SAP Security Authorization Interview Questions

Hi All,

Here I am going to share some important interview questions in SAP Security & Authorizations.

SU25:-

1) How will you Initialize the SAP Security in your organization ?
2) What are the steps we have in SU25?
3) What is the purpose of SU25 in SAP Security?
4) What is  the relationship between USOBT ,USOBX tables And USOBT_C , USOBX_C Tables in SAP Security?
5) Why Should we  perform Initially fill the customer tables in SU25?


SU01:-

1) What are the types of users  in SAP System
2) In which scenario we will use these users and with Example for types of users?
3) What is the use of User group field under Logondata Tab?
4) Difference between Log on data user group and User group in SU01?
5) What is  the  use  of Parameters tab & Personalization tab?
6) What is the validity period  for your end users?
7)Authorization checks for the USER?
8) How will you delete the user?
9) How to Reset the password for the Mass users at a time?
8) How to lock/unlock the Mass users at a time in sap security?
**9) In which scenario you will go for Reference type user?
10)What is the purpose of Defaults tab?
11)Where we can add Reference type user id
12)How many  Max no.of profiles you can be Assigning for a particular user in SAP?
13)What is length of the User Buffer in SAP System?
**14)What are the mandatory fields to create user in SAP System?
15) What is the difference between Communication & System type Users in SAP?
16)What is the use of Licensing data Tab in SU01?
17)How will you  get URF in your organization?
18) How can you change Existing User id?

SU10,LSMW & SECATT SCRIPTING :-

1)How will you create 1000 users at a time in SAP system?
2)Explain LSMW Process? 
3)What is the difference between su10 and su01 ?
4)what is URF? 
5)When will you get creation of Mass users at a time in SAP system? 
6)In which scenario you will get Mass password reset for users in SAP?
7)Have you created  Mass Users using SECATT? If yes, tell me the  process?
8) While creating Mass users in SECATT what are the changes you need to do in SAP System?
9)What are the Advantages of creating Mass Users  using Scripts other than SU10?
10)What are the Advantages & Disadvantages of SU10?
11)How you Share System generated password for particular user?

User Related Tables (SE16):-
USR* tables

1)What is USR02?
2)Where you can  find the user lock status at table level and under which field ?
3)In which table we can find user license data at table level?
4)In  which table we can incorrect logon attempts for the user?
5)In which table you can find user buffer size?

6)Where can we find Alias name for the user at table level?
7)Where can we find user login sessions?
8)What is MODDA,MODBE,MODT fields and under which table we can find these fields?
9)Where can we find last missing Authorizations for the user at Table level?
10)Where you can find Email address of the user?


PFCG :-

1)Have you worked on profile generetor?
2)Have you worked on roles creation?how roles you created?
3)How will you  create roles in your organazition?naming convention in your organization?
4)Why derived roles?
5)Can we add composite roles to composite role?if no then why?
6)How many profiles we can add to a single user?
7)What is difference between profile and role?
8)Can we assign profiles directly to the users?If yes,How many profiles we assign to a single user?
9)What is auth.object?
10)Why should we generate a profile?
11)Which type of roles your organization is following?
12)What is the relation ship between PFCG and SU24
13)How will you make changes in derived roles?
14)Have you worked on Expert mode?
15)what  are the types of statuses you know in profile generetaor?
16)what are  the traffic signal you know in PFCG?what does it means?
17)Have you worked on SU22 Tcode?
18) What is the relation ship between SU22and PFCG?
19)Have you created Custom Authorization objects?

20)What are the system login parameters you will use as a administrator?

21)How will you find out the User Access related issues?
22)How to convert fields to organization values?
23)How to delete a role?
24)how to transport a role from Development to Production system?
25)How will you delete roles from the Production systems?
26)Why do single roles sometimes has more profile?
27) How will you delete all expired role assignments to multiple user ?
28)How to assign a single role to multiple users?
29)How will you delete multiple roles from SAP System at a time?
30)How to  give access for the Tables?


31) How will you restrict the reports?
32)How to Extract users list like who didn't login since 3 months?
33)What are the Authorization checks for a Dialogue user?
34)How to check weather user has locked or unlocked in SAP System? 
35)Can we assign generated profiles directly to the users?If i assign what will happen?
36)Internally what will happen when user will execute a Tcode in SAP System?
37)What the differnce between Short and Long description in PFCG screen?
38)What is the use of Read menues TAB in PFCG?


