SAP Authorizations Audit Information System Cockpit - SAP Stuff

Direkt zum Seiteninhalt
Audit Information System Cockpit
Deletion of change documents
Create a function block in the Customer Name Room. You can choose the supplied SAMPLE_INTERFACE_00001650 as the template. For us, it has proven itself, in the name of the new function block, the name BTE and the number of the template (here: 1650).

The S_RFCACL authorization object is removed from the SAP_ALL profile by inserting SAP Note 1416085. This notice is included in all newer support packages for the base component; This affects all systems down to base release 4.6C. The reason for this change is that the S_RFCACL authorization object, and especially the expression "total permission" (*), is classified as particularly critical for its fields RFC_SYSID, RFC_CLIENT and RFC_USER. These fields define from which systems and clients or for which user IDs applications should be allowed on the target system. Thus, the overall authorisation for these fields allows the login from any system and client or for any user and thus creates significant security risks.
Set up permission to access Web Dynpro applications using S_START
The organisation of a company is represented in the SAP system. Keep an overview here to identify dependencies and control access permissions in an organisation-specific way. In customising, different organisational values are stored for the individual ERP components to enable an organisational mapping of the root and movement data. This mapping is required, among other things, to control access permissions or constraints. We will show you how you can get an overview of the well-maintained organisational units and see dependencies between the different organisational values.

With "Shortcut for SAP systems" you can automate the assignment of roles after a go-live.

You can also find some useful tips from practice on the subject of SAP authorizations on the page "www.sap-corner.de".

Depending on the requirements, the suggested values provided by SAP may be sufficient or need to be supplemented.

SAP Stuff
Zurück zum Seiteninhalt