https://raw.githubusercontent.com/ajmaradiaga/feeds/main/scmt/topics/Security-qa.xml SAP Community - Security 2026-04-20T14:01:46.984818+00:00 python-feedgen Security Q&A in SAP Community https://community.sap.com/t5/technology-q-a/start-report-in-suim-change-documents/qaq-p/14280058 START_REPORT in SUIM Change Documents 2025-11-28T17:23:43.442000+01:00 jake1122 https://community.sap.com/t5/user/viewprofilepage/user-id/2013638 <P>Hi SAP Security Gurus,</P><P>My SUIM change documents reports showing <STRONG>START_REPORT</STRONG> with my User ID in Production system. Like I have done role assignment/deletion using START_REPORT into Transaction Code column.&nbsp;</P><P>Any idea, why it is showing and did I ran any report using SUIM or something else. This is an audit concern.</P><P>I made composite role adjusment i.e. remove / add roles but my transport date moved to PROD and this SUIM START_REPORT does not match.&nbsp;</P> 2025-11-28T17:23:43.442000+01:00 https://community.sap.com/t5/technology-q-a/set-up-custom-security-logs/qaq-p/14286271 Set up custom security logs 2025-12-08T20:45:19.377000+01:00 christineha https://community.sap.com/t5/user/viewprofilepage/user-id/59325 <P>Hello Community,</P><P>I have a request from a customer who needs to implement monitoring on the following events to comply with their internal Security requirements :</P><UL><LI>User logons and logon attempts (successful and failed)</LI><LI>User account modifications (creation, modification, deletion, role changes)</LI><LI>Access to sensitive data and critical transactions</LI><LI>Unauthorized access attempts (authorization failures)</LI><LI>System configuration and&nbsp;security parameter changes</LI><LI>Privileged user activities (administrators)</LI></UL><P>Their Security requirements are the following:</P><OL><LI>Confirmation that the Security Audit Log is enabled on their tenant with capture of critical security events</LI><LI>Access to the “Display Security Audit Log” Fiori application for security/audit teams</LI><LI>Documentation on the complete list of events captured in their Cloud edition</LI><LI>Ability to export these logs to enable automated security alerting and monitoring</LI></OL><P>I was advised that CAS (Cloud Application Services) could address these kind of needs but these are not for "one shot" request, CAS are indeed used for recurring activities ; I also raised a CISA request but the <A href="https://help.sap.com/docs/ABAP_PLATFORM/addb96cd90c945dfb3182865363bbc47/4e21012c35d44180e10000000a15822b.html?locale=en-US&amp;version=1709.013" target="_self" rel="noopener noreferrer">URL</A> they've provided seems to be outdated.&nbsp;</P><P>Thanks much in advance</P> 2025-12-08T20:45:19.377000+01:00 https://community.sap.com/t5/financial-management-q-a/monitor-gr-ir-account-reconciliation-app-issue/qaq-p/14292926 Monitor GR/IR Account Reconciliation app issue 2025-12-18T06:14:43.277000+01:00 KarthikaMalla25 https://community.sap.com/t5/user/viewprofilepage/user-id/2111531 <P>For the app Monitor GR/IR Account Reconciliation(<SPAN>F3303)</SPAN>, user is able to view the data for few company codes and for few he's not able to view, if i give personal area as *, user is able to view the data for missing company codes.<BR />personal area is maintained on the basis of each company code, but it is not working for few company codes, what can be the issue</P> 2025-12-18T06:14:43.277000+01:00 https://community.sap.com/t5/enterprise-resource-planning-q-a/list-authorization-objects-to-be-maintained-for-a-developer-role-in-s4-hana/qaq-p/14295733 List authorization objects to be maintained for a developer role in S4 HANA. 2025-12-23T06:55:07.357000+01:00 gayathri_kunjaniyanpillai https://community.sap.com/t5/user/viewprofilepage/user-id/2267735 <P>Any standard sap role available in S4 HANA to create a copy of ?</P><P>If we create developer role from SAP_ALL,&nbsp;List authorization objects to be maintained for a developer role in S4 HANA.</P><P>&nbsp;</P><P>List the authorization objects to be removed?