Translate

Central User Administration(CUA) configuration

Why do we need CUA ?

CUA or central use administration is actually configured to save the money and resource to manage large and similar user exist in many system in the landscape .This tool help us to manage all the user master record centrally from on client of the system .
Complex system landscapes.
Manual Maintenance of  user information in all the available systems.
Tedious Administrative task
Complex administrative job may lead to Security problems

Benefits of Central User Administration

•Once you configure CUA users can only be created or deleted in the central system.
•User attributes can be maintained only locally, only centrally, or both centrally and locally
•Therefore, the required roles and authorizations must exist in active form in all child systems.
•As a result each user only has to be administered once centrally which gives the administration a much clearer overview of all users and authorizations.

Steps by Step Process :Few Points

  1. We need a SAP Landscape/single system with multiple clients
  2. The administrator should have access to SAP and tcodes SU01, BD54, BD64, SCC4, SCUA, SCUM, SM59
  3.  We do need to create Create system users in central system and child systems
  4.  Create RFC connections between systems
  5.  Create logical system
  6.   Assign logical system to corresponding clients
  7.   Create model view
  8.   Add BAPI to model view
  9.   Generate partner profiles and distribute model view
  10.   Create CUA and distribution model
  11.   Maintain parameters between central and child systems

Preperation:

 First we would be needing 2 client of  system's for the configuration .
For example I am hereby taking a system EC3 with 2 client : 400 (Central client ) ; 410 (Child System )

1.)  Create system user :


These system users required for RFC configuration between two clients.These RFC are being required to transfer the data here. We do need to create following in the respective clients with the below defined roles :
Client 1:    400 User ,this is a central system : CUA_EC400
Client 2:    410  User,this is a child system  : CUA_EC410
Above are the usernames created in client 400 and 410 respectively with below roles.
User CUA_EC400 with below roles(roles in the central system)
SAP_BC_USR_CUA_CENTRAL
SAP_BC_USR_CUA_CENTRAL_BDIST
SAP_BC_USR_CUA_CENTRAL_EXTERN

User CUA_EC410with below roles( roles in the child system)
SAP_BC_USR_CUA_CLIENT
SAP_BC_USR_CUA_SETUP_CLIENT 

2.)Create RFC connections between system:


1.Go to SM59 tcode and select ABAP connections
2.Click "Create" button or press F8
3.Enter the RFC connection name(ie.EC3CLNT400&EC3CLNt410) and choose connection type as 3 which means ABAP connecions
4.Enter the description of the RFC like "RFC connection for CUA" and save
5.Now Enter the Target Host as system name(Computer name) of the EC3 system or enter the IP address of the system and system number of EC3(like 00)
6.All the above settings must be carried out on "Technical Settings" tab
7.Next go to "Logon & Security" tab
8.Enter the Client number of the target client EC3system i.e.
9.Also enter the username and password which is created in EC3 target client  in initial stage
10.Language is optional and similarly Unicode option in Unicode tab
11.You can select "Unicode" option if target system is Unicode system or leave it
12.Now save the settings and you will be prompted "Connection will be used for Remote logon"
13.Click "OK" and Click "Connection Test" or Ctrl+F3

3.)Create logical system: 


You need to create logical system for each client/ system and make sure it shouldn’t defer from RFC connections respectively
Go to BD54 tcode and setup logical systems.
 

 4.)Assign logical system to corresponding clients:


Go to tcode SCC4 and assign the logical systems to each client/system respectively
  

 5.)Create model view:


this steps need to be done in the Central system .
  1. Login to the central client of the system
  2. Go to transaction BD64 amd click on chage button .
3. click create model view button and enter the model  view
4. Enter a short description and technical name as shown in the below and hit ok button

  6.)Add BAPI to model view:


Select the model view and click “Add BAPI”.
 
You need to enter model view, sender/client, receiver/server object name/interface and method.As said initially I used 400 client as sender/central system and 410 client as receiver/child systems
Enter the “object name and Method” as per above figure and click ok button
 

 7.)Generate partner profiles and distribute Model View:


We are done with model view creation and BAPI.Now we need to generate partner profiles go to Environment and click generate partner profiles
 
You will get a message saying partner profiles are generated newly if your generating 1st time or you will get a system message like below figure.
 
Come back to the BD64 screen and select the model view and go to Edit ModelView --> select Distribute.This will distribute your model view to child systems and you will get message like below
 
So now we are done with model view creation and distribution.

Installation :

8.)Create CUA and distribution model:

Go to tcode SCUA and create distribution model.Enter the model view name which is created in BD64 earlier and click create button as shown in below figure.
Now you will get a screen like below and select the child systems in the pop up screen
Once you selected the system name and click save.You will get a screen like below if you are done everything correctly which means your CUA configuration is done successfully.

