Insights · SAP Basis
Creating, deleting and configuring an SAP client in SCC4
Before a client copy can run, the target client has to exist. It is created in SCC4, and the settings there determine who may change what in the client and whether it can be overwritten. This article explains how to create a new SAP client, log on safely, populate it and delete it again.
Creating a new SAP client in SCC4
In SAP, a client is initially just an entry in table T000. This table is maintained with the transaction SCC4 (client administration). This is how you create a new client:
- Provide the logical system. If the client is to exchange data with other systems, create its logical system name in BD54 beforehand, following the usual convention, for example QASCLNT200.
- Open SCC4. The client overview appears in display mode. Use Display ↔ Change to switch to change mode.
- Choose New Entries. Enter the client number, name, city, logical system and standard currency.
- Set role, change options and protection. In line with the purpose of the client. The next section explains what the fields mean.
- Save. The client is now in client table T000. That is all it is so far: Customizing, application data and users are still missing.
- Populate. Fill the client with a client copy and then complete the follow-up tasks.
The new client is empty. Only the copy brings in Customizing, users and, if required, application data. Which clients belong in which system is described in the article Client strategy and system landscape.
The settings in SCC4
The detail view of a client in SCC4 contains these fields. The first four describe the client; the others control what is permitted in it.
| Field | What it defines |
|---|---|
| Client | Three-digit number that is not yet in use in the system. 000 is the SAP reference client. |
| Name and city | Free text for orientation, for example ‘QA Finance’ and ‘Hamburg’. |
| Logical system | Name of the client as a communication partner, for example for ALE and IDocs. Optional, but required as soon as the client exchanges data with other systems. |
| Standard currency | Currency key of the client, for example EUR. |
| Client role | Production, Test, Customizing, Demo, Training/Education or SAP reference. |
| Changes and transports for client-specific objects | Whether Customizing may be changed in this client and whether the changes are automatically recorded in transport requests. |
| Cross-client object changes | Whether repository objects and cross-client Customizing may be changed from this client. |
| Protection: client copier and comparison tool | Whether the client may be overwritten or used as a source for copies and comparisons. |
| Restrictions for CATT and eCATT | Whether test scripts with eCATT or its predecessor CATT may run in the client, optionally only via trusted RFC. |
Client role
The role describes the purpose of the client, and it has an effect. SAP KBA 2391632 describes the case where SCCL, SCC9 or SCC1 terminate in a client with the role Production: message TA133, stating that the target client is productive and protected against client copy. So assign the role Production only to the real production client and the role Test to QA and test clients.
Changes and transports for client-specific objects
- Automatic recording of changes: Every Customizing change is recorded in a transport request. This is the setting for the Customizing client in the development system.
- Changes without automatic recording: Changes are allowed but are not automatically recorded in a transport request.
- No changes allowed: Customizing only enters the client by transport. Usual for production and QA clients.
- Changes without automatic recording, no transports allowed: Changes remain in the client and cannot be transported, not even manually. This keeps a sandbox client cleanly separated from the transport route.
Cross-client object changes
Repository objects such as programs and table definitions, as well as cross-client Customizing, apply to all clients in a system. A change in one client takes effect immediately in all others. SCC4 offers four levels: both allowed, only cross-client Customizing locked, only the repository locked, or both locked. Only allow such changes in the Customizing client of the development system.
Protection against the client copier and comparison tool
- Level 0, no restriction: The client may be overwritten, copied and compared.
- Level 1, no overwriting: The client remains a source for copies and comparisons but cannot be overwritten. Usual for production clients.
- Level 2, no overwriting and no external availability: In addition, nobody can use it as a source for copies or comparisons.
Logging on to the new client: SAP* and profile parameter
A newly created client does not yet have any users. However, the classic tools SCCL and SCC9 are started in the target client. User SAP* is intended for this. If there is no user master record for SAP* in a client, a user of this name that is hard-coded in the system takes effect: password PASS, no authorisation check, and therefore all rights.
By default, this logon is blocked by the profile parameter login/no_automatic_user_sapstar. For a classic copy, you temporarily set it to 0 and restart the application server.
Security risk. The parameter does not apply to a single client but to all of them. As long as it is set to 0, anyone with the well-known password can log on as SAP* in every client without a user master record for SAP* and has all authorisations there. Keep this window as short as possible.
