cancel
Showing results for 
Search instead for 
Did you mean: 

TDMS user authorization clarification

jonlarruzea
Explorer
0 Kudos

Hi,

We just configured TDMS 3.0 in our Solman (control system) over our HCM systems (sender and receiver). The user concept is not clear for us even after reading the TDMS 3.0 Security Guide.

As we understand there are 2 main configurations regarding the user logon from the control system to the sender/receiver systems (in our case HCM):

- The user to be specified in the RFC destination

- The technical switch "SND_LOGON"

When we execute the activities in TDMS more or less the process is:

- The user logs on in the control system (our Solman).

- It executes several tasks associated to the TDMS package... One of the tasks ("Transfer Selection Criteria") I guess that must be executed with a dialog user in the sender system (HCM) so that the user selects the data to be transfered. In order the system to ask for a manual logon I guess that "SND_LOGON" technical swith must be activated with the value "X".

- Other tasks ("Data transfer" etc) are executed in batch with the communication user specified in the RFC (no dialog user is necessary).

Is it right??

Which authorizations are necessary in this case?? According to the info in the Security Guide, I understand that we should assign to both the communication user and the HCM dialog users the roles "SAP_TDMS_HCM_MASTER" (read HCM data) and "SAP_TDMS_USER" (authorizations for TDMS transactions).

As a system administrator I saw that "SAP_TDMS_USER" has quite much basis authorizations which I would prefer not to assing to an end user in our HCM system.

Is it right??

I'm sorry for the long mail... Is the described authorization concept for TDMS right??

Thanks in advance,

Jon Larruzea

Accepted Solutions (0)

Answers (1)

Answers (1)

suman_pr
Active Participant
0 Kudos

Hi Jon,

Please find below the answer to your queries:

1. Regarding the query about SND_LOGON -> Yes, it is correct that some activities like Authorization check and Transfer Selection Criteria would require a dialog logon while the rest would work with a communication user.

2. For running a TDMS HCM package, the SAP_TDMS_HCM_MASTER would be required mandatorily in all systems. I understand that SAP_TDMS_USER has some important basis authorizations, you may proceed ahead and restrict these as per your requirement.

Thanks & Best Regards,

Suman