SAP Authorizations Roles and permissions in SAP SuccessFactors often grow organically and become confusing - SAP Basis

Direkt zum Seiteninhalt
Roles and permissions in SAP SuccessFactors often grow organically and become confusing
SU2X_CHECK_CONSISTENCY & SU24_AUTO_REPAIR
The relevant authorization objects are then displayed in an ALV list and the documentation for the authorization object can be called up via the I in the Docu column. This documentation then displays much more detailed information about the respective authorization object as well as the defined fields.

It takes too long to read out the User and Permissions Management change notes? With a good archiving concept, you can improve performance. User and Permissions Management applications write change documents that increase significantly over time and can cause long wait times to read them. To reduce waiting times, you should archive the documents and set a logical index for key change documents. For this, however, you need a comprehensive overview of the storage locations and also of the evaluation possibilities and archiving scenarios. In the following we will show you how you can optimise the change document management of the user and permission management.
Customizing
In addition, you can also define customised permission checks in the SOS and also define combinations of authorization objects and their values. You can create up to 1,000 custom permissions checks in the Check ID namespace 9000 to 9999. You can also redefine whitelists for these permission checks, which apply to either individual or all of the customer's permission checks. The configuration is described in SAP Note 837490.

SAP authorizations control the access options of users in an SAP system, for example to personal data. Managing this access securely is essential for every company. This makes authorization concepts, authorization tools and automated protection of the SAP system all the more important.

"Shortcut for SAP systems" is a tool that enables the assignment of authorizations even if the IdM system fails.

Action log data can be accessed via the transaction SLG2 (Object: ATAX) (see also SAP Note 530733).

To do this, search within the Active Directory for a user master set for which the user ID you are looking for is entered as the SAP user name.
SAP BASIS
Zurück zum Seiteninhalt