For example, to change a material master record, authorizations are required for the :
· Transaction change
· Specific material
· General authorization to work within the company code
RSUSR010 - Transaction Lists According to Selection With User, Profile or Object.
List of Transaction codes of the user.
RSUSR007 - List Users Whose Address Data is Incomplete
The program check for space in the address data field. To print the whole list, tick a field which is always
space. (e.g. Room No.)
Version 4.6x
RSUSR002_ADDRESS - Users by address data
In 4.6x you used Role for each users and SAP will generate the necessary profiles and authorizations.
PFCG - Basic Maintenance
Type in a meaningful ZXXX role name and click Create
Menu -> Transaction (insert all the transaction code for this role)
Authorization -> Change authorization data -> Generate
What is Transaction RZ10- Edit Profiles?
choose the instance profile
click Extended maintenance
click the display or change button
look for this parameter name login/system_client
Work Processor :-
rdisp/wp_no_dia DialogProcessor
rdisp/wp_no_vb UpdateProcessor
rdisp/wp_no_vb2 Update 2 Processor
rdisp/wp_no_enq Enquiry Processor rdisp/wp_no_btc BackgroundProcessor rdisp/wp_no_spo Spool Processor
ABAP,ABAP report,Interactive Report,ALV grid,ALV list,IDOC,User Exit,RFC,Smartform,sapscript,ABAP Performance,Remote Function Module( RFC ),Function Module,Modularization techniques,ABAP tools,ALV report Generator,ABAP Interview Questions,BDC,BAPI,ALE,BADI, EDI,InternalTable,DataStructure,LSMW,Domain,DataElement,Basis and Administration ,ABAP HR development,ABAP Debugger,BW,ExceptionHandling,Download FI, CO, MM, PP, SD, PM, PS, QM, SM, HR, BW, APO,ABAP Tutorial
Search on this Website
Saturday, November 29, 2008
SAP Authorization, Profiles, Address
Basis interview questions
Ask him/her to describe how SAP handles Memory Management?
ST02 / ST03 In general via table buffers, you could go into the whole Work Process, roll in, roll out, heap (private) memory, etc. however just as a Unix or DBA admin would know, is you look this up when needed for the exact specifics.
Ask him/her to describe where they would look at the buffer statistics, and what steps they would use to adjust them?
ST02, RZ10
Ask him/her to describe how to setup a printer in SAP or where they would look to research why a user/users can not print?
SPAD, SP01, SM50, SU01
Interview to 3 general areas:
DB (what is the directory structure/ where are the files kept oracle alerts, init.ora, redo logs, archive logs, etc.; possibly some basics stuff like what to do "high level" when the archive directory fills up, etc. Keep this minimal as from a SAP basis admin point of view Oracle is just a big giant bit bucket and SAP can handle to the daily monitoring and maintenance itself.
OS (what is the directory structure (what is NFS mounted and why / where are the message files contained for the OS error log; basic commands for the OS eg. Unix, mv, cp, ls, grep, ps-ef, df-k, etc. That is pretty much all the SAP basis admin will need to know. Client/Server architecture.
SAP (what is the directory structure / where are files located ie. profiles - start, instance, default (what are they and what is the order of precendence) start is for statup only, instance is the first to be read then the default and if a given parameter cannot be found in the instance or then the default then the internal standard is taken from RZ10 setting.
You can ask them to ran Transaction codes to you. Menus constanly change so go with T-codes. He should have a good knowledge of the following areas; transports, user / print / spool / batch management, monitoring, client tools and copies, support packages, kernel patches, workload analysis, Roles and Security, etc.
The standard list of t-codes is pretty much
SM50, SM51, SM66, SM12, SM13, SM21, DB01, DB02, DB13, ST01, ST02, ST03, ST04, ST05, ST06, SU01, SUIM, PFCG, SCC4, SE01, SE09, SE10, SPAM, SM35, SM36, SM37, SPAD, SP01 SCC3, SCCL, SCC9 this are pretty much you heavy hitters for monitoring and support.
