adManus

Newsletter February 2009

How to save the assignment of authorizations in SAP Portal

Implementing the applications ESS and MSS in Enterprise Portal (EP) increases the maintenance effort for authorization administrators. They have in a new environment not only to maintain correspondent user names but also assign special Portal roles to them. Now, get to know how you can save the assignment of roles to portal users.

The SAP User Management Engine (UME) administrates the users in EP. During the dual stack installation of the AS Java define that the dual stack UME uses the user data of the AS ABAP dual stack (that is the SAP basis, where the user administration of ABAP area is implemented). Now all users maintained in the ABAP stack you not need to create once again in the Portal (JAVA-Stack), because they are automatically known there – their data base is ABAP (see figure 1). Now, every portal needs portal authorization. This is the assignment you can save, if you know the following rules:

  1. You can Portal Roles not only assign to users but also to groups.
  2. The system automatically assigns every role of the backend as a group to the user in the portal (see figures 1 and 2).

Knowing this, you would now assign the portal role to a group, which has the exact same name as the role in the backend (see figure 3). So because of the automatic group assignment the portal role is automatically assigned, too. Your advantage: you don’t have to maintain this on every single user manually – provided that the UME uses the ABAP stack.

I give you an example of an ESS user:

  • You have assigned the user to the role „Backend-ESS“ in the ABAP area.
  • You have assigned the role „Portal-ESS“ to the group „Backend-ESS“ in EP.
  • Now the user is automatically assigned with the portal group „Backend-ESS“ in the portal and automatically receives the portal authorization „Portal-ESS“.

The system automatically assigned the Group SAP_J2EE_ADMIN to the User IPROCON
Fig. 1: The system automatically assigned the Group SAP_J2EE_ADMIN to the User IPROCON

In Backend there the Role SAP_J2EE_ADMIN is assigned user IPROCON
Fig. 2: In Backend there the Role SAP_J2EE_ADMIN is assigned user IPROCON

Assignment of Portal Role to the Group SAP_J2EE_ADMIN Fig. 3: Assignment of Portal Role to the Group SAP_J2EE_ADMIN


06.02.2009
Anja Junold, iProCon GmbH
(Please contact me, if you need help with this.)

Back to Newsletter 02/2009

adManus