logo

Are you need IT Support Engineer? Free Consultant

Step-by-Step Demo: How to Restrict Users' Business Data Access in SAP S/4HANA Cloud Public Edition

  • By Sanjay
  • 18/09/2026
  • 10 Views



Use Case: Sales authorization control — I want sales representatives to see sales orders only from Sales Organizations A and B, and not from any other sales organization.

When I described this requirement to Joule and received an incorrect solution, I realized it was time to write this blog post…

The requirement is straightforward: I want to restrict which sales orders a sales user can view. For example, a specific salesperson should only be able to see sales orders belonging to Sales Organization A and B. In the demo below, I use Sales Organizations 1310 and 1320 to represent A and B.

The following is a step-by-step guide on how to configure authorization restrictions to control what business data a user can access:


  1. For demo purposes, I assign the user only one Business Role that contains a single Business Catalog related to sales order processing.

    The Business Role Under Business User

     The Business Catalog Under Business Role

     

  2. When we log in and open the sales order application, we can currently see all sales orders — not only Sales Organizations 1310 and 1320, but also others such as 1020 and 1810.

    Initially Can See All The Sales Orders

     

  3. Now let's get to the key configuration. Open the Business Role for editing and click “Maintain Restrictions” in the upper right corner. By default, you should see that all three restriction levels (Write, Read, Value Help) are set to Unrestricted.

    Initially, All Are Unrestricted

     

  4. Based on our requirement, change the Write and Read restriction levels to Restricted. Leave Value Help as Unrestricted for now.

    Set Restricted On Write And Read Levels

     

  5. Scroll down in the left-side menu to the section “Assigned Restriction Types”. Here you will see various restriction fields available for configuration. Under Sales Area, you can find the Sales Organization field — exactly what we need.

    Find The Field Sales Organization Under Sales Area

     

  6. For both the Write and Read layers of the Sales Organization field, enter the values 1310 and 1320.

    Maintain Sales Org 1310 And 1320
  7. At this point, if you go back to the application and search for sales orders, you will find that nothing is returned. This is a common mistake that many people encounter.

    No Sales Orders Can Be Found
  8. The reason is that we have not yet configured all the required restriction fields. Go back to Maintain Restrictions. You will notice that the restriction types on the left side are still showing in yellow rather than green, meaning there are still fields that have not been maintained.

    Restriction Fields Not Maintained
  9. Since our goal is only to restrict access by Sales Organization, all other fields should be set to Unrestricted Access. Select those fields and choose “Unrestricted Access” from the top-right menu.

    Maintain Other Fields As Unrestricted

     

  10. Also make sure to set Distribution Channel and Division under Sales Area to Unrestricted as well.

    Maintain Distribution Channel And Division

     

  11. Now all restriction types on the left side should turn green, meaning every field has been properly maintained — either with specific restriction values or with Unrestricted Access.

    All The Fields Are Maintained

     

  12. Open the application again. You will now see that the user can only view sales orders belonging to Sales Organizations 1310 and 1320, exactly as intended.

    As Expected, User Can Only See The Sales Orders From 1310 And 1320

     


Key Takeaway: This demo uses Sales Organization as the example field. The same approach applies to other fields such as Company Code or Plant. The important thing to remember is: for any field you do not intend to restrict, always explicitly set it to Unrestricted Access. Leaving fields unconfigured (yellow state) will prevent the system from returning any results.

I hope this blog post is helpful to you. If you have any questions, feel free to leave a comment or send a private message. Thank you for reading!





Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

Chat with us on WhatsApp!