Protecting Special Users in SAP
Protecting Special Users in SAP Standard Users in SAP: SAP system comes with SAP* and DDIC. These are the super users and they are created during the SAP installation process. Password is set during the installation process. The SAP* user is created in 000, 001 and all new clients while DDIC is created in 000 and 001 clients only. Apart from these users, there are other users like EARLYWATCH, SAPCPIC and TMSADM. SAP* and DDIC users should be monitored regularly and should be protected from unauthorized access. Protecting the SAP Special Users: a. SAP* user should exists in all clients and should be deactivated in all clients. The default password for SAP* and DDIC should be changed. Report RSUSR003 displays special users that are exists in all the client and changes made to these users. b. Set the user group to "SUPER" for all these users in all clients. All these users should be locked in all clients. c. There is a transport background job called RDDIMPDP whi...