What are the critical authorization objects in SAP? Is there an official list of which ones they are and how they should be managed?
In recent SAP releases, something has changed on this topic. Read on to find out what.
Several SAP authorization objects can be considered critical. In this context, we are specifically referring to those authorization objects that should only be assigned to system administrators — and under no circumstances to end users.
There is no official comprehensive list, other than what is referenced in SAP documentation or described in official SAP courses — in particular ADM940 and ADM950. From release SAP_BASIS 7.55 onwards (SAP Note 2986858 — Revision of transaction SU21), SAP completely redesigned transaction SU21, which is used to search and manage authorization objects.
As part of this revision, SAP introduced a dedicated attribute in the authorization object master data called "Criticality". This information can be found in table TOBJVORFLG, field FLAG3 = C.
The purpose of this attribute is not to directly flag an object as dangerous, but rather to prevent the authorization check from being deactivated (in relation to transactions SU22 and SU24) for any object marked as critical. This means SAP itself considers it critical. The same applies to all authorization objects in the Basis class (name pattern S_*) and HCM class (name pattern P_* and object PLOG).
In short: if an authorization object is considered critical, its check cannot be deactivated.
Did you know it is possible to deactivate the check for individual authorization objects at system level?
Several categories of authorization objects require particular attention. For each category below you will find: the relevant critical objects (note: this is not a complete list) and the risk associated with granting them without proper controls.
Remember that launch objects — S_TCODE, S_SERVICE, S_RFC, and S_START — are also considered critical. Always evaluate carefully before using a wildcard (*) in these authorization objects.
This is unquestionably the most critical object in the system: it allows bypassing any authorization check entirely.
Authorization object:
S_DEVELOP — ABAP WorkbenchWhat to do: This object must not be assigned to any user in the production system with operational activities.
These objects relate to the execution of SAP programs. Every transaction or app that is launched effectively calls an underlying program. The objects below specifically cover programs that can be executed through transactions SA38 and SE38.
Authorization objects:
S_PROGRAM — ABAP: Program Flow ChecksS_PROGNAM — Generic Program StartWhat to do: These must not be assigned with program group fields set to a wildcard (*).
For this family of authorization objects (S_TABU*), refer to the dedicated in-depth article: S_TABU_NAM and S_TABU_DIS in SAP.
Authorization objects:
S_TABU_CLI — Cross-Client Table MaintenanceS_TABU_DIS — Table Maintenance (using standard tools such as SM30)S_TABU_LIN — Authorization for Organizational UnitS_TABU_NAM — Table Access by Generic Standard ToolsS_TABU_RFC — Client Comparison and Copy: Data Export with RFCS_TABU_SQL — Authorization Object for SQL Command EditorWhat to do: These must not be assigned with table group/table name fields set to a wildcard (*).
Incorrect management of this authorization object can enable unauthorized data exfiltration from SAP. See our video on data exfiltration via SAP for a detailed explanation of the risk.
Authorization object:
S_RFC — Authorization Check for RFC AccessWhat to do: This must not be assigned with function group fields set to a wildcard (*).
For this topic, refer to the dedicated article: SAP Query Security.
Authorization object:
S_QUERY — SAP Query AuthorizationWhat to do: Refer to the SAP Query Security article for full guidance.
This group of objects covers background jobs — programs scheduled to run recursively to perform system tasks such as invoicing, report generation, and similar processes.
Authorization objects:
S_BTCH_ADM — Background Processing: Background AdministratorS_BTCH_API — Background Processing: Special Authorizations for APIS_BTCH_EXT — External SchedulerS_BTCH_JOB — Background Processing: Operations on Background JobsS_BTCH_NA1 — Batch Processing: User Name and ProgramS_BTCH_NAM — Background Processing: Background User NameS_BTCH_TMP — Background Processing: Operations on Job TemplatesWhat to do: Only users who genuinely need to manage background jobs should hold these objects. No end user should have them. The one exception is S_BTCH_JOB with value RELE, which may be granted to end users if they need to immediately release their own jobs without administrator intervention.
This authorization object enables system-level administrative actions. No end user has any operational need for it.
Authorization object:
S_ADMI_FCD — System AuthorizationsThe full list of values defined for this authorization object is provided below:
AMSM — Basis Schema MappingAUDA — Basis audit administrationAUDD — Basis audit display authorizationBTCH — Batch input test environmentCONV — Table conversion by release upgradeFONT — Maintenance of SAPscript font dataLANG — Language handling configurationMEMO — Allocation of SAP memory management (RSMEMORY)NADM — Network administration using transactions SM54, SM55, and SM58PADM — Process administration using transactions SM04, SM50RSET — Reset/delete data without archivingSCP1 — Settings for character sets, languagesSCP2 — Database character conversionSHMU — Shared Memory Monitor Update FunctionsSM21 — Analyze system logST22 — Cross-Client Dump AnalysisSP01 — Use of SP01 (All Users and Clients)SPOS — Use of Transaction SP01 (all systems)SP0R — Spool request management (all users)SPAD — Spool administration (all clients)SPAR — Client-specific spool administrationSPTD — TemSe administration (all clients)SPTR — Client-specific TemSe administrationSMON — Call system monitoring toolsST0M — Change trace switchesST0R — Analyze tracesSTAM — Display Single Record Statistics in Transaction STATSSTAU — Display User Name for External Single Record StatisticsSTUF — Change Filter of User Traces for Authorization ChecksSTUR — Evaluation of User Traces for Authorization ChecksSYNC — Reset buffers (buffer synchronization with $sync, $tab…)T000 — Create new clientTLCK — Lock/unlock transactionsTRNL — Translation administration (Transaction SLW2)TRNR — Translation administration SLWA/SLWBTCTR — System-wide table control settingsUADM — Update AdministrationUNIX — UNIX commandsCOLA — OLE administrationX25 — Open X.25 connection for SAPSPAA — Spool administration (device administration)SPAB — Spool administration (general settings)SPAC — Spool administration (device type, character sets)SPAM — Spool administration (cross-client job authorization)F4MX — Search help support by switching ActiveX on/offF4IS — Activate/deactivate proposal search system-wideTOUC — Execution of report TOUCHALLSM02 — System MessagesSLIC — SAPLICENSE: Transaction SLICENSELC01 — liveCache Administration (Display Functions)LC02 — liveCache Administration (Start, Stop)LC03 — liveCache Administration (Integration, Configuration)LC04 — liveCache Administration (Initialization)PRIN — Cross-User Maintenance of Default Print ValuesUBUF — Execute Report RSUSR405ICFR — ICF Recorder Authorization for Administration ConsoleICFA — ICF Administration Authorization (Transaction SICF)RFCA — RFC Administration Authorization (Transaction SM59)ICFS — ICF Authorization for PUBLIC Services (Transaction SICF)DBA — Authorization for Database AdministrationSMSS — MS SQL Server: Command WindowUMON — Administer Update Records (without Update System)UDSP — Display Update Requests and their DataQDEL — Authorization to delete a queue: RSTRFCQDS, RSTRFCIDSIGS — IGS Administration Authorization (Transaction SIGS)SFTP — SAP FTP AdministrationPOPU — TH_POPUPSQMA — Administration of SQL MonitorSQMD — Read SQL Monitor Statistical DataSCMA — Administration of ABAP Call MonitorSCMD — Read ABAP Call Monitor DataSCHD — Maintain Control Parameters for Change DocumentsSUM — Use Software Update Manager ToolsST13 — Use ST13 (BW Tools)UCCC — Cross-Client Functions for UCONHMAC — Security Audit Log — Generate HMACHMAD — Security Audit Log — Download HMACQADM — Queue Administration (SMQ1, SMQ2, SMQ3, BDA1)Contact us to find out how we have helped our clients manage these and other critical authorization objects in their SAP systems.