<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAP* in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955156#M945250</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to lock SAP* in SU01, you need to create it first in SU01. Normally, it makes sense to create SAP* otherwise it could possibly create itself, unless it exists in SU01.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 May 2008 20:31:48 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2008-05-27T20:31:48Z</dc:date>
    <item>
      <title>SAP*</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955155#M945249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just a very simple question. If I need to LOCK the user ID SAP* how can I do it ? I tried SU01 --.But tells me the user itself is not exsistent. Do I need to do it at the OS level?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2008 20:24:12 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955155#M945249</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-05-27T20:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: SAP*</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955156#M945250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to lock SAP* in SU01, you need to create it first in SU01. Normally, it makes sense to create SAP* otherwise it could possibly create itself, unless it exists in SU01.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2008 20:31:48 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955156#M945250</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-05-27T20:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: SAP*</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955157#M945251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Never Knew This!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So The following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.Create SAP* in ALL the Clients ( Or 000 Clients only) Using SU01&lt;/P&gt;&lt;P&gt;2. Then Lock it up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question --&amp;gt; We certainly need to assign the Authorizations to it, right. This I will accordingly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mentioned SAP* CAn create itself--how is this  done ?  Just out of curiousity&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My idea is the change the password and lock the user. once created in SU01 ..then like any other user or is there any other way ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Julu!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: george G on May 27, 2008 10:56 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2008 20:55:59 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955157#M945251</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-05-27T20:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: SAP*</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955158#M945252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; We certainly need to assign the Authorizations to it, right. This I will accordingly.&lt;/P&gt;&lt;P&gt;If you don't use it, then which authorizations does it need?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;gt; You mentioned SAP* CAn create itself--how is this  done ?  Just out of curiousity&lt;/P&gt;&lt;P&gt;George?? Did you give your password to someone else? &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Everyone&lt;/EM&gt; knows that answer... it has a default installation password = 'PASS', if the user has never logged on in that client (see also infos on system param login/no_automatic_user_sapstar).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Report RSUSR003 is usefull for checking this type of thing!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2008 21:07:29 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955158#M945252</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-05-27T21:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: SAP*</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955159#M945253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem is ht efollowing ;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Since everybody knows this pasword, iwant to change it. This ID is being used by folks who should not.&lt;/P&gt;&lt;P&gt;Now Juluis, I want to restrict the password which is PASS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. I want to change the password&lt;/P&gt;&lt;P&gt;2. Lock in the ID &lt;/P&gt;&lt;P&gt;3. Use it only when needed..hence new password !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do i do it...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2008 21:22:12 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955159#M945253</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-05-27T21:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: SAP*</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955160#M945254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RZ11 allows me to Dispaly the parametes....just deactivate the profile by giving the value 1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so Whats the TCD to Change these profiles ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2008 21:29:39 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955160#M945254</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-05-27T21:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: SAP*</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955161#M945255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not a consultant, but a consultant would probably tell you:&lt;/P&gt;&lt;P&gt;&amp;gt; 1. I want to change the password&lt;/P&gt;&lt;P&gt;Then change it at logon.&lt;/P&gt;&lt;P&gt;&amp;gt; 2. Lock in the ID &lt;/P&gt;&lt;P&gt;In SU01.&lt;/P&gt;&lt;P&gt;&amp;gt; 3. Use it only when needed..hence new password !&lt;/P&gt;&lt;P&gt;Assign it to a protected user group (S_USER_GRP) and restrict access to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, in all clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should work.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;gt; How do i do it...&lt;/P&gt;&lt;P&gt;For a qualified "how to" answer, the NW Admin forum ("basis") is probably the best place to ask.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you wish, I can move this thread there (or create a thread referencing this one, and lock it?).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Personally, there is one aspect about the user group which I find a bit of a bother: 'SUPER' is not as close to the end of the alphabet as for example 'ZAMBIA', 'Z9999', etc. Sometimes it makes sense to protect specific standard users, and not specific expected user groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There have also been some changes in defaults a few releases ago. The "automatic" feature for SAP* in a client is now '1' for example (disabled). When you remove the default access and save, then you don't need to logon again to &lt;EM&gt;experience&lt;/EM&gt; the new authority-check results when you try to click somewhere else. etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Much like DDIC, it depends on what you use it for...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2008 22:29:07 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955161#M945255</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-05-27T22:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: SAP*</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955162#M945256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are the answers :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. SAP* Doesnot have a User master record. hence it will have all the Special properties. One cannot change the password PASS if SAP* is absent in the UMR.Therefore we need to create VIA SU01 ( As Juluis had suggested !) this will make the SAP*  Behave like a normal user subject to authorization checks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ideally we -meaning- the Sec Admins ought to deactivate the SAP* , and create our own super User. This is the best practice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2008 03:15:24 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955162#M945256</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-05-28T03:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: SAP*</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955163#M945257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; 1. SAP* Doesnot have a User master record. hence it will have all the Special properties. One cannot change the password PASS if SAP* is absent in the UMR.Therefore we need to create VIA SU01 ( As Juluis had suggested !) this will make the SAP*  Behave like a normal user subject to authorization checks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nope. In SAP authorizations never substract. Creating a UMR for SAP* does not take away any abilities.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2008 06:18:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955163#M945257</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2008-05-28T06:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: SAP*</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955164#M945258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pls compare also point with one of [SAP Note 2383|https://service.sap.com/sap/support/notes/2383] &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b.rgds, Bernhard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2008 06:34:47 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955164#M945258</guid>
      <dc:creator>Bernhard_SAP</dc:creator>
      <dc:date>2008-05-28T06:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: SAP*</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955165#M945259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All right. I stand corrected. Thanks for the note!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2008 06:56:42 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955165#M945259</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2008-05-28T06:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: SAP*</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955166#M945260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now, If you check table USR01 then the SAP* is present but when you  go to SU01 and display the user SAP*  the answer is its not present. !! Any explanations ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2008 13:04:33 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955166#M945260</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-05-28T13:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: SAP*</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955167#M945261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi George,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;maybe somwone has deleted the USR02-entry with DB-tools to be able to login with sap*/PASS sometime in the past.....&lt;/P&gt;&lt;P&gt;Then no changelogs exist for that deletion and all other tables still contain the SAP*-entry.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b.rgds, Bernhard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2008 14:03:45 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap/m-p/3955167#M945261</guid>
      <dc:creator>Bernhard_SAP</dc:creator>
      <dc:date>2008-05-28T14:03:45Z</dc:date>
    </item>
  </channel>
</rss>

