Security & GRC
What is Authorization Concept?
The design of roles, authorization objects, and user assignment that controls what each user can do in SAP.
It defines role structure, naming conventions, and approval processes. It must enforce least privilege and segregation of duties. Role testing with real test users is needed before go-live, not only SAP_ALL testing.
Related terms
PFCG Role
An SAP role created in the profile generator that bundles menus, authorizations, and generated profiles for users.
Authorization Object
A definition of up to ten fields, such as activity and company code, checked by programs to permit actions.
Segregation of Duties
A control principle preventing one person from performing conflicting tasks, such as creating suppliers and paying them.
Role Testing
Testing that users with production-equivalent roles can perform their tasks and are blocked from unauthorized actions.
More in Security & GRC
Planning an S/4HANA move?
Read the field guides on testing an ECC to S/4HANA migration and grab the free template library.