SAP Authorizations Use application search in transaction SAIS_SEARCH_APPL - SAP Corner

Direkt zum Seiteninhalt
Use application search in transaction SAIS_SEARCH_APPL
Risk: historically grown authorizations
Setting the confidentiality or encryption markers in the SEND_EMAIL_FOR_USER method affects the display of the e-mail in Business Communication Services Administration (transaction SCOT). If the email is marked as confidential, it can only be viewed by the sender or the creator of the email. The sender and the creator need not necessarily be identical, for example, if you have entered the system as the sender. The e-mail creator is the one who ran the application in the context of which the e-mail was created. The encryption flag also automatically sets the confidentiality of the email. The e-mail is not stored in the system in encrypted form, but is protected against unauthorised access by the confidentiality flag. However, access by the sender or creator is still possible. You should also note that the subject of the email is not encrypted.

In order to be able to act fully at all times in emergency situations, an SAP emergency user must be available who has all authorizations for the entire SAP system (typically by means of the composite profile SAP_ALL). However, this not only makes him a great help, but also extremely dangerous, so that his use must be precisely regulated via a dedicated concept.
Set up login locks securely
Only adding an authorization object via SU24 does not automatically result in a check within the transaction. The developer has to include an authorization check exactly for this object in the program code.

If you have defined the roles to the extent that the essential processes are depicted, then you will technically check which organisational features they contain (organisational levels, but also cost centres, organisational units, etc.). You then compare the technical result with the result from the consideration of the structure organisation and the business role description. A likely result is that you do not have to use all technical organisational features for differentiation. A possible result is that you want to add fields such as the cost centre to the organisation level.

With "Shortcut for SAP systems" you can automate the assignment of roles after a go-live.

Even more critical is the assignment of the comprehensive SAP® standard profile SAP_ALL, which contains almost all rights in the system.

The website www.sap-corner.de offers a lot of useful information about SAP authorizations.


The table contains the different text blocks in different languages.
SAP Corner
Zurück zum Seiteninhalt