Hello Abhishek,
You should have administration authorization on all clients when you are configuring CUA.
But CUA users (that are used in RFCs) don't need SAP_ALL auhts. They can be system type users and there are speciala roles for them.
You can check your configuration and follow below links.
Central User Administration(CUA) configuration - Basis Corner - SCN Wiki
These are my notes. They may help.
Central System
BD54
METCLNT100
METCLNT001
MSTCLNT001
SU01
CUA_MET (System)
ZSAP_BC_USR_CUA_CENTRAL
ZSAP_BC_USR_CUA_CENTRAL_BDIST
ZSAP_BC_USR_CUA_SETUP_CENTRAL
CUA_MST (System)
ZSAP_BC_USR_CUA_CENTRAL
ZSAP_BC_USR_CUA_CENTRAL_BDIST
ZSAP_BC_USR_CUA_SETUP_CENTRAL
RFC
METCLNT100 CUA_MET
METCLNT001 CUA_MET_001
MSTCLNT001 CUA_MST_001
CHILD 1 MET 001
BD54
METCLNT100
METCLNT001
MSTCLNT001
SU01
CUA_MET_001 (System)
ZSAP_BC_USR_CUA_CLIENT
ZSAP_BC_USR_CUA_SETUP_CLIENT
SM59
METCLNT100 CUA_MET
CHILD 2 MET 001
BD54
METCLNT100
METCLNT001
MSTCLNT001
SU01
CUA_MST_001 (System)
ZSAP_BC_USR_CUA_CLIENT
ZSAP_BC_USR_CUA_SETUP_CLIENT
SM59
METCLNT100 CUA_MET
SCUA--> CUA Create
Regards,
Yuksel AKCINAR