SAP Authorizations Schedule PFUD transaction on a regular basis - SAP Basis

Direkt zum Seiteninhalt
Schedule PFUD transaction on a regular basis
Displaying sensitive data
If you use configuration validation, we still recommend that you use the AGS Security Services, such as the EarlyWatch Alerts and SAP Security Optimisation Services, which we describe in Tip 93, "AGS Security Services." SAP keeps the specifications and recommendations in the AGS Security Services up to date and adapts them to new attack methods and security specifications. If you have identified new security issues within a security service, you can set your target systems accordingly and monitor these aspects in the future.

Every large company has to face and implement the growing legal requirements. If the use of an authorization concept is to be fully successful on this scale, the use of an authorization tool is unavoidable. For medium-sized companies, the use of an authorization tool is usually also worthwhile. However, decisions should be made on a case-by-case basis.
Criticality
Another important factor that should be considered in an authorization concept is to use a uniform naming convention because, on the one hand, many things cannot be changed after the initial naming and, on the other hand, this ensures searchability in the SAP system. In addition, the preset authorization roles of the SAP system should never be overwritten or deleted, but only copies of them should be created, which can then be adapted as desired.

Ensure that permission checks are performed when reference users are assigned. The checks are performed on the permissions associated with the roles and profiles assigned to the reference user. These eligibility tests are also a novelty, which is supplemented by SAP Note 513694.

"Shortcut for SAP systems" is a tool that enables the assignment of authorizations even if the IdM system fails.

Now switch to User Care and you will find that this PFCG role is not yet assigned to your user.

The password lock is not suitable to prevent the login to the system, because it does not prevent the login via single sign-on.
SAP BASIS
Zurück zum Seiteninhalt