SAP ABAP IMG Activity ISP_BERECHTIGUNGEN (Create Activity Groups for Users and Authorization Maintenance)
Hierarchy
IS-M (Software Component) SAP MEDIA
   IS-M (Application Component) SAP Media
     JAS (Package) Application development R/3 Publishing Advertising System***
IMG Activity
ID ISP_BERECHTIGUNGEN Create Activity Groups for Users and Authorization Maintenance  
Transaction Code S_KK4_74001536   IMG Activity: ISP_BERECHTIGUNGEN 
Created on 19990816    
Customizing Attributes ISP_BERECHTIGUNGEN   Maintain Authorizations 
Customizing Activity ISP_BERECHTIGUNGEN   Maintain Authorizations 
Document
Document Class SIMG   Hypertext: Object Class - Class to which a document belongs.
Document Name ISP_BERECHTIGUNGEN    

Create roles for user and authorization maintenance. You must log on as superuser.

If you only have one administrator, this person is the superuser and can perform all actions. Create an appropriate role to which you assign the corresponding transactions. The following actions are not required in this case.

If you want to create a "distributed administration" with multiple administrators in your company, it makes sense to split the work of the administrators as follows. At least two people are always involved in this three-step concept when a user's authorizations are changed.

  • Define a role for each of the following:
    • Authorization administration
      Using transaction PFCG, the authorization administrators define the roles (role maintenance). They choose transactions and edit the corresponding authorization data. They are allowed to save the authorization data for the roles, but not generate a profile.
      Create a role that is not assigned any transactions but for which you choose the template SAP_ADM_AU and generate a corresponding profile.
    • Activation administration
      The activation administrators check the authorization data using transaction SUPC (mass generation of profiles). They are not allowed to change them but can generate the corresponding profiles.
      Create an activity group which is not assigned any transactions but for which you choose the template SAP_ADM_PR and generate a corresponding profile.
    • User administration
      User administrators assign roles to the users using transaction SU01 (user maintenance). This automatically assigns the profiles corresponding to the roles.
      Create a role that is not assigned any transactions but for which you choose the template SAP_ADM_US and generate a corresponding profile.

When saving the authorization data for the roles, ensure that the profile names do not begin with 'T'. Apart from the superuser, all administrators may generate profiles that do not begin with the letter 'T'. This ensures that you cannot change the profiles that are assigned to you.

Creating sub-administrators:

  • A sub-administrator does not have authorization to maintain users in the user group "SUPER".
  • If you want to define further sub-administrators, ensure that these people do not have maintenance authorizations for users in the user group "SUPER". The value "SUPER" must not be included in the authorizations for the object S_USER_GRP for these sub-administrators. This prevents you from assigning authorizations to yourself. In addition, you should not have authorization to regenerate and assign profiles that are assigned to yourself. You can prevent this by only allowing certain profile names for the authorization object S_USER_PRO, only profiles that begin with 'T' for example.

Additional information

The following authorization objects are important for distributed administration. You can use these to finetune administration:

For more information, see BC - Users and Roles.

Transport

You transport authorizations as follows:

  1. Display the list of authorizations.
  2. Select the object class.
  3. Choose Authorization -> Transport.
  4. Select the authorizations you wish to transport.
  5. Confirm your selections and enter the correction number.

Business Attributes
ASAP Roadmap ID 209   Establish Authorization Management 
Mandatory / Optional 2   Optional activity 
Critical / Non-Critical 2   Non-critical 
Country-Dependency A   Valid for all countries 
Assigned Application Components
Documentation Object Class Documentation Object Name Current line number Application Component Application Component Name
SIMG ISP_BERECHTIGUNGEN 0 I170007100 SAP Media 
Maintenance Objects
Maintenance object type C   Customizing Object 
Assigned objects
Customizing Object Object Type Transaction Code Sub-object Do not Summarize Skip Subset Dialog Box Description for multiple selections
PFCG T - Individual transaction object PFCG ISM00002 Maintain Activity Groups - Profile Generator 
History
Last changed by/on SAP  20000209 
SAP Release Created in