Symptom
A business role defines the access profile for a specific job function, such as a warehouse clerk. It aggregates one or more business catalogs and IAM apps and carries the restriction values that scope that access, for example, to a specific company code or plant.
Note: Business roles are custom entities. SAP isn't responsible for issues that arise during the design phase, and analyzing custom role configurations falls outside the scope of SAP Support. We recommend the tools described in this KBA.
Consider the following approaches to help identify and resolve unexpected access behavior:
- Cumulative authorization behavior: Authorizations are cumulative across all business roles assigned to a user. The least restrictive authorization always takes precedence.
- Build from least to most access: Start with the most restrictive role and validate it on its own. Then introduce additional roles one by one, moving gradually toward broader access.
- Add roles incrementally: Introduce each additional business role one at a time. Validate after each step that the required restrictions remain intact.
For best practices on business role design, refer to the following documentation:
- Identity and Access Management | SAP Help Portal
- SAP S/4HANA Cloud, Identity and Access Management ... - SAP Community
- Plan and Design Identity and Access Management - Road Map Viewer - SAP for Me
- How to set up a Naming Convention for Business Roles, Spaces and Pages and Business User in a 3-System-Landscape
- Key Concepts | SAP Help Portal
- Self-Enable on SAP S/4HANA Cloud Identity and Access Management - Road Map Viewer - SAP for Me
- Accelerating IAM Activities with SAP Activate - S/4HANA Technology
Environment
SAP S/4HANA Cloud Public Edition
Resolution
1. How to find out if an IAM app can be restricted by a field
Access each IAM app using the Display IAM App app to find the relevant restriction types.
For example, the IAM app F0842A_TRAN (Manage Purchase Orders) contains 12 restriction types:
| Description | Restriction Type ID | Write Access | Read Acces | F4 Access |
| Asset Master Data Maint: Company Code/Asset Class | A_S_ANLKL | No | No | Yes |
| New Asset Master Data Maintenance | A_S_MD | No | No | Yes |
| Order Status/Order Type | ASTNR_AUFART | No | No | Yes |
| Sales Document Type | AUART | No | No | Yes |
| Purchasing Document Type | BSART | Yes | Yes | Yes |
| Company Code | BUKRS | No | Yes | Yes |
| Purchasing Group | EKGRP | Yes | Yes | Yes |
| Purchasing Organization | EKORG | Yes | Yes | Yes |
| Project | PPM_PRJ | No | No | Yes |
| Responsibility Area for Internal Orders | RESPAREA_IO_AUFART_AUTH_KSTAR | No | No | Yes |
| Sales Area | SALES_AREA | No | No | Yes |
| Plant | WERKS | Yes | Yes | Yes |
For more information, see Display IAM Apps | SAP Help Portal
2. What are app authorization variants?
For example, Manage Purchase Orders (F0842A) (Manage Purchase Orders (Version 2) | SAP Fiori Apps Reference Library) has the following app authorization variants:
- F0842A_TRAN (Manage Purchase Orders)
- F0842A_03_TRAN (Display Purchase Orders) - Display Only
- F0842A_08_TRAN (Display Change Documents of Purchase Orders) - Display Only
For more information, see Authorization Model | SAP Help Portal and Work with IAM Apps (App Authorization Variants) | SAP Help Portal
Using the Display IAM Apps app, filter by transaction code (for example, F0842A) to find all relevant app authorization variants for a given transaction code.
3. How to find out which IAM apps contain a specific restriction type
Use the Display Restriction Types app to find which IAM apps contain a certain restriction type.
For example, restriction type Purchasing Document Type (BSART) is used in many apps, such as F0349A_TRAN (Purchase Requisition Item), F0350_TRAN (Purchase Contract), and F0712_TRAN (Manage Supplier Line Items).
For more information, see Display Restriction Types | SAP Help Portal
4. How to find out which business users are assigned to a business role that contains a specific IAM app
Use the IAM Information System app:
- Select Main Entity: IAM App.
- Open the IAM App - Business User tab to display this relation.
- Filter by IAM App ID (for example, F0842A_TRAN).
For more information, see IAM Information System | SAP Help Portal
5. How to find out which business role that gives access to an IAM app is assigned to a business user
Follow these steps:
- Use the IAM Information System app and select Main Entity: Restriction.
- Open the Restriction - IAM App tab.
- Filter by IAM App ID (for example, F0842A_TRAN).
- Download the list of business roles.
- From the downloaded Excel file, copy the values under the Business Role ID column.
- Use the IAM Information System app and select Main Entity: Business Role.
- Open the Business Role - Business User tab.
- Filter by Business User ID (for example, CB9980000000).
- Paste the business role IDs in the Business Role ID filter.
- Select Go to get the business roles that are assigned to the user.
6. How to find out if an IAM app is restricted based on a restriction type and its restriction fields
Use the IAM Information System app:
- Select Main Entity: Business Role.
- Open the Business Role - IAM App tab.
- Filter by IAM App ID (for example, F0842A_TRAN).
- For example, restriction type BSART (Purchasing Document Type) is part of the list.
7. How to find out if a business role is restricted based on a restriction type
Use the IAM Information System app:
- Select Main Entity: Business Role.
- Open the Business Role - Restriction tab.
- Filter by Access Restriction: Restricted.
- Filter by Restriction Field (for example, Purchasing Document Type).
- Note Value Count > 0.
- Select the line and check the Restriction Values (for example, "NB").
8. How to find out if a business user or role is restricted based on a restriction type
Follow these steps:
- Use the IAM Information System app and select Main Entity: Business Role.
- Open the Business Role - Restriction tab.
- Filter by Access Restriction: Restricted.
- Filter by Restriction Field (for example, Purchasing Document Type).
- Note Value Count > 0.
- Select the line and check the Restriction Values (for example, "NB").
- Export the list to Excel.
- From the downloaded Excel file, copy the values under the Business Role ID column.
- Use the IAM Information System app and select Main Entity: Business Role.
- Open the Business Role - Business User tab.
- Filter by Business User ID (for example, CB9980000000).
- Paste the business role IDs in the Business Role ID filter.
- Select Go to get the restricted business roles that are assigned to the user.
9. Is it possible to enable a restriction type for an IAM app if it isn't part of it?
No. This is a feature request. For more information, see 2963059 - How to Submit Feature Requests for SAP S/4HANA Cloud Public Edition - SAP for Me
10. Is it possible to enable an access category for a restriction type?
No. This is a feature request. For more information, see 2963059 - How to Submit Feature Requests for SAP S/4HANA Cloud Public Edition - SAP for Me
11. How to find out if an app is activated in the business role
Navigate to the Maintain Business Roles app, search by the business role, and access the IAM Apps tab. Filter by IAM App ID (for example, F0842A_TRAN).
12. How to activate an IAM app in a business role
For more information, see How to Activate or Deactivate IAM Apps (App Authorization Variants) | SAP Help Portal
13. How to find out unmaintained restriction types
Use the IAM Key Figures app. For more information, see IAM Key Figures | SAP Help Portal.
Alternatively, use the IAM Information System app:
- Select Main Entity: Business Role.
- Open the Business Role - Restriction tab.
- Filter by Access Restriction: Restricted.
- Filter by Restriction Field (for example, Purchasing Document Type).
- Note Value Count = 0.
14. How to check when the business role was updated
Use the Extensibility Inventory app. For more information, see Extensibility Inventory | SAP Help Portal
15. How to check the changes performed to a business role
Check all changes made to a business role using the Display Changes option in the Maintain Business Roles app.
For more information, see How to Display Change Documents for Business Roles | SAP Help Portal
16. How to handle changes in IAM objects before, during and after the upgrade
For an overview of the changes, refer to 2975653 - Identity and Access Management (IAM): Central Change Overview for SAP S/4HANA Cloud Public Edition - SAP for Me
For more information about the activities to perform, refer to the following documentation: Upgrade Phase | SAP Help Portal
- Activities for the New Release (Before Test System Upgrade) | SAP Help Portal
- Activities for the New Release (After Test System Upgrade) | SAP Help Portal
- Activities for the Current Release (After Development and Production System Upgrade) | SAP Help Portal
Refer to the following information about the most relevant IAM apps:
- Manage Business Role Changes After Upgrade | SAP Help Portal
- IAM Information System | SAP Help Portal
- IAM Key Figures | SAP Help Portal
See Also
Identity and Access Management | SAP Help Portal
SAP S/4HANA Cloud, Identity and Access Management ... - SAP Community
Plan and Design Identity and Access Management - Road Map Viewer - SAP for Me
Key Concepts | SAP Help Portal
Self-Enable on SAP S/4HANA Cloud Identity and Access Management - Road Map Viewer - SAP for Me
Accelerating IAM Activities with SAP Activate - S/4HANA Technology
Keywords
iam, business role, IAM App, restriction type, authorization, restriction field, maintain business roles, maintain business users, Display IAM App, Display IAM Apps, Display Restriction Types, IAM Information System, IAM Key Figures, Maintain Business Roles, Extensibility Inventory, Fiori Apps Library, IAM, Identity and Access Management, IAM app, App authorization variants, Restriction type, Restriction field, Restriction values, Access category, Access restriction, Business role, Business user, Authorization, Transaction code, Value Count, Change documents, Feature request, Upgrade, Write Access, Read Access, F4 Access, Restricted, SAP S/4HANA Cloud Public Edition, SAP Help Portal, SAP for Me, Excel, Test system, Development system, Production system, Activate, Deactivate, Filter, Export, Download, Navigate, Assign, Display Change Documents, Upgrade Phase, Main Entity, Business Role ID, Business User ID, s4hc, s/4HANA cloud, public cloud, public edition , KBA , CA-GTF-IAM , S/4HANA Cloud: Authorization Content , BC-SRV-APS-IAM , Identity and Access Management , Problem
SAP Knowledge Base Article - Public