SAPAuditInformationandApproachAuthorizationExample1.UserMasterRecordUser:FrankW.LyonsProfile:Example2.Profile:ExampleObject:Authorizations:S_ProgramABAP:3.Authorization:ABAP:Object:S_ProgramValues:Fields:*ProgramGroupSUBMIT,VARIANTActivityAuthorizationSystem:1.ProfilesOneormoreassignedtoauser2.ObjectsMustbeuniquenameswithoneormorefields3.FieldsContainvaluesforauthoritychecking4.AuthorizationsCanhavethesamenamesastheyarephysicallyandphysicallylinkedtoanobjectFieldgroupforanobjecthasmultiplevaluesandcanbesharedacrossobjectsInitialDefaults1.InitialClientsClient000StandardmodelClient001Modelforuserdefinedclients.(template)2.InitialUserIdsSAP*Defaultsuperuser.AusermasterrecordiscreatedduringinstallationbutitisnotneededbySAP*toaccessthecompletesystem.IftheSAP*masterrecordisdeleted,theSAP*accounthasthefollowingspecialprivileges:ItisnotsubjecttoauthorizationchecksandthereforehasallauthorizationsIthasthepassword“PASS”,whichcannotbechangedwithoutcreatinganewusermasterrecord.Topreventdeletion,assignSAP*usertoagroupcalledSUPERandonlysuperusershouldbeabletomaintainusergroupSUPER.3.InitialSecurityParametersParametersforuserlogonlogin/min_password/lngMinimumpasswordlengthdefaultis(3)login/password_expiration_timeNumberofdaysafterwhichapasswordmustbechanged.Thedefaultiszero,whichdoesnotenforcepasswordchanges.Recommendedvalue=45.login/fails_to_session_endNumberoftimesausercanenteranincorrectpasswordbeforethesystemendstheloginattempt.Thedefaultis(3).login/fails_to_user_lockNumberoftimesausercanenteranincorrectpasswordbeforethesystemlockstheuseragainstfurtherlogonattempts.Thedefaultis(12).Recommend(3).Whenapasswordislockedinthismanner,itisautomaticallyunlockedbythesystematthestartofthenextday(midnight).AddingUsers1.Eachusermusthaveamasterrecord.2.Eachusermasterrecordreferstooneormoreprofilesthatdeterminetheaccessrightsfortheuser.3.Masterrecordcontains:UserIDPasswordUsergroupsUsertypePeriodofvalidityreferencestoauthorizationprofilesMasterrecordscanbedeletedbutitwillaffecttheaudittrail.Bettertolocktheuser’smasterrecordMenuPath:Tools-Administration-UserMaintenance-User-Lock/Unlock.4.UserGroupIfapersonisassignedtoausergroup,onlytheadministratorswhoareauthorizedforthatusergroupcanalterusermasterrecords.Ifauserisnotassignedtoagroupthenanyuseradministratorcanaltertheusermasterrecord.AddingProfilesProfilesandAuthorizationsexistinbothmaintenanceandactiveversions.Allowsforupdatestomaintenancebeforeitisactivated.Separationofmaintenanceandactivationfunctions.1.SystemProfilesSAPStandardandSuperUserProfilesS_A.SYSTEMUnlimitedaccesstoallusers,profiles,andauthorizationsS_A.ADMINAuthorizationsforSAPsystemadministration.Thisincludesallauthorizationsexceptfor:MaintenanceofusersinusergroupSUPERMaintenanceofprofilesandauthorizationswithnamesbeginning“S_A.”S_A.CUSTOMIZAuthorizationsforuseintheSAPCustomizingsystemS_A.DEVELOPAuthorizationsforuseintheSAPDevelopmentenvironment(excludesanyuserorprofileauthorizations)S_A.USERBasissystemauthorizationsforend-users(e.g.,S_Program,S_DBC_MONI,etc.2.StartupProfilesProfileNameDescriptionS_ABAP_ALLAllABAP/4authorizationsS_ADMI_ALLAllsystemadministrationfunctionsS_BDC_ALLAllbatchinputactivitiesS_BTCH_ALLAllbatchprocessingauthorizationsS_DDIC_ALLDDIC:AllauthorizationsS_DDIC_SUDataDictionary:AllauthorizationsS_NUMBERNumberra...