Manage SAP Business One access rights
22 Feb

Manage SAP Business One access rights

The administration of SAP Business One access rights plays a central role. This can quickly become a challenging aspect of SAP B1 management, which is why a thorough understanding of the functions available in SAP Business One is essential. In this guide, we look at the effective organisation of user rights within SAP Business One.

General authorisations in SAP Business One

SAP Business One provides a number of functions that enable specific access rights to be customised and configured for individual user access. This not only makes it possible to define access rights for individual users, but also offers the option of transferring these settings to other user profiles. The assignment of these access rights is generally based on the SAP Business One menu options and is divided into three main levels depending on the type of authorisation:

  • Full access
  • Read access
  • No access

By default, newly created user profiles are initially not granted access in any area, which serves as an effective security measure to prevent new users from automatically being granted unrestricted access. These basic access rights are then used to define the specific user authorisations.


It is important to note that Superuser are an exception in SAP Business One. Full access rights are always displayed for them in the basic authorisation settings. These cannot be modified. The reason for this is that superusers by definition have all authorisations, including the assignment of authorisations, which makes the assignment of specific user rights superfluous.

Flexible setting of access rights in SAP Business One

In SAP Business One, access rights can also be assigned in a comprehensive way by applying them across an entire hierarchy tree. This means that it is possible to assign access rights to a user based on the name of a module (for example "PURCHASE") to assign specific rights. In this way, all associated sub-functions of the purchasing module are automatically assigned the same rights. From this point, it is then possible to individually assign different access rights to certain functions within this hierarchy tree. This procedure offers considerable time savings, especially if almost all functions within a module are to be released, with the exception of a few specific functions that are to remain restricted. In such cases, a fourth access level is practically created, namely "MIXED AUTHORISATIONS". This level reflects the situation described, but cannot be set directly.

It is also possible to search within the structure tree specifically for individual Authorisations to search. The "SEARCH" search field above the authorisation tree is available for this purpose. Please note, however, that the exact name of the authorisation you are looking for must be known for a successful search; the use of wildcards is not possible.


The need to assign authorisations remains, despite the restrictions that the so-called Limited licences of SAP Business One entail. These licences define limits that also apply if authorisations would theoretically grant access to functions requiring a licence. However, it is possible that the conditions of the limited licence may change and there is no guarantee that users with restricted access rights will not still be able to access certain functions.

Efficient transfer of user rights in SAP Business One

If a user already has the appropriate access rights, it is possible to transfer these settings to other users who work on similar tasks. There is a special function for this purpose below the list of user profiles. With this option, you can easily apply the selected rights of a specific user to several other users. Alternatively, this can also be done via drag & drop from the user table of the general authorisations.

Extended user rights and their monitoring

In addition to the basic access rights, which are configured as a tree structure within the authorisation overview, there are three further important authorisation settings below this overview specifically for each user. These additional settings are displayed in a clear table format. All modifications to the basic authorisations are subject to continuous monitoring and can be tracked at any time in the SAP Business One change log (under the menu item EXTRAS > CHANGE LOG).

User groups in authorisation management with SAP Business One

Authorisation management with SAP Business One

The main purpose of user groups is to collectively assign rights to users with similar areas of responsibility, although individual customisations are still possible for each user. User groups are set up via the path ADMINISTRATION > DEFINITION > GENERAL. It is important to mark the group type as either AUTHORISATION or ALL TYPES to ensure that the group is available later when assigning general authorisations. The assignment of specific rights to a user group also takes place in this area, whereby care must be taken to ensure that the GROUPS tab is selected. The familiar tree structure, which displays individual authorisations, also applies to groups. It is also possible to transfer the rights of a group to other groups, either using the COPY AUTHORISATIONS function or via drag & drop.

Effective authorisation of an SAP B1 user

It becomes particularly interesting when you analyse the permissions of a user who is a member of one or more groups and also has individual permissions. In such cases, the EFFECTIVE AUTHORISATION column on the USER tab provides valuable insights. This shows the authorisation that ultimately applies to the user, while the AUTHORISATION column only reflects the user's directly assigned rights. Due to possible differences due to group membership, the effective authorisation can be viewed in more detail by clicking further.


