SAP S/4HANA Administration
Users & Authorizations
64 flashcards · answers and spaced-repetition review in the KnowCard app
You want to enforce an idle-session timeout tonight without a restart. Can rdisp/gui_auto_logout do that, and what does it actually terminate?
You finished editing a role's authorizations in PFCG and clicked Save. A user assigned to it still gets authorization failures. What did you skip?
Why must you copy an SAP standard role into the customer namespace before customizing instead of editing it directly?
You set a login/min_password_lng in an instance profile and RZ10 warns you. Why won't password policy params work there?
In an authorization, a colleague leaves * in a field thinking it means "unset." Why is that dangerous?
A compromised user must be lockable from the child system immediately, but you also want role assignments owned centrally. Which SCUM distribution options give you each?
A user wants the ID "!ADMIN" and another wants "AD!MIN". Which is allowed, and what gets normalized?
After an S/4HANA upgrade, a long-time admin reaches for the SAP_NEW profile. What changed?
A colleague says "just copy JANE's roles from client 100 and she'll have them in client 200 too — same user." Why is that wrong?
You try to add one composite role inside another to build a role hierarchy. Why does SAP not allow that?
You need to find out exactly which authorization checks a user is failing. Why does SAP point you to STAUTHTRACE instead of the older ST01?
A CUA user change shows as unconfirmed in SCUL. What's the right next step before re-sending anything from the master?
A user is assigned several roles. How is the SAP Easy Access menu they see assembled?
In CUA, you can reset a locked-out user's initial password from the child client directly, but you cannot create that user there. Why the asymmetry?
AUTHORITY-CHECK runs against a user with five roles. Does the user need the required authorization in all of them, or just one?
A consultant's 6-week engagement ends. Why set Valid To at creation rather than relying on someone to lock the account later?
Why is directly assigning profiles (and SAP_ALL in particular) discouraged, and what's the one sanctioned exception?
You're onboarding a new client into CUA and it refuses to join. Why does every CUA client require a logical system to be defined first?
You created a role in PFCG and released your transport, but the role didn't arrive in QA. What's the trap with role transport?
You try to delete a green (Maintained) authorization object from a role and it won't go. What's the required intermediate step, and why is it actually useful?
Best practice is named superuser copies of SAP*. Why disable SAP* afterward but never delete it?
You inherit a system and need to know fast whether a client is in CUA and whether it's the master or a child. What's the quickest check?
During an audit you rely on user change documents to prove who changed what. What category of change won't be there?
In SUIM you see a user holds a profile named T-AB12. Did someone hand-assign a profile, or is this normal?
Why is leaving a user's license type blank in a productive client a money problem at audit time?
You type * into an authorization field to grant everything and it's rejected. Why might that field not accept it?
A user complains they can't reuse a recent password. Which parameter is responsible, and what do its siblings control?
You assign users to SUGR groups to delegate admin. What actually gets restricted, and which users stay editable by everyone?
In SU01, when creating an RFC/background account, why pick Create Technical User over Copy?
You mass-create 50 users in SU10 and want to hand out passwords. Why won't SU10 set the initial password for you?
A colleague thinks CUA means all systems share one user database. What does CUA actually centralize, and where does it run?
You tighten the password policy. Why might existing non-compliant users still log on with their old weak passwords?
A new client ships with SAP* and DDIC. Why is treating DDIC as a low-privilege "transport account" a security mistake?
A teammate says "to grant access, link the role to the authorization object." Trace the actual chain — where do roles and field values really attach?
You transport roles from dev to production. Generated profiles arrive — but users still can't use them. What didn't transport?
You're choosing a user type for a fixed RFC interface account. Which type fits, and what trips people up between System and Communication?
You assigned a role to users in PFCG but they still lack the authorizations. What did you forget to run?
Security asks for every user who currently holds SAP_ALL. What's the right tool, and which feature answers it directly?
What makes S_TCODE different from every other authorization object, and why does it matter for locking down access?
You need stricter password rules for a handful of privileged users only, not the whole system. How, and why not just change the global parameters?
You're wiring up CUA RFC links and they authenticate as the dialog admin. Why is that wrong, and what's the often-skipped setup?
You lock a compromised user in SU01. Do their scheduled background jobs and RFC connections also stop?
A new business process needs a role and nobody knows which authorization objects it requires. What's the cleanest way to find out?
Failed-logon auto-lock is on. Which setting decides whether a locked-out user waits for an admin vs. unlocks overnight, and which value is which?
With login/disable_multi_gui_login = 1 set, a user complains a second session was blocked — but their RFC jobs still run in parallel. Is that a bug?
An admin sets a password for a user. Why shouldn't the admin treat that as the user's lasting password?
Across SAP authorization objects, are activity codes 01/02/03 fixed in meaning, and what do they mean?
A role's Authorizations tab shows a yellow triangle. What does it mean, and what must you do before users can rely on the role?
With no custom policy, which password content rules does SAP enforce by default (the ones that trip up auto-generated passwords)?
You gave a user a role valid only next month. What background job actually makes that start and stop on time, and what happens if it isn't scheduled?
Why is deleting SAP* from any client actively dangerous, and what default-on parameter is your backstop?
An identity was provisioned into S/4HANA through SAP Cloud Identity Services. Where does the admin see it, and why can't the address be edited in SU01?
In on-premise S/4HANA you want to link employees to business partners manually, but the admin Fiori app for it isn't available. Why, and how do you get it?
A colleague locks the standard user DDIC to harden the system, and afterward the SAP system refuses to start. What was overlooked?
With SAP IDM having no direct successor, what identity reference architecture does SAP now point to, and how does an on-premise S/4HANA system plug into it?
Your company isn't ready to move identity management to the cloud after SAP IDM's end of maintenance. Which on-prem-capable SAP product still covers workflow-based authorization management, and why does it survive IDM's retirement?
ST01 and STAUTHTRACE only give you a short-term snapshot of authorization checks. Which transaction do you use for long-term authorization analysis, and where are its traces kept?
After a user is deleted, someone recreates the same user ID for a different person, and now audit trails point at the wrong employee. How do you stop the ID from being reused, and how do you deliberately allow it later?
Your S/4HANA employee master data (emails, phone numbers, addresses) keeps drifting out of sync across systems. What layer does S/4HANA add on top of the classic SU01 user to fix this, and what happens to the SU01 address data afterward?
You'd rather not juggle a separate SQL tool to manage HANA database users alongside your ABAP users. How does S/4HANA let you do both from one place, and what do you switch on first?
You need to create hundreds of HANA platform users at once, but SU10 mass maintenance won't touch them. What tool do you use, and how do you check the links afterward?
Since which S/4HANA release does SAP ship security settings already active, and give a concrete parameter example of this policy.
A customer's identity strategy still centers on SAP Identity Management (IDM). Why is that now a problem, and what does SAP point to instead?
Central User Administration (CUA/ZBV) is still available and fast to set up in S/4HANA, so why does SAP now steer customers away from it as a central identity strategy?
Start learning today
Free to start — download the app or use it in your browser.
