SAP transaction codeObjectSU01DModuleSECURITY_GRC

SU01D — Display User

SU01D is used to display an ABAP user master record, including user type, validity, roles, profiles and selected logon data without changing it. It is most useful when Security, Basis or support needs to verify user status and assignments safely before changing access. For reliable SAP support, capture the exact system, client, user, time and object context first, then use the transaction's evidence before making configuration or data changes.

Verified practitioner reference for SU01D — Display User. It explains what the transaction does, when it is appropriate, which parameters and evidence matter, how to use it safely, common diagnostic traps, and how its role changes or remains relevant in S/4HANA.

Published 19 Sept 2026· 637 words

Purpose

display an ABAP user master record, including user type, validity, roles, profiles and selected logon data without changing it. The transaction is most valuable when used as part of an evidence chain rather than as a shortcut. Start from the exact business or technical incident, preserve its user, time, system and object context, and distinguish display/analysis functions from actions that can alter system state.

When it is used

SU01D is typically used when Security, Basis or support needs to verify user status and assignments safely before changing access. Consultants also use it during project testing and post-change validation because a repeatable selection gives objective evidence. In production, keep the initial scope narrow and widen it only after confirming that the first result matches the reported incident.

How to use it in practice

  • Open the affected user and confirm you are in display-only mode.
  • Check lock and validity before investigating application authorization.
  • Review user type because dialog, system and communication users have different purposes.
  • Check role/profile assignments and validity.
  • Use SU53/STAUTHTRACE for failed business authorization rather than inferring access from role names alone.

Key data objects

These are the most useful anchors for work in SU01D. Capture them in incident notes or test evidence so another consultant can reproduce the same result.

  • user ID — verify the exact value and its relationship to the affected execution or business object.
  • user type — verify the exact value and its relationship to the affected execution or business object.
  • validity and lock status — verify the exact value and its relationship to the affected execution or business object.
  • roles/profiles — verify the exact value and its relationship to the affected execution or business object.
  • defaults/parameters — verify the exact value and its relationship to the affected execution or business object.

How to prove it in the data

Build a reproducible before-and-after proof. Capture the exact selection or object, record the status, log or result that demonstrates the issue, then apply one controlled correction and repeat the same check. Correlate with neighboring SAP logs, documents or repository objects where needed. A successful retry with changed input is not the same as proving the original root cause.

ECC vs S/4HANA

SU01D remains a safe display transaction in current ABAP user administration. Availability of a classic transaction does not automatically make it the preferred implementation pattern for new work; distinguish support compatibility from clean-core and cloud-oriented design guidance.

Common pitfalls and how to diagnose them

  • Assuming a role assignment proves every authorization value is present. Validate the exact object, user, timestamp and release context before applying a fix.
  • Ignoring expired role assignments or user validity. Validate the exact object, user, timestamp and release context before applying a fix.
  • Using a technical user interactively to reproduce an authorization issue. Validate the exact object, user, timestamp and release context before applying a fix.

Whose problem this is

Primary ownership is usually with the SECURITY GRC team. Bring in Basis, Security, functional or development specialists only when the evidence crosses those boundaries. A high-quality escalation includes the exact transaction, selection or object, timestamp, expected result, actual result and checks already completed.

Related SAP objects

Reviewed pages this object connects to in the ERPClimb knowledge graph.

Source: ERPClimb — https://erpclimb.com/sap-tcodes/su01dERPClimb is an independent platform and is not affiliated with SAP SE. Reference pages are written and reviewed by SAP consultants for learning and troubleshooting.