I would ask in general how he would troubleshoot the following:
- User cannot connect to SAP
check SAP logon settings, ping the host, check message server, check dispatcher, etc.
- User cannot print
check SAP user setup, check SPAD, check spools, check unix queue or print queue at the os level, etc
- System seems slow
check SM66, SM51, SM50, SM21, ST06, ST03, SMLG, AL08 etc.
Some important things to remember is to ask not get specific to your installation or specific system setup as all SAP instances are different, keep your question to general topics and general answers.
The most important thing to notice when choosing a candidate is not how they parrot back answers to you, but if they can a) think for themselves and b) they actually like to and will keep on learning as no one knows it all and c) they have a good background and willingness to perform analyis and will keep on digginging until the answer is found or until their resources are exhausted and then they will pull in what is required to figure it out.
Question about Go Live Check
What's Go-Live Check?
Who's responsible for Go-Live Check?
What should we prepare before Go-Live Check?
How many times for Go-Live Check?(I mean that Go-
Live Check seperate into how many steps/types such as 3 times for 1 Month before Go-Live, 2 Weeks before Go-Live
and 2 Weeks after Go-Live etc.) What's recommend schedule for each time?
How can we proceed Go-Live Check?
You have to open a message in component XX-SER-TCC to find out if your installation is scheduled for a Go-Live check which is conducted by SAP and it’s partners.
Go-Live Functional Upgrade Analysis – ideally 6 months before Golive – basically checks your hardware requirement , will it be able to accommodate the increase in the functionalities caused by the Go-Live, also some parameter recommendations to fine-tune your system.
Go-Live Functional Upgrade Verification – This is normally 2 months after the Go-live which is to see e’thing is fine after the upgrade.
Then you have normal Earlywatch session , each installation is entitled for 2 free earlywatch session in a year, in this performance tuning is done for your system, hardware,memory, I/0 bottlenecks are identified.
Reports of all these sessions carried out by SAP is then sent to you in form a MS-Word document and you can follow the guidelines mentioned and call up SAP or mail the person who has done the session for you for any clarifications.
Usually once a session is scheduled.
SAP will contact you to open the connections for them, so that they can prepare the system before the actual session takes place , in which they see , if SDCC version is good enough so that they can download the data from your system into their internal system on which they carry out the analysis, see if SAPOSCOL is running and enough history data is there in ST03n for them to carry out reasonable analysis. If e’thing is set a download is scheduled on your system using SDCC for a day prior to the actual session , and on the day of the session you open the connections for them again and provide them with userid and password normally it is earlywatch in 066 client.
Sunday, August 19, 2007
Generating Profiles using Automatic Profile Generator
achieved by assigning authorization profiles to users.
The various terms used in Authorizations are :
1. Authorization fields
Authorization fields identify the elements of the system that need to be protected.
These fields are associated with the data elements of the ABAP/4 Dictionary. For
example if you consider Sales order creation as an activity for which authorization is
required, the fields associated with this activity are :
VKORG – Sales Organization
VTWEG – Distribution Channel
SPART – Division
These fields form the part of the standard ABAP/4 function call AUTHORITYCHECK.
2. Authorization object
Authorization object identifies an activity that needs to be protected in the SAP
system. For example Creation of a Sales Order is an activity. An object is made up of
authorization fields. A user can perform an activity only if they satisfy the
authorization check for each field in the authorization object.
Eg. V_VBAK_VKO is an object for Sales Area comprising of the following fields:
VKORG – Sales Organization
VTWEG – Distribution Channel
SPART – Division
ACTVT – Activity
Authorization objects are grouped into Object class depending up on the application
area.
3. Authorization
Authorization is used to define permitted values for the fields of an authorization
object. For example you want to define an authorization for displaying a sales order
for a Sales organization 3000, Distribution Channed 01 and Division 02, the
values that will be assigned to fields of the object V_VBAK_VKO are:
VKORG – 3000
VTWEG – 01
SPART – 02
ACTVT – 03 (Display)
4. Authorization profiles
As a rule authorizations are not directly assigned to a user. Instead these authorization
are clubbed in an authorization profile and are then assigned to the user master
records.
