
About this episode
Listen to the SAP Security & GRC podcast – helping you on your journey to effective access risk management in SAP.
In this episode, Ross Robertson walks through the SAP short-term user authority check trace (STAUTHTRACE) – a real-time authorisation trace that captures both successful and failed authority checks as users execute transactions, Fiori apps, and RFC calls. Think of it as a far more powerful evolution of the classic SU53 report.
🔑 Key Takeaways:
What STAUTHTRACE is and how it differs from the classic SU53 report
How to activate the trace system-wide or on a specific application server
Why STAUTHTRACE runs on a rolling memory buffer with minimal system impact – so you can leave it active long-term
How to filter results by user, date/time, application type, application name, authorisation object, and check result
A live troubleshooting walkthrough: diagnosing a failed SU01 user-change authorisation (S_USER_GRP)
Reading both passed and failed checks – including table access checks in SE16 (e.g. EKKO) and CDS view entity checks in S/4HANA
Inspecting the user buffer via SU56
👥 Featuring:
Ross Robertson – Senior SAP Authorisations Consultant, Soterion
Get every episode summarized
Each time SAP Security & GRC publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from SAP Security & GRC

How to Set up and Analyse STUSOBTRACE
SAP Security & GRC

How to Set Up and Analyse STUSERTRACE
SAP Security & GRC

How to Convert an Authorisation Field into an Organisational Level Field
SAP Security & GRC

Technical Series: Using LSMW in SAP Authorisation Management
SAP Security & GRC