Introducing Authorization Control

Objective

After completing this lesson, you will be able to define roles and set the authorization objects.

Authorization Control

Authorization objects are defined within roles and assigned to end users. Through these roles, end users are permitted to execute specific transactions with clearly defined authorizations.

SAP Display Roles interface for the role SAP_BR_BOM_ENGINEER with the description BOM Engineer. The interface includes various tabs such as Description, Menu, Workflow, Authorizations, User, MiniApps, and Personalization, with a hierarchy of menu items displayed on the left and node details on the right.

When you use transaction PFCG to create a new role or modify an existing one, the first step is to define the transactions that are assigned to the role. These transactions are then displayed in the user menu. If a user attempts to start a transaction from the SAP standard menu that is not assigned to their role, the system issues an error message.

Within authorization maintenance, you generate an authorization profile based on the selected transactions. When you assign Document Management transactions, the system automatically proposes the required authorization objects for DMS.

Work with Authorization Control

Introduction

So far, you and your team have worked in the SAP system using the authorizations assigned to you. You have now been approached by colleagues from other areas of the company who also require access to the documents they have created.

To address this requirement, you decide to define a new role with restricted authorizations.

Task 1: Define a role and authorization

Watch the following video to see how a role is defined and how authorizations are set up.

Task 2: Test authorization

Then watch the next video, which demonstrates how the defined role and its authorizations are used.