- After the copy, reactivate the parameter (value 1) and restart the application server again
- Do not delete SAP*: SAP recommends creating a user master record for SAP* in every client, assigning it to user group SUPER and removing all its authorisations except for licence administration
- For emergencies, create a separate superuser of type Service with an emergency role for user administration instead of working with SAP*
From SAP_BASIS 7.54, i.e. from S/4HANA 1909, this detour is no longer necessary. The new tools such as SCCLN and SCC9N do not have to run in the target client. SAP recommends starting them from a third, uninvolved client, for example 000. SAP* and the restart are no longer needed. What else the new tools change is shown in the article on SCCLN, SCC9N and SCC1N.
Populating the new client
What goes into the client is determined by the client copy: locally from a client in the same system, remotely from another system or by export and import. The copy profile determines whether only Customizing, the users as well, or also the application data is transferred. Both are explained in the basics article on SAP client copy.
- First client of a new system: Copy from reference client 000 with profile
SAP_CUST. The application data in 000 is not guaranteed to be consistent and does not belong in the new client. - Additional client in the same system: local copy, for example for a training or test client.
- QA or test client with production-like data: Copy from production. Afterwards, the logical system names have to be converted, see BDLS after a system or client copy.
From SAP_BASIS 7.54, transaction SCC_CLIENT_SIZE estimates in advance how much space the copy needs. This is worthwhile, because in SAP HANA the copied data resides in main memory. You check the copy runs in SCC3, followed by the follow-up tasks after the copy.
Deleting an SAP client: SCC5 and SCC5N
Clients that nobody needs any more take up space and still have to be secured. Delete them with the client administration tools. Back up anything you still need beforehand, for example by client export.
Classic method with SCC5: You log on to the client you want to delete and start SCC5. Optionally, you remove the entry from T000 at the same time; otherwise the empty client remains listed in SCC4. Parallel processes shorten the runtime.
From SAP_BASIS 7.54 with SCC5N: Here you do not have to log on to the client concerned; instead, you select it from a list. SCC5N also asks whether the entry in T000 is to be deleted as well. In addition, there is a test mode, parallel processes and the option of starting it as a background job.
SAP Help points out that in most databases the space freed up only becomes available after a reorganisation. Plan for this if you want to gain space by deleting clients.
Common errors and pitfalls
- Copy terminates immediately: The target client has the role Production or a protection level that prohibits overwriting. Check in SCC4 whether this is intentional before you change anything.
- SAP* remains open: The profile parameter was set to 0 for the copy and not reset afterwards.
- Logical system missing or assigned twice: Documents and IDocs then refer to the wrong partner. After every copy from production, convert the names in the data.
- Change options too generous: If Customizing may be changed in the QA client, QA and production drift apart unnoticed, and tests lose their validity.
- Wrong client deleted: SCC5 always deletes the client you are logged on to. Check the client number twice before starting.
- Full copy without memory planning: In SAP HANA, an additional client with all application data needs almost as much additional main memory as the source client occupies.
Prepare the target client, populate it with DRO
Creating the client, setting the role, securing it: you do all this in SCC4. What remains open is what you fill the client with. Along with the application data, the standard client copy always brings the complete history. The Data Refresh Operator instead copies a time slice, for example the last 90 days, plus all dependent objects from earlier years, resolved up to the fixpoint. DRO replaces logical system names during the import, before the data is written to the database. No subsequent BDLS run is needed.
Two levels work independently of each other to protect production. In DRO, system roles prevent imports into production. In SAP, the client role Production and the protection level in SCC4 ensure that the standard tools do not overwrite the production client. If you maintain both, protection does not depend on a single setting.
Playbooks automate the surrounding procedure: suspending jobs, locking users, backing up user master records, importing, completing customer-specific follow-up tasks. DRO runs on SAP S/4HANA from release 2023 and replaces the client copy, not the system copy. What such a procedure looks like is shown in the sample playbook.
Sources
- SAP PRESS Blog, 17 November 2023: How to Create Clients in an SAP S/4HANA System
- SAP Help: Client Copier: target client, user SAP* and profile parameter (SAP NetWeaver 7.3)
- SAP Help: Securing User SAP* Against Misuse
- SAP Help: Deleting Clients (SAP NetWeaver 7.3)
- SAP Learning: Client Copy and Client Transport Tools (SCCLN, SCC9N, SCC5N, SCC_CLIENT_SIZE)
- SAP KBA 2391632: TA133: Target client is productive and protected against client copy (SAP Support Portal, login required)