</P><P>Share the list of tcodes to be white listed. share the range of tcodes to be maintained in S_TCODE</P> 2025-12-23T06:55:07.357000+01:00 https://community.sap.com/t5/technology-q-a/seeking-advice-on-tools-amp-methodology-for-legacy-rfc-user-permissions/qaq-p/14301772 Seeking Advice on Tools & Methodology for Legacy RFC User Permissions Cleanup 2026-01-06T03:45:52.366000+01:00 constance_ye https://community.sap.com/t5/user/viewprofilepage/user-id/2273299 <P>Hello SAP Security &amp; Basis Experts,</P><P>We are embarking on a critical security remediation project to address over-privileged RFC users across our SAP landscape with 600+ systems. Many of these users and connections are years old, lack clear ownership, and serve various backend tasks.</P><P>Our goal is to understand what business operations each RFC user/interface actually performs and then redesign brand new ones following the principle of least privilege without disrupting genuine business processes.</P><P>There are several key challenges we meet:</P><P>1) Many RFC users were created long ago with no clear current responsible person.</P><P>2) Activities are often triggered by background jobs, making them less visible.</P><P>3) We must not miss crucial but infrequent operations (e.g., year-end financial closing), which short-term monitoring would fail to capture.</P><P><STRONG>We are seeking practical advice on the following specifically:</STRONG></P><P>1) Tool Recommendation: beyond native SM19/SM20 and STUSOBTRACE, what commercial or open-source tools have you successfully used for cross-system RFC user discovery, permission analysis, and activity monitoring? What are their pros/cons for this use case?</P><P>2) Methodology for business need collection: How do you practically identify the business purpose behind legacy technical RFC accounts? Are there effective techniques for correlating job schedules (SM37), interface configurations (BD64/WE20), and log data to reverse-engineer their function?</P><P>3) Capturing low-frequency activities: What is the best practice to ensure yearly/quarterly critical processes are identified? Are there technical methods to trace such execution history?</P><P>We greatly appreciate any insights, war stories, or links to useful resources you can share. Thank you for helping us!</P> 2026-01-06T03:45:52.366000+01:00 https://community.sap.com/t5/sap-learning-q-a/reccommended-c-sec-quot-sap-security-administration-quot-practical-not/qaq-p/14303287 Reccommended C_SEC "SAP Security Administration" Practical (not Theoretical) certification material? 2026-01-07T22:45:15.307000+01:00 NV_Nguyen https://community.sap.com/t5/user/viewprofilepage/user-id/1505986 <P>Hello, I am looking to take the&nbsp; <STRONG>C_SEC "SAP Certified Associate - Security Administrator"</STRONG> Practical (not Theoretical, as now that version of the examination is retired) certification:&nbsp;</P><P><A href="https://learning.sap.com/certifications/sap-certified-associate-security-administrator" target="_self" rel="noopener noreferrer">https://learning.sap.com/certifications/sap-certified-associate-security-administrator</A><BR /><BR />Does anyone have recommendations on practice materials relevant to the practical version, that are <STRONG><EM>not</EM></STRONG> listed below? (because I am already reviewing them):</P><UL><LI>All "Recommended steps to prepare for the exam" Learning Journeys/Courses on the webpage</LI><LI>All digital exercises in each Learning Journey attached (quizzes, step-by-step exercises)</LI><LI>All Live Sessions attached to each Learning Journey (under "Level up your skills" section)</LI><LI>And the following Hands-On practice systems:&nbsp;<SPAN><A class="" href="https://learning.sap.com/practice-systems/exploring-the-authorization-concept-for-sap-fiori-on-sap-s-4hana" target="_blank" rel="noopener noreferrer">Hands-on Practice for Exploring the Authorization Concept for SAP Fiori on SAP S/4HANA (for textbook ADM945),&nbsp;</A><A class="" href="https://learning.sap.com/practice-systems/abap-as-authorization-concept" target="_blank" rel="noopener noreferrer">Hands-on Practice for Exploring the Authorization Concept for SAP S/4HANA and SAP Business Suite (for textbook ADM940)</A></SPAN></LI></UL><P>&nbsp;The Live Sessions directly recommended for this certification are spread out across several months, and not all of them have recordings of previous sessions. I'm not sure what other Hands-On Practice systems or Live Sessions would be beneficial as there are only two Hands-On practice systems directly recommended for this.