27.04.2013 Views

SAP Basis

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Unit 11: Basics of User Administration ADM100<br />

Lesson:<br />

354<br />

Authorization Concept<br />

Lesson Duration: 60 minutes<br />

Lesson Overview<br />

In this lesson, the terms authorization object, authorization profile,<br />

authorization check, and role are discussed in a common context. The<br />

focus here is on role maintenance; that is, on creating a role.<br />

Lesson Objectives<br />

After completing this lesson, you will be able to:<br />

• Copy, create, and maintain roles<br />

• Maintain the assignment of roles and users<br />

Participants often do not understand the meaning of the differentiation<br />

between roles and profiles. A role is primarily a functional description,<br />

such as HR employee. At this point, there is no consideration of the<br />

required technical authorizations for editing tables or data. The technical<br />

realization of the role, in the form of concrete authorizations is achieved<br />

through the authorization profile associated with the role. If you assign<br />

a role to a user without performing a user master comparison, the user<br />

does not have any of the authorizations that belong to this role. You<br />

would be creating a pseudo-user that was assigned the role but to which<br />

no profile was assigned. This user can only log on and off the system, but<br />

cannot perform any actions in the system.<br />

The advantages of this two-level approach are, on one hand, the<br />

opportunity to implement a security checking principle requiring at<br />

least two persons, that is, an administrator is authorized to assign a<br />

role to users, and another user is authorized to perform a user master<br />

comparison. On the other hand, it also allows administrators to maintain<br />

a time dependency for authorizations of a user.<br />

Business Example<br />

The authorizations for users are created using roles and profiles. The<br />

administrator creates the roles, and the system supports him or her in<br />

creating the associated authorizations.<br />

414 © 2003 <strong>SAP</strong> AG. All rights reserved. 2003/Q3

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!