Preparatory Steps 

When you activate the Profile Generator, you permit specified authorization checks to be deactivated. The Profile Generator is active in the standard system (the system profile parameter auth/no_check_in_some_cases is set).

This setting has the following effect:

Perform the following steps in the Implementation Guide (IMG):

  1. Copy SAP default settings for check indicators and authorization field values
  2. Using Transaction SU25 (step 1), copy the default values delivered by SAP. This is how you import the SAP check indicator default values for the authorization objects within a transaction, and the authorization field values for the Profile Generator into the customer tables (tables USOBX_C and USOBT_C). You can edit these in Transaction SU24.

    You can change both configurations to meet your requirements.

    To import an upgrade, follow steps 2a to 2d.

    It may take a few minutes to copy the SAP defaults into the customer tables.

    See the documentation in Transaction SU25.

  3. Schedule Background Job for Time Limits

You can set a time limit on the assignment of users to roles. To ensure that these changes are reflected in the user master record, you need to schedule a background job to make the relevant adjustments daily.

See Comparing user master record profiles with roles.

To maintain the default check indicator settings, use Transaction SU24 (see the following topics). To do this you need the User Master Maintenance: User Groups (S_USER_GRP) authorization, with the value ‘*’ in the CLASS and ACTVT fields.

You can edit the default authorizations for the Profile Generator on the initial screen of the Profile Generator (see Elements in the Browser View).