You are on page 1of 7

Authorizations required for fiori developer: -

For accessing FLP and deploying normal apps.

SAP_UI2_ADMIN

SAP_UI2_USER

For accessing FACT SHEET Apps, I need to be assigned these roles.

SAP_ESH_ADMIN

SAP_ESH_DISPLAY_QUERY_LOG

SAP_ESH_REORG_QUERY_LOG

For accessing Analytical Apps, I need to be assigned these roles.

SAP_BR_ANALYTICS_SPECIALIST

Prerequisite Roles for KPI Modeler:

 You have installed the SAP Smart Business modeler apps on the front-end server and on the
SAP HANA server.
 Your front-end user is assigned the PFCG role /UI2/SAP_KPIMOD_TCR_S.
 Your SAP HANA user is assigned the roles

sap.hba.r.sb.core.roles::SAP_SMART_BUSINESS_MODELER and

sap.hba.r.sb.core.roles::SAP_SMART_BUSINESS_RUNTIME.

Open Security folder -> User -> AdminUser. Click on granted roles and assign the
following roles:
o sap.hba.r.sb. core.roles::SAP_SMART_BUSINESS_MODELER
o sap.hba.r.sb.core.roles::SAP_SMART_BUSINESS_RUNTIME
o sap.hba.apps.kpi.s.roles::SAP_SMART_BUSINESS_ MODELER
o sap.hba.apps.kpi.s.roles::SAP_SMART_BUSINESS_RUNTIME
o KPI_SPECIFIC_HANA_ROLE (You can find the role from FIORI Apps library)

Open EndUser. Click on granted roles and assign the following roles:
o sap.hba.r.sb.core.roles::SAP_SMART_BUSINESS_RUNTIME
o sap.hba.apps.kpi.s.roles::SAP_SMART_BUSINESS_RUNTIME
o KPI_SPECIFIC_HANA_ROLE (You can find the role from FIORI Apps library)

Now login to Gateway server from SAP GUI and execute transaction SU01.
Enter “AdminUser” and click on edit, navigate to roles tab and assign the following roles:
o /UI2/ SAP_KPIFRW5_TCR_S
o /UI2/SAP_KPIMOD_TCR_S (For KPI Modeler)
o KPI_SPECIFIC_PFCG_ROLE(You can find the role from FIORI Apps
library)
Launch SAP FIORI Launchpad with AdminUser

 Now for the “EndUser” go to su01 transaction in your gateway server and assign
the following roles
o /UI2/ SAP_KPIFRW5_TCR_S
o KPI_SPECIFIC_PFCG_ROLE(You can find the role from FIORI Apps library)

Security team has to assign these roles to Fiori developer, then he will get all the above tiles in his
Launchpad to configure KPI Modeler related tasks.

For smart business you will also need to activate


/sap/opu/odata/SSB/SMART_BUSINESS_DESIGNTIME_SRV
/sap/opu/odata/SSB/SMART_BUSINESS_RUNTIME_SRV

Fiori Developer accessing T-Codes:-

/IWFND/MAINT_SERVICE -- Activate and Maintain Services

/IWFND/GW_CLIENT -- SAP Gateway Client

/IWFND/ERROR_LOG -- SAP Gateway Error Log

/IWBEP/ERROR_LOG -- SAP Backend Error Log

/IWFND/CACHE_CLEANUP -- Cache of GW Model Cache

/IWBEP/CACHE_CLEANUP -- Cleanup of GW Backend Model Cache

/UI2/FLC -- Fiori Launchpad Checks

/UI2/FLP -- Fiori Launchpad

/UI2/FLPD_CUST -- SAP Fiori Launchpad Designer (Current Client)

/UI2/FLPD_CONF -- SAP Fiori Launchpad Designer (Cross-Client)

ESH_COCKPIT -- SAP NetWeaver Enterprise Search


/UI2/SEMOBJ -- Define Semantic Object

/UI2/GW_SYS_ALIAS -- Manage Sap System Aliases

SWFVISU -- Task Visualization

SICF -- Define Services

SMICM -- Icm Monitor

SM59 -- Configuration of RFC

PFCG -- Role Creation

SM59 -- Configuration of RFC Connections

SE10 -- Transport Creation

SE38 -- ABAP Editor

SE80 -- Object Navigator

SEGW -- Session gateway

SE37 -- Function Modules

SE11 -- ABAP Dictionary

ST22 -- ABAP Runtime Errors

PFTC -- Task : Maintain

SWETYPV -- Event Type Linkages

SWIA -- Process Worktime

SWDD -- Workflow Builder

Authorizations required for fiori developer: -

For accessing FLP and deploying normal apps.

SAP_UI2_ADMIN

SAP_UI2_USER

For accessing FACT SHEET Apps, I need to be assigned these roles.

SAP_ESH_ADMIN

SAP_ESH_DISPLAY_QUERY_LOG

SAP_ESH_REORG_QUERY_LOG

For accessing Analytical Apps, I need to be assigned these roles.


SAP_BR_ANALYTICS_SPECIALIST

Roles And Auth for Gateway.


If the users you require already exist in your SAP Business Suite backend system, you can replicate
these users in the SAP Gateway system by connecting the SAP Gatewaysystem to Central User
Administration or to SAP Identity Management and synchronize the users.

End users

Templates follow the naming convention /IW<component>/RT_USER_<application name>

SAP Gateway Developer Role

Create a developer role based on the available templates for all users that are to carry out
development tasks such as creating services. Use the developer role /IWBEP/RT_MGW_DSP for
accessing a remote system from the Service Builder (transaction SEGW) at design time.

The following templates are available for developers:

Template Type Template Name Template for

Framework /IWFND/RT_BOR_DEV SAP Gateway BOR Developer

Framework /IWFND/RT_DEVELOPER SAP Gateway Developer

OData Channel /IWBEP/RT_MGW_DEV OData Channel Developer

SAP Gateway Administrator Role

Template Type Template Name Template for

Framework /IWFND/RT_ADMIN SAP Gateway Framework Administrator


Template Type Template Name Template for

OData Channel /IWBEP/RT_MGW_ADM OData Channel Administrator

Business Enablement IWBEP/RT_BEP_ADM Business Enablement Provisioning


Provisioning Administrator

Workflow /IWWRK/RT_WF_ADM SAP Gateway Workflow Administrator

SAP Gateway User Role:


If you use Web service based scenarios, copy
the SAP_BC_WEBSERVICE_CONSUMER role to a customer role for end users. Then
assign this customer role to your end users.

Template Type Template Name Template for

Framework /IWFND/RT_GW_USER SAP Gateway User

Framework /IWFND/RT_TU_NOTIF SAP Gateway Technical User for


Notifications

OData Channel /IWBEP/RT_MGW_USR OData Channel User

OData Channel /IWHDB/RT_USER OData Channel HANA Integration User

OData Channel /IWBEP/RT_SUB_USR On-behalf Subscription User

Business Enablement /IWBEP/RT_BEP_USR Business Enablement Provisioning User


Provisioning

Workflow /IWWRK/RT_WF_GW_USR SAP Gateway Workflow User

Workflow /IWWRK/RT_WF_SUB_USR On-Behalf Subscription for SAP


Template Type Template Name Template for

Gateway Workflow Services

SAP NetWeaver Support User Role

The following templates are available for developers:

Template TypeTemplate Name Template for

sSupport /IWFND/GW_SUPPORT_RO Read-only supportability role for SAP Gateway system

Support /IWBEP/GW_SUPPORT_RO Read-only supportability role for SAP Business Suite


backend system

S_ICF_ADM - Without this authorization, a user would not be able to deploy a UI5 application
to the Gateway.

Fiori Developer accessing T-Codes:-

/IWFND/MAINT_SERVICE -- Activate and Maintain Services

/IWFND/GW_CLIENT -- SAP Gateway Client

/IWFND/ERROR_LOG -- SAP Gateway Error Log

/IWBEP/ERROR_LOG -- SAP Backend Error Log

/IWFND/CACHE_CLEANUP -- Cache of GW Model Cache

/IWBEP/CACHE_CLEANUP -- Cleanup of GW Backend Model Cache

/UI2/FLC -- Fiori Launchpad Checks

/UI2/FLP -- Fiori Launchpad

/UI2/FLPD_CUST -- SAP Fiori Launchpad Designer (Current Client)

/UI2/FLPD_CONF -- SAP Fiori Launchpad Designer (Cross-Client)

ESH_COCKPIT -- SAP NetWeaver Enterprise Search

/UI2/SEMOBJ -- Define Semantic Object


/UI2/GW_SYS_ALIAS -- Manage Sap System Aliases

SWFVISU -- Task Visualization

SICF -- Define Services

SMICM -- Icm Monitor

SM59 -- Configuration of RFC

PFCG -- Role Creation

SM59 -- Configuration of RFC Connections

SE10 -- Transport Creation

SE38 -- ABAP Editor

SE80 -- Object Navigator

SEGW -- Session gateway

SE37 -- Function Modules

SE11 -- ABAP Dictionary

ST22 -- ABAP Runtime Errors

PFTC -- Task : Maintain

SWETYPV -- Event Type Linkages

SWIA -- Process Worktime

SWDD -- Workflow Builder

You might also like