CSI tools Facebook CSI tools Twitter CSI tools LinkedIn CSI tools Instagram
  • Home
  • Newsroom
    • Awards
    • Events
    • Press Releases
    • Publications
  • Software
    • By Solution
      1. Access Risk Management
      2. Access Request Management
      3. Privileged Access Management
      4. Access Role Management
      5. SAP License Audit
      6. Mass User Maintenance
    • Tools
      1. CSI Authorization Auditor
      2. CSI Automated Request Engine
      3. CSI Emergency Request
      4. CSI Role Build & Manage
      5. CSI Mass User Maintenance
      6. CSI Integrate & Collaborate
    • Pathlock
    • Legacy Tools
    • Pathlock Cloud: The Successor of CSI tools
  • Customer Center
  • Community
    • CSI tools Forum
    • Meta's Blog
    • Tech Updates
    • Training
  • About
    • Contact
    • Jobs
    • Partners
      • Become a Partner
    • References
    • Testimonials
    • Sustainability
  • Login
  • You are here:  
  • Home
  • Meta's Blog Home
  • User type reference not always taken into account

User type reference not always taken into account

We are all aware that different type of user types exists in the SAP system (http://help.sap.com/saphelp_nw04/helpdata/en/3d/3272396ace5534e10000000a11405a/content.htm).
I find the use of reference users a bit "tricky" and my experience is that this user type is not always investigated properly during an authorization analysis.

What are reference users:
Reference user type 'L'
Authorization enhancement
No logon possible.
Reference users are used for authorization assignment to other users.
Usage: Internet users with identical authorizations

Using reference users has it benefits, if a user is assigned to a reference user, it inherits the authorizations from this reference user. This can be helpful with Employee Self Service users for example.
However, the link to the reference user isnot always in your SAP report (via SUIM or table agr_users).
There are some reports in SUIM that will give you the link between a user ID and the reference user (like users by complex selection criteria (S_BCE_68001400)

Please be aware that not all SUIM reports will make the link to the reference user
Also bare in mind that the table AGR_USERS will not show the user with the authorizations from a reference user will (therefore you won't see what roles are assigned to the user via this reference user).

How to search for the usage of reference users (this action can be part of your periodic authorization review)
1. Check if reference users are existing in your system (like SE16->URS02 usertpe L)

2. If they do exist.
2a.Check the assignment of authorizations to this reference user
2b.Check the assignment of users to this reference users (via S_BCE_68001400)

(C) Meta Hoetjes 2014
CSI Authorization Auditor and CSI Role Build and Manage are registered trademarks by CSI tools bvba
www.csi-tools.com

Get in touch

Pathlock Benelux
Support Direct
Link to the support portal https://support.pathlock.com

To gain access to the new support portal, please contact us at customersupport@pathlock.com

Tel. +32 16 308 008

Address
Kempische Steenweg 303/200
B-3500 Hasselt, Belgium

Via phone
Tel: +32 16 308 000

Last Updates

  • Pathlock Cloud: The Successor of CSI tools
  • Pathlock named Market Leader for Zero Trust by Cyber Defense Magazine

Solutions

  • SoD and Risk analysis - CSI Authorization Auditor
  • Compliant Provisioning - CSI Automated Request Engine
  • Emergency Access Management - CSI Emergency Request
  • Compliant Role and Mass User Management - CSI Role Build & Manage
  • Extract SAP data - CSI Data Xtractor
  • CSI Integrate & Collaborate

©1997-2025 Pathlock Benelux. All rights reserved. - Privacy Policy  - Cookie Policy - Code of Ethical Conduct - Sitemap