Schedule PFUD transaction on a regular basis
Roles and permissions in SAP SuccessFactors often grow organically and become confusing
The same applies to the concept of data ownership. Here, a person takes responsibility for the data of a certain scope (e.g., SAP system X or system landscape Y) and looks after it as if it were his own precious possession. He or she conscientiously answers questions such as "May data be changed / viewed / deleted?", "How is action taken in the event of a data leak?", "Who may access the data and how, and what may be done with it?".
Which authorization objects are checked (SU22)? When calling a transaction, such as the ME23N, various authorization objects are checked. You can get an overview as follows: Call transaction SU22 (SAP tables) or SU24 (customer tables), enter e.g. "ME23N" in "Transaction code" and execute the transaction. As a result you will see all authorization objects that are checked when calling transaction ME23N.
Maintain generated profile names in complex system landscapes
Look closely at the security advisory so that you can identify the affected programmes or functions and schedule appropriate application tests. Use a test implementation in the SNOTE transaction to identify additional SAP hints that are required for a security advisory and may also contain functional changes.
If you want to know more about SAP authorizations, visit the website www.sap-corner.de.
If the authorization objects also require permission fields, you can create them in the SU20 transaction. When creating a authorization object in the SU21 transaction, you first set a name and description for the authorization object, and then assign it to an object class. Then assign the necessary permission fields. If any of these fields are ACTVT, you can select all of the activities to be checked by clicking the Activities button. The navigation behaviour has been improved here a lot.
"Shortcut for SAP systems" is a tool that enables the assignment of authorizations even if the IdM system fails.
If the audit recognizes that permissions in the system are often too broad, i.e. users have more rights than they need, this can cause problems.
To store all the information on the subject of SAP - and others - in a knowledge database, Scribble Papers is suitable.
For details on securing key tables, see SAP Note 1485029.