&nbsp;</P><P>Thank you for any advice</P> 2026-01-07T22:45:15.307000+01:00 https://community.sap.com/t5/enterprise-resource-planning-q-a/authorisations-of-business-partners-roles/qaq-p/14306463 Authorisations of Business Partners Roles 2026-01-13T12:39:00.282000+01:00 FD64 https://community.sap.com/t5/user/viewprofilepage/user-id/1629611 <P>We are struggling with the authorizations of Business Partners.</P><P>&nbsp;</P><P>Our process:</P><OL><LI>Creation of a business partner by finance FLN00 or CLU00 by the finance department</LI><LI>Extend the supplier or customer BP data by the business, with multiple addresses, contacts, etc..</LI></OL><P>&nbsp;</P><P>When using the Manage Supplier Master Data App, we&nbsp; like to extend the supplier BP data with the role FLN01, so the supplier contains both roles FLN00 (set up/ maintained by Finance department) and FLN01 (maintained by Business). But this is not working. Without &nbsp;authoriza<SPAN>tions for the role 000000, we are not able to extend a supplier. NO data can be extended, like contacts.</SPAN></P><P>With the 000000 role users can change with the supplier/ customer &nbsp;master data app also change financial data like bank accounts etc.. They are not allowed to do this. In our governance only people from finance department are allowed to maintain this data.</P><P>&nbsp;</P><P>Can&nbsp; you advise us how we can use the supplier and customer master data apps without giving the role 000000 in te authorization?</P> 2026-01-13T12:39:00.282000+01:00 https://community.sap.com/t5/technology-q-a/access-for-creating-purchase-requisition/qaq-p/14309919 ACCESS FOR CREATING PURCHASE REQUISITION 2026-01-19T12:30:05.549000+01:00 seunabati https://community.sap.com/t5/user/viewprofilepage/user-id/787944 <P>Hello,</P><P>I am creating a business role On SAP public Cloud that allows users to create purchase requisitions. I have assigned the following business catalogs to the role: <STRONG>SAP_MM_BC_PURCH_DOC_DSP_PC</STRONG>, <STRONG>SAP_PS_BC_PROJ_FIN_ANLYTC_MC</STRONG>, and <STRONG>SAP_MM_BC_PR_MANAGE_PC</STRONG>.</P><P>However, users still encounter the error <STRONG>“Missing authorization: PReq Create: Doc. Type”</STRONG> when attempting to create a requisition. My intention is to keep the role limited to core access only.</P><P>Please advise which additional business catalog is required to resolve this authorization issue.</P><P>Thank you.</P> 2026-01-19T12:30:05.549000+01:00 https://community.sap.com/t5/technology-q-a/forms-service-by-adobe-btp-persistent-quot-no-client-with-requested-id-quot/qaq-p/14311416 Forms Service by Adobe (BTP): Persistent "No client with requested id" Error after Configuration 2026-01-20T20:49:08.473000+01:00 Hossam_Fathy https://community.sap.com/t5/user/viewprofilepage/user-id/1960909 <P><STRONG>Hello SAP Community,</STRONG></P><P>I am seeking assistance with a persistent authentication issue while setting up <STRONG>SAP Forms Service by Adobe</STRONG> in the BTP Cloud Foundry environment.</P><P>Despite following the standard setup documentation, I am unable to access the <STRONG>Template Store UI</STRONG>. I consistently receive the following error: <CODE>No client with requested id: sb-ads-xsappname!b65488</CODE></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hossam_Fathy_0-1768938457447.