI><LI>S/4 checks Business Role assignments provisioned via IPS</LI></UL><P>Ariba</P><UL><LI>IAS federates login → Ariba validates user groups</LI></UL><P><STRONG>Step 7 — Rohan Changes Department (Employee Movement)</STRONG></P><P>After 1 year, Rohan moves from Finance to Supply Chain.</P><P>HR updates this in SuccessFactors.</P><UL><LI>IPS reads update</LI><LI>IPS updates IAS + BTP + S/4HANA + Ariba</LI><LI>IAG dynamically checks if old roles must be removed.</LI><LI>Roles get de-provisioned: Finance roles removed & New Supply Chain roles added</LI></UL><P><STRONG>Step 8 — Employee Exit</STRONG></P><P>When Rohan leaves company:</P><UL><LI>HR marks employee as terminated in SuccessFactors</LI><LI>IPS deactivates him in IAS</LI><LI>IPS removes roles in BTP, S/4, Ariba</LI><LI>IAS blocks login</LI></UL><P>User access fully revoked</P><P> </P><P> </P><P> </P>2025-11-07T15:28:51.630000+01:00https://community.sap.com/t5/technology-q-a/su01-user-group-mandatory-field/qaq-p/14278915SU01 User group mandatory field2025-11-27T11:19:32.300000+01:00SAPSupporthttps://community.sap.com/t5/user/viewprofilepage/user-id/121003<P>Are there any SAP Note to inform how to configure in SU01 tcode that the User group mandatory is a mandatory field to avoid creation of user with blank groups?</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B>2025-11-27T11:19:32.300000+01:00https://community.sap.com/t5/technology-q-a/seeking-advice-on-tools-amp-methodology-for-legacy-rfc-user-permissions/qaq-p/14301772Seeking Advice on Tools & Methodology for Legacy RFC User Permissions Cleanup2026-01-06T03:45:52.366000+01:00constance_yehttps://community.sap.com/t5/user/viewprofilepage/user-id/2273299<P>Hello SAP Security & Basis Experts,</P><P>We are embarking on a critical security remediation project to address over-privileged RFC users across our SAP landscape with 600+ systems. Many of these users and connections are years old, lack clear ownership, and serve various backend tasks.</P><P>Our goal is to understand what business operations each RFC user/interface actually performs and then redesign brand new ones following the principle of least privilege without disrupting genuine business processes.</P><P>There are several key challenges we meet:</P><P>1) Many RFC users were created long ago with no clear current responsible person.</P><P>2) Activities are often triggered by background jobs, making them less visible.</P><P>3) We must not miss crucial but infrequent operations (e.g., year-end financial closing), which short-term monitoring would fail to capture.</P><P><STRONG>We are seeking practical advice on the following specifically:</STRONG></P><P>1) Tool Recommendation: beyond native SM19/SM20 and STUSOBTRACE, what commercial or open-source tools have you successfully used for cross-system RFC user discovery, permission analysis, and activity monitoring? What are their pros/cons for this use case?</P><P>2) Methodology for business need collection: How do you practically identify the business purpose behind legacy technical RFC accounts? Are there effective techniques for correlating job schedules (SM37), interface configurations (BD64/WE20), and log data to reverse-engineer their function?</P><P>3) Capturing low-frequency activities: What is the best practice to ensure yearly/quarterly critical processes are identified? Are there technical methods to trace such execution history?</P><P>We greatly appreciate any insights, war stories, or links to useful resources you can share. Thank you for helping us!</P>2026-01-06T03:45:52.366000+01:00https://community.sap.com/t5/technology-q-a/password-deactivation-through-bapi-user-change/qaq-p/14315645Password deactivation through BAPI_USER_CHANGE2026-01-27T11:52:36.366000+01:00SAPSupporthttps://community.sap.com/t5/user/viewprofilepage/user-id/121003<P>Hi team,</P><P>We are using IDM to manage our user provisioning. As we are implementing SNC, we got a requirement to deactivate password during the new user creation. We are using BAPI_USER_CHANGE to set the password .We are trying to deactivate the password now, but the field LOGONDATA-CODVN is an internal field only.