Basis Authorization Components

The table below shows the components with their authorization objects. For detailed information, see the following topics or the online authorization object documentation.

ABAP and the ABAP Workbench

Component

Authorization objects

ABAP programming language and Workbench

ABAP: Program Run Checks (S_PROGRAM): run programs, schedule background jobs.

ABAP Workbench (S_DEVELOP): Development authorizations for all Workbench components except the Workbench Organizer:

ABAP Workbench
Menu Painter
Screen Painter
ABAP Dictionary
Data Modeler
Application hierarchy
Repository Browser
Information System
Function Builder
Transaction management (table TSTC maintenance)
ABAP trace and SQL trace
Authorization object maintenance

Correction and Transport Organizer (S_TRANSPRT): Authorizations for creating development projects and objects

Standard profile for end users (run programs only): S_A.USER

Standard profile for developers (all development tasks): S_A.DEVELOP

For more information, see ABAP and Workbench Authorizations.

ABAP Dictionary

For more information, see ABAP Dictionary Authorizations.

ABAP Query

Authorization for ABAP Query (S_QUERY): Run and maintain queries.

Standard profile for end users (run queries): S_A.USER

Standard profile for maintaining queries: S_A.DEVELOP

For more information, see ABAP Query Authorizations.

Matchcodes

ABAP Workbench (S_DEVELOP): Maintaining matchcodes

User-programmable exit routine.
Naming convention:
MC_<Name of matchcode object>&

Standard profiles: S_A.USER, S_A.ADMIN

For more information, see Matchcode Authorizations.

Customizing (IMG)

IMG: Authorization for Generating the Enterprise IMG (S_IMG_GENE): Generate the Customizing model to be used for all Customizing projects in the R/3 System. Should be restricted to high-level users.

IMG: New Authorizations for Projects (S_PRO_AUTH): Authorization to display or make changes to a Customizing project. The authorization is assigned by project number.

Standard profiles: S_A.CUSTOMIZ (both authorizations)

For more information, see SAP Customizing System Authorizations.

Table contents

Table Maintenance (Using Standard Tools) (S_TABU_DIS): Maintain table entries.

Table Maintenance for Client-Independent Tables (S_TABU_CLI): Maintain entries in cross-
client tables.

Applies to table entry maintenance with the standard and extended table maintenance (Transactions SM30, SM31), and the Data Browser, and to table entry maintenance in the Customizing system.

Standard profiles (no authorization for cross-client tables): S_A.USER, S_A.DEVELOP

Standard profiles (with authorization for cross-client tables): S_A.ADMIN, S_A.CUSTOMIZ, S_A.SYSTEM

For more information, see Authorizations for Table and View Entries.

Field selection editor

Central Field Selection (S_FIELDSEL): Specify field selection rules.

Standard profiles: S_A.DEVELOP, S_A.ADMIN

For more information, see Field Selection Editor Authorizations.

Maintain online documentation with SE61

Authorization for Document Maintenance (S_DOKU_AUT): Create and maintain documentation.

Standard profiles: S_A.ADMIN, S_A.CUSTOMIZ, S_A.SYSTEM

For more information, see Online Documentation Authorizations.

Transport and correction system, Workbench Organizer

Correction and Transport Organizer (S_TRANSPRT): Create corrections and transport
requests, perform transports.

Standard profiles: S_A.DEVELOP, S_A.CUSTOMIZ, S_A.ADMIN, S_A.SYSTEM

For more information, see Correction and Transport Authorizations.

 

R/3 System Administration

Component

Authorization objects

User master records

User Master Maintenance: User Groups (S_USER_GRP): Maintain user master records.

For further information, see Setting Up User Administrators.

Standard profiles: S_A.ADMIN (restricted), S_A.SYSTEM (unrestricted)

Authorization profiles

User Master Maintenance: Authorization Profile (S_USER_PRO): Maintain authorization profiles

For further information, see Setting Up Authorization and Activation Administrators.

Standard profiles: S_A.ADMIN (restricted), S_A.SYSTEM (unrestricted)

Authorizations

User Master Maintenance: Authorizations (S_USER_AUT): Maintain authorization profiles.

For further information, see Setting Up Authorization and Activation Administrators.

Standard profiles: S_A.ADMIN (restricted), S_A.SYSTEM (unrestricted)

GUI activities

Authorization for GUI Activities (S_GUI): Authorization to download lists to local files (list download)

System monitoring functions

System Authorizations (S_ADMI_FCD): Operations on work processes and sessions other than user's own update records.

Standard profiles: S_A.ADMIN, S_A.SYSTEM

For more information, see System Administration Authorizations.

Update record management tool

System Authorizations (S_ADMI_FCD): Execute operations on entries other than user's own. Users do not need an authorization to display update records or execute operations on their own records.

Standard profiles: S_A.ADMIN, S_A.SYSTEM

For more information, see System Administration Authorizations.

System log

System Authorizations (S_ADMI_FCD): Start component.

Standard profiles: S_A.ADMIN, S_A.SYSTEM

System trace

System Authorizations (S_ADMI_FCD): Set options, trace authorizations.

Standard profiles: S_A.ADMIN, S_A.SYSTEM

For more information, see System Administration Authorizations.

Copy clients

Table Maintenance for Client-Independent Tables (S_TABU_CLI): Copy tables from one client to another.

Table Maintenance (Using Standard Tools) (S_TABU_DIS): Maintain table CCCFLOW.

System Authorizations (S_ADMI_FCD): Create new client in table T000 with the SAP Customizing system.

User Master Maintenance: User Groups (S_USER_GRP): Copy user master records from one client to another (optional).

Standard profiles: S_A.SYSTEM

For more information, see Authorizations for Creating and Copying Clients.

Transaction locking

System Authorizations (S_ADMI_FCD): Lock, unlock transactions.

Standard profiles: S_A.ADMIN, S_A.SYSTEM

For more information, see System Administration Authorizations.

Computing center management system

CCMS: System Administration (S_RZL_ADM): Use management system display, management functions.

Standard profiles: S_A.ADMIN, S_A.DEVELOP, S_A.SYSTEM

Tools Performance Monitor (S_TOOLS_EX): Use the RDBMS-Specifics function in the CCMS and the performance monitor.

Authorization to Execute Logical Operating System Commands (S_LOG_COM): Use the CCMS planning calendar for database administration.

Standard profiles: S_A.SYSTEM

For more information, see Authorizations for the Computing Center Management System.

Operating system commands in R/3

CCMS: System Administration (S_RZL_ADM): Define operating system commands in the R/3 System. Commands are saved in the database.

Standard profiles: S_A.ADMIN, S_A.SYSTEM

Authorization to Execute Logical Operating System Commands (S_LOG_COM): Use the CCMS planning calendar for database administration.

Standard profiles: S_A.ADMIN, S_A.SYSTEM

Performance monitor

Tools Performance Monitor (S_TOOLS_EX): Access to special functions.

Standard profiles: S_A.SYSTEM

For more information see Performance Monitor Authorizations.

Early watch

Background Processing: Background Administrator (S_BTCH_ADM): Administrator access.

ABAP Workbench (S_DEVELOP): Type SYST authorization for using debugging tools.

Computer Center Management System: System Administrator (S_RZL_ADM): Use management system display, management functions.

Tools Performance Monitor (S_TOOLS_EX): Use the RDBMS Specifics function in the CCMS and the performance monitor.

Standard profiles: None.

Background processing

ABAP: Program Runtime Checks: Submit ABAP programs for background processing.

Background Processing: Operations on Background Jobs (S_BTCH_JOB): Additional end-user actions in the job monitor (delete your own jobs, for example).

Background Processing: Background User Name (S_BTCH_NAM): Specify a runtime authorizations user other than your own user.

Background Processing: Background Administrator (S_BTCH_ADM): Full access to all functions for administrators.

ABAP Workbench (S_DEVELOP): Use debugging functions on background jobs.

Standard profiles: All S_A.* profiles contain background processing authorizations. S_A.USER can only schedule jobs.

For more information, see Background Processing Authorizations.

Batch input

Batch Input Authorizations (S_BDC_MONI): Run, manage sessions.

Standard profiles: All S_A.* profiles. S_A.USER is limited to running and analyzing sessions

For more information, see Batch Input System Authorizations.

Queue management

Queue Management Authorizations (S_QIO_MONI): Use function.

Standard profiles: S_A.ADMIN, S_A.SYSTEM

For more information, see Queue Management Authorizations.

Spool system, use output devices

Spool: Device Authorizations (S_SPO_DEV): Authorization to use a particular output device (by name in the SAP spool system).

Standard profiles: All S_A.* profiles

For more information, see Queue Management Authorizations.

Spool system, manage spool requests; define and manage
output devices and associated
objects

System Authorizations (S_ADMI_FCD): Display requests other than user's own, use management functions.

Standard profiles: S_A.ADMIN, S_A.SYSTEM

For more information, see Spool System and TemSe Database Authorizations.

Spool system, manage spool
requests that have authorization protection

Spool: Actions (S_SPO_ACT): Execute operations on spool requests that are protected by authorization strings.

Standard profiles: S_A.ADMIN, S_A.SYSTEM

For more information, see Spool System and TemSe Database Authorizations.

TemSe (temporary sequential object) database

System Authorizations (S_ADMI_FCD): Manage TemSe objects (spool request data, job logs from the background processing system.

Standard profiles: S_A.ADMIN, S_A.SYSTEM

For more information, see Spool System and TemSe Database Authorizations.

Lock management

Enqueue: Display/Delete Lock Entries (S_ENQUE): Display, manage lock entries other than user’s own entries, use special management functions. Users do not need an authorization to display their own lock entries.

Standard profiles: S_A.ADMIN, S_A.SYSTEM

For more information, see System Administration Authorizations.

SAP communications server

SAPcomm Server Authorization (S_SKOM_SRV): Required authorization for the CPI-C user that is used for SAPcomm logons.

Standard profiles: S_A.SYSTEM

Text processing (SAPscript)

SAPscript: Standard Text (S_SCRP_TXT): Edit texts.

SAPscript: Style (S_SCRP_STY): Edit styles.

SAPscript: Form (S_SCRP_FRM): Edit forms.

Standard profiles: All S_A.* profiles

For more information, see SAPscript Text Processing Authorizations.

Factory calendars

Public Holiday and Factory Calendar Maintenance (S_CALENDAR): Display, maintain calendars.

Standard profiles: S_A.CUSTOMIZ, S_A.SYSTEM, S_A.USER (display only)

For more information see Holiday and Factory Calendar Authorizations.

Number ranges

Number Range Maintenance (S_NUMBER): Display, maintain number ranges.

Standard profiles: S_A.CUSTOMIZ, S_A.SYSTEM, S_A.USER (display only)

For more information, see Number Range Authorizations.

Change documents

Change Documents (S_SCD0): Display, maintain change documents.

Standard profiles: All S_A.* profiles (S_A.USER has only restricted access)

For more information, see Change Document Authorizations.

Central address management

Central Address Management: Address Type 1 (Organization, Company)(S_ADDRESS1): Use the central address management facility.

Standard profiles: S_A.SYSTEM, S_A.USER (display only)

Application log

Applications Log (S_APPL_LOG): Use the application logging facility.

Standard profiles: S_A.SYSTEM, S_A.USER (display only)

System profile

Tools Performance Monitor (S_TOOLS_EX): Display and maintain system profile parameters from within the R/3 System.

Standard profiles: S_A.SYSTEM

Language installation

Language Administration (S_LANG_ADM): Import additional R/3 System languages.

Standard profiles: S_A.ADMIN, S_A.CUSTOMIZ, S_A.SYSTEM

 

For information on defining authorizations for other Basis components and for R/3 applications, see the documentation of the components.