SAP Standard Users

SAP Standard Users


 Standard Users 


By default, the AS Java provides standard users for administrative and guest access, as well as communication users for connecting to the installed data source. The standard users on the AS Java are as shown in the table below. 

AS Java Standard Users


Type of User User Description Administrator user Administrator This user has unlimited administrative permissions over the AS Java.


We recommend that you use strong password and auditing policies for this user. Guest user Guest This user is also used for anonymous access to the AS Java.

tion. Example: SAP<SID>DB The AS Java also uses this user for DB connectivity when you configure the UME with the DB.


In addition to the above standard users, a default AS Java installation can also contain the following technical user: 


User Description ADSuser Used for communication between the AS Java and the Adobe Document Services (ADS) . 

This user is created in the AS Java or in the AS ABAP depending on the user store installation settings.

 For more information, see the Adobe Config Guide in the ADS Documentation and SAP Interactive Forms by Adobe Security Guide in the SAP NetWeaver Security Guide.


Security Considerations for Standard Users You assign initial passwords for the AS Java standard users during installation. 

In your productive operations or after the installation is complete, you can use the user management engine (UME) to change the initial passwords, manage the default properties for these users, lock users and create users with equivalent permissions. By default, the administrator user is used by certain applications on the AS Java to perform administrative and installation tasks, for example software deployment and undeployment.


If you used the default name for the standard administrator create another administrator user with equivalent administrative privileges. (For example, assign this user to the Administrators user group.)

 Then lock the default Administrator user.

 Do not delete the default administrator. Do this to avoid attacks on your system by malicious users attempting to guess the password of the well-known default names. Create more than one administrator to avoid the case where the only administrator is locked, due to failed logon attempts, for example.

 The avoids the necessity of activating the emergency user, which forces you to restart the system. For more information, see Administration of Users, Groups, and Roles in the Administration Manual.


Emergency User In case of emergency, you can enable the Emergency User store on the AS Java. By default this user store contains only one user SAP*.

 For security purposes, when the Emergency User store is enabled, users defined in other user stores will be unable to access the AS Java. 

The SAP* user is the emergency user that has full administrative authorizations and can be used to reconfigure UME if the configuration is faulty and administrators and users can no longer access applications. 

To use this user, you must explicitly activate it and specify its password. For more information, see Activating the Emergency User in the Administration Manual.





Comments

Popular posts from this blog

Advanced JAVA

C++

SAP NWA: Net Weaver Administration Tool