SAP Security & GRC made easy

Assigning Authorization Objects to Users in SAP BI/BW

Step 1: Open the Authorization Assignment Screen
1️⃣ Go to Transaction RSECADMIN
2️⃣ Navigate to the User Tab
3️⃣ Click on the Assignment Button

Step 2: Assigning an Authorization Object to a User

🔹 Using this tool, you can assign the created Authorization Object to any user.
🔹 Example: Assigning Authorization Object (ZDWKJTEST) to User (ZNBITSRTS).
This user will be used throughout the process to validate query restrictions applied via the Authorization Object.

Step 3: Assigning Authorizations via Role/Profile

🔹 Instead of direct assignment, you can also assign authorizations through roles or profiles using the standard Authorization Object S_RS_AUTH.

Step 4: Understanding 0BI_ALL Authorization

🚨 A user with Authorization Object 0BI_ALL has full data access and can override any other authorization restrictions assigned to them.

Step 5: Running a Query with Authorization Restrictions
🔹 To test the applied restrictions, execute a query on an InfoProvider that includes the restricted InfoObject (e.g., ZDWKJTEST).
This ensures that the authorization settings are correctly enforced in SAP BI/BW reporting. 🚀





No comments:

Post a Comment