ioppride.blogg.se

S tabu dis rights to change table sm30
S tabu dis rights to change table sm30





s tabu dis rights to change table sm30

Fortunately SAP in its latest service packs has come up with a new authorization objects for securinf tables, S_TABU_NAM. Also, the new authorization groups might be overwritten by SAP service packs so this becomes a recurring check for upcoming upgrades. Changing authorizations groups for such tables can potentially impact the functioning of tcodes calling them. For example a lot of tables are accessed to by standard tcodes. But this soluation came with its own problems, specially when adopted for standard tables. Technically it is has always been possible to create a new authorization group and link the offending table. Once a user has access a particular table authorization group, the user can access all tables linked to the authorization group. The limitation with authorization groups is the lack of granular security on individual tables. However, till now security for tables was based on the authorization groups.

s tabu dis rights to change table sm30

S_TABU_LIN is meant for Line Oriented Authorizations which allows us to authorize indivdual rows of a table. S_TABU_CLI is needed when a user needs access to maintain client independent tables. S_TABU_DIS secures tables on the basis of activity (02, 03) and authorization group for the table.

s tabu dis rights to change table sm30

Out of this, S_TABU_DIS is the one that is needed for all tables. So most of us are already aware of the authorization objects used to secure tables, S_TABU_DIS, S_TABU_CLI and S_TABU_LIN. As security consultants, we are often asked to secure or grant access to SAP tables.







S tabu dis rights to change table sm30