SAP AS ABAP Administration
Authorization Concept & Roles (PFCG)
29 flashcards · answers and spaced-repetition review in the KnowCard app
You created a replacement super user to retire SAP*. Later a regular user administrator tries to modify that account and cannot. Why, and what governs it?
In PFCG settings you can pick simple maintenance, basic maintenance, or complete view. A team wants to assign roles to HR positions instead of named users. Which mode, and what is the precondition?
A junior admin treats the PFCG Menu tab as cosmetic navigation and plans to add every authorization by hand on the Authorizations tab. Why is skipping the menu the wrong move?
You transport a role from DEV and tick the option to include user assignments. The role already exists in PROD with its own assigned users. What happens to them?
An auditor asks 'which users can currently execute transaction SM59, and via which role?' What tool answers this, and what would report RSUSR070 give you instead?
After you build a role's menu in PFCG, the Authorizations tab is already pre-filled with proposed values. Where do those proposals come from, and which transaction changes them globally?
After an upgrade you reopen a role's authorization data and nodes are flagged Old or New instead of the usual Standard or Maintained. What is each state telling you?
A role worked for months. After someone edited its menu, the PFCG Authorizations tab status turned yellow ('no longer current') on its own. What does that mean and what must you do?
Central User Administration is active in the landscape. An admin assigns a role to a user directly in the child (production) system. Why is that a mistake?
Two admins argue: one says an authorization object is 'just the ACTVT activity,' the other says ACTVT alone cannot scope access. Who is right and why?
A team migrating to S/4HANA Fiori assumes PFCG is obsolete and authorizations now live only in Fiori catalogs. Where do the authorization objects for a Fiori business role actually come from?
You edit an SAP-delivered role (name starts SAP_) directly to add a transaction. Everything works for months. Then an upgrade runs. What happens, and what should you have done?
A request asks to let a user 'just view' data. An admin sets ACTVT to 02. Why is that wrong, and which value should it be?
Roles arrive in production by transport and assignments include validity dates. If you never schedule PFCG_TIME_DEPENDENCY, what slowly goes wrong?
A new SAP role grants nothing for a transaction you forgot to include. A junior admin assumes 'no explicit deny means it's allowed.' Why is that wrong, and what does it imply for role design?
After an upgrade, an admin wants users to keep working without auth errors and reaches for a profile. Which of SAP_ALL, SAP_NEW, or S_A.* fits, and what is the trap with each?
A composite role grants one user too much in a single object. An admin opens the composite role to trim that authorization. Why will this fail, and where must the fix actually go?
A role transport just imported into production. Users still don't have the new authorizations. An admin is about to regenerate the profiles in PROD. Is that the missing step?
In a small team, one trusted admin both creates users and assigns their authorizations. An auditor flags it. What control is violated and why does 'they're trusted' not answer it?
Someone says 'I gave the user the S_TCODE authorization.' What's imprecise about that, and what's the real difference between an authorization object and an authorization?
An admin learned profiles years ago and starts hand-building an authorization profile to attach to a new role. In the modern PFCG model, why is that backwards?
Right after a release upgrade, what transaction reconciles your authorizations with SAP's new proposals, and how do you keep users productive while you work through it?
A user reports one action failed with an authorization error. Do you reach for SU53 or ST01 first, and what does the other one buy you?
You open a customer role's Authorizations tab in PFCG and the traffic light is red, not yellow. What specifically is unfinished, and can you generate the profile yet?
An admin needs to do spool, user, and transport administration and asks for SAP* with SAP_ALL 'to be safe.' What should you grant instead and why is the blanket grant the wrong call?
A user can open a transaction fine but gets an authorization error when they try to change a record inside it. How can both be true at once?
You assigned a role and the profile is generated, but the user still gets authorization errors. Assignment isn't enough — what two things actually make the profile take effect?
On a current SAP release, an admin troubleshooting role generation plans to set auth/no_check_in_some_cases = Y to 'turn on the profile generator.' Why is that usually a non-action today?
On DEV you regenerate a role constantly and keep clicking User Comparison after every save. Is there a way to stop doing it by hand, and why not rely on that in production?
Start learning today
Free to start — download the app or use it in your browser.
