
You can use the RSUSR030 report to display authorization data in a client. You can call the report and its variants by choosing the area menu nodes User > Authorizations by Complex Selection Criteria in transaction code SUIM. The variant “Authorizations by Complex Selection Criteria” covers all of the possible selection criteria.

Selection
To determine authorizations with particular characteristics, restrict the selection by making specifications in the fields. If you execute the report without making any specifications, all authorizations in the current client are displayed.
The selection screen consists of a number of different selection criteria:
Selection criteria
- Authorization Object
- Authorization
- Authorization Text
- Active Version
- Maintenance Version
- Object Class
Selection by values
- Always Convert Values
- Converts the selected values in accordance with the conversion exit SAP Note 667409 defined, for the maintenance of authorizations, that conversion exits are used in general for authorization fields. The checkbox “Conversion for authorization fields allowed”, which can be used in the authorization object maintenance tool (transaction SU21), has been ignored since then in the maintenance transactions PFCG and SU03.
- However, this object-related characteristic is still taken into account in the SUIM reports, meaning that there can be differences between the maintenance transactions and the information system in input field properties for an authorization field.
- In these cases, search variants entered in the information system do not take into account certain field properties (such as leading zeroes).
- Authorization Object 1 (2, 3, or 4)
- Full authorization refers only to the authorization that is defined with an asterisk (*) (search pattern ‘#’). Authorizations that contain all possible values for a field are not taken into account for this search criterion.
- Authorization objects and their authorization values. A maximum of four authorization values can be entered for each authorization field.
- If you enter the search pattern ‘#’, the system finds only the authorizations for which the number of values for a field corresponds to the complete set of all possible values.
- The search for complete sets of all possible values is restricted to fields that have either fixed values or check tables. For fields with free value specifications, it is not possible to search for the complete set of all possible values.
- When searching for the complete set of all possible values, only the values that give the complete set in one authorization are taken into account. This means that users, roles, or profiles that have the complete set of all possible values due to a combination of several authorizations are not taken into account here.
- Note that the four authorization objects are analyzed using an OR linkage, since an authorization always applies only for one authorization object. The first part of the selection, “Selection Criteria” is linked with all other selection fields with an AND linkage. A search for an authorization object from the “Selection Criteria” and for an authorization object from the “Selection By Values” will always return an empty results list, if it relates to two different authorization objects.
- Additional Selection Criteria for Authorizations
- Last Changed By
- Last Change Since
- Last Change To



