Introducing Authorization Control

Objective

After completing this lesson, you will be able to define roles and set the authorization objects.

Authorization Control

The authorization objects are defined in a role and assigned to the end-users. With this role, an end-user can execute specific transactions with defined authorizations.

SAP Display Roles interface for the role SAP_BR_BOM_ENGINEER with the description BOM Engineer. The interface includes various tabs such as Description, Menu, Workflow, Authorizations, User, MiniApps, and Personalization, with a hierarchy of menu items displayed on the left and node details on the right.

If you use transaction PFCG to create a new role or change an existing role, first, you define the transactions that are to be used. These transactions will then be visible in the user menu. In the SAP standard menu, if you attempt to call different transactions to those which are assigned to you, the system issues an error message.

You create an authorization profile within the authorization control. This is now based on the selected transactions. Therefore, if you select transactions of the document management, you are now provided with the necessary authorization objects.

Work with Authorization Control

Introduction

Up to now, you and your team have worked in the SAP system with the authorizations assigned to you. However, you have now been approached by colleagues from other areas of the company who also want to have access to the documents they have created.

Therefore, you are now considering defining a new role with restricted authorizations.

Task 1: Define a role and authorization

Watch the following video, which first shows you a role definition and the definition of authorizations.

Task 2: Test authorization

Watch the following video, which shows the use of the defined role and authorizations.

Log in to track your progress & complete quizzes