What is the Profile Generator?
SAP’s Profile Generator allows authorization administrators to automatically generate
and assign authorization profiles. Released with 3.1G, this tool accelerates R/3
implementation by simplifying the task of setting up the authorization environment. The
administrator needs only to configure the customer-specific settings; the Profile
Generator manages all the other tasks, such as selecting the relevant authorization objects
for consideration. The Profile Generator is fully integrated in R/3 and is available on all
R/3-supported platforms. The Profile Generator represents another improvement of
SAP’s tool-based support and a reduction in R/3 implementation time.
The Profile Generator is a new approach to defining the authorization environment. The
administrator no longer uses the authorization objects to define the authorizations for
various user groups; instead, authorization profiles are built around the functions to be
performed in R/3. Based on function selection, the Profile Generator selects the relevant
authorization objects and groups them in a new authorization profile.
Using functions to define authorization profiles:
• Speeds up the process
• Defines authorization profiles more reliably (because only the required authorizations
are granted)
• Simplifies administrator/user communication, allowing both the administrator and
users to use the same R/3 function terminology To generate an Authorization profile automatically you first need to create an Activity
Group.
What is an Activity Group?
The process of security implementation with the new PG is based on the creation
of activity groups or a collection of linked or associated activities, such as tasks, reports,
and transactions. An activity group is a data container for the PG to generate
authorization profiles and usually represents a job role in your company.
For example, to implement security for a buyer:
1. Create an activity group, Buyer
2. Include all of the business transactions Buyer can access
3. Generate the appropriate authorization profile for Buyer
4. Assign Buyer to a new user or a position in your system
5. Update the user master record for the user
The new user now has all the necessary access rights needed to work as a buyer in your
company.
Activity groups are user-defined and allow you to systematically organize and efficiently
maintain system activities. The SAP Session Manager, SAP Business Workflow, and
Personnel Planning and Development require activity information. Using an activity
group as an information database reduces data entry time. Select the criteria, such as
access rights, and divide the activities into appropriate groups. For example, you could
decide to group activities by subject matter, such as personnel, payroll, or budgeting. Or,
you could group activities by job classes, such as translation activities, computer
programmer activities, or secretarial activities. You could also set up a combination of
subject matter and job-oriented activity groups. Activity groups are created and
maintained in the activity group maintenance transaction, PFCG. After setting up activity
groups, you may assign them to various R/3 objects.
Activity Group Assignments
• R/3 Users
An R/3 user is an individual who is recognized by the R/3 System and is allowed to
logon. For the system to recognize users, their names must be entered in the user
master record of the Basis component.
• Jobs
A job represents a general classification of work duties, such as secretary, computer
programmer, instructor, etc. Many employees in your company may hold the same
job classification. (For example, there might be 20 people whose job is secretary.)
Positions are usually based on jobs. Anyone who holds a job automatically inherits
the infotype settings, attributes, and properties of the job. Unless the activity groups
grants general access rights such as the rights needed to work with SAPoffice, be
careful when assigning activity groups to jobs.
• Positions
A position represents a unique, individual employee assignment within a company
(for example, marketing secretary, sales manager, etc.) Positions should not be
confused with jobs. You can handle authorization management in an almost
completely position-oriented fashion. All the access rights are then linked to the
position, so it does not matter who fills this position. Once a user changes positions
after the user master record is updated, the authorization profile automatically
changes.
• Organizational units
Organizational units represent any organizational entity that performs a specified set
of functions within a company. For example, organizational units represent
subsidiaries, divisions, departments, groups, special project teams, etc. Identify the
organizational structure at your firm by creating organizational units and identifying
the relationships among the units. Anyone who is assigned to an organizational unit
automatically inherits the infotype settings, attributes, and properties of this
organizational unit.
