IT CanvassTalk to an advisor
SAP administration · LessonBy , SAP Trainer, 13 yrs · Published · SAP S/4HANA 2023 · all levels

RFC

RFC administration manages the connections (RFC destinations) that let SAP communicate with other SAP and external systems, and secures them. Because RFC underpins most integration, healthy, secure RFC configuration is essential.

Quick answer

RFC is powerful, so it is a security focus: destinations should use least-privileged service users (not dialog users with wide access), the gateway should be secured against unauthorised registered programs, and trusted-RFC relationships must be controlled.

Key takeaways
  • An RFC destination, maintained in SM59, defines how to reach another system: its type (ABAP connection, TCP/IP, HTTP), target host…
  • Create and test destinations in SM59 (there is a built-in connection test).
  • Manage the credentials/users destinations log on with (least privilege).
  • Watch out: Dialog/over-privileged users in RFC destinations.

RFC destinations (SM59)

An RFC destination, maintained in SM59, defines how to reach another system: its type (ABAP connection, TCP/IP, HTTP), target host, and logon credentials. Interfaces, BAPIs called remotely, ALE/IDoc distribution and many integrations all rely on correctly configured destinations.

Administering RFC

  • Create and test destinations in SM59 (there is a built-in connection test).
  • Manage the credentials/users destinations log on with (least privilege).
  • Maintain trusted-system relationships where used.
  • Adjust destinations after system copies (they inherit the source’s settings).

Security is paramount

RFC is powerful, so it is a security focus: destinations should use least-privileged service users (not dialog users with wide access), the gateway should be secured against unauthorised registered programs, and trusted-RFC relationships must be controlled. Insecure RFC is a well-known attack path.

Troubleshooting

RFC failures, connection refused, logon failed, authorization missing, are among the most common integration issues. SM59’s connection test and the target system’s logs usually reveal the cause quickly.

Common pitfalls

  • Dialog/over-privileged users in RFC destinations.
  • Insecure gateway allowing rogue registered programs.
  • Stale destinations after a system copy pointing at the wrong system.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
Which statement is true of RFC?

Frequently asked questions

What does RFC stand for, and how is it used in SAP Basis administration?
RFC administration manages the connections (RFC destinations) that let SAP communicate with other SAP and external systems, and secures them. Because RFC underpins most integration, healthy, secure RFC configuration is essential.
What is connected to RFC in an SAP landscape?
An RFC destination, maintained in SM59, defines how to reach another system: its type (ABAP connection, TCP/IP, HTTP), target host, and logon credentials.
What is the practical takeaway on RFC?
RFC is powerful, so it is a security focus: destinations should use least-privileged service users (not dialog users with wide access), the gateway should be secured against unauthorised registered programs, and trusted-RFC relationships must be controlled.
What tends to go wrong with RFC in SAP Basis administration?
Dialog/over-privileged users in RFC destinations. Insecure gateway allowing rogue registered programs. Stale destinations after a system copy pointing at the wrong system.
Already working on SAP and stuck on a live ticket?Get an expert SAP developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support