SAP transaction codeObjectSU01ModuleSECURITY_GRC

SU01 — User Master Maintenance

SU01 creates and maintains individual user master records: logon data, validity period, user type, roles and profiles, parameters, and address data. It is the single-user counterpart to SU10's mass maintenance. Most confusion around it comes from the gap between assigning a role on the Roles tab and that assignment actually becoming effective in the authorization buffer.

This page covers what SU01 writes when a user record is saved, the practical sequence for creating or fixing a user, and the diagnostic categories behind the most common complaints: locked accounts, roles that do not seem to work, and password or user-type mismatches. It also separates what belongs to security administration from what belongs to Basis.

Reviewed by an ERPClimb SAP consultant on 15 Sept 2026· 1,149 words

Esta página ainda não está disponível em português.

Purpose

SU01 is the single-user maintenance transaction for the user master record. It covers logon data (password, validity dates, user type), roles and profiles, parameters, defaults, and personal address data, all stored across several linked tables rather than one flat record. The structural fact that explains most confusion: a role assignment made here is not the same event as authorization becoming active. Assigning a role writes an entry with its own validity window; the actual authorization values only take effect once the role has been generated with the correct organizational levels and the user's buffer has picked up the change. A user record can look perfectly configured on the Roles tab and still fail every authorization check because generation or comparison never ran.

When it is used

SU01 is reached for one-off requests: onboarding a single new hire, fixing a locked account, correcting a validity date, changing a user type, or checking exactly which roles and profiles a specific person carries right now. For bulk work — resetting passwords for a department, extending validity for a batch of contractors, assigning the same role to fifty users — SU10 is the correct tool; using SU01 repeatedly for that is a sign the wrong transaction was chosen. In S/4HANA landscapes with identity management or a cloud IAS/IPS setup, provisioning may originate outside SAP entirely, with SU01 reduced to a read-only verification step to confirm what actually landed in the system after the upstream process ran.

How to use it in practice

  • Enter the user ID; choose Create, Change, or Display, and Copy from an existing template user when onboarding to inherit roles and defaults quickly.
  • On the Address tab, maintain name, department, and email; this feeds workflow notifications and the central address tables.
  • On the Logon Data tab, set user type (dialog, system, communication, service, reference) and initial password if not using SSO.
  • Set validity dates on the same tab or on Roles/Profiles individually; an expired validity here silently disables access without a lock flag.
  • On the Roles tab, assign roles; note the validity column defaults to open-ended unless overridden.
  • Save, then confirm the role shows a green traffic light, not yellow (pending generation) or red (missing authorization data).

Key data objects

  • USR02 - core logon data: password hash, user type, validity from/to, lock status flags.
  • USR21 - links the user ID to the person and address number used by the central address tables.
  • ADRP - person-level address data (name, title) referenced via USR21.
  • ADR6 - email address records tied to the same person/address key.
  • AGR_USERS - assignment of roles to users, including the validity window for each assignment.
  • USH02 - change history log for user master records, useful for reconstructing who locked, unlocked, or reassigned a user and when.

How to prove it in the data

To confirm a lock or validity issue, pull USR02 by BNAME and check the lock indicator fields and the validity date range against today's date. To confirm a role assignment problem, pull AGR_USERS filtered on the user ID and compare the validity dates and the role name against what SU01's Roles tab displays; a role present in the table with an expired end date will still show on screen but will not authorize. Cross-check USH02 for the same user ID to see the sequence of changes, which quickly separates 'never assigned correctly' from 'assigned correctly, then someone changed it'.

ECC vs S/4HANA

SU01 exists unchanged in S/4HANA and remains the primary transaction for single-user maintenance in on-premise and private cloud systems. A Fiori app for user maintenance exists as a lighter alternative for simple changes, but SU01 is still the fuller tool for validity windows, parameters, and detailed role review. In public cloud or IAS/IPS-integrated landscapes, user creation and role assignment may originate outside the ABAP stack, with SU01 used mainly to verify the result rather than to originate the change.

Common pitfalls and how to diagnose them

  • Account locked but reason unclear: distinguish an administrator lock, a failed-logon lock (too many wrong password attempts), and a global system lock set through a profile parameter. SU01 shows the lock type on the Logon Data tab; only the failed-logon lock can usually be cleared by the user's own security team, the other two need a parameter check or explicit unlock decision.
  • Role assigned but authorization missing: check the validity dates on the Roles tab first, then check whether the role's traffic light is yellow, meaning the profile has not been generated with current values, before assuming the role itself is wrong. A yellow or red light means the fix is in PFCG, not SU01.
  • User can log on but gets no data: often a user comparison was never run after a role's organizational values changed, so the buffer still holds the old profile. Re-running the comparison and forcing a buffer refresh resolves this without touching the role assignment.
  • Password reset does not work as expected: confirm the user type is dialog; system, service, and communication users behave differently around password rules and expiration, and resetting a password on a service user often has no visible effect if SSO or a certificate is the actual logon path.
  • Change made in SU01 does not stick: check whether the landscape uses upstream identity provisioning that overwrites local changes on its next sync cycle, which looks identical to a save that silently failed.

Whose problem this is

This is security administration territory, not functional or ABAP. A functional consultant requests access through the standard access-request process rather than editing SU01 directly. A clean handover to security includes the user ID, the exact symptom (locked, missing authorization, wrong roles), the role name and org values expected, and whether the issue reproduces after a fresh logon; escalate to Basis only when the cause traces to a system-wide lock parameter or SSO/certificate configuration.

Related SAP objects

Reviewed pages this object connects to in the ERPClimb knowledge graph.

Source: ERPClimb — https://erpclimb.com/sap-tcodes/su01ERPClimb is an independent platform and is not affiliated with SAP SE. Reference pages are written and reviewed by SAP consultants for learning and troubleshooting.