All topics
SECURITY_GRCbeginner

SU24

SU24 is the SAP transaction used to maintain authorization defaults (the USOBT/USOBX relationship between transactions and authorization objects) that drive what appears in the PFCG role authorization proposal. Getting SU24 right is foundational to least-privilege role design, controlling authorization object check behavior, and reducing audit findings caused by over-generous or missing authorization proposals across ECC and S/4HANA.

Overview

SU24 is the SAP transaction used to maintain authorization defaults (the USOBT/USOBX relationship between transactions and authorization objects) that drive what appears in the PFCG role authorization proposal. Getting SU24 right is foundational to least-privilege role design, controlling authorization object check behavior, and reducing audit findings caused by over-generous or missing authorization proposals across ECC and S/4HANA.

Lessons in this topic

Related topics