SAP AS Java Administration
Users, Groups & Principals
19 flashcards · answers and spaced-repetition review in the KnowCard app
In the UME data model, which properties live on the 'user account' principal rather than on the 'user' principal?
A user belongs to group G, and G is a lower-level group under parent group P. Which role assignments does the user effectively possess?
After switching the UME data source to an ABAP client, how do ABAP roles and ABAP user-role assignments appear inside AS Java?
The SAPJSF communication user connects the UME to AS ABAP over JCo. What decides whether the UME can only read, or also write, ABAP user data?
How do the built-in UME groups Everyone, Authenticated Users, and Anonymous Users relate to one another?
No user is directly assigned the default 'Everyone' role, yet every user has its authorizations. How does that work?
Under what conditions must you activate the SAP* emergency user in the UME, and what does it let you do?
What happens to all the normal users while the SAP* emergency user is active in the UME?
Why is the SAP* emergency user largely unnecessary in an AS Java that runs successfully on the ABAP data source?
In the Config Tool, which two UME properties do you set to activate the SAP* emergency user?
When stopping application servers to activate the UME emergency user, which instance do you not need to stop?
With an ABAP data source, what do ABAP user groups become inside the UME, and what capability does that unlock?
Why is the default Guest user normally kept locked yet must never be deleted?
A colleague claims the user-admin tool you use in AS Java changes depending on the configured data source. Is that true of the UME Administration Console?
Among the UME user types, which one can never log on to AS Java at all, and why is 'Technical users' not the answer?
When creating a user in the UME Administration Console, which user type can you not assign, and what is special about changing a user's type afterwards?
You need to find out who modified a user and when a role was created in the UME. Which of the four UME-relevant logs records that, and what governs whether the entry appears?
With a remote ABAP system as the UME data source, why does the default administration user appear as J2EE_ADM_<SID> instead of just Administrator?
Why does the UME deliberately expose ABAP PFCG roles as groups instead of leaving ABAP and Java authorizations completely separate?
Start learning today
Free to start — download the app or use it in your browser.
