SAP
Nova manages accounts – called users in SAP – and their roles in SAP ABAP systems. To do so, Nova calls standard BAPIs and the function module RFC_READ_TABLE via RFC.
Prerequisite: SAP NetWeaver RFC SDK
For RFC, Nova uses the Python library pyrfc, which requires the SAP NetWeaver RFC SDK. Nova does not ship the SDK; the operator obtains it from SAP. Without the SDK, the SAP functions are not available.
Connection
One target system stands for one SAP system with one client. The fields: “SID”, “Application Server Host”, “System number”, “Client”, “User” and “Password” of the RFC user, and “Language”. Under “Advanced” are “Message server host”, “Message server port” and “Logon group” for load balancing, and the “SAP router string”. “Check status” calls RFC_PING.
Accounts
| Action | Function module |
|---|---|
| Create | BAPI_USER_CREATE1 |
| Change address data | BAPI_USER_CHANGE |
| Lock, unlock | BAPI_USER_LOCK, BAPI_USER_UNLOCK |
| Delete | BAPI_USER_DELETE |
Nova commits every change with BAPI_TRANSACTION_COMMIT. For SAP, first and last name must be available separately; Nova does not split a full name itself. After creating an account and after name changes, Nova reads the name fields back and reports any deviation.
Nova passes passwords as initial passwords, not as productive passwords. SAP therefore requires a dialog user to choose a new password at the first logon. If Nova creates an account without a password, password logon is deactivated. Passwords that Nova generates for SAP have at most 40 characters and start neither with “!” or “?” nor with three identical characters.
Nova reads the last logon from table USR02.
Roles
Nova supports single and composite roles. A job of type “Import SAP Roles” reads the role catalogue, optionally filtered (for example Z*). Nova recognises composite roles by their flag in AGR_FLAGS, reads their single roles from AGR_AGRS and short texts in German and English from AGR_TEXTS. If SAP returns the role structure incompletely, the import stops and leaves the previously imported definitions unchanged. Roles are scoped to their target system: roles with the same name in two SAP systems remain separate entitlements.
Validity
SAP manages validity periods of role assignments itself (FROM_DAT, TO_DAT). Nova passes on the start and end date of every assignment, even when it only begins in the future. Without a start date, Nova uses the current date; without an end date, 31 December 9999. If the same role has several periods with a gap in between for one account, Nova writes nothing and reports an error instead of bridging the gap.
Writing and reading back
SAP only accepts role assignments as a complete list (BAPI_USER_ACTGROUPS_ASSIGN). Nova therefore sends the account's complete target role set, with its periods, on every change.
Taking over existing accounts
Because SAP takes the list it receives as the complete role set, the existing roles of an account should be known to Nova before Nova assigns roles to it for the first time: import the role catalogue, then run a reconciliation with the target system as the leading side. In future, roles that Nova does not manage stay untouched when Nova assigns roles. planned
After the commit, Nova reads the account's roles back and compares names and periods with the target state, taking the single roles of a composite role into account. If anything differs, the change counts as failed and Nova names the roles concerned. Nova records the changes it detects per role in the change journal.
One role for many accounts
A background job of type “Bulk SAP account roles” grants one SAP role to many accounts or revokes it from them, with an optional validity period. Accounts are selected through filters such as identity type or department; without a status filter, Nova selects only active identities, and never AI agents. A run covers at most 500 accounts.
Nova processes the accounts one after another and writes and checks each of them as described above. The job does not revoke roles that a valid business role of the identity requires. Nova collects errors of individual accounts in the result without aborting the run. A cancellation by an administrator takes effect between two accounts.
Authorisations Nova needs in the SAP system
The SAP connector calls the following function modules. The SAP Basis team can derive a role for the RFC user from them.
| Function module | Purpose |
|---|---|
RFC_PING | connection test |
BAPI_USER_GETLIST | list accounts (import) |
BAPI_USER_GET_DETAIL | read address, lock status and roles |
BAPI_USER_CREATE1 | create accounts |
BAPI_USER_CHANGE | change address data, set passwords |
BAPI_USER_LOCK, BAPI_USER_UNLOCK | lock, unlock |
BAPI_USER_DELETE | delete accounts |
BAPI_USER_ACTGROUPS_ASSIGN | assign roles |
BAPI_TRANSACTION_COMMIT | commit changes |
RFC_READ_TABLE | read tables, see below |
| Table | Fields read | Purpose |
|---|---|---|
AGR_DEFINE | AGR_NAME, PARENT_AGR | role catalogue |
AGR_FLAGS | AGR_NAME, FLAG_TYPE, FLAG_VALUE | recognise composite roles |
AGR_AGRS | AGR_NAME, CHILD_AGR | single roles of a composite role |
AGR_TEXTS | AGR_NAME, SPRAS, TEXT | role texts |
USR02 | BNAME, TRDAT, LTIME | last logon |
For orientation: SAP usually checks such calls through the authorisation objects S_RFC (function modules), S_USER_GRP (user maintenance), S_USER_AGR (role assignment) and S_TABU_NAM or S_TABU_DIS (reading tables). Which objects and values a system actually checks is decided by the SAP Basis team.
The add-on module “SoD-Analyse (SAP ABAP)” has to be switched on separately. It additionally reads table AGR_1251 with the authorisation values of the roles; see Segregation of duties (SoD).