Securing User DDIC Against Misuse
Context
User DDIC is a user with special authorizations for installation, software logistics, and the ABAP dictionary. SAP NetWeaver Application Server (AS) creates the user master record for user DDIC automatically in clients 000 and 001 when you install your SAP system. The installer also assigns the default password for this user that you designated as the master password during installation. The system code allows user DDIC special authorizations for certain operations. For example, DDIC is the only user that is allowed to log on to SAP NetWeaver AS during an upgrade.
Procedure
-
Secure DDIC against misuse by changing the default password in all clients.
-
Lock DDIC and unlock it only when necessary.