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/363526i6E3C02EFCF8BB924/image-size/medium?v=v2&amp;px=400" role="button" title="Hossam_Fathy_0-1768938457447.png" alt="Hossam_Fathy_0-1768938457447.png" /></span></P><P><STRONG>What I have configured so far:</STRONG></P><OL><LI><P><STRONG>Entitlements:</STRONG> Added "Forms Service by Adobe" and "Forms Service by Adobe API" (free plans).</P></LI><LI><P><STRONG>Subscription:</STRONG> Successfully subscribed to "Forms Service by Adobe" (default plan).</P></LI><LI><P><STRONG>Instance:</STRONG> Created a service instance for "Forms Service by Adobe API" in my space.</P></LI><LI><P><STRONG>Role Collections:</STRONG> Created and assigned a Role Collection containing <CODE>ADSAdmin</CODE> and <CODE>TemplateStoreAdmin</CODE>.</P></LI><LI><P><STRONG>Direct Access:</STRONG> I have tried accessing the UI via the "Go to Application" link and via the direct URL found in the destination configuration.</P></LI></OL><P><STRONG>Steps taken to resolve the issue (but failed):</STRONG></P><UL><LI><P>Verified that the <STRONG>Application Identifier</STRONG> in the Role Collection matches the subscription.</P></LI><LI><P>Unsubscribed and re-subscribed to force a new OAuth registration.</P></LI><LI><P>Cleared browser cache and used Incognito/Guest modes.</P></LI><LI><P>Waited for propagation (over 30 minutes).</P></LI></UL><P>It seems the XSUAA service is still looking for a specific client ID (<CODE>!b65488</CODE>) that perhaps isn't being correctly mapped or registered in the Trust Configuration.</P><P><STRONG>System Details:</STRONG></P><UL><LI><P><STRONG>Environment:</STRONG> Cloud Foundry</P></LI><LI><P><STRONG>Region:</STRONG>&nbsp;US10</P></LI><LI><P><STRONG>Identity Provider:</STRONG> Default and Custom</P></LI></UL><P>Has anyone encountered this specific mismatch before? Is there a way to force a refresh of the OAuth2 clients in the subaccount, or is this a backend issue that requires an SAP Support ticket?</P><P><STRONG>Thank you for your help!</STRONG></P> 2026-01-20T20:49:08.473000+01:00 https://community.sap.com/t5/enterprise-resource-planning-q-a/best-practice-for-managing-business-role-changes-after-an-upgrade/qaq-p/14312677 Best Practice for Managing Business Role Changes After an Upgrade 2026-01-22T14:03:24.158000+01:00 ReginaCr https://community.sap.com/t5/user/viewprofilepage/user-id/1800974 <P>Dear community,</P><P>what is in your opinion the best way to manage the changes after an upgrade in consideration of transports of software collections?</P><P>At the moment it seems for me, you have to maintain the changes two times with a 3 landscape system:</P><P class="lia-indent-padding-left-60px" style="padding-left : 60px;">1. Update the business roles in Test system to make the changes available for testing the release</P><P class="lia-indent-padding-left-60px" style="padding-left : 60px;">2. Update the business roles in Q system again after the release was deploy to Q and Productive System to transport the changes with the software collection to all 3 systems</P><P>Is this the correct procedure? Is there a better way which I am missing?</P><P>thank you for your inputs,&nbsp;</P><P>kind regards</P><P>Regina</P><P>&nbsp;</P><P>&nbsp;</P> 2026-01-22T14:03:24.158000+01:00 https://community.sap.com/t5/technology-q-a/password-deactivation-through-bapi-user-change/qaq-p/14315645 Password deactivation through BAPI_USER_CHANGE 2026-01-27T11:52:36.366000+01:00 SAPSupport https://community.sap.com/t5/user/viewprofilepage/user-id/121003 <P>Hi team,</P><P>We are using IDM to manage our user provisioning. As we are implementing SNC, we got a requirement to deactivate password during the new user creation. We are using BAPI_USER_CHANGE to set the password .We are trying to deactivate the password now, but the field LOGONDATA-CODVN is an internal field only.</P><P>&nbsp;</P><P>Please suggest how to deactivate the password for users through the BAPI.