</P><P> </P><P>Please suggest how to deactivate the password for users through the BAPI.</P><P><BR /><BR /><BR /></P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B>2026-01-27T11:52:36.366000+01:00https://community.sap.com/t5/technology-q-a/12-characters-limit-on-userid-in-su01/qaq-p/1432068912 characters limit on UserID in SU012026-02-03T13:41:51.062000+01:00SAPSupporthttps://community.sap.com/t5/user/viewprofilepage/user-id/121003<P>We are not able increase the 12 character limit on UserID created in SU01. it is not accepting UserID longer than 12 characters.</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B>2026-02-03T13:41:51.062000+01:00https://community.sap.com/t5/technology-q-a/fiori-quot-my-inbox-quot-error-intermittent-issue/qaq-p/14329794Fiori "My Inbox" Error - Intermittent issue,2026-02-17T03:28:43.975000+01:00AJeBhttps://community.sap.com/t5/user/viewprofilepage/user-id/781848<P>Hello,</P><P>I encounter an issue in fiori " My Inbox". The error is intermittent (sometimes there's an error but sometimes it is working properly)</P><P><BR />sample uri with error(sorry but I cannot post the whole URI): /sap/opu/odata/IWPGW/TASKPROCESSING;v=2;mo/<STRONG>TaskCollection</STRONG>/$count/?$filter=Status%20eq%20%27READY%........</P><P>Method: GET</P><P>Status code: 500 after successful login, 400 after clicking the My Inbox with error</P><P> </P><TABLE border="1" width="100%"><TBODY><TR><TD width="100%" height="38px"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AJeB_0-1771293389959.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/373346iF34E687783C38CBB/image-size/medium?v=v2&px=400" role="button" title="AJeB_0-1771293389959.png" alt="AJeB_0-1771293389959.png" /></span></TD></TR><TR><TD width="100%" height="53px"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AJeB_1-1771293419768.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/373347i57EFD00958BA3C66/image-size/medium?v=v2&px=400" role="button" title="AJeB_1-1771293419768.png" alt="AJeB_1-1771293419768.png" /></span></TD></TR><TR><TD width="100%" height="370px"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AJeB_3-1771293494543.png" style="width: 221px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/373349i373942E23DD7C325/image-dimensions/221x217?v=v2" width="221" height="217" role="button" title="AJeB_3-1771293494543.png" alt="AJeB_3-1771293494543.png" /></span></TD></TR><TR><TD width="100%" height="229px"><P>If the tile has error , this error message will appear</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AJeB_2-1771293449469.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/373348iE10D438BC09334AF/image-size/medium?v=v2&px=400" role="button" title="AJeB_2-1771293449469.png" alt="AJeB_2-1771293449469.png" /></span></P></TD></TR></TBODY></TABLE><P>I think there's no issue in the configuration because sometimes it is working</P><P>The RFC Destination is NONE, and connection Type is "I" (Internal Connection)</P><P>the ZTASKPROCESSING we maintained in /IWFND/MAINT_SERVICE and the taskprocessing maintained in SICF is activated</P><P>no dump in ST22</P><P>no duplicate keys/task </P><P>but there is an error in /IWFND/ERROR_LOG and IWBEP/ERROR_LOG</P><P>Frontend - An exception was raised</P><P>Backend - Soapfaultcode: Authentication failed (not sure yet if this is the root cause)</P><P><STRONG>FYI</STRONG>: we are using BPM for the workflow, the standard software version we used in /IWFND/ROUTING is /IWPGW/BPM, current system is ECC. The tasks in the "My Inbox" is coming from custom table</P><P>what could be the other possible cause of the intermittent error, any idea or anyone has experienced this kind of issue? or can you share your techniques on how to find the root cause of error</P><P> </P><P> </P>2026-02-17T03:28:43.975000+01:00