Neglecting SAP SU24 optimisation and authorisation proposals during an SAP role redesign almost guarantees chaotic PFCG builds, widespread over-authorisation, and severe audit findings. Treating SU24 and SU25 as administrative utilities rather than strategic levers forces security teams into endless manual corrections. Restoring discipline to your SU24 tables establishes a predictable, auditable foundation that defends against risk and reduces PFCG build times. Implementing effective SAP SU24 Optimisation is essential for maintaining security integrity.
Implementing an effective SAP SU24 Optimisation strategy simplifies your security management process and significantly elevates your overall security posture. Regular reviews and updates prevent critical security loopholes, while automated SU24 maintenance dramatically reduces manual interventions and streamlines ongoing security processes.
SU24: The Authorisation Backbone of SAP Security
Enhancing Security Through SAP SU24 Optimisation
Transaction SU24 maintains customer authorisation proposals stored in system tables USOBT_C and USOBX_C. These tables dictate which authorisation objects and field values automatically populate into PFCG whenever a transaction code is added to a role menu.
When SU24 is outdated or ignored, security teams resort to manually inserting authorisation objects directly inside PFCG. This practice breaks role inheritance, creates inconsistent security baselines, and can result in painful external audits.
- SU24 vs SU22: SU22 stores SAP standard default proposals (USOBT/USOBX) and must never be altered. SU24 represents your customer-specific baseline.
- SU25 Synchronisation: Transaction SU25 copies updated SAP baseline proposals into customer tables following system upgrades or support package application.. Executing SU25 ensures legacy proposal gaps do not break roles during S/4HANA migrations.
- Transport Scope: SU24 proposal data is system-local and maintained exclusively in your Development (DEV) client where roles are built. Only custom authorisation objects (SU21) travel along the transport path.
Prioritising SAP SU24 Optimisation ensures strict compliance with security standards while streamlining role management for peak operational efficiency. Embedding these effective practices into your daily governance elevates your overall SAP security framework, defending your landscape against unmitigated risk and audit findings.
The Dangerous Trap of Over-Specifying Default Field Values
Adopting SAP SU24 Optimisation helps in identifying and mitigating risks early.
A common mistake during SU24 maintenance is blindly accepting default activity values (ACTVT). Over-specifying default activities creates severe, unmonitored security risks across dual-purpose transactions.
For example, on dual display/maintain transactions like MIGO, if the SU24 default proposal includes activities 01 (Create), 02 (Change), and 03 (Display), every role incorporating MIGO will default to full maintain capability. To grant display-only access, administrators are forced to manually deactivate object instances in PFCG and create manual entries.
With SAP SU24 Optimisation, businesses can achieve better compliance and governance.
To prevent over-authorisation, populate SU24 defaults strictly with display values (03), or configure the proposal status as Yes – Without Values, allowing role builders to specify field values intentionally during construction.
Preparation: Trace-Driven Precision via STUSOBTRACE
Designing roles around subjective user interviews leads to bloated permissions. Clean role redesign requires empirical execution evidence.
Executing STUSOBTRACE alongside system activity logs (ST03N) in the weeks leading up to a redesign captures real-time authorisation checks across active business processes. This execution data pinpoints missing or redundant SU24 proposal entries before a single role is constructed, replacing speculative guesswork with mathematical certainty.
Automating SU24 Governance with the Tango Cortex Suite
Manually updating thousands of SU24 proposals across legacy ECC landscapes is slow and prone to human error. Tango Technologies embeds SU24 optimisation into our automated Cortex Suite:
Integrating SAP SU24 Optimisation into your strategy can streamline operations.
- Cortex REFRAME (Role Design & Maintenance): Automatically evaluates SU24 proposals against multi-year execution history. REFRAME groups users into similarity clusters, translates obsolete ECC transactions into modern S/4HANA Fiori equivalents, and generates compliant position-based composite roles (ZPC_LON_FIN_MGR) wrapping dedicated Read (ZPS_…_R) and Update (ZPS_…_U) single roles.
- Cortex INSIGHT (Visual GRC): Performs pre-emptive Segregation of Duties (SoD) simulations before physical role generation in PFCG, verifying that updated SU24 proposals do not introduce toxic access combinations.
- Cortex ECHO (SAP Licence Optimisation): Evaluates transaction inheritances driven by SU24 proposals. It provides deep insight into why a Role will attract the RISE or S/4HANA it is destined for giving the opportunity for pre build adjustment.
- Cortex VAULT (Execution Analytics): Compresses historical system activity data into an audit-ready repository, providing external auditors with proof that Users accessed transactions or Fiori Apps, when and what they did.
Zero-Disruption Shadow Simulations
Understanding the role of SAP SU24 Optimisation is critical for enterprise SAP professionals seeking to maintain continuous compliance and robust landscape security. Executing routine SAP SU24 Optimisation eliminates authorisation proposal drift, enhances operational system performance, and establishes a predictable, audit-ready security framework.
Traditional security testing forces key business users into disruptive manual testing in outdated QA clients. Cortex REFRAME transforms validation through background shadow simulations.
Using automatically provisioned Reference Users, REFRAME traces real-world execution patterns in live runtime environments. It catches missing authorisation objects and or field values and injects the selected authorisations back into the blueprints automatically allowing end users to work uninterrupted while proving new security profiles are completely safe for go-live.
Building clean, compliant roles requires clean proposal data. By combining disciplined governance with automated execution through Cortex REFRAME, enterprises eliminate SoD risks, accelerate S/4HANA migrations, and secure lasting licence cost reductions.
Investing in SAP SU24 Optimisation can lead to significant cost reductions in the long run.
Frequently Asked Questions (FAQ)
What is the main difference between SAP SU24 and SU25?
SU24 is used for daily customer maintenance of authorisation proposals (USOBT_C/USOBX_C) in Development. SU25 is an upgrade utility used to compare and synchronise customer proposal tables with newly delivered SAP standard baselines after support package updates or S/4HANA migrations.
Why shouldn’t authorisation objects be inserted manually into PFCG roles?
Inserting objects manually in PFCG bypasses standard SU24 proposal logic, making manual objects orphaned when the unlinked transaction they are there for is removed.
How does SU24 optimisation reduce S/4HANA RISE licence costs?
SAP determines FUE licence tiers based on potential assigned access within roles. Simply put, reducing the access in precision built Roles reduces SoD Risk and offers the greatest chance to attract low level licenses as the Role Profile carries the smallest number of objects and values.


