Showing posts with label SAP Q&A. Show all posts
Showing posts with label SAP Q&A. Show all posts

Saturday, 15 November 2014

SAP Security Interview Questions And Answers Part -2

1. How do you identify SAP standard roles?
SAP standard roles will start with “SAP*”

2. How do you assign SAP standard role to user or what is the procedure to assign SAP standard role?
It’s good to avoid direct assignment of SAP standard roles and copy SAP standard role to a new role and assign it to the users.

3. There is no authorization profile assigned to a role whether its considered as composite role?
No its not considered as composite role and it’s a incomplete single role

4. What are the role types available?
  • Single role
  • Composite role
  • Derived role
  • Master role
  • Copy role

5. What is the relationship between parent role and derived role?
Parent role is the place where we maintain list of tcodes and derived role will inherit all the authorizations from parent role except Org values.

6. What are the values for user lock?
  • 00 - not locked
  • 32 – Locked Globally by administrator
  • 64 – Locked by administrator
  • 128 – Locked due to incorrect logon attempt

7. How do you deactivate a authorization object globally?
Goto tcode SU25 and select step 5. Deactivate authorization object globally

8. If all users are locked mistakenly and how do you login to sap system
Check link how to unlock SAP* at OS level

9. Which authorization object used to check transaction codes?
S_tcode

10. Which authorization object is used to check HR transaction codes?
P_tcode

11. Why do we need to create a TR for a role?
Roles are developed in development system and tested in quality system and moved to production system, so that’s why we need to create a transport request for a role when its created/changed

12. List out important security tcodes
PFCG                 Role Maintenance
SM19                 Security Audit Configuration
SM20                 Security Audit Log Assessment
ST01                 System Trace
SU01                 User Maintenance
SU02                 Maintain Authorization Profiles
SU03                 Maintain Authorizations
SU10                 User Mass Maintenance
SU21                 Maintain Authorization Objects
SU24                 Auth. Obj. Check Under Transactions
SU25                 Upgrade Tool for Profile Generator
SU53                 Display Check Values
SUIM                 User Information System

13. What are the mandatory fields while creating a username?
Password and lastname

14. What is the difference between USOBX_C and USOBT_C?
Table USOBX_C defines which authorization checks are to be performed within a transaction and which not (despite authority-check command programmed ) when its executed. This table also determines which authorization checks are maintained in the Profile Generator.
Table USOBT_C  defines for each transaction and for each authorization object which default values an authorization created from the authorization object should have in the Profile Generator.

15. How do you create usernames in SAP?
Goto transaction SU01 and creating a new username, you must enter an initial password for that user on the Logon data tab and last name in address tab


16. What are the authorization objects are required to create and maintain user master records?
  • S_USER_GRP: User Master Maintenance: Assign user groups
  • S_USER_PRO: User Master Maintenance: Assign authorization profile
  • S_USER_AUT: User Master Maintenance: Create and maintain authorizations

17. List R/3 User Types
  • Dialog - users are used for individual user. Check for expired/initial passwords Possible to change your own password. Check for multiple dialog logon
  • Service user - Only user administrators can change the password. No check for expired/initial passwords. Multiple logon permitted
  • System - users are not capable of interaction and are used to perform certain system activities, such as background processing, ALE, Workflow, and so on.
  • Reference - user is, like a System user, a general, non-personally related, user. Additional authorizations can be assigned within the system using a reference user. A reference user for additional rights can be assigned for every user in the Roles tab.
  • Communication data – GUI logon not possible and and check for expired/initial passwords and its used for RFC connections

18. What does user compare do?
If you are also using the role to generate authorization profiles, then you should note that the generated profile is not entered in the user master record until the user master records have been compared. You can automate this by scheduling report FCG_TIME_DEPENDENCY on.

19. What is the difference between the table buffer and the user buffer?
The table buffers are in the shared memory. Buffering the tables increases performance when accessing the data records contained in the table. Table buffers and table entries are ignored during startup. A user buffer is a buffer from which the data of a user master record is loaded when the user logs on. The user buffer has different setting options with regard to the 'auth/new_buffering' parameter.


20. How do you find out who has deleted a user from your system, Is there a table where this is logged?
Debug or use RSUSR100 to find the info's.
Run transaction SUIM and down its Change documents.

21. What is the difference between role and a profile?
Role and profile go hand in hand, Profile is bought in by a role.
Role is used as a template, where you can add T-codes, reports. Profile is one which gives the user authorization.  When you create a role, a profile is automatically created.

22. What is system profile version?
Profile versions are nothing but when you modify a profile parameter in RZ10 and generates a new profile is created with a different version and it is stored in the database and physical backup file is created as .bak.

23. What is the use of role templates?
User role templates are predefined activity groups in SAP consisting of transactions, reports and web addresses.

24. What is the different between single role & composite role?
A role is a container that collects the transaction and generates the associated profile.  A composite roles is a container which can collect several different roles

25. Is it possible to change role template? How?
Yes, we can change a user role template. 
  • we can use it as they are delivered in sap
  • we can modify them as per our needs through PFCG
  • we can create them from scratch
SAP Security Interview Questions And Answers Part -1
SAP Security Interview Questions And Answers Part - 3


Please do share if you like this post:)

Sunday, 9 November 2014

SAP Client Copy transaction codes and Profiles



Client Copy Tcodes 
Below tcodes are used to administrate your sap client 
SCC1             - Client copy special (transport import within local clients)
SCC3             - Client copy log overview/client copy monitoring
SCC4             - Client Administration
SCC5             - Used to delete a client
SCC7             - Client import post processing methods
SCC8             - Client Export
SCC9             - Remote Client copy
SCCL              - Local client copy
STMS_IMPORT          - Used to import client in the form of transports/TR import

Client copy profiles:

I given below list of profiles which is used for various types of client copy methods some of the profiles are available in all client copy profiles list, do not confuse with it.
SAP client copy profiles are given in 3 categories Local client copy, Remote client copy and Client export/import method profiles 

Local client copy profiles:

Profiles   Meaning
SAP_ALL    All Client-Specific Data w/o Change Documents
SAP_APPL   Customizing and Application Data w/o Change Docs
SAP_CUST   Customizing
SAP_CUSV   Customizing and User Variants
SAP_UCSV   Customizing, User Master Records and User Variants
SAP_UCUS   Customizing and User Master Records
SAP_USER   User Master Records and Authorization Profiles

Remote client copy profiles:

Profiles   Meaning                                            
SAP_ALL    All Client-Specific Data w/o Change Documents
SAP_APPL   Customizing and Application Data w/o Change Docs
SAP_CUST   Customizing
SAP_CUSV   Customizing and User Variants
SAP_RECO   Recovery (Only if Source Client = Target Client)
SAP_UCSV   Customizing, User Master Records and User Variants
SAP_UCUS   Customizing and User Master Records
SAP_USER   User Master Records and Authorization Profiles

Client Export profiles:

Profiles   Meaning
SAP_ALL    All Client-Specific Data w/o Change Documents
SAP_CUST   Customizing
SAP_CUSV   Customizing and User Variants
SAP_EXBC   Customizing, Users and Cross-Client Customizing
SAP_EXPA   SAP_ALL with Cross-Client Customizing
SAP_EXPC   Customizing Including Cross-Client Customizing
SAP_RECO   Recovery (Only if Source Client = Target Client)
SAP_UCSV   Customizing, User Master Records and User Variants
SAP_UCUS   Customizing and User Master Records
SAP_USER   User Master Records and Authorization Profiles

Wednesday, 29 October 2014

Step by Step Single Role Creation in SAP



1. Goto tcode PFCG and enter your role name as per your company naming convention and  click single role button along with short description



2. Enter detailed description for role in the description tab like below and save it

3. It should have details like who created and when its created and what are the authorizations are available in the role, so it will give clear idea about role purpose and it can be easily understandable by new security consultant
4. Goto Menu tab and enter the tcode which you need by clicking Transaction button




5. Click “Assign Transactions” button and now your Menu tab status will turn to green color

6. Now goto Authorizations tab and click Hand icon to create profile name automatically along with description

7. Now save the changes and click “Change authorization Data” option to get authorization mapping screen like below where you can add/maintain authorization objects/tcode/company codes etc.

8. Now click the circular button to generate the profile

9. Now your Authorizations tab status will turn to green color

10. Now we have successfully created a role and now assign the role to required users, once you assigned the role to users and “Users” Tab status will turn to green color
Do user master comparison if the status light is yellow color and will turn to green color

Hope this will be helpful for you.


Tuesday, 28 October 2014

SAP Transport Management System Question and Answers

1. How to import a transport request at os level?
Logon to the target system and make sure request is released
Add TR to your buffer:
tp addtobuffer <TRANSPORT-REQUEST> <SID> Client=<CLIENT-NUMBER>
pf=/usr/sap/trans/bin/TP_DOMAIN_<DOMAIN_SID>.PFL
Example:
tp addtobuffer DEV12345 QAS Client=000
pf=/usr/sap/trans/bin/TP_DOMAIN_DEV.PFL
Import the request:
tp pf=/usr/sap/trans/bin/TP_DOMAIN_<DOMAIN_SID>.PFL
import <TRANSPORT-REQUEST> <SID> U128 client=<CLIENT-NUMBER>
Example:
tp pf=/usr/sap/trans/bin/TP_DOMAIN_DEV.PFL
import DEV12345 QAS U128 client=000

2. How to lock TMS?
Login to domain controller
Goto STMS tcode and click system overview
Select a system which you want to lock and goto menu and select lock
Confirm and distribute to activate

3. How to unlock TMS?
Login to domain controller
Goto STMS tcode and click system overview
Select a system which you want to unlock and goto menu and select unlock
Confirm and distribute to activate
How to delete system from TMS?
Login to domain controller
Goto STMS tcode and click system overview
Select the system which you want to delete TMS and click trash button/click delete option in menu
Confirm and distribute to activate

4. How to import Transport request different client within a single system?
Use SCC1 tcode to achieve it

5. How to disable IMPORT ALL option in transport queue?
Go to STMS Tcode in DC
Click systems Overview & click on systems which you want to disable import all
Go to Transport Tool Tab or double click it
Click Change button
Click ADD new row button
Insert the parameter NO_IMPORT_ALL with value 1.
Save it.
IMPORT_ALL icon will be disabled from stms_import tcode for a particular system and you have to do it for all system in the DC one by one

6. How to troubleshoot a TR is running longtime?
Check whether file system is having enough space in sapmnt
Update is activated/deactivated in SM13
Check there is available background work process is available to import TR in SM50
How to terminate a TR which is running for long time?
Check whether are you able to cancel it in import queue or goto SM50 tcode and identify which work process assigned for particular TR
Select the work process and cancel it with core or without core
If you are not able to cancel it in SM50 go to os level and kill the process which is assigned to it
Linux and unix
Kill -9 pid
For windows use taskkill command

7. What are common transport errors?
Return code (4) indicates imported ended with warning.
Ex:
1. Generation of programs and screens
2. Column missing and Rows missing
Return code (8) indicates not imported ended with error
Ex:
1. Syntax error
2. Program generation error
3. Dictionary activation error
4. Method execution error
Return code (12) indicates import is cancelled.
Ex:
1. Import is cancelled due to object missing
2. Objects are not active
3. Program terminated due to job? RDDEXECL? is not
working
Return code (16) indicates import is cancelled.
Ex:
1. Import cancelled due to system down while importing
2. Import cancelled due to user expires while importing
3. Import cancelled due to insufficient roles

8. What is domain controller?
Domain controller is the central place where you can administrate TMS.
It acts as a leader and controls all system in the landscape, where it contains details about all systems in the landscape

9. How to change password of all TMS RFC usernames using a report?
TMS_UPDATE_PWD_OF_TMSADM

10. What is the default authorization profile assigned to TMSADM user?
S.A_SYSTEM