---
sourceDocument: Australia Asset Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/it-asset-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Asset Management

ft:clusterId :

    - itam

bundleId :

    - itam

workflow :

    - Technology


---

# Create SAP users, roles, and authorizations

# Create SAP users, roles, and authorizations {#ariaid-title1}

* Release version: Australia
* 
* Updated May 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Create the SAP user, roles, and authorization objects required for the Software Asset Management integration with the central and satellite SAP systems.

## Before you begin

The SAP transport files must be imported into the central system before configuring users and roles.

Role required: SAP Basis administrator

## About this task

The Software Asset Management integration requires a dedicated SAP user with separate roles for the central system and each satellite system. Central system roles control background job scheduling and service access. Satellite system roles control RFC execution and
table display access.{#create-sap-users-roles-auth__create-sap-users-roles-auth-context-1}

## Procedure

1. Create a user ID `S_SERVICENOW` in your SAP system.  
   If the user already exists, remove the current authorizations and set up new authorizations with central and satellite system permissions.
2. Create a central system role.
   1. Navigate to transaction code PFCG.
   2. On the Role Maintenance page, enter a role name in the Role field.  
      For example, <kbd class="ph userinput">Z_SNOW_CTR</kbd>.

   3. In the Description field, enter a brief description of the role and save.
   4. Add authorization object <kbd class="ph userinput">S_SERVICE</kbd> and add external service name <kbd class="ph userinput">/NOW/SAMP//NOW/SAMP_USER_DETAILS_WSDL</kbd>.  
   5. Add authorization object <kbd class="ph userinput">S_BTCH_ADM</kbd> and select the N (No administrator authorization) option in the Activities field.  
   6. Add authorization object <kbd class="ph userinput">S_BTCH_JOB</kbd>, select RELE (Release Jobs) in the Activities field, and leave the JOBGROUP field empty.  
   7. **Optional:** If the central system is a SAP S/4HANA system, add authorization object <kbd class="ph userinput">S_PROGNAM</kbd> and the following values in the corresponding fields.  
      * P_ACTION --- <kbd class="ph userinput">BTCSUBMIT</kbd>
      * P_PROGNAM --- <kbd class="ph userinput">/NOW/SAMP_USER_PROG_BCKJOB_RUN</kbd>

      {#create-sap-users-roles-auth__ul_uh4_mlr_hjc}

   {#create-sap-users-roles-auth__substeps_sfx_nvh_hjc}
3. Create a satellite system role.
   1. Navigate to transaction code PFCG.
   2. On the Role Maintenance page, enter a role name in the Role field.  
      For example, <kbd class="ph userinput">Z_SNOW_CLT</kbd>.

   3. In the Description field, enter a brief description of the role and save.
   4. Add authorization object <kbd class="ph userinput">S_RFC</kbd> and fill in the following values for the fields.  
      {#create-sap-users-roles-auth__table_twp_rzh_hjc__entry__2}

      | Field | Value |
      |-|-|
      | Activity | <kbd class="ph userinput">16</kbd> This code refers to Execute. |
      | RFC_NAME | <kbd class="ph userinput">/OSP/CORE</kbd>, <kbd class="ph userinput">/OSP/PRGN_GET_ALL_AGRS</kbd>, <kbd class="ph userinput">BAPI_USER_GETLIST</kbd>, <kbd class="ph userinput">BAPI_USER_GET_DETAIL</kbd>, <kbd class="ph userinput">MENU_READ_TSTC</kbd>, <kbd class="ph userinput">RFC_READ_TABLE</kbd>, <kbd class="ph userinput">RFCPING</kbd>, <kbd class="ph userinput">SCSM_COLLECTOR</kbd>, <kbd class="ph userinput">SDTX</kbd>, <kbd class="ph userinput">SMNV_MIGRATION</kbd>, <kbd class="ph userinput">STR9</kbd>, <kbd class="ph userinput">SU_USER</kbd>, <kbd class="ph userinput">SWNC_COLLECTOR_GET_AGGREGATES</kbd>, <kbd class="ph userinput">SYSU</kbd>, <kbd class="ph userinput">TR_SYS_PARAMS</kbd>, <kbd class="ph userinput">/NOW/SAMP</kbd>, <kbd class="ph userinput">/NOW/SAMP_HANADB</kbd> |
      | RFC_TYPE | <kbd class="ph userinput">FUGR</kbd> and <kbd class="ph userinput">FUNC</kbd> Here, FUGR is the Function Group and FUNC is the Function Module. |
      [Table 1. Field values for authorization object S_RFC]