There is no specific "deny" status for authorisations in SAP Business One. Therefore, all authorisations granted in this system, both at individual user level and at group level, are considered together. This means that the most comprehensive authorisation level assigned is automatically adopted for the user. This procedure should be observed in particular when authorisations are distributed that are also based on group memberships.

Customisable access rights for extensions

SAP Business One can be functionally expanded with various extensions, such as add-ons. In order to integrate these additional functions appropriately, SAP Business One provides extended access settings. These can be found in the menu under ADMINISTRATION > SYSTEM INITIALISATION > AUTHORISATIONS. These special authorisation settings make it possible to define additional authorisations for users and user groups. This applies even if the basis of these authorisations - the extensions - are not part of the standard scope of SAP Business One.

Creation of customised authorisation hierarchies

The extended access rights in SAP Business One can be organised in a hierarchy similar to a tree structure. Using special options such as "ADD EQUAL ELEMENT" and "ADD SUBORDINATE ELEMENT", it is possible to create detailed authorisation structures that are precisely tailored to the requirements of specific extensions.

Integration of individual authorisations via form IDs

SAP B1 additional authorisations

The allocation of additional access rights is always based on the assignment of a specific form ID. This must always be specified when setting up the authorisations. A crucial element in this process is the "ELEMENT" checkbox. This determines whether the entry in question represents an authorisation for an entire window or whether it is a specific authorisation element within an SAP Business One window. This can be a text box or a button, for example. This authorisation element can then be linked to one or more form IDs.

Assignment of extended access rights to users and groups

The assignment of these extended access rights to individual users or groups is handled within the general authorisations area. The overview of user authorisations appears at the end of the list of authorisations. This section lists all the authorisation elements that have been defined within the extended authorisation settings.


Extended access rights can also be created via the SAP Business One SDK (Software Development Kit). This offers add-on developers the option, implement their own functionality. They can also also provide appropriate authorisation mechanisms for these functions.

Data ownership in SAP Business One

The data ownership function in SAP Business One allows you to define exactly who is considered the data owner. This function enables the assignment of data and information ownership. As a result, company data and personal information can be managed securely using preset access rights. In this way, access to data and information is reserved exclusively for users and roles with appropriate authorisations.

To activate the data ownership features, navigate to Administration > System initialisation > General settings in the SAP Business One main menu and tick "Activate data ownership" under the GP tab.

Instructions for setting up data ownership:

  • To define data access rights, go to the SAP Business One main menu and select Administration > System initialisation > Authorisations > Data ownership > Authorisations for data ownership.
  • To establish rules for sharing data ownership with documents and business partners, select in the main menu: Administration > System initialisation > Permissions > Data ownership > Options for sharing data ownership.
Contact Versino
UPDATE Versino Financial Suite

MARIProject 8.0.000: New design, expanded production and optimised processes

With MARIProject 8.0.000, users get a revised design with flexible Horizon themes, closer integration with the SBO Web Client and ...
SAP B1 update

New features in SAP Business One 10.0 FP 2508

With the FP 2508 feature package for SAP Business One 10.0, SAP is clearly focussing on the web client - ...
Accruals and deferrals SAP Business One

Accruals and deferrals in SAP Business One

The annual financial statements have their very own pitfalls. One of the most intriguing challenges is the timing of business transactions. Because anyone who thinks that expenses ...
SAP Business One Web Client

SAP Business One web client - additional feature or strategic step

For a long time, the SAP Business One web client was regarded as additional - a tool for isolated use cases. However, with the current functional developments ...
SAP B1 Elster 2025

Elster 2025 for SAP Business One

Companies must update the ELSTER add-on for SAP Business One at the start of the 2025 tax year. This measure ensures the legally compliant transmission ...
FAQ e-bill

E-bill 2025 FAQs

The introduction of e-billing is a significant step towards digitalisation and more efficient business processes. However, it also raises many ...
Wird geladen …