30 comments:

  1. boss your questions are very helpfull..can u provide real time answers

    ReplyDelete
  2. ya u r right ,these questions are really helpful .thanku for ur help ..
    could you please provide answers for those qusts

    ReplyDelete
  3. USOBT and USOBX are tables that hold the default values and authorisation objects in SAP

    USOBT_C , USOBX_C This two tables are customer specify tables whenever you modify any authorization object that data will be updated in this two tables

    ReplyDelete
  4. What are the types of users in SAP System?

    Dialog Individual, interactive system access.
    System Background processing and communication within a system (such as RFC users for ALE, Workflow, TMS, and CUA).
    Communication Dialog-free communication for external RFC calls.
    Service Dialog user available to a larger, anonymous group of users.
    Reference General, non-person related users that allows the assignment of additional identical authorizations, such as for Internet users created with transaction SU01. No logon is possible

    ReplyDelete
  5. What is the use of User group field under Logondata Tab?

    By using User group field under Logondata Tab we can allocate user group
    to number of users at a time, this is for find the list of
    users of a particular user group but we cannot restrict any
    user to any region or any location.

    ReplyDelete
  6. Difference between Log on data user group and User group in SU01?

    In Logon data group you can map one user with
    only one group.But in groups you can map one user with
    multiple group.

    ReplyDelete
  7. How to Reset the password for the Mass users at a time?

    By using SECAT,LSMW script

    ReplyDelete
  8. How to lock/unlock the Mass users at a time in sap security?

    By using SU10 we can do mass lock/unlock the users.

    ReplyDelete
  9. In which scenario you will go for Reference type user?

    To delegate the responsibility from one person to other person

    ReplyDelete
  10. Where we can add Reference type user id?

    Goto PFGC select the role for which you want to add the Reference user and select change mode and goto roles tab there you can find Reference user for additional rights then assign the Reference user in that option.

    ReplyDelete
    Replies
    1. Reference user for additional rights option available in SU01 not in PFCG.
      Generally, If the user already have access to 312 profiles but user need additional access then we can give the additional access through the reference user

      Delete
    2. Reference user for additional rights option available in SU01 not in PFCG.
      If user already having access to 312 profiles and user need additional access then we can assign the additional access through the reference user.

      Delete
    3. thank you Saraswathy for correcting me with the answer

      Delete
    4. Hiiii can we add reference user in SUIM

      Delete
  11. How will you delete all expired role assignments to multiple user ?

    we need to run a report PRGN_COMPRESS_TIMES

    ReplyDelete
  12. Q)What is the use of Parameters tab & Personalization tab?
    Q)To find a list of roles which contain only S_tcode object but (SUIM,ROLES BY COMPLEX SELECTION CRITERIA) will give list of roles which contain other objects also apart from s_tcode?
    can u please tell me answers for above questions

    ReplyDelete
  13. what is difference between USOBT_C and USOBX_C tables?

    ReplyDelete
    Replies
    1. USOBT and USOBX are tables that hold the default values and authorisation objects in SAP

      USOBT_C , USOBX_C This two tables are customer specify tables whenever you modify any authorization object that data will be updated in this two tables

      Delete
  14. Answers please

    ReplyDelete
  15. some of the questions, i havn't found answers, could you please update the answers for the questions,
    thankyou

    ReplyDelete
  16. All latest and updated SAP certification dumps in PDF format is available with us, contact us at completeexamcollection@gmail.com. Refer our blog for more details http://completeexamcollection.blogspot.in

    ReplyDelete
  17. Thanks for the great information in your blog SAP HR Training in Chennai

    ReplyDelete
  18. HI ,

    Can i get answers for all the questions

    ReplyDelete
  19. When user asks for additional access, as a security consultant, on what basis do you select a role for particular user? And How do you decide that user is actually authorised to have that particular role.

    ReplyDelete
  20. questions were really helpful . . can u pls provide answers for those questions ..

    ReplyDelete
  21. Fabulous..!! Thank you.The information you provided is much useful information on sap video trainings.

    ReplyDelete
  22. I am glad that I saw this post. It is informative blog for us and we need this type of blog thanks for share this blog, Keep posting such instructional blogs and I am looking forward for your future posts.
    Cyber Security Projects for CSE

    JavaScript Training in Chennai

    Project Centers in Chennai for CSE

    JavaScript Training in Chennai


    ReplyDelete
    Replies
    1. What is the answer for this How will you Initialize the SAP Security in your organization ?

      Delete
  23. Thank you. It is such a wonderful post. it has great information it is very useful for sap s4 hana server access in hyderabad.

    ReplyDelete