SAP Authorizations ICS for business processes in SAP systems - NW Admin

Direkt zum Seiteninhalt
ICS for business processes in SAP systems
Existing permissions
For an authorization concept, a clear goal must be defined that is to be achieved with the help of the concept. This should list which regulatory requirements the respective system and the associated authorization concept must take into account. In this way, the legal framework is defined, which is a legal necessity for successful implementation.

A user reports that he or she is receiving a permission error even though you have granted him or her the required permissions. This could be due to a faulty buffering of the permission data. Although a user has been assigned a role with the correct permission data, this user is presented with a permission error due to missing permissions. This may be surprising at first glance, but it can almost always be fixed by a short analysis.
In the transaction, select SU10 by login data of users
You assign a reference user to a dialogue user by registering the reference user for additional rights in the SU01 transaction on the Roles tab in the Reference User field. If you are using Central User Administration (ZBV), the assignment applies to all connected systems. If the reference user does not exist in one of the systems, the mapping is ignored. However, the use of reference users also creates risks. This makes it easier to summarise permissions because it is difficult to keep track of the assigned permissions. In SAP NetWeaver AS ABAP 7.0 and above, reference users are considered in the reports of the user information system.

To store all the information on the subject of SAP - and others - in a knowledge database, Scribble Papers is suitable.


The assignment of combinations of critical authorizations (e.g., posting an invoice and starting a payment run), commonly known as "segregation of duties conflicts," must also be reviewed and, if necessary, clarified with those responsible in the business departments as to why these exist in the system. If compensating controls have been implemented for this purpose, it is helpful if the IT department also knows about this so that it can name these controls to the IT auditor. The IT auditor can then pass this information on to his or her auditor colleagues.

Authorizations can also be assigned via "Shortcut for SAP systems".

An ABAP programme now allows you to write the counterparts for the text fields in the target language into the fields in the tables.

It must therefore be ensured that these authorizations have not been assigned to any user, not even to SAP® base administrators.
NW BASIS
Zurück zum Seiteninhalt