SAP Knowledge Base Article - Public

2868559 - How to find and handle changes to Business Roles after a S/4HANA Cloud Public Edition upgrade

Symptom

Changes to authorizations are always expected during upgrades. There are many reasons why IAM objects need to be updated according to each release:

  • New features and enhancements require updates to authorization objects, restriction types, and business catalogs to enable access to new functionality. Each SAP S/4HANA Cloud Public Edition release introduces innovations that necessitate new business catalogs, IAM apps, or restriction types to grant users access to these capabilities.
  • Outdated or redundant authorization objects are deprecated and replaced with more efficient successors to streamline authorization management 
  • Changes to underlying authorization logic, such as modifications to restriction type access categories (e.g., from "Read" to "Write"), ensure authorizations remain aligned with business processes
  • SAP refines authorization structures to improve usability, reduce complexity, and support best practices in business role design
  • Business role templates and business catalogs are updated to reflect SAP's recommended authorization models for specific business scenarios

SAP S/4HANA Cloud Public Edition operates as a fully managed cloud service with a continuous innovation approach and this also means that authorization changes are mandatory and cannot be deferred.

Then, how to identify all of the changes made to the Business Catalogs and Restrictions assigned to Business Roles as part of an upgrade to SAP S/4HANA Cloud Public Edition?

Environment

SAP S/4HANA Cloud Public Edition

Resolution

Starting with SAP S/4HANA Cloud Public Edition 1911, a new app has been added which can generate a report of all Business Catalog and Restriction changes made to Business Roles as a result of the upgrade. The app Display Business Role Changes after Upgrade is available for this operation but it is only available in Q systems.

The app is not displayed by default. To "activate" (pin) the app, follow the steps below:

  1. Launch App Finder by clicking the "Me Icon" 2868559 - Me Icon.PNG in the upper right corner of the page and selecting App Finder from the resultindata:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAABkAAAAcCAYAAACUJBTQAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsMAAA7DAcdvqGQAAACiSURBVEhLYzD1iv9PazxqCUl4xFly8P/mF///X4Tjp/+7sarDjglbMuHa/+NAgzevQRJb8xRo0df/SyYgieHBBC3pPo9mAQyDLDp/EFMcCyZgCSiYcAUNPjlUPBgsoUtwATE9Ih6CaZqE0Q1Hx5TGCbZgQsdEBhtOS3BGODomIgHgsIT45EmM2lFLkDBFlmBLsrgwWZZQF49aQhIeLpbE/wcAGIaNiKgnlisAAAAASUVORK5CYII=r.PNG" src="/documents/cudata:image/jpeg;base64,iVBORw0KGgoAAAANSUhEUgAAABkAAAAcCAYAAACUJBTQAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsMAAA7DAcdvqGQAAACiSURBVEhLYzD1iv9PazxqCUl4xFly8P/mF///X4Tjp/+7sarDjglbMuHa/+NAgzevQRJb8xRo0df/SyYgieHBBC3pPo9mAQyDLDp/EFMcCyZgCSiYcAUNPjlUPBgsoUtwATE9Ih6CaZqE0Q1Hx5TGCbZgQsdEBhtOS3BGODomIgHgsIT45EmM2lFLkDBFlmBLsrgwWZZQF49aQhIeLpbE/wcAGIaNiKgnlisAAAAASUVORK5CYII=9 - App Finder.PNG" />
  2. Click on the group "Identity and Access Management (Obsolete)" or "Search in Catalog" for "Display Business Role Changes"
  3. In the tile "Display Business Role Changes after Upgrade", click on the "pin" icon
    2868559 - App Finder Tile.PNG
  4. Select the group where you wish to pin the tile to pin the tile "Display Business Role Changes after Upgrade"2868559 - Pin.PNG
  5. The app will allow you to select a specific role or roles for which to show changes
  6. If no roles are selected, all roles will be checked but for large number of roles, this could take some time and the resulting list could be unmanageable
    *Please only use this app for upgrade support and only in your Q system

Additionally, we suggest that you check Central Change Overview notes (2975653 - Identity and Access Management (IAM): Central Change Overview for SAP S/4HANA Cloud Public Edition) to download the spreadsheet and check what has been changed. 

See Also

For more information, check Manage Business Role Changes After Upgrade.

Keywords

business role, changes, business catalogs, restrictions, upgrade, s/4hana cloud, update, hotfix, manage, IAM , KBA , BC-SRV-APS-IAM , Identity and Access Management , How To

Product

SAP S/4HANA Cloud Public Edition all versions