SAP security interviews test whether you understand how access flows: from user to role to authorization object to application. These are the questions that come up most often.
Core Concepts
What is the difference between a role and a profile in SAP?
A role is the business-level container assigned to users; it holds authorizations, transactions, and Fiori catalogs. A profile is the generated technical object created from a role via PFCG. You maintain roles, SAP generates profiles, users get roles in SU01.
What is an authorization object?
An authorization object is a set of up to 10 fields defining one checkable permission, like S_TCODE with field TCD. Programs call AUTHORITY-CHECK against it; the user passes only if their role holds an authorization with matching values.
What is the difference between single roles and composite roles?
A single role contains its own authorizations and menu. A composite role collects single roles and has no authorizations of its own. Use composites to assemble job functions from reusable single-role building blocks.
What is the difference between master and derived roles?
A derived role inherits the menu and authorizations of a master role; you adjust only organizational values like company code or plant. Change the master and all derived roles inherit it. The standard pattern for multi-org landscapes.
Role Design and PFCG
Walk through creating a role in PFCG.
Create the role, add transactions or Fiori catalogs to the menu, then generate the authorization profile. Maintain field values on the authorizations tab, assign the role to users, and run user comparison so the profile lands in the user masters.
What is user comparison in PFCG and why does it matter?
User comparison writes the generated authorization profile into the user master records of assigned users. Without it, the role assignment exists but the authorizations are not active. Always run it after changing a role's authorizations.
What are organizational levels and why do they matter?
Fields like company code, plant, and sales organization that scope authorizations to parts of the business. They default into roles from central maintenance. Wrong values are the top reason a user "has the role but cannot do the thing."
What is SU24 and how is it used?
SU24 maintains the proposal values for authorization objects per transaction — the checks a transaction proposes when added to a role menu. Security teams tune it to cut manual maintenance. Changes affect every role using that transaction, so handle with care.
Fiori Authorizations
How do Fiori authorizations differ from classic GUI authorizations?
Fiori access starts with catalogs and groups in business roles, which control tile visibility. But OData services and backend transactions still need classic authorizations — the tile alone is not enough. Catalog without service authorization means a visible tile that errors on launch.
What is the difference between a business catalog and a business group?
A catalog is the technical container of apps (tiles, target mappings) exposed to roles. A group is the visual arrangement of tiles on the launchpad home page. Users need the catalog for access and the group for tiles to appear.
How do you troubleshoot "tile not visible" in the Fiori launchpad?
Check the user's business roles for the catalog containing the app, then verify the OData service and backend authorizations. Confirm the tile's target mapping in the catalog. Visibility is catalog-driven; errors after clicking mean missing service or backend authorizations.
Key takeaway: Fiori security is two layers — catalogs for visibility, classic authorizations for execution. A missing tile is a catalog problem; an error after clicking is an authorization problem.
SoD, Auditing, and Maintenance
What is segregation of duties (SoD) and how is it enforced?
SoD means no single user holds conflicting permissions, like creating and approving the same purchase order. It is enforced through role design and monitored with SAP Access Control (GRC). SoD conflicts rank among the most common audit findings.
What is the difference between SU01, SU10, and SUIM?
SU01 maintains individual user masters, SU10 does mass user maintenance, and SUIM is the information system for reporting on users, roles, and authorizations. When asked "how do you find who has access to X," the answer is SUIM.
How do you find which users have a specific authorization?
Use SUIM reports to search by authorization object and field values across roles and users. You can also trace from the role side with PFCG where-used lists. This is standard work during audits and SoD remediation.
What is a critical authorization? Give an example.
A high-risk access that auditors flag, like S_TABU_DIS for table maintenance or S_DEVELOP with debugging activity. Roles containing them need documented business justification and often mitigating controls. Know S_TABU_DIS and S_DEVELOP by name.
How do you diagnose a "No authorization" error?
Run SU53 right after the failure — it shows the last failed check: the object, the values checked, and what the user actually has. The fix is usually a missing value in the role, not a code problem. SU53 is the fastest diagnostic you have.
Key takeaway: SU53 for the failed check, SUIM for who-has-what reporting, PFCG user comparison after every role change. Those three cover most day-to-day security questions.
Which security question caught you off guard in an interview? Drop it in the comments.