      {#create-sap-users-roles-auth__table_twp_rzh_hjc}

   5. Add authorization object <kbd class="ph userinput">S_TABU_DIS</kbd> and enter <kbd class="ph userinput">03</kbd> in the Activity and <kbd class="ph userinput">&amp;NC&amp;</kbd>, <kbd class="ph userinput">SS</kbd> in the Table Authorization Group field.  
   6. Add authorization object <kbd class="ph userinput">S_TABU_NAM</kbd> and fill in the following values for the fields.  
      {#create-sap-users-roles-auth__table_hzj_1w3_hjc__entry__2}

      | Field | Value |
      |-|-|
      | Activity | <kbd class="ph userinput">03</kbd> This code refers to Display. |
      | Table Name | <kbd class="ph userinput">AGR_FLAGS</kbd>, <kbd class="ph userinput">AGR_TEXTS</kbd>, <kbd class="ph userinput">TSTCT</kbd>, <kbd class="ph userinput">TUPL</kbd>, <kbd class="ph userinput">TUPLT</kbd>, <kbd class="ph userinput">TUREP</kbd>, <kbd class="ph userinput">TUTYPA</kbd>, <kbd class="ph userinput">TUTYPNOW</kbd>, <kbd class="ph userinput">TUTYPPL</kbd>, <kbd class="ph userinput">USR41_MLD</kbd>, <kbd class="ph userinput">T000</kbd> |
      [Table 2. Field values for authorization object S_TABU_NAM]

      {#create-sap-users-roles-auth__table_hzj_1w3_hjc}

   7. Add authorization object <kbd class="ph userinput">S_TOOLS_EX</kbd> and enter <kbd class="ph userinput">S_TOOLS_EX_A</kbd> in the Authorization name in user master main field.  
   8. Add authorization object <kbd class="ph userinput">S_BTCH_ADM</kbd> and select the N (No administrator authorization) option in the Activities field.
   9. Add authorization object <kbd class="ph userinput">S_BTCH_JOB</kbd>, select RELE (Release Jobs) in the Activities field, and leave the JOBGROUP field empty.
   10. Add authorization object <kbd class="ph userinput">S_RZL_ADM</kbd> and enter <kbd class="ph userinput">01</kbd> in the Activity field.  
   11. Add authorization object <kbd class="ph userinput">S_USER_GRP</kbd> and enter <kbd class="ph userinput">03</kbd> in the Activity field and <kbd class="ph userinput">SUPER</kbd> in the User group in user master main field.  
   {#create-sap-users-roles-auth__substeps_km5_zyh_hjc}
4. Assign the central system role to the `S_SERVICENOW` user in the central system, and the satellite system role to the same user in each satellite system.  
   {#create-sap-users-roles-auth__table_tyj_xgj_hjc__entry__2}

   | Authorization object | Description |
   |-|-|
   | S_RFC | Verifies that the called RFC user is authorized to execute RFC function modules. |
   | S_SERVICE | Verifies the start of your external services. |
   | S_TCODE | Initiates an SAP transaction from the command box or menu. |
   | S_BTCH_ADM | Manages background processing. |
   | S_BTCH_JOB | Manages background jobs. |
   | S_RZL_ADM | Maintains external system commands. |
   | S_TABU_DIS | Controls table access to users. |
   | S_TABU_NAM | Provides authorizations for tables based on the table name instead of the table authorization group. |
   | S_TOOLS_EX | Monitors tool performance. |
   | S_USR_GRP | Performs user maintenance for several transactions. |
   [Table 3. Authorization objects and their descriptions]

   {#create-sap-users-roles-auth__table_tyj_xgj_hjc}

## What to do next

Select the Remote Function Call (RFC) connections that the SAP ABAP program uses to import data from your SAP clients. For details, see [Select SAP clients to import data](https://servicenow-prod.fluidtopics.net/NmbWBL1coWE6uVl9B_uIPg "Select the Remote Function Call (RFC) connections that the SAP ABAP program uses to import data from your SAP clients into the central system and then into your ServiceNow instance.").

