You should never make changes to a productive R/3 System. Therefore, you should not assign following authorizations to users in a production system.
- ABAP Workbench development authorizations (ABAP Workbench (S_DEVELOP)and Change and Transport Organizer authorization objects (S_TRANSPRT))
- Executing operating system commands from within the R/3 System (Transaction SM52) (System Authorizations (S_ADMI_FCD) value UNIX).
- Authorizations to deactivate authorization checks (Transaction AUTH_SWITCH_OBJECTS) with the authorization object S_USER_OBJ.