<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Profiles for Basis Admins in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984979#M1161385</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think idea here should be to understand the process more than giving actual values for such kind of posts. If, Lee were to make a role directly based on these tcodes what would be his justification as a security consultant for having provided these values.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Every company would have its own unique policy for authorizing Basis consultants.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some may want the consultants to be authorized with relevant tasks like system admin or database admin or security admin or user admin seperately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While some may want these tasks to combined by one group of consultants.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also want to provide the display access to all functional tcodes to the security roles as it may be needed more often or not to solve the authorization issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would rather stick to the security policy of my company and the job rrequirements of the consultant when designing these roles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Jan 2009 07:24:15 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-01-02T07:24:15Z</dc:date>
    <item>
      <title>Profiles for Basis Admins</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984976#M1161382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone have a list of transactions that would be considered adequate for a basis administrator on a production system, which would allow them to do all the work they may need to without logging in with a sap_all id?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the best practice for access for basis in production?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jan 2009 21:25:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984976#M1161382</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-01T21:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: Profiles for Basis Admins</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984977#M1161383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may use the SAP delivered standard roles and create a copy of the same according to your convenience. The roles in the standard system like:&lt;/P&gt;&lt;P&gt;SAP_BASIS_ADMIN	Admin role for basis people&lt;/P&gt;&lt;P&gt;SAP_BC_BASIS_ADMIN	System Administrator&lt;/P&gt;&lt;P&gt;SAP_BC_AUTH_DATA_ADMIN	Authorization Data Manager&lt;/P&gt;&lt;P&gt;SAP_BC_AUTH_PROFILE_ADMIN	Authorization Profile Administrator&lt;/P&gt;&lt;P&gt;SAP_BC_BATCH_ADMIN	Background Processing Administrator&lt;/P&gt;&lt;P&gt;SAP_BC_BDC_ADMIN	Batch Input Administrator&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and more can be used to suit your requirements.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jan 2009 04:12:59 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984977#M1161383</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-02T04:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: Profiles for Basis Admins</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984978#M1161384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Lee-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can understand where are you coming from :). You needed the list of all possible basis tcodes in production environment rather adopting strenuous task of deriving and identifying all required functionality from SAP Standard role template for basis. Not an issue &lt;SPAN __jive_emoticon_name="grin"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can refer the tcodes listed below in production environment. It includes all required for regular support, monitoring &amp;amp; performance analysis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SSO2	 Workplace Single Sign-On Admin.&lt;/P&gt;&lt;P&gt;STRUSTSSO2	 Trust Manager for Logon Ticket&lt;/P&gt;&lt;P&gt;BD82	 Generate Partner Profiles&lt;/P&gt;&lt;P&gt;SMT2	 Trusting systems (Display &amp;lt;-&amp;gt;Maint.)&lt;/P&gt;&lt;P&gt;SPAU	 Display Modified DE Objects&lt;/P&gt;&lt;P&gt;SDCCN	 Service Data Control Center&lt;/P&gt;&lt;P&gt;SLG1	 Application Log: Display Logs&lt;/P&gt;&lt;P&gt;SGEN	 SAP Load Generator&lt;/P&gt;&lt;P&gt;STMS_MONI	 TMS Import Monitor&lt;/P&gt;&lt;P&gt;STMS	 Transport Management System&lt;/P&gt;&lt;P&gt;SCOOL	 COOL Repository&lt;/P&gt;&lt;P&gt;PFUD	 User Master Data Reconciliation&lt;/P&gt;&lt;P&gt;SMMS	 Message Server Monitor&lt;/P&gt;&lt;P&gt;SICK	 Installation Check&lt;/P&gt;&lt;P&gt;SMICM	 ICM Monitor&lt;/P&gt;&lt;P&gt;SE38	 ABAP Editor&lt;/P&gt;&lt;P&gt;AL04	 Monitor call distribution&lt;/P&gt;&lt;P&gt;AL08	 Users Logged On&lt;/P&gt;&lt;P&gt;AL11	 Display SAP Directories&lt;/P&gt;&lt;P&gt;AL12	 Display table buffer (Exp. session)&lt;/P&gt;&lt;P&gt;AL13	 Display Shared Memory (Expert mode)&lt;/P&gt;&lt;P&gt;AL15	 Customize SAPOSCOL destination&lt;/P&gt;&lt;P&gt;AL16	 Local Alert Monitor for Operat.Syst.&lt;/P&gt;&lt;P&gt;BD21	 Select change pointer&lt;/P&gt;&lt;P&gt;BD50	 Activate Change Ptrs for Mess. Type&lt;/P&gt;&lt;P&