Security

User Administration and Authentication

Authorizations

The SAP BW/4 HANA authorization concept is based on assigning authorizations to users based on roles. For role maintenance, use the profile generator (transaction PFCG).

To define the models and data within those models to which users have access, you can use data access profiles in both the standard and embedded configurations of Planning and Consolidation. For detailed steps in a standard configuration, refer to Data Access Profile Setup; For details in a embedded configuration, refer to .

To define what types of activities or tasks a user is authorized to perform in different functions, you can leverage the SAP NetWeaver authorization concept:
  • In the Business Planning and Consolidation embedded configuration, you assign authorization objects to users based on roles.

  • In the Business Planning and Consolidation standard configuration, you assign task profiles to users or a team of users in the web client.

For more information about how to maintain roles, see the SAP NetWeaver role administration information on the SAP Help Portal at http://help.sap.com.