Steps for Implementing Profile Generator
SETTING UP PROFILE GENERATOR SAP R/3 4.0B
1. Logon to Client = ‘xxx’ with SAP_ALL
2. Enter transaction code RZ10. Set system parameter ‘ auth/no_check_in_some_cases
= Y ’ in the instance profile. This setting is required for proper functioning of the
Automatic Profile Generator. Activate the instance profile.
3. Stop and restart the designated R/3 instance now
4. Logon to the same client as in step 1 with SAP_ALL
5. Make sure the parameter set in step 2 is active by running RSPARAM report using
transaction SA38
6. Go to the Implementation Guide by entering the transaction SPRO. Within the IMG
go to the option Basis components => System Admin => Users and Authorizations
=> Maintain Authorizations and Profiles using profile generator => Execute next to
Activate profile generator.
7. You get “ Choose Activity ” screen
a) Maintain System Profile Parameter ( Done in step 2 – 5 )
b) Set active plan version. (Transaction OOAP). Plan version is set to 01 if not set
it.
c) Set up PD transport connection (Transaction OOCR). No value in Value abbr.,
indicates that automatic transport connection is active
8. Enter transaction SPRO => F5 => Basis components => System Admin => Users
and Authorizations => Maintain Authorizations and Profiles using profile generator
=> Execute next to Work on SAP check indicators and field values
9. You get “ Choose Activity ” screen
a) Create development class. (Transaction OY08). Hit enter at ‘ The table is client-
independent ’ message screen. Click New Entries and create new development
class with following details:
Development Class: ZDEV
Description: Development class for security
Transport Layer: ZDEV
Person Responsible: Enter user name
Check the box ‘ Link to Workbench Organizer ’
Save
b) Copy SAP checks Ids field values (Transaction SU25). Click the icon next to
initially fill the customer tables. Got an information message box. Enter. Step
performs successfully in few minutes.
Click the icon next to 3. Transport the customer tables. Enter at information box.
Step will be performed successfully in few minutes.
c) Change check indicator. (Transaction SU24). This transaction helps to deactivate
the authority check against authorization objects. No changes were set in during
this setup. Defaults were chosen.
Note : SU25 while configuring first time on the m/c we got a information saying that
“PROFGEN_INFO_TEXT does not exists “
this may be because of the first time .
Enter transaction SPRO => F5 => Basis components => System Admin => Users and
Authorizations => Maintain Authorizations and Profiles using profile generator =>
Generate company menu => Execute. Alternatively use transaction SSM1.
10. Make sure that English is present in the choose languages section
11. Click execute for 1.
SAP standard menu generation. Click enter at information box.
Takes few minutes and completes successfully.
12. Click execute next to 2a.
Company menu generation. Click enter at information box.
Takes few minutes and completes successfully.
13. Click Activate next to 2c.
Activate company menu. Click yes at confirmation for
activating the company menu.
14. Create an activity group using transaction PFCG to test the setup of profile generator.
SETUP OF SAMPLE ACTIVITY GROUP
1. Enter transaction code PFCG
2. Screen ‘ Edit Activity Group’ is shown
3. Enter activity group name. Do not use an _ in the second character. It is reserved for
SAP.
4. Example activity group name: Z:MKTDIRCT
5. Click create icon
6. At ‘Do you want to allow responsibilities for activity groups’? screen choose NO
7. Activity Group Basic Data: Create screen is shown
8. Enter a descriptive text in the NAME field eg: Activity group for market director
9. Click Menu push button
10. Enter at change request # popup box
11. Menu tree is displayed
12. Find the transaction codes needed by position in question by Edit => find
13. Choose the transactions by clicking
in the box next red traffic light eg: VD02
transaction
14. Likewise choose all transactions needed
15. When done save your work by clicking save button
16. Click enter at change request number
17. Go back
18. Click authorizations push button
19. At define organizational levels screen choose select values or put a * in all of them.
Organizational level includes fields like Company code, Sales Organization,
Controlling area etc.
