AGLEA Blog

SAP Critical Authorization Objects

Written by Massimo Manara | Sep 23, 2026, 6:15:01 AM

What are the critical authorization objects in SAP? Is there an official list of which ones they are and how they should be managed?

In recent SAP releases, something has changed on this topic. Read on to find out what.

SAP Authorization Objects: What Makes One "Critical"?

Several SAP authorization objects can be considered critical. In this context, we are specifically referring to those authorization objects that should only be assigned to system administrators — and under no circumstances to end users.

 

There is no official comprehensive list, other than what is referenced in SAP documentation or described in official SAP courses — in particular ADM940 and ADM950. From release SAP_BASIS 7.55 onwards (SAP Note 2986858 — Revision of transaction SU21), SAP completely redesigned transaction SU21, which is used to search and manage authorization objects.

 

As part of this revision, SAP introduced a dedicated attribute in the authorization object master data called "Criticality". This information can be found in table TOBJVORFLG, field FLAG3 = C.

The purpose of this attribute is not to directly flag an object as dangerous, but rather to prevent the authorization check from being deactivated (in relation to transactions SU22 and SU24) for any object marked as critical. This means SAP itself considers it critical. The same applies to all authorization objects in the Basis class (name pattern S_*) and HCM class (name pattern P_* and object PLOG).

 

In short: if an authorization object is considered critical, its check cannot be deactivated.

 

Did you know it is possible to deactivate the check for individual authorization objects at system level?

 

The Main Critical SAP Authorization Objects

Several categories of authorization objects require particular attention. For each category below you will find: the relevant critical objects (note: this is not a complete list) and the risk associated with granting them without proper controls.

 

Remember that launch objects — S_TCODE, S_SERVICE, S_RFC, and S_START — are also considered critical. Always evaluate carefully before using a wildcard (*) in these authorization objects.

 

ABAP Development in SAP

This is unquestionably the most critical object in the system: it allows bypassing any authorization check entirely.

Authorization object:

  • S_DEVELOP — ABAP Workbench

What to do: This object must not be assigned to any user in the production system with operational activities.

 

Program Execution

These objects relate to the execution of SAP programs. Every transaction or app that is launched effectively calls an underlying program. The objects below specifically cover programs that can be executed through transactions SA38 and SE38.

Authorization objects:

  • S_PROGRAM — ABAP: Program Flow Checks
  • S_PROGNAM — Generic Program Start

What to do: These must not be assigned with program group fields set to a wildcard (*).

 

Table Data Access and Modification

For this family of authorization objects (S_TABU*), refer to the dedicated in-depth article: S_TABU_NAM and S_TABU_DIS in SAP.

Authorization objects:

  • S_TABU_CLI — Cross-Client Table Maintenance
  • S_TABU_DIS — Table Maintenance (using standard tools such as SM30)
  • S_TABU_LIN — Authorization for Organizational Unit
  • S_TABU_NAM — Table Access by Generic Standard Tools
  • S_TABU_RFC — Client Comparison and Copy: Data Export with RFC
  • S_TABU_SQL — Authorization Object for SQL Command Editor

What to do: These must not be assigned with table group/table name fields set to a wildcard (*).

 

External RFC Calls

Incorrect management of this authorization object can enable unauthorized data exfiltration from SAP. See our video on data exfiltration via SAP for a detailed explanation of the risk.

Authorization object:

  • S_RFC — Authorization Check for RFC Access

What to do: This must not be assigned with function group fields set to a wildcard (*).

 

Query Management

For this topic, refer to the dedicated article: SAP Query Security.

Authorization object:

  • S_QUERY — SAP Query Authorization

What to do: Refer to the SAP Query Security article for full guidance.

 

Background Job Management

This group of objects covers background jobs — programs scheduled to run recursively to perform system tasks such as invoicing, report generation, and similar processes.

Authorization objects:

  • S_BTCH_ADM — Background Processing: Background Administrator
  • S_BTCH_API — Background Processing: Special Authorizations for API
  • S_BTCH_EXT — External Scheduler
  • S_BTCH_JOB — Background Processing: Operations on Background Jobs
  • S_BTCH_NA1 — Batch Processing: User Name and Program
  • S_BTCH_NAM — Background Processing: Background User Name
  • S_BTCH_TMP — Background Processing: Operations on Job Templates

What to do: Only users who genuinely need to manage background jobs should hold these objects. No end user should have them. The one exception is S_BTCH_JOB with value RELE, which may be granted to end users if they need to immediately release their own jobs without administrator intervention.

 

System Administrator Functions

This authorization object enables system-level administrative actions. No end user has any operational need for it.

Authorization object:

  • S_ADMI_FCD — System Authorizations

The full list of values defined for this authorization object is provided below:

  • AMSM — Basis Schema Mapping
  • AUDA — Basis audit administration
  • AUDD — Basis audit display authorization
  • BTCH — Batch input test environment
  • CONV — Table conversion by release upgrade
  • FONT — Maintenance of SAPscript font data
  • LANG — Language handling configuration
  • MEMO — Allocation of SAP memory management (RSMEMORY)
  • NADM — Network administration using transactions SM54, SM55, and SM58
  • PADM — Process administration using transactions SM04, SM50
  • RSET — Reset/delete data without archiving
  • SCP1 — Settings for character sets, languages
  • SCP2 — Database character conversion
  • SHMU — Shared Memory Monitor Update Functions
  • SM21 — Analyze system log
  • ST22 — Cross-Client Dump Analysis
  • SP01 — Use of SP01 (All Users and Clients)
  • SPOS — Use of Transaction SP01 (all systems)
  • SP0R — Spool request management (all users)
  • SPAD — Spool administration (all clients)
  • SPAR — Client-specific spool administration
  • SPTD — TemSe administration (all clients)
  • SPTR — Client-specific TemSe administration
  • SMON — Call system monitoring tools
  • ST0M — Change trace switches
  • ST0R — Analyze traces
  • STAM — Display Single Record Statistics in Transaction STATS
  • STAU — Display User Name for External Single Record Statistics
  • STUF — Change Filter of User Traces for Authorization Checks
  • STUR — Evaluation of User Traces for Authorization Checks
  • SYNC — Reset buffers (buffer synchronization with $sync, $tab…)
  • T000 — Create new client
  • TLCK — Lock/unlock transactions
  • TRNL — Translation administration (Transaction SLW2)
  • TRNR — Translation administration SLWA/SLWB
  • TCTR — System-wide table control settings
  • UADM — Update Administration
  • UNIX — UNIX commands
  • COLA — OLE administration
  • X25 — Open X.25 connection for SAP
  • SPAA — Spool administration (device administration)
  • SPAB — Spool administration (general settings)
  • SPAC — Spool administration (device type, character sets)
  • SPAM — Spool administration (cross-client job authorization)
  • F4MX — Search help support by switching ActiveX on/off
  • F4IS — Activate/deactivate proposal search system-wide
  • TOUC — Execution of report TOUCHALL
  • SM02 — System Messages
  • SLIC — SAPLICENSE: Transaction SLICENSE
  • LC01 — liveCache Administration (Display Functions)
  • LC02 — liveCache Administration (Start, Stop)
  • LC03 — liveCache Administration (Integration, Configuration)
  • LC04 — liveCache Administration (Initialization)
  • PRIN — Cross-User Maintenance of Default Print Values
  • UBUF — Execute Report RSUSR405
  • ICFR — ICF Recorder Authorization for Administration Console
  • ICFA — ICF Administration Authorization (Transaction SICF)
  • RFCA — RFC Administration Authorization (Transaction SM59)
  • ICFS — ICF Authorization for PUBLIC Services (Transaction SICF)
  • DBA — Authorization for Database Administration
  • SMSS — MS SQL Server: Command Window
  • UMON — Administer Update Records (without Update System)
  • UDSP — Display Update Requests and their Data
  • QDEL — Authorization to delete a queue: RSTRFCQDS, RSTRFCIDS
  • IGS — IGS Administration Authorization (Transaction SIGS)
  • SFTP — SAP FTP Administration
  • POPU — TH_POPUP
  • SQMA — Administration of SQL Monitor
  • SQMD — Read SQL Monitor Statistical Data
  • SCMA — Administration of ABAP Call Monitor
  • SCMD — Read ABAP Call Monitor Data
  • SCHD — Maintain Control Parameters for Change Documents
  • SUM — Use Software Update Manager Tools
  • ST13 — Use ST13 (BW Tools)
  • UCCC — Cross-Client Functions for UCON
  • HMAC — Security Audit Log — Generate HMAC
  • HMAD — Security Audit Log — Download HMAC
  • QADM — Queue Administration (SMQ1, SMQ2, SMQ3, BDA1)

Contact us to find out how we have helped our clients manage these and other critical authorization objects in their SAP systems.