SAP Program RSCSAUTH - Maintain/Restore Authorization Groups

Report Authorization Maintenance
Many SAP programs are supplied either with an authorization group whichdoes not fit in with the customer's authorization system or without anauthorization group altogether. This report allows you to maintain theauthorization groups for such programs without the need to change theprogram attributes. It also allows you to restore customer-specificauthorization groups following an Upgrade.
Program RSCSAUTH generates a list of type 1 reports ("Program" column),the authorization groups as maintained by SAP ("SAP" column), and thosemaintained by the customer "Customer" column).
The "Customer" column is an input field where you can enter your ownauthorization groups.
When you choose "Save", the customer-specific authorization groups forall SELECTED reports are copied into Table TRDIR. This has the sameeffect as changing the authorization group in the program attributes,as existing SAP authorization groups are overwritten. The authorizationgroups for each report are also entered in Table SREPOATH. This is toallow you to restore customer-specific authorization groups followingan upgrade by running RSCSAUTH again.

Selection Screen

Report Selection
Here you can select the programs whose authorization groups you wish tomaintain. You can limit your selection to

  • Particular programs ("Program name" selection)

  • Programs supplied by SAP with a particular authorization group (or
  • without authorization group) ("Authorization group (SAP)" selection)
    • Programs from particular applications ("Application" selection)

    • Programs with a particular logical database ("Log. DB directory" and
    • "from application" selection).

      Authorization Groups
      You can choose here whether to maintain customer-specific authorizationgroups ("Maintain" box) or whether to transport customer-specificauthorization groups between SAP Systems or restore old settings afteran Upgrade ("Restore/ Transport" box).
      You cannot maintain and transport (or restore) authorization groupssimultaneously. If you wish to maintain and then transportauthorization groups, you will need to run the report twice; once withthe "Create/ change" option in the "Maintain" box, and then with the"Restore with transport" option in the "Restore/ Transport" box. If youtry to select options from both boxes at the same time, an errormessage is displayed.

      Maintain
      Select "Create/ change" to maintain customer-specific authorizationgroups.
      Defaults can also be supplied for the new authorization groups:

      • Copy authoriziation groups from:

      • Default authorization group
        The value entered here is now suggested for all reports for which nocustomer-specific authorization group has yet been entered.
        Report tree
        Here you can enter the name of a report tree. The node authorization issuggested as a default for all reports in the tree. The nodeauthorization is also displayed in a separate column. Existingcustomer-specific authorization groups are NOT overwritten by the nodeauthorization. If a report exists in more than one node, theauthorization of the first node (alphabetically!) is used.Authorizations for private nodes are ignored.
        If both a default value and an authorization tree are specified, thedefault value is only used for reports for which no node authorizationcould be found.

        Restore/ transport
        The functions in this box are not for maintaining but transportingcustomer-specific authorization groups, as well as for restoring themfollowing an Upgrade.
        The following functions are available:

        • Test run

        • All reports for which customer-specific authorization groups exist arelisted: Report name, SAP authorization group, Customer-specificauthorization group.
          • Restore

          • You can use this function to restore customer-specific authorizationgroups (ex. following an upgrade). A check list is output (as with thetest run). The SAP authorization groups are shown in the SAP column. Inthe "Customer" column are the customer-specific authorization groupswith which the SAP authorization groups are overwritten.
            • Restore with transport

            • You first see a dialog box in which you specify a transport request.Alternatively, you can branch from here into the transport andcorrection system. The selected reports with the customer-specificauthorization groups are entered in the transport request where thecustomer authorization group differs from the SAP authorization group.Afterwards a check list is output, similarly to the "Restore" function.
              When you release the transport request, the authorization groups aretransported into the target system. In order to change the programattributes in the target system, in other words, to copy theauthorization groups into Table TRDIR in the target system, you need torun Report RSCSAUTH using the "Restore" option.

210785Web release of reports, queries (MiniALV, MidiALV)
7642Authorization protection of ABAP/4 programs