   9.)Maintain parameter between central  and child systems:

Once we are good with CUA configuration there are parameter setup needs to be done from central system like which all are maintained in central and child systems
Go to SCUM tcode ànd click to change mode for parameter maintenance
It will give you broad idea about what are the parameters should be maintained centrally and which can be maintained child system as well as globally.
Ex. Role addition should be done from central system and password reset and  defaults can be maintained from both centrally and local

Labels

sap hana hana database aws s4 hana hana db s4hana conversion steps sap hana azure bw4hana hana migration s4hana migration sap cloud migration steps sap hana migration steps sap hana migration to azure s4hana sap fiori fiori performance fiori erp s4 hana fiori sap fiori app sap fiori client sap fiori launchpad sap s4 hana fiori cisco ecc AI SAP AI abap dumps hana sap S/4HANA S/4HANA Conversion best sap ui5 & fiori training configuration database fiori tutorial on webide free sap ui5 & fiori training s/4 hana sap dumps sap fiori tutorial sap ui5 sap ui5 & fiori sap ui5 & fiori tutorial sara ui5cn 2367245 - Troubleshooting performance issues with SAP BPA Amazon free tier for SAP AWS setup Experience CALL_FUNCTION_NOT_FOUND CCMS Configuration and Use Create New Data Class in SAP (Oracle) Critical top SAP Abap dumps DHCP Clients Not Receiving IP Addresses Download Stack.xml HAN-DB HAN-DB-ENG High CPU Usage Due to Excessive Process Switching How To How to Start and Stop SAP Hana Tenant Database How to change SAP Hana Sql Output results are limited to 5000 Records How to perform SAP Dual Stack Split - Netweaver Inactive Objects in SAP Intercompany transactions in SAP AP / AR : Cross Company Code Transaction Interface Flapping Due to Duplex Mismatch KBA LOAD_PROGRAM_LOST MSSQL shrinking transaction log file Migrating to SAP hana database NAT Overload Causing Internet Access Failure Note 500235 - Network Diagnosis with NIPING OSPF Adjacency Not Forming PRINCE2 Foundation Sample Questions Preparing for S/4HANA Conversion and the MUST know items Push to Download Basket S/4HANA Migration Cockpit S/4JANA SAP BI Support Data Load Errors and Solutions SAP BI/BW Landscape SAP BPA SAP Basis SAP Basis Automation SAP Business Objects SAP CPS SAP Certification SAP FI Certification SAP FI Certification Sample Questions SAP HANA Admin - Cockpit SAP HANA DB Engines SAP HANA Database SAP HANA terminate session connection disconnect cancel kill hang stuck SAP Hana DB restore SAP Hana Numeric Error Codes SAP Landscape SAP Language installation SAP MM and Purchase Order Tables SAP Maintenance Planner SAP Note 500235 SAP R/3 Glossary SAP Readiness Check SAP S/4HANA 1709 Installation Files SAP S/4HANA 2023 SAP S/4HANA 2023 Installation SAP S/4HANA 2023 running SAP S/4HANA Installation SAP Scheduling SAP Solman 7.2 CHARM: SAP Support Package Stack Strategy SAP Support package SAP Upgrade SAP support stack upgrade SP stacks STORAGE_PARAMETERS_WRONG_SET SUSE/SLES/Kernel versions Setup of S/4hana 2023 TSV_TNEW_PAGE_ALLOC_FAILED TSV_TNEW_PAGE_ALLOC_FAILED error Transaction ID Unable to download an SAP Note Unix/Linux Command That Are Helpful For SAP Basis Upgrading SAP Kernel Without Downtime Upgrading windows server 2008 to windows server 2019 What is OSS Notes? SAP SNOTE Tutorial accounting agile ale idoc ale/edi archive FI documents audit auditing auditor aws aws cloud basic type bluefield approach ccms ccmsidb charm copilot datavard dbacockpit download sap note download snote edi idoc electronic data interchange enable sap archiving objects erpprep ffid firefighter fraud functional hana admin how to apply sap security note https://www.erpprep.com/ idoc install install sap fiori installation interfaces intermediate document internal control license key linux version materials management messsage niping test order type port prince2 agile prince2 agile practitioner purchasing quick info s4 hana sap abap dumps sap abbreviations sap activate certification sap activate project manager sap authorization sap aws sap brownfield sap ccms sap ccms configuration sap erp sap error sap grc sap greenfield sap internet demo system sap license sap maintenance certificate sap material management sap meaning sap mm sap mm consultant sap monthly security note sap netweaver sap network diagnostic sap niping sap note sap oss sap patch day sap performance sap performance issue sap purchase order sap s/4hana sap sales and distribution sap sap otc sap sd sap sd certification training sap sd course sap sd jobs sap sd module sap sd online training sap sd training sap sd tutorial sap sd tutorial for beginners sap security sap security note sap snote sap snote tutorial sap solution manager sap sql segregation of duties separation of duties sles slicense smc snote snote in sap system sod conflict solution manager solution maneger stop start hana database suse linux techie trex two step upgrade required waterfall