SAP Technical Architecture guide
User & Authorization Administration
Review SU01, SU10, PFCG, user types, roles, profiles, groups, validity, locks, defaults, and least-privilege administration.
SU01 mental model
SU01 maintains one ABAP user. The PDF shows the tabs Address, Logon Data, SNC, Defaults, Parameters, Roles, Profiles, Groups, Personalization and License Data. Use Logon Data for user type, security policy, password action, authorization-check group and validity. Use Defaults for language, date/number/time formats, spool settings and time zone.
| Object / setting | Purpose | Do not assume |
|---|---|---|
| User type | Controls intended logon/usage behavior | Every technical account should be Dialog |
| Role | Business/technical authorization container maintained with PFCG | A role is the same as a user group |
| Generated profile | Technical authorization profile generated from a role | Profiles and roles are interchangeable |
| User group | Organizes users and can support administrative responsibility | Membership alone grants the role's authorizations |
| Validity period | Limits when the user is valid | A valid date range proves least privilege |
| Administrator lock | Explicit administrative lock | Same cause as password lock after failed attempts |
| Defaults / parameters | Personal behavior and parameter IDs | Authorization assignments |
Safe review workflow
1. Confirm the exact user and approved request. 2. Review account purpose, user type, security policy, validity and lock state. 3. Check roles, profiles and groups as separate objects. 4. Apply least privilege and segregation-of-duties review. 5. Save only approved changes, then test with a non-privileged scenario and record the evidence.
Use SU10 for controlled mass maintenance only after narrowing and reviewing the selected user set. Use PFCG to maintain roles; assigning a role in SU01 is not the same as designing the role.
Active recall
Test yourself
1. Where would you change a user's time zone, and where would you change validity?
Reveal answer
Time zone is under Defaults; validity is under Logon Data.
2. What is the clean distinction between role, generated profile and user group?
Reveal answer
Role models access, its profile contains technical authorizations, and a group organizes/administers users.
3. Why should mass maintenance in SU10 begin with selection review?
Reveal answer
A mistaken selection broadens one change to many accounts.
Practice this module
This guide maps to 4 questions in the SAP Technical Architecture Top 40 bank.
Open practice