-
Non-Product Related Assistance
Request for existing cases, user IDs, Portal navigation support and more
Authorizations: Overview, Landscape Independent vs. Landscape Dependent Authorizations and Manage Authorizations
Purpose: Define the role-based authorization framework for S-Users, specifying set of applications that a S-User can access with every authorization and authorizations could be landscape-independent or landscape-dependent.
1. Prerequisites
1. Have an active S‑User account (authorizations can be assigned only to S‑Users).
2. Understand the two authorization classifications: Landscape‑Independent and Landscape‑Dependent.
- Landscape‑Independent Authorization: These authorizations are at customer level and not at landscape level.
- Landscape‑Dependent Authorization: These authorizations are specific to landscape.
2. Overview
Authorizations define which applications the users can access on Landscape Hub. Authorizations that could be assigned to a user are:
- Users & Contacts Admin
- Users & Contacts Viewer
- Landscape Owner
- Landscape Viewer
- Fund Owner
- Onboarding Form Contributor
- Onboarding Form Owner
- Onboarding Form Reviewer
- Onboarding Form Submitter
3. Access & Navigation Steps
1. Logon to SAP for Me: https://me.sap.com/home(opens in new tab)
2. Click on: “Portfolio & Products”, and later “My Product Portfolio”
3. Choose tile: “Landscape Hub”
4. Landscape Hub will open in a new window
4. Authorization Types
Authorizations are classified into Landscape Independent and Landscape Dependent.
Landscape-Independent authorizations:
- These authorizations are at customer level and not at landscape level
- Users & Contacts Applications can be accessed with Users & Contacts Admin/Viewer Authorization
- Fund Consumption Reporting can be accessed with Fund Owner authorization
Landscape-Dependent authorizations:
- These authorizations can be assigned for a complete Landscape or for one or more solutions/tiers within a landscape
- Skyline & Landscape Gantt application can be accessed with Landscape Owner / Viewer authorization
- Onboarding Form application can be accessed with Onboarding Form Contributor, Owner, Reviewer or Submitter authorization
5. Navigation Steps
1. Login to Landscape hub Application
2. Click Users & Contacts
3. Click Navigation arrow and navigate to the user details page
6. Adding Authorizations
Step 1: From the user detail page, click Add Authorizations
Step 2: A pop-up window opens; Check required authorization under "Landscape Dependent Roles" and click “Next Step”
Step 3: Select Landscape and click "Next Step"
Step 4: Summary step displays selected landscapes
Step 5: Click "Previous Step" to navigate to "Define Landscape" step
Step 6: Click "Save" to assign authorization for selected landscapes to the user
Added authorization shall be listed under Authorizations section in user detail.
6.1 Add authorizations for Landscape Independent Roles
Step 1: Select the landscape independent authorization as required
- Note: More than one role can be selected by S-user/Super admin.
Step 2: Review the added authorizations and click Save
Selected landscape independent authorization is now assigned to the user.
6.2 Add authorizations for Landscape Dependent Roles
Add Authorizations: Landscape Dependent
Landscape Dependent Authorizations can be defined at
- Open Role
- Landscape
- Solution
- System/Tier
- Landscape level
- Onboarding Form
Choose one of the following as per requirement:
- Complete Landscape or
- Expand Landscape, choose solution or
- Expand Solution, choose tiers
- Landscape Owner / Landscape Viewer authorization – Open Role
- Onboarding Form Contributor, Owner, Reviewer, Submitter – Landscape Level
Adding Landscape Owner authorization to a S-User:
1. Select Landscape Owner authorization, click on "Next Step"
2. Select one or more Landscapes
3. Choose the Solution as required
4. Choose Systems/Tiers
- SAP BW/4HANA is at solution level, user will be authorized if any new system/tier will be added in the future
SAP S/4HANA on Premise is at tier level
1. Partial selection only 2-tier Production and Quality are selected
2. Partial selection though all tiers are selected, all tiers are selected individually rather than selection at Solution level. In this case, if a new tier is added, user will not be authorized for the new tier
5. Summary step displays all landscapes in the previous step
6. Click Save, authorization for selected landscapes will be assigned to User
7. Authorization added to User with Landscapes / Solutions / Tier will be displayed in user detail
Selecting 1 or more Solutions:
Selection of a combination of Landscape along with one or more solutions is also possible.
- Summary step displays all landscapes and solutions in the previous step
- Click Save and authorization for selected landscapes will be assigned to User
- Authorization added to User with Landscapes / Solutions / Tier.
- Select one or more systems / tiers
- Selection of combination of Landscape + 1 or more solutions + 1 or more systems/tiers is also possible
- Summary step displays all landscapes, solutions and tiers selected in the previous step
- Click Save and authorization for selected landscapes, solutions and tiers will be assigned to User. If a new tier gets added to the solution SAPS/4HANA On Premise, this S-User will have access only to the selected tiers and will not get access to view the new tier on Skyline/Gantt because the user is authorized to view only selected tiers in this solution not the complete solution.
- Authorization added to User with Landscapes / Solutions / Tiers
- Add New Authorizations wizard will list all available authorizations that can be added to a user
- As Contact Viewer and Landscape Owner authorizations are added already, only other authorizations are listed
6.3 Editing Authorizations
Step 1: Hover mouse over Authorization assigned to User
Step 2: Click Edit
Step 3: User is assigned as a Landscape Owner for landscapes - VLAB test CSS Skyline O and VLAB
Step 4: Click on Edit, de-select above landscapes and select VLAB CSS Skyline 3P
Step 5: Summary step displays changes made in the previous step
Step 6: Click Save
6.4 Removing Authorizations
Step 1: Hover mouse over Authorization assigned to User
Step 2: Click Remove
Step 3: A Pop-up will appear and click to confirm, Authorization will be removed
7. Expected Results
Users & Contacts
- User& Contacts Admin: Can manage access for everyone: add, change, or remove permissions for all users and contacts.
- Users & Contacts Viewer: Can see what access rights users and contacts have but cannot change anything.
Reporting
- Fund Owner: Can view reports showing how funds are being used.
Onboarding Form
- Onboarding Form Owner: Can read, edit, and submit onboarding forms. Has full responsibility for the form.
- Onboarding Form Contributor: Can read and edit onboarding forms but cannot submit them.
- Onboarding Form Submitter: Can read and submit onboarding forms but cannot edit them.
- Onboarding Form Reviewer: Can only read onboarding forms.
Landscape & Skyline
- Landscape Viewer: Can view landscapes, solutions, system types, and tiers, but cannot make changes.
- Landscape Owner: Can manage assigned landscapes and related elements, label tiers, and create change requests.
Change Requests
- Change Request Approver: Can review and formally approve service changes.
- Change Request Reviewer: Can review proposed service changes and request formal approval when needed.