SAP Authorizations Note the maintenance status of permissions in roles and their impact - SAP Basis

Direkt zum Seiteninhalt
Note the maintenance status of permissions in roles and their impact
Unclear responsibilities, especially between business and IT
Especially in complex and multi-level system landscapes, roles may be assigned to a user twice. In addition, roles may also have expired due to the specification of a validity period. To keep your role concept and your user administration maintainable and clean, it is recommended to delete these obsolete roles. You can do this by clicking on the report PRGN_COMPRESS_TIMES. This program is also available via the PFCG under the system tab "Utilities" and category "Mass adjustment".

Other dangers include admins simply copying user roles, not having control processes for permission assignments, or not following the processes over time. In this context, two things should be clarified: Which SAP user is allowed to access which data? How do the roles differ (especially if they are similar)?
Our services in the area of SAP authorizations
Each roll can be written to any number of transport orders. Information about existing records of the same role by other administrators does not take place.

The customising parameters in the table PRGN_CUST control the password generator in the transactions SU01 and SU10. The values of the profile parameters override the customising parameter entries to prevent invalid passwords from being generated. If the value of a customising parameter is less than the value of the corresponding profile parameter, the default value of the customising parameter is drawn instead. The same is true if no value is maintained. You can exclude certain words or special characters as passwords by entering them in the USR40 table. In this table you can enter both specific passwords (e.g. your company's name) and patterns for passwords (e.g. 1234*). '*' stands for any number of additional characters (wild card) and '?' for any character. However, when maintaining the USR40 table, note that the number and type of entries affect performance.

"Shortcut for SAP systems" is a tool that enables the assignment of authorizations even if the IdM system fails.

You can view the contents of the checked permission fields by double-clicking on the respective variables.

You can evaluate the configuration of the operating system, the database, and profile parameters in the ABAP and Java systems.
SAP BASIS
Zurück zum Seiteninhalt