20. Save
21. This will take you to authorization screen
22. Expand the tree by clicking on the + sign
23. Choose all the needed authorizations by clicking besides it
24. When done click save icon
25. Accept the default profile name and enter
26. Accept the change request # and enter
27. Click activate button after saving your work
28. At generate profile screen click generate
29. Click enter at change request #
30. Go back and notice the authorization push button is active
31. Next click agents push button
32. You will get ‘Maintain Agent Assignment’
33. Click user icon
34. Enter user name and click enter
35. Enter at change request number box
36. Click icon update user master data records
37. User master data reconciliation screen is shown
38. Click execute
39. This step completes the assignment of the activity group (authorization profiles to be
precise) to the user master records.
Methods of correcting Profiles
• Through Company Menu : Here if a user wants to execute a menu function, the
authorization for this can be added by using the Menu option of transaction PFCG.
• Manual Method : Authorization objects can be manually added to the profiles
generated using Profile Generator. If a user gets a Authorization failure while
executing a transaction, the object required and the necessary values that needs to be
defined for the fields of the object for executing that transaction can be obtained by
using the transaction SU53. This object can be added to the existing profiles by
executing PFCG => Authorization => Edit old data => Edit => Insert Auth => Insert
manually. You can also insert existing profiles and templates using the same menu.
Templates are nothing but a set of authorization objects having blank values in their
respective authorization fields. These templates can be included in the profiles and
necessary values assigned.
Friday, August 17, 2007
Scheduled weekly tasks
Content : Content :
(1)The R/3 System
(2)Database
(3)Operating System
(4)Other
(5)Notes
Download Whole ContentScheduled Annually tasks
Content :
(1)The R/3 System
(2)Database
(3)Operating System
(4)Other
(5)Notes
Download Whole Content
(1)The R/3 System
(2)Database
(3)Operating System
(4)Other
(5)Notes
Download Whole Content
Click Here to Read More !!!!
Scheduled Annually tasks
Content :
(1)The R/3 System
(2)Database
(3)Operating System
(4)Other
(5)Notes
Download Whole Content
Click Here to Read More !!!!
Scheduled Monthly tasks
Content :
(1)The R/3 System
(2)Database
(3)Operating System
(4)Other
(5)Notes
Download Whole Content
Click Here to Read More !!!!
Monday, August 13, 2007
Remote Services
In this pdf, readers will learn about SAPSERV4 and early watch. The information in this
chapter should help the user understand how to:
Download Complete Tutorial
Click Here to Read More !!!!
Wednesday, August 8, 2007
BASIS Learn Your self
Content :
(1) Basis (BC)
(2) System
(3) Administrator
(4) Database Administrator SQL Server
(5) Database Administrator Informix
(6) System Administration Assistant: System Administrator
(7) System Administration Assistant: System Administrator (Maintenance)
(8) System Administration Assistant: Application Administrator
(9) Data Archiving Administrator
(10) System Administration Assistant: Project Team Leader
(11) System Administration Assistant: Project Team Member
(12) Netzwerk- und Betriebssystem-Administrator
(13) SAP DB Database Administrator
(14) Spool Administrator
(15) Background Administrator
(16) Basis: Mandantenkopie
(17) Customizing Project Administrator
(18) Customizing Project Team Member
(19) ABAP-Entwickler
(20) SAP Services & Support CATT Tester
(21)Test Organizer
(22) Administrator for Communication, Folders and Appointment Planning
(23) Administrator for External Communication
(24) IDoc Administrator
(25) IDoc Developer
(26) Output Control (PPF): Administrator
(27) ALE Administrator
(28)ALE Developer
(29)Distribution of Accounting Master Data
(30)Distribution of Human Resources Master Data
(31)Distribution of Logistics Master Data.
(32) User of Communication, Folders and The Appointment Calendar
(33) Transport Administrator
(34) Transport Operator
(35) Business Workflow: Implementation Team
(36) Business Workflow: Developer
(37) Business Workflow: Controller
(38) Workflow System Administrator
(39) System Administrator for SAP ArchiveLink
(40) Administrator for the SAP Knowledge Provider.
Download Complete tutorial
Click Here to Read More !!!!