</P><P><BR /><BR /><BR /></P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B> 2026-01-27T11:52:36.366000+01:00 https://community.sap.com/t5/technology-q-a/12-characters-limit-on-userid-in-su01/qaq-p/14320689 12 characters limit on UserID in SU01 2026-02-03T13:41:51.062000+01:00 SAPSupport https://community.sap.com/t5/user/viewprofilepage/user-id/121003 <P>We are not able increase the 12 character limit on UserID created in SU01. it is not accepting UserID longer than 12 characters.</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B> 2026-02-03T13:41:51.062000+01:00 https://community.sap.com/t5/technology-q-a/odata-v4-url-encoding-issue-with-sap-web-dispatcher-proxy-sales-order/qaq-p/14323140 OData V4 URL Encoding Issue with SAP Web Dispatcher + Proxy (Sales Order Management App) 2026-02-06T16:09:11.380000+01:00 Veeranna_Vyapari https://community.sap.com/t5/user/viewprofilepage/user-id/1884968 <P>Hi SAP Community,</P><P>We are facing an issue with <STRONG>OData V4 URL encoding</STRONG> after activating the <STRONG>standard Sales Order Management application</STRONG> in <STRONG>S/4HANA</STRONG>.</P><BLOCKQUOTE><P><STRONG>Note:</STRONG> An <STRONG>SAP incident has already been created</STRONG>, and in parallel we are reaching out to the community to learn from experts who may have faced a similar issue.</P></BLOCKQUOTE><HR /><H3 id="toc-hId-1918633819">Issue summary</H3><P>The problem occurs because <STRONG>equal signs (=) in the OData V4 request URL are being URL-encoded (%3D)</STRONG> before the request reaches the <STRONG>S/4HANA ICM</STRONG>.</P><P>In the <STRONG>browser</STRONG>, the request URL is correct and the <CODE>=</CODE> signs are <STRONG>not encoded</STRONG>:</P><PRE><CODE>https://etgwdsp.etgworld.com/sap/opu/odata4/sap/c_salesordermanage_srv/srvd_f4/sap/c_orgdivisionvaluehelp/0001;ps='srvd-c_salesordermanage_sd-0001';va='com.sap.gateway.srvd.c_salesordermanage_sd.v0001.ae-c_salesordermanage.createwithsalesordertype.organizationdivision.SalesOrderManageType.X'/$metadata?sap-language=EN</CODE></PRE><P>However, when the request reaches the <STRONG>ICM</STRONG>, the raw HTTP request shows that:</P><UL><LI><P><CODE>=</CODE> is encoded as <CODE>%3D</CODE></P></LI><LI><P><CODE>%27</CODE> is converted back to <CODE>'</CODE></P></LI></UL><P>Example from <STRONG>ICM level 3 trace</STRONG>:</P><PRE><CODE>GET /sap/opu/odata4/.../0001;ps%3D'srvd-c_salesordermanage_sd-0001';va%3D'com.sap.gateway.srvd.c_salesordermanage_sd.v0001.ae-c_salesordermanage.createwithsalesordertype.organizationdivision.SalesOrderManageType.X'/$metadata?sap-language=EN</CODE></PRE><P>The <STRONG>SAP Gateway expects the “=” characters to remain unencoded</STRONG>, and because of this encoding, the request fails.</P><HR /><H3 id="toc-hId-1722120314">Landscape and behavior</H3><P><STRONG>Middleware involved</STRONG></P><UL><LI><P>SAP Web Dispatcher</P></LI><LI><P>Corporate HTTP Proxy</P></LI></UL><P><STRONG>Observed behavior</STRONG></P><OL><LI><P>All apps work when the <STRONG>proxy is bypassed</STRONG> (Web Dispatcher active)</P></LI><LI><P>All apps work when the <STRONG>Web Dispatcher is bypassed</STRONG> (proxy active)</P></LI><LI><P>The issue occurs <STRONG>only when both proxy and Web Dispatcher are active</STRONG></P></LI></OL><P>This strongly indicates that the URL is being modified due to an <STRONG>interaction between the proxy and Web Dispatcher</STRONG>.</P><HR /><H3 id="toc-hId-1525606809">Troubleshooting performed</H3><UL><LI><P>All required <STRONG>roles, authorizations, services, and ICF nodes</STRONG> are active</P></LI><LI><P>Web Dispatcher <STRONG>profile parameters</STRONG> adjusted to prevent URL encoding</P></LI><LI><P>Web Dispatcher <STRONG>mod file changes</STRONG> attempted for OData V4 handling<BR />→ Issue still persists</P></LI></UL><P>As per <STRONG>internal network team analysis</STRONG>:</P><UL><LI><P>A change may be required in the <STRONG>Web Dispatcher index file</STRONG></P></LI><LI><P>Neither the <STRONG>network team nor BASIS team</STRONG> has access to modify it</P></LI><LI><P>Only <STRONG>SAP</STRONG> can make changes at this level</P></LI></UL><HR /><H3 id="toc-hId-1329093304">Questions to the community</H3><UL><LI><P>Has anyone experienced a <STRONG>similar OData V4 URL encoding issue</STRONG> with <STRONG>Web Dispatcher + proxy</STRONG>?