Skip to content
Help improve CertGuru

Optional analytics show which pages and controls are useful. We do not send personal details, answers, scores, percentages, or completion time.

CertGuruYour certification study desk
HomeCertificationsPracticeLearnNotesAbout
Find my path↗
HomeCertificationsPracticeLearnNotesAbout
Home→Study→User & Authorization Administration

SAP Technical Architecture guide

User & Authorization Administration

Review SU01, SU10, PFCG, user types, roles, profiles, groups, validity, locks, defaults, and least-privilege administration.

SU01SU10PFCG

SU01 mental model

SU01 maintains one ABAP user. The PDF shows the tabs Address, Logon Data, SNC, Defaults, Parameters, Roles, Profiles, Groups, Personalization and License Data. Use Logon Data for user type, security policy, password action, authorization-check group and validity. Use Defaults for language, date/number/time formats, spool settings and time zone.

Object / settingPurposeDo not assume
User typeControls intended logon/usage behaviorEvery technical account should be Dialog
RoleBusiness/technical authorization container maintained with PFCGA role is the same as a user group
Generated profileTechnical authorization profile generated from a roleProfiles and roles are interchangeable
User groupOrganizes users and can support administrative responsibilityMembership alone grants the role's authorizations
Validity periodLimits when the user is validA valid date range proves least privilege
Administrator lockExplicit administrative lockSame cause as password lock after failed attempts
Defaults / parametersPersonal behavior and parameter IDsAuthorization assignments

Safe review workflow

1. Confirm the exact user and approved request. 2. Review account purpose, user type, security policy, validity and lock state. 3. Check roles, profiles and groups as separate objects. 4. Apply least privilege and segregation-of-duties review. 5. Save only approved changes, then test with a non-privileged scenario and record the evidence.

Use SU10 for controlled mass maintenance only after narrowing and reviewing the selected user set. Use PFCG to maintain roles; assigning a role in SU01 is not the same as designing the role.

Exam and security trap: an administrator lock and a password lock caused by failed logons are different conditions. Never copy passwords or demo user IDs from training material, and never infer authorization from a menu entry, group or profile name alone.

Active recall

Test yourself

1. Where would you change a user's time zone, and where would you change validity?

Reveal answer

Time zone is under Defaults; validity is under Logon Data.

2. What is the clean distinction between role, generated profile and user group?

Reveal answer

Role models access, its profile contains technical authorizations, and a group organizes/administers users.

3. Why should mass maintenance in SU10 begin with selection review?

Reveal answer

A mistaken selection broadens one change to many accounts.

Practice this module

This guide maps to 4 questions in the SAP Technical Architecture Top 40 bank.

Open practice↗
Last reviewed 23 July 2026. Independent study material for certification preparation; not official SAP documentation or exam content.

Guide map

Use this page actively.

Read one section, close the guide, explain the rule from memory, then validate it with linked questions.

04
concept sections
03
recall prompts
04
linked questions
Practice this domain↗← All study guides
CertGuruYour certification study desk

A calmer way to prepare: diagnose the gaps, study what matters, and walk into exam day with a plan.

Study deskHomeCertificationsWhich certification?PracticePractice set overviewsStudy libraryCertification notesAbout CertGuru
Trust & clarityEditorial policyMethodology overviewPrivacy policyTerms & disclaimer
Choose → Check → Learn → Practise → SimulateProgress stays in your browserFree access · No account requiredIndependent · No provider affiliation© 2026 CertGuru