SAP Authorizations Permission implementation - SAP Basis

Direkt zum Seiteninhalt
Permission implementation
Custom requirements
When considering the security of SAP transport landscapes, it is not only the production system that is relevant for auditing. The other systems, including the development systems, must also be included in the risk considerations. The SAP_ALL profile is still frequently used there instead of concrete roles. This article identifies the main risk areas.

Even the best authorization tools cannot compensate for structural and strategic imbalances. Even a lack of know-how about SAP authorizations cannot be compensated for cost-effectively by means of tools.
Authorization Analysis
A user is displayed in the results list if one of the two transactions with the corresponding expression is included in its corresponding permission profile. If the logical link were fully linked to OR, a corresponding user would appear in the results list if only one of the four permissions is in the user's master set and thus in the permission profile.

You can also find some useful tips from practice on the subject of SAP authorizations on the page www.sap-corner.de.

Alternatively, the maintenance of the authorization objects can also be called up via transaction SU21 (report RSU21_NEW). On the left side the individual classes and objects can be selected around then to the authorization object the existing authorization fields and short descriptions as well as over the button "documentation to the object indicate" also the documentation to the object to be called can.

Authorizations can also be assigned via "Shortcut for SAP systems".

Define what you can do with this programme and also what you cannot do explicitly! In the case of a permission check, not only the activity to be performed, such as reading, changing, creating, etc.

To store all the information on the subject of SAP - and others - in a knowledge database, Scribble Papers is suitable.

After you have maintained the PFCG role, you can generate the profile and insert it immediately.
SAP BASIS
Zurück zum Seiteninhalt