cancel
Showing results for 
Search instead for 
Did you mean: 

How to secure SAP* and DDIC

Former Member
0 Kudos

Hi Experts,

Please tell me how to protect SAP* and DDIC.

Shall i use entire copy of SAP* and ddic insted of using directly these ids? whats SAP recomendations?

Kindly suggest me some notes.

Regards,

Nagendra.

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

Usage of users:

User SAP* for initial access to the R/3 System

User DDIC for the transport and correction system

To protect SAP* and DDIC from unauthorized access, you must change the initial passwords for these users in all clients of your R/3 System. We recommend that you add the user group SUPER to the user master records. This user group can only be accessed by the superuser. Please review the note 2383.

User DDIC is a user with special privileges in installation, Software logistics , The ABAP dictionary and Run/schedule system jobs. Hence, I would not recommend to remove the functional and operational rights in DDIC user. The best way to secure DDIC is to implement policy on its usage and limit access to the password for this user.

Always have at least two administrative user IDs for each client,

so you do not lock yourself out of the client. SAP* and DDIC should only be used for tasks that require those user IDs be used. A better solution is to create an administrative user ID, which is a copy of the user SAP*.

Former Member
0 Kudos

Thank you Warren Wong, I need information about DDIC user also. i didn't find any information about ddic from the note 2383 and from related notes.

Regards,

Nagendra.

Former Member
0 Kudos

Hi Nagendra,

I hope the following link may helpfull to you.

[Protecting Standard Users |http://help.sap.com/saphelp_nw70/helpdata/en/3e/cdaccbedc411d3a6510000e835363f/content.htm]