</P></LI><LI><P>Is this a <STRONG>known limitation or defect</STRONG> in SAP Web Dispatcher for OData V4?</P></LI><LI><P>Are there any <STRONG>supported parameters, SAP Notes, or workarounds</STRONG> to prevent encoding of <CODE>=</CODE> in the URL?</P></LI><LI><P>Should this be handled via <STRONG>ICM settings, Web Dispatcher configuration, or proxy rules</STRONG>?</P></LI><LI><P>Is there any <STRONG>recommended architectural workaround</STRONG> until SAP provides a fix?</P></LI></UL><P>Any guidance, experiences, or references would be greatly appreciated.</P><P>Thanks in advance for your support.</P><P>Varsha J S</P><HR /><P>&nbsp;</P><P>#SAP #S4HANA #ODataV4 #SAPGateway #SAPWebDispatcher #ICM #SAPBasis #SAPFiori #SAPCommunity<BR />@SAP @SAPCommunity <a href="https://community.sap.com/t5/user/viewprofilepage/user-id/121003">@SAPSupport</a></P><HR /><P>&nbsp;</P> 2026-02-06T16:09:11.380000+01:00 https://community.sap.com/t5/enterprise-resource-planning-q-a/looking-for-clarification-for-auth-object-if-role-has-multiple-entries/qaq-p/14328102 looking for clarification for auth object. If role has multiple entries 2026-02-13T15:51:57.007000+01:00 SCHAEF111 https://community.sap.com/t5/user/viewprofilepage/user-id/1682498 <P>If a security role has&nbsp;F_BKPF_BLA has two entries one with&nbsp;ACTVT=03&nbsp;BRGRU=* second has ACTVT=01,02 and&nbsp;BRGRU=ZDZ4.&nbsp; Is the finale combination be ACTVT=01,02,03 for&nbsp;BRGRU=*.</P><P>Does it make a difference if the same auth object is in One role vs two roles</P> 2026-02-13T15:51:57.007000+01:00 https://community.sap.com/t5/technology-q-a/xsuaa-not-getting-the-subject-name-identifier-as-id/qaq-p/14346211 XSUAA not getting the subject name identifier as ID 2026-03-11T07:57:57.377000+01:00 dvvelzen https://community.sap.com/t5/user/viewprofilepage/user-id/1831 <P>Hi,</P><P>We're trying to change `req.user.id` used from xsuaa to the User ID of IAS instead of the email.</P><P>BTP is connected to IAS with OpenID Connect (so "Default Name ID Format = Unspecified" as with SAML is not available).&nbsp;</P><P>In the IAS logs the sub is changed to the expected value `<SPAN>jwtPayload="{"sub":"`.</SPAN></P><P><SPAN>However the req.user.id we get in CAP / JWT token remains the email. </SPAN></P><P><SPAN>Not sure if it's related, but adding a custom atribute in `xs-security.json` and in IAS attributes also isn't reflected in `req.user.attr`. (it only shows the default value configured in `xs-security.json`)</SPAN></P><P><SPAN>Anyone have some insights on how to get the id ?</SPAN></P> 2026-03-11T07:57:57.377000+01:00 https://community.sap.com/t5/technology-q-a/is-transaction-s-alr-87005540-a-reporting-tcode/qaq-p/14348952 Is transaction S_ALR_87005540 a reporting tcode? 2026-03-14T13:47:45.379000+01:00 Shivi_t https://community.sap.com/t5/user/viewprofilepage/user-id/1463515 <P>I have to create a role for tcode&nbsp;S_ALR_87005540. I asked my colleague to if this is a reporting tcode and he said yes it is however, chatgpt and copilot is saying it is not a reporting tcode.</P> 2026-03-14T13:47:45.379000+01:00 https://community.sap.com/t5/human-capital-management-q-a/zbv-cua-is-not-working-as-expected/qaq-p/14355899 ZBV / CUA is not working as expected 2026-03-23T13:40:39.929000+01:00 DominikK https://community.sap.com/t5/user/viewprofilepage/user-id/1457207 <P>Hello experts,</P><P>I'm currently having a strange issue with the CUA. Everything is working perfectly in our CUA system. We don't have duplicate company addresses, and users are assigned the correct one. Our Q-system is also working as expected. We are currently on S4/HANA 2023 SP 03/2025.</P><P>But here’s the problem: We’re currently having issues with our P-system. In this system, there are several users assigned to a different company; for example, the correct company address would be 41000 – Standard Company, and now we have about 90 addressesSAP with a new number and a new description -&gt; 41001 – Standard Company0000012345, etc.</P><P><SPAN>We have deleted or corrected these incorrect company addresses in the CUA system, the Dev system, and the Q system, but we cannot delete them in the P system. Do you have any idea how we can delete these incorrect entries? I tried using transaction SUCOMP, but it doesn’t work. I receive the following error message when I try to delete a company address, and the address we want to use is the default address:<BR /></SPAN></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DominikK_0-1774268501017.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/387664i58AB22683C13A803/image-size/medium?v=v2&amp;px=400" role="button" title="DominikK_0-1774268501017.png" alt="DominikK_0-1774268501017.png" /></span></P><P><SPAN>And even if I assign a new company to the user, I still can't delete that incorrect company.<BR />Sincerely, Dominik <span class="lia-unicode-emoji" title=":slightly_smiling_face:">🙂</span>&nbsp;<BR /></SPAN></P> 2026-03-23T13:40:39.929000+01:00 https://community.sap.com/t5/technology-q-a/ecs-broke-our-rise-pce-waf-2-and-ecs-cannot-fix-it/qaq-p/14362803 ECS broke our RISE PCE WAF 2 and ECS cannot fix it 2026-03-31T14:03:24.712000+02:00 Bakerm00 https://community.sap.com/t5/user/viewprofilepage/user-id/155308 <P>After 4 years in RISE PCE (Azure) we finally were requested by SAP to raise a ticket with ECS to migrate from WAF v1 to WAF v2.</P><P>it looks like ECS have hand crafted the configuration - its not via a defined terraform, bicep or arm template.&nbsp; the WAF v2 rules are in restricted mode and&nbsp;nothing really works...</P><P>Fiori tiles won't work;&nbsp; icon image are missing</P><P>ECS won't provide an export of the WAF config so we can compare and review - even though its our tenant and a shared security model.</P><P>you will have to forgive my ignorance in that as RISE PCE the WAF should have a defined security template that doesn't need any tweaking.</P><P>we already know SAP don't follow MS best practice for SAP on azure; or i would have had WAF v2 4 years ago.</P><P>Anyone got any suggestions i can bat back into ECS?</P> 2026-03-31T14:03:24.712000+02:00 https://community.sap.com/t5/technology-q-a/sap-certification/qaq-p/14371226 Sap certification 2026-04-11T03:05:47.327000+02:00 pradyumna2 https://community.sap.com/t5/user/viewprofilepage/user-id/2023737 <P>Hello all&nbsp;</P><P>I want to schedule SAP certification exam security administrator C_sec_2601 exam , how should I prepare for it ? It's system based exam with new format.&nbsp;</P><P>Please guide&nbsp;</P> 2026-04-11T03:05:47.327000+02:00 https://community.sap.com/t5/technology-q-a/saprouter-reverse-invoke-design-guidelines-and-performance-best-practices/qaq-p/14371436 saprouter reverse invoke : Design guidelines and Performance best practices 2026-04-11T15:43:45.910000+02:00 anganch1 https://community.sap.com/t5/user/viewprofilepage/user-id/1410927 <P>Dear Community,</P><P>&nbsp; &nbsp; &nbsp; As per the security documentation, the usage of reverse invoke saprouter can offer better protection as ports dont have to be opened from DMZ to SAP network zones.&nbsp;</P><P>Using saprouter with reverse invoke would mean that all traffic that otherwise would go directly from frontend (e.g gateway) to backend (e.g S4) networks would now go via the two saprouter (one in DMZ acting as client one in backend acting as server).</P><P>&nbsp;</P><P>There is little information in help.sap or sap notes on this topic.&nbsp;Please can you someone share your experience of using saprouter in this manner (i.e. reverse invoke)</P><P>around</P><UL><LI>best practices /</LI><LI>desgin recommendations /</LI><LI>throughtput and performance /</LI><LI>typical problems like stuck situations and</LI><LI>ofcourse the requirement to have&nbsp; high availability for saprouter as this now becomes the single point of failure for SAP end users etc</LI></UL><P>Thx</P> 2026-04-11T15:43:45.910000+02:00