SAP Knowledge Base Article - Public

3788562 - Business Roles/IAM Apps/Restriction Types - Frequently Asked Questions - SAP S/4HANA Cloud Public Edition

Symptom

Business roles are custom items that can be designed and modeled based on available templates to include the scoped IAM apps and their default restriction types.

     

Note: Please notice business roles are custom items and SAP is not responsible for issues identified during the design phase of those items, the analysis of custom role configurations falls outside the scope of SAP Support, we recommend the tools described in this KBA.

     

Please consider following approaches to help identify and resolve any unexpected access behavior independently.

  • Be aware of cumulative authorization behavior: Authorizations are cumulative across all business roles assigned to a user — the least restrictive authorization always takes precedence.
  • Build from least to most access: Start with the most restrictive role and validate it on its own, then introduce additional roles one by one, moving gradually toward broader access
  • Add roles incrementally: Introduce each additional business role one at a time, validating after each step that the required restrictions remain intact.

       

Best practices regarding business role design can be found under the following documentation:

Environment

SAP S/4HANA Cloud Public Edition

Resolution

1. How to find out if an IAM app can be restricted by a field

Access each IAM app using the Display IAM App app to find the relevant restriction types.

For example, the IAM app F0842A_TRAN (Manage Purchase Orders) contains 12 restriction types:

DescriptionRestriction Type IDWrite AccessRead AccesF4 Access
Asset Master Data Maint: Company Code/Asset ClassA_S_ANLKLNoNoYes
New Asset Master Data MaintenanceA_S_MDNoNoYes
Order Status/Order TypeASTNR_AUFARTNoNoYes
Sales Document TypeAUARTNoNoYes
Purchasing Document TypeBSARTYesYesYes
Company CodeBUKRSNoYesYes
Purchasing GroupEKGRPYesYesYes
Purchasing OrganizationEKORGYesYesYes
ProjectPPM_PRJNoNoYes
Responsibility Area for Internal OrdersRESPAREA_IO_AUFART_AUTH_KSTARNoNoYes
Sales AreaSALES_AREANoNoYes
PlantWERKSYesYesYes

For more information, see Display IAM Apps | SAP Help Portal

      

2. What are app authorization variants?

For example, Manage Purchase Orders (F0842A) (https://fioriappslibrary.hana.ondemand.com/sap/fix/externalViewer/#/detail/Apps('F0842A')/S37) has the following app authorization variants:

  • F0842A_TRAN (Manage Purchase Orders) 
  • F0842A_03_TRAN (Display Purchase Orders) - Display Only
  • F0842A_08_TRAN (Display Change Documents of Purchase Orders) - Display Only

For more information, see Authorization Model | SAP Help Portal and Work with IAM Apps (App Authorization Variants) | SAP Help Portal

      

Using the Display IAM Apps app, filter by transaction code (for example, F0842A) to find all relevant app authorization variants for a given transaction code.

               

3. How to find out which IAM apps contain a specific restriction type

Use the Display Restriction Types app to find which IAM apps contain a certain restriction type.

For example, restriction type Purchasing Document Type (BSART) is used in many apps, such as F0349A_TRAN (Purchase Requisition Item), F0350_TRAN (Purchase Contract), and F0712_TRAN (Manage Supplier Line Items).

For more information, see Display Restriction Types | SAP Help Portal

          

4. How to find out which business users are assigned to a business role that contains a specific IAM app

Use the IAM Information System app:

  1. Select Main Entity: IAM App.
  2. Open the IAM App - Business User tab to display this relation.
  3. Filter by IAM App ID (for example, F0842A_TRAN).

For more information, see IAM Information System | SAP Help Portal 

        

5. How to find out which business role that gives access to an IAM app is assigned to a business user

Follow these steps:

  1. Use the IAM Information System app and select Main Entity: Restriction.
  2. Open the Restriction - IAM App tab.
  3. Filter by IAM App ID (for example, F0842A_TRAN).
  4. Download the list of business roles.
  5. From the downloaded Excel file, copy the values under the Business Role ID column.
  6. Use the IAM Information System app and select Main Entity: Business Role.
  7. Open the Business Role - Business User tab.
  8. Filter by Business User ID (for example, CB9980000000).
  9. Paste the business role IDs in the Business Role ID filter.
  10. Select Go to get the business roles that are assigned to the user.

            

6. How to find out if an IAM app is restricted based on a restriction type and its restriction fields

Use the IAM Information System app:

  1. Select Main Entity: Business Role.
  2. Open the Business Role - IAM App tab.
  3. Filter by IAM App ID (for example, F0842A_TRAN).
  4. For example, restriction type BSART (Purchasing Document Type) is part of the list.

       

7. How to find out if a business role is restricted based on a restriction type

Use the IAM Information System app:

  1. Select Main Entity: Business Role.
  2. Open the Business Role - Restriction tab.
  3. Filter by Access Restriction: Restricted.
  4. Filter by Restriction Field (for example, Purchasing Document Type).
  5. Note Value Count > 0.
  6. Select the line and check the Restriction Values (for example, "NB").

    

8. How to find out if a business user or role is restricted based on a restriction type

Follow these steps:

  1. Use the IAM Information System app and select Main Entity: Business Role.
  2. Open the Business Role - Restriction tab.
  3. Filter by Access Restriction: Restricted.
  4. Filter by Restriction Field (for example, Purchasing Document Type).
  5. Note Value Count > 0.
  6. Select the line and check the Restriction Values (for example, "NB").
  7. Export the list to Excel.
  8. From the downloaded Excel file, copy the values under the Business Role ID column.
  9. Use the IAM Information System app and select Main Entity: Business Role.
  10. Open the Business Role - Business User tab.
  11. Filter by Business User ID (for example, CB9980000000).
  12. Paste the business role IDs in the Business Role ID filter.
  13. Select Go to get the restricted business roles that are assigned to the user.

     

9. Is it possible to enable a restriction type for an IAM app if it isn't part of it? 

No. This is a feature request. For more information, see 2963059 - How to Submit Feature Requests for SAP S/4HANA Cloud Public Edition - SAP for Me

         

10. Is it possible to enable an access category for a restriction type? 

No. This is a feature request. For more information, see 2963059 - How to Submit Feature Requests for SAP S/4HANA Cloud Public Edition - SAP for Me

       

11. How to find out if an app is activated in the business role 

Navigate to the Maintain Business Roles app, search by the business role, and access the IAM Apps tab. Filter by IAM App ID (for example, F0842A_TRAN).

      

12. How to activate an IAM app in a business role

For more information, see How to Activate or Deactivate IAM Apps (App Authorization Variants) | SAP Help Portal

       

13. How to find out unmaintained restriction types 

Use the IAM Key Figures app. For more information, see IAM Key Figures | SAP Help Portal.

Alternatively, use the IAM Information System app:

  1. Select Main Entity: Business Role.
  2. Open the Business Role - Restriction tab.
  3. Filter by Access Restriction: Restricted.
  4. Filter by Restriction Field (for example, Purchasing Document Type).
  5. Note Value Count = 0.

         

14. How to check when the business role was updated

Use the Extensibility Inventory app. For more information, see Extensibility Inventory | SAP Help Portal 

      

15. How to check the changes performed to a business role 

Check all changes made to a business role using the Display Changes option in the Maintain Business Roles app.

For more information, see  How to Display Change Documents for Business Roles | SAP Help Portal 

      

16. How to handle changes in IAM objects before, during and after the upgrade

For an overview of the changes, refer to 2975653 - Identity and Access Management (IAM): Central Change Overview for SAP S/4HANA Cloud Public Edition - SAP for Me 

For more information about the activities to perform, refer to the following documentation: Upgrade Phase | SAP Help Portal 

Refer to the following information about the most relevant IAM apps:

              

         

See Also

Identity and Access Management | SAP Help Portal

SAP S/4HANA Cloud, Identity and Access Management ... - SAP Community

Plan and Design Identity and Access Management - Road Map Viewer - SAP for Me

How to set up a Naming Convention for Business Roles, Spaces and Pages and Business User in a 3-System-Landscape

Key Concepts | SAP Help Portal

Self-Enable on SAP S/4HANA Cloud Identity and Access Management - Road Map Viewer - SAP for Me 

Accelerating IAM Activities with SAP Activate - S/4HANA Technology

Keywords

iam, business role, IAM App, restriction type, authorization, restriction field, maintain business roles, maintain business users, Display IAM App, Display IAM Apps, Display Restriction Types, IAM Information System, IAM Key Figures, Maintain Business Roles, Extensibility Inventory, Fiori Apps Library, IAM, Identity and Access Management, IAM app, App authorization variants, Restriction type, Restriction field, Restriction values, Access category, Access restriction, Business role, Business user, Authorization, Transaction code, Value Count, Change documents, Feature request, Upgrade, Write Access, Read Access, F4 Access, Restricted, SAP S/4HANA Cloud Public Edition, SAP Help Portal, SAP for Me, Excel, Test system, Development system, Production system, Activate, Deactivate, Filter, Export, Download, Navigate, Assign, Display Change Documents, Upgrade Phase, Main Entity, Business Role ID, Business User ID, s4hc, s/4HANA cloud, public cloud, public edition , KBA , CA-GTF-IAM , S/4HANA Cloud: Authorization Content , BC-SRV-APS-IAM , Identity and Access Management , Problem

Product

SAP S/4HANA Cloud Public Edition all versions