System Trace
System Trace
Use the trace data to identify issues, such as unauthorized access attempts,
slow-performing SQL queries, or other system problems.
Based on that the security consultants give the authorization, if fails by
identify by using the return codes in red color.
Note = > It is important to deactivate the trace when not in use.
Return Codes
RC = > 0 --- Authorization is successful.
RC = > 4 --- User has required authorization object, but different
authorization Values.
RC = > 8 --- User does not have required authorization values in the user
buffer.
RC = > 12 --- User does not have access to authorization object.
Note = > ST01 trace should be applied in the local server only. Hence before
applying ST01 trace, ensure that user and you are in the same system.
AL08 = > Users in each server.
SM51 = > List of application servers.
STAUTHTRACE
Exclusive authorization Trace.
Trace is applied across all application servers.
Note = > This T code is available in the updated version of SAP.
How to Use STAUTHTRACE:
Access the Transaction:
o Enter STAUTHTRACE in the SAP command field and press Enter.
Perform Activities:
o Inform the user to perform the actions that are causing access issues, such
as trying to execute a transaction they cannot access.
Stop the Trace:
o Once the activities are completed, go back to the STAUTHTRACE screen,
and click "Deactivate Trace".
It displays the details about the authorization objects, field values, program
name and the return codes.
Note = > Click on System Wide Trace to view the trace for each application
server. Apply the necessary filters, then click on Execute.
PFUD
Mass User Comparison
For a single role we can do user comparison in PFCG -> User comparison
Tab.
4) Cleanups
It ensures that expired roles are removed from SU01, record of users.
Program related to PFUD = > PFCG_TIME_DEPENDENCY
SM01 = > Lock T code
EWZ5 = > Mass User Lock
SU10 = > SU12