Could you please let me know the exact step by step process
for the following Questions.

1.How to get the E-Mail address for 100 users at a time.
2.While Creating BW roles what are the Authorization Objects
we will use.
3.While Creating Single role what will be happened in the
functional side, when entered the Template role in the
derived role tab.
4.when we changed the password for more users(for
example:100 users) where the password will be stored or from
where you can Re-Collect the password and how will you
Communicate the password to all users at a time.
5.What is Virsa? Once you entered in to the screen what it
will perform.
6.What is the use of SU24 & SM24.
7.While Creating BW roles what are the Authorization Objects
we will use.
8.While Creating Single role what will be happened in the
functional side, when you entered the Template role in the
derived role tab.
9.What is Dialog users, Batch users and Communicate users.
What is the use with Communicate user.
10.Can we add one Composite role in to another Composite
role at any urgent user requests or in normal user requests.
11.In Transport what type of Request we will use.Why don't
we use Workbench request in transport.
12.When we added Authorization Object in Template role, at
the same time what will be happen in Derived role.
13.How to Check Profile parameter. And how to find whether
any transport has ended with error and where we can check.
14.How to Extract users list like who didn't login since 3
months. And In 90 Days user Locking in which table we will use.
15.What is OSS Connection and System Opening and why we have
to open these.
16.What will have in one single role and how many prifiles
will be in one sap cua system.
17.What is the difference between Template role & Derive role.

Answer Posted / parthu

READ CAREFULLY QUESTIONS AND THERE ANSWERS BELOW.


1.How to get the E-Mail address for 100 users at a time.
ANS: scatt script

2.While Creating BW roles what are the Authorization
Objects we will use.
ANS: s_rs_auth, s_rs_icube, s_rs_odso , s_rs_mpro,
s_rs_ipro, s_rs_admwb (for BI consultants & admins) and
s_rs_rsec (for BI Security consultant)

3.While Creating Single role what will be happened in the
functional side, when entered the Template role in the
derived role tab.
ANS : Don't NO

4.when we changed the password for more users(for
example:100 users)
ANS:
a) at the time of implementation we create users & PWD
b) depend on business users requests
c) if locked users needed to unlock and make them use then
we generate new PWDs.
d) monthly or quaterly basis we send a message to endusers
to change there PWDs.
e) users got locked due to incorrect log on.
f) users locked with the expiration of there user ids.

5. (A) where the password will be stored (B)from where you
can Re-Collect the password and (C) how will you
Communicate the password to all users at a time.
ANS:
A) PWD information will be stored in table USR02.
B) There is NO re-collect password process in SAP again
user needs to send request to security team to re-issue new
PWD
C) we can do it through scatt script.

6.What is Virsa? Once you entered in to the screen what it
will perform.
ANS: Before GRC comes into picture there were other tools
which are running in the market in order to do analysis.
those are VIRSA and APPROVA. both are an INDIAN Companies
and VIRSA developed Tools like Firefighter, Compliance
Calibrator, Access Enforcer and Role expert to do risk
analysis but In the Year 2006 VIRSA took over by SAP and it
changed names as Superuser Privilage Management (SPM), Risk
Analysis and Remediation (RAR), Compliant User Provisioning
CUP) and Enterprise Role Management (ERM) respectively.

Virsa FireFighter for SAP: enables super-users to perform
emergency activities outside the parameters of their normal
role, but to do so within a controlled, fully auditable
environment.The application assigns a temporary ID that
grants the super-user broad yet regulated access & tracks
and logs every activity the super-user performs using that
temporary ID.

7.What is the use of SU24 & SM24.
ANS: There is no SM24 t-code in SAP. coming to SU24, here
we can maintain the assignment of Authorization Objects by
entering into particular t-code and we can check the
relation between the t-code and concern authorization
objects and we can make changes according to business
needs. it means maintain Authorizations and its fields and
field values.

8.While Creating Single role what will be happened in the
functional side, when you entered the Template role in the
derived role tab.

QUESTION IS NOT CLEAR

9.What is Dialog users, Batch users and Communicate users.
What is the use with Communicate user.
ANS:
Dialog user is used by an indiviual to do all kinds of log
on.
Batch user is used for Background processing and
communication within the system.
Communicate user is used for external rfc calls. (across
the systems we can connect)

10.Can we add one Composite role in to another Composite
role at any urgent user requests or in normal user
requests.
ANS: We can not add a composite role into another composite
role but we can add multiple derived roles into one
composite roles.

11.In Transport what type of Request we will use.Why don't
we use workbench request in transport.
ANS: most of the time we do transport workbench and
customized requests. 95% we do customized transport as we
do settings,configurations,creation etc at DEV system and
transport them to QUA or PRD systems.
settings,configurations etc are done by BASIS,Security and
Functional consultants then those will be treated as
Customized and if ABAPers do programs and packages etc and
transport them then those will be treated as workbench.

12.When we added Authorization Object in Template role, at
the same time what will be happen in Derived role.
ANS: Template Roles will be provided by default by SAP
while we do implementation (install SAP).when we want to
have template role we should not use that role directly,
instead of that we can go for COPY option and we can copy
it and do customize according to our business needs.

13.How to Check Profile parameter. And how to find whether
any transport has ended with error and where we can check.
ANS: T-code RZ10 to check Profile Parameter & T-code STMS
we can check the Transport error logs. click on Import
Overview (Truck icon) in STMS screen and in next screen we
have options like : Import Monitor, Import Tracking and
Import History.... these will show the transport issues.

14.How to Extract users list like who didn't login since 3
months. And In 90 Days user Locking in which table we will
use.
ANS: T-code SUIM : Users -> Click on By Logon Date and
password change -> Give * in user and give 90 days in
No.days since last logon and check Locked users and then
EXECUTE.

(OR) RSUSR200 report to get info

15.What is OSS Connection and System Opening and why we
have to open these.
ANS: OSS means Online Service System where SAP is going to
give Service to R/3 Users.

16.What will have in one single role and how many prifiles
will be in one sap cua system.
ANS: Single role will contain T-codes, Reports and URL's,
Profiles and Users. Max profile are 312.

17.What is the difference between Template role & Derive
role.
ANS: Template role is nothing but a default role provided
by SAP. this template role might be a single or composite
or derived role. template roles are not generated profiles
or authorizations nor assigned to users and org levels are
not maintained.Derived role is nothing but a single role
and its derived from a Master role and can restrict org
levels and can assign them to users.

Is This Answer Correct ?    15 Yes 1 No



Post New Answer       View All Answers


Please Help Members By Posting Answers For Below Questions

What happens to change documents when they are transported to the production system?

1185


As a SAP security consultant what is the most challenged you faced in previous company?

674


By which parameter number of entries are controlled in the user buffer?

916


what is the critical issue u are faced in your previous experience

1435


Explain secure store and forward?

630






Explain transport system-level security?

654


Please also send me details about CRM 5 and CRM 7 security issues and scenarios.

2225


Giving fire call access and extending fire call access by using VIRSA’s VFAT tool? can u brief give the explanation

3059


Which transaction should not be given to BASIS and DEV team in Production?

1918


How we Provided SAP Security design, configuration, and support for SAP Net Weaver systems running BI/BW 7.0 (Net Weaver 2004s)

1798


You want to remove a developer's and developer keys from a system. How would you do that?

638


What is the use of Personalization tab in SU01?

5017


1) Explain different type of Users? Explain specifically Service User? 2) Difference between System and Communication User?Explain in Context of Profile Parameter? 3) There are 5 systems say BI, SOLMAN, CRM, PI, SRM etc etc. Which system will act as a satellite system in CUA and Why? HOw CUa system works? 4) State different types of Transactions & Tables in Strutural Authorization Profile in HR Security? 5) What is L0 , L1 , L2 , L3 , L4 code called in HR Security? 6) What fields are required to create Strutural Authorization Profile in HR Security? State significance of Evaluation Path? 7) What is Structural Authorization Profile in HR Security? When required Role has already been assigned to User then why Structural Authorization Profile is required by user? 8) How are structural Authorization Profile are created? 9) Important Authorization Object in HR Security? 10) Fields in P_ORGIN A.O? 11) Important infotypes and What is PA? 12) How access is provided for tables to user? Significance of Authorization Group in TDDAT table? 13) Difference between SU22 and SU24? 14) Explain Authorization Structure? 15) Which table stores the Authorization Object of a User? 16) What we do to keep Roles consistent in DEV QAS and PRD? 17) A User has create and display access? Will he have access to change as well? 18) How User can have access to view salary slip of other employees(HR Security)?Explain in detail. 19) In HR security does we add Employee ID anywhere in Roles? 20) Any issue you have faced while Transport? 21) Have you faced any issue in Upgrade? Expalain how to compare Roles from older version of SAP to new version of SAP? 22) Any typical issue you have resolved in HR Security?

4629


In pfcg where we can add customized t-codes. And where we can see customized t-codes

1235


Can you explain protecting public keys?

603