Authorization Management

In this section you determine which functions users can execute in the SAP System using the SAP authorization concept.

To do so, you must define authorizations , place them together in profiles , and assign these profiles to individual users. Authorizations are made for authorization objects , which are predefined by SAP. You can group authorizations belonging to a specific area into an authorization profile, and can also group these profiles together into composite profiles.

For the users who will work with the SAP System, you must

For this you need to decide

Requirements

To maintain users, you must have the authorization for the following authorization objects:

This authorization object controls the access to authorization groups and activities.
You need authorization for this object if you want to create or change a user in the SAP System.
This authorization object controls the access to authorization objects, authorization names and activities.
You need authorization for this object if you want to maintain authorizations or to group authorizations into profiles.
This authorization object controls the access to authorization profiles and activities.
You need authorization for this object if you want to maintain profiles or assign profiles to users.

Note

Because different SAP System modules are integrated, users in CO also need display functions in other components, particularly in Financial Accounting (FI).

You can find more information about authorizations required in the Implementation Guide for the individual applications.

Recommendation

Because it is possible to assign different authorizations for user maintenance according to specialized areas and user groups, SAP recommends that you maintain users and manage authorizations locally instead of centrally.

Further notes

For more information on user maintenance, see the R/3 Library under "BC - System Administration".