Home > SAP software/management Tips > SAP NetWeaver tips > User management with SAP NetWeaver Administrator
SAP Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SAP NETWEAVER TIPS

User management with SAP NetWeaver Administrator


Heidrun Reichart
08.10.2007
Rating: -4.33- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


As an administrator, you control who has access to applications by creating users and providing these users with a means of authenticating themselves to an application.In SAP NetWeaver Application Server Java, the User Management Engine (UME ) provides you with the functions to manage users, groups, and roles. The UME functionalities are integrated into SAP NetWeaver Administrator, starting with release NetWeaver 2004.This part of the application is dedicated to user administrators. It provides the functions they need to manage users, groups, roles, and user-related data for Java systems in the User Management Engine (UME).Just go to SAP NetWeaver Administrator => System Management => Administration =>Identity Management

[IMAGE]

General Information

Groups:

To simplify user administration, users can be collected in groups according to:

  • Users' functions in a company
  • Department they work in
  • And so on

[IMAGE]

Roles:

Roles define the users' authorizations. You can assign roles to either single users or groups.


Roles contain a set of ‘Actions'. You can use these actions to create new custom roles. Roles are the powerful part of User Management. Therefore, always search for a role and add users or groups, not the other way round.

SAP provides four different predefined roles for use with SAP NetWeaver Administrator:

[IMAGE]

Local roles enable the management of the local system where the SAP NetWeaver Administrator runs.
Central roles enable the management of the entire landscape that is available from SLD.

The read-only roles do not allow any changes in the managed system such as start/stop or configuration changes, whereas the other roles allow full control.

If you want to create new Java users in a Java system, you can use the User Management plug-in in SAP NetWeaver Administrator. This is the case for ...


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
SAP NetWeaver tips
Using SAP NetWeaver MDM with CRM, SCM and NetWeaver BI
The importance of master data management following mergers and acquisitions
Designing your SAP NetWeaver master data management strategy
Enterprise MDM: SAP MDM for reducing data silos and duplicate records
How to move SAP NetWeaver Enterprise Portal between servers
Getting started with SAP NetWeaver PI (formerly XI)
Top 10 SAP tips of 2007
Retrieve BI data with Web Services
Eliminate database read/write times with ABAP shared memory
XI: Search through the payload of a message... without TREX!

SAP Business Process Management
Increasing operational efficiency and agility with BPM
Software AG to acquire BPM vendor IDS Scheer
More SAP customers adopting BPM tools despite the recession
SAP NetWeaver training tutorial
SAP CEOs preach networks, collaboration and BPM
How can ABAP developers survive in a NetWeaver era?
Becoming (and staying) a business process expert takes business, technical skills
Model-driven development in the enterprise
The definition of the BP category: 'group'
Keys to SAP business process success

SAP Solution Manager
Getting ready for SAP TechEd 2009 with tips from Jon Reed
SAP TechEd 2009 Phoenix: SearchSAP.com Special Report
Few SAP customers using SAP Solution Manager to full potential
Explaining Run SAP and Solution Manager
Installation procedure, configuration details for SAP Solution Manager
Installing Solution Manager on a mixed Windows/Unix platform
Do I need to install Java to install Solution Manager?
Installing SAP's Solution Manager 4.0
Generating a Solution Manager key
Why might the dispatcher not show up in SAP Solution Manager?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


standalone Java systems and double-stack systems (ABAP and Java).

The user management engine (UME) can also use an SAP NetWeaver Application Server (AS) ABAP as its data source for user management data (double-stack-system). This enables you to take advantage of the following:

  • Users of the ABAP system are visible as users in the UME and can log on with their passwords from the ABAP system.
  • User and role assignments in the ABAP system appear as user and group assignments in the UME.
  • You can use the ABAP roles for authorization management in the UME, by adding the groups representing the ABAP roles to the UME roles.

Example:

Create a restricted role within Local SAP NetWeaver Administrator

 =>permission to view logs

Local System Administration:

Go to System Management and choose the working center: Administration => Identity Management

Choose "Role" in the search criteria and then choose [IMAGE] . Now fill out the important details.

General Information:
Give the new role a unique name like "LoggingADM". This is a mandatory input field.

 

[IMAGE]

Assigned Groups: From the list, choose groups to which the new role should be assigned.

Assigned Users: From the list, choose users to which the new role should be assigned.

Assigned Actions: You can restrict the role here by selecting only the actions required for the new role.

In this case, select "Logs_Display", "Logs_Configure" and "WebAdmin_Local" from the set of available actions.

[IMAGE]

Important:

You need to assign either tc~lm~webadmin~permissions.WebAdmin_Central or
tc~lm~webadmin~permissions.WebAdmin_Local, plus the action which you want this role to allow, for example tc~lm~webadmin~permissions.Logs_Display

[IMAGE]

After you have created the new Logging ADM Role, you can add this role right away or later on to certain users or groups, if you haven´t already done this. The result is that all added users or groups will have limited local administration access.

Adding users or groups to a role:

Choose local system administration mode:

System Management → Administration → Identity Management and select, for example, your newly-created role to modify it.

Keep in mind, that the role is the powerful part. Therefore, select Role from the drop-down list of search criteria.

You can now modify the new role with regard to users or groups. You open details by clicking the specific role and choosing "Modify" in the details section.

[IMAGE]

[IMAGE]

You can now filter for users or groups to which you want to assign permission for certain actions. To complete the user management, choose Add and then Save.

With SAP NetWeaver Administrator, SAP provides you a central entry point to administer your Java system landscape. The interface allows seamless navigation to other SAP NetWeaver administration tools like User Management Engine so you can save time and get space for other things to do!

You can check for further information in:

http://help.sap.com/saphelp_nw70/Administration_of_users_roles_and_groups


Heidrun Reichart Heidrun Reichart specializes in SAP NetWeaver system administration topics and works for SAP NetWeaver Product Management.


This content is reposted from the SAP Developer Network.
Copyright 2007, SAP Developer Network


SAP Developer Network (SDN) is an active online community where ABAP, Java, .NET, and other cutting-edge technologies converge to form a resource and collaboration channel for SAP developers, consultants, integrators, and business analysts. SDN hosts a technical library, expert blogs, exclusive downloads and code samples, an extensive eLearning catalog, and active, moderated discussion forums. SDN membership is free.

Want to read more from this author? Click here to read Heidrun Reichart's Weblog. Click here to read more about the Application Server on the SDN.



Rate this Tip
To rate tips, you must be a member of SearchSAP.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



NetWeaver SAP White Papers
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
SearchSAP.com is a search service provided by TechTarget and is completely
independent of and not affiliated with SAP AG.
  TechTarget - The IT Media ROI Experts