Monday, 23 May 2011

SAP SECURITY INTERVIEW - What authorization objects are needed for PFCG?

SAP Transport Authorization

To release Task

S_TRANSPRT
ACTVT=43, 03, 75
TTYPE=TASK
Other type:CLCP  Client Transports
CUST  Customizing Requests
DTRA Workbench Requests
MOVE Relocation transports
PATC  Preliminary Corrections and Deliveries
PIEC    Piece lists
TASK  Tasks
TRAN  Transport of copies

S_DATASET  
PROGRAM=SAPLSTRF, SAPLSLOG 
ACTVT=34
FILENAME=* 

To release Customizing Requests

S_TRANSPRT  
TTYPE=CUST
ACTVT=43, 03, 75
S_DATASET  
PROGRAM=SAPLSCTS_RELEASE, SAPLSLOG, SAPLSTRF
ACTVT=33, 34
FILENAME=*
S_RFC 
FC_TYPE=FUGR
RFC_NAME=STPA
ACTVT=16; 

 

Authorization object needed for PFCG access 
 

S_USER_AGR 
ACT_GROUP= * (You can restrict by role, if proper naming convention is used)
ACTVT=01, 02, 03, 64 other fields below
01   Create or Generate
02   Change
03   Display
06   Delete
08   Display change documents
21  Transport
22   Enter, Include, Assign
36   Extended maintenance
59   Distribute
64   Generate
68   Model
78   Assign
79   Assign Role to Composite Role
DL   Download
UL   Upload

S_USER_GRP 
CLASS=  
ACTVT=22; 03   
Other activity
01        Create or Generate
02        Change
03        Display
05        Lock
06        Delete
08        Display change documents
22        Enter, Include, Assign
24        Archive
68        Model
78        Assign

S_USER_TCD 
TCD=   * (Transaction in role)

S_USER_PRO
PROFILE= *
ACTVT=01, 06   
Other activity
01        Create or Generate
02        Change
03        Display
06        Delete
07        Activate, generate
08        Display change documents
22        Enter, Include, Assign
24        Archive

S_TCODE
TCD=PFCG;

No comments:

Post a Comment