SAP AS ABAP Administration
User Administration
38 flashcards · answers and spaced-repetition review in the KnowCard app
You're setting up an administrator to log on to the NetWeaver Administrator (AS Java side). Where do you actually create and manage that user, and what role do they need?
In production, a support team wants five people sharing one Dialog user ID logged on at once. What breaks that plan?
You open SU01 to create a user. Which fields are the technical minimum to save the record, and on which tab do they live?
An admin assigns an accounting number and cost center to a user expecting it to restrict what that user can do. What does that field actually do?
A user in an overseas office reports all timestamps and the logon language are wrong. Which tab fixes this, and can the user do it themselves?
A user asks why a screen field is auto-filled with their user name every time. What mechanism does this, and how is it configured?
You're rolling out single sign-on with an external security product. Which SU01 tab must you populate, and what is the underlying network prerequisite?
An application team asks you to enable a personalization object on the Personalization tab, but nothing shows up to select. What step did they skip?
You're about to run a system measurement but discover many users were never classified. Why is that a problem, and when should classification have happened?
You must change roles and lock a specific slice of 800 users at once. Which transaction, and what makes the target selection painless versus painful?
A user mistypes their password a few times and their GUI window closes, but they can still log on again. A different threshold would have locked the account. Which two parameters are these, and how do they differ?
A user was locked out yesterday by failed logons and finds the account working again this morning, with no admin action. What setting explains this?
An auditor asks you to prove idle SAP GUI sessions are dropped automatically. Which parameter does this, and what value silently disables the protection?
After a security review you delete the SAP* user master record entirely, assuming that removes the all-powerful account. Why is the system now less secure, not more?
You want to permanently close the emergency SAP*/PASS logon path. Which parameter do you set, where do you set it, and what mistake reopens the hole later?
Instead of deleting SAP*, what is the recommended way to neutralize it while still protecting the account from tampering?
A colleague treats DDIC as just a second all-powerful superuser like SAP*. What is DDIC actually for, and what can it uniquely do that SAP* is not meant for?
An admin plans to delete the EarlyWatch user to tidy up unused accounts. Why leave it, and what is the only hardening step it actually needs?
During installation SAP* gets a master record in clients 000 and 001 with password 06071992. Beyond just setting a password, what does creating that record actually change about SAP*?
A user just changed their password and immediately wants to change it again, but the system won't let them for a day. Which parameter causes this and why does it exist?
Which SU01 tabs make up a user master record, and does maintaining SNC or License data change what the user is allowed to do?
Why is it deliberately risky to let one person both create users and assign their authorizations, and what is the standard mitigation?
Your organization already keeps user identities in a corporate directory. What SAP mechanism lets you store that user data once instead of duplicating it, and what protocol does it need?
You need central identity management spanning both SAP and non-SAP systems. Why is CUA not the right answer, and what is?
Memory consumption on a system spikes as you onboard thousands of users with rich role menus. What is the non-obvious cause, and what are the two levers to relieve it?
Since SAP NetWeaver 7.0 you can set long, mixed-case passwords. Which specific password choices make an account no longer downward-compatible, and which parameter governs this?
You need a technical account behind a public web service used by a large anonymous crowd. Which user type fits, and why is Dialog or System the wrong pick here?
You want every Internet user to inherit one identical authorization set without maintaining each account. Which user type do you build the template as, and what is special about logging on with it?
You created a user in client 100, but the user reports they cannot log on to client 200 on the same system. SU01 shows the account exists. What is wrong, and how do you fix it?
You used SU10 to remove a role from 200 users during an incident. Minutes later an affected user is still doing the restricted action in their open session. Did the change fail?
For an annual license measurement across a multi-system landscape, why isn't running USMM in each system enough, and what is the correct end-to-end chain to SAP?
A junior admin assumes that putting a user into a user group (SUGR) controls what that user can do in the system. Why is that wrong, and what do user groups actually govern?
A background job and a periodic RFC interface both need a technical account that must never stop working because a password expired. Which user type do you pick, and why not Communication?
On a freshly installed system with default password profile parameters, an auditor asks how often passwords expire and how many old passwords are blocked. What do the defaults actually mean, and where is the audit gap?
You are provisioning an account that will only ever log on via single sign-on. Among the initial-password options, which do you choose, and what breaks if you instead enter or generate one?
An admin sizing an S/4HANA license assumes counting named users (as in the classic model) is sufficient. What does that miss, and how does S/4HANA measurement actually differ?
Independent of any profile parameters, a user tries to set their password to SAP* and it's rejected. Which built-in default password rules are always enforced?
During an audit you must show who changed a sensitive user's roles last quarter, but someone claims the log was cleared. Why is that claim implausible, and where do you look?
Start learning today
Free to start — download the app or use it in your browser.
