cancel
Showing results for 
Search instead for 
Did you mean: 

Permission for SAPService<SID> and adm<SID>

0 Kudos

Hi,

R3SETUP and SAPINST adds users SapService<SID> and <SID>adm into Local

Administrators group on a Local Installation.

What if I don't want those users as members of Local Administrators

group? What permissions should I setup for those users in order to keep

R/3 running just fine?

Accepted Solutions (0)

Answers (1)

Answers (1)

former_member433984
Active Contributor
0 Kudos

Up to 6.40 the SAPService<SID> and <SID>adm must be member of local admins.

The SAP system will not start if SAPService<SID> is not a member, because it must attach to shared memory segments.

As of 6.40 SAPService<SID> is not member of local admin group and attaching to shared memory is done under normal user.

<SID>adm is account to perform administrative tasks (backup, kernel update etc.), so it would be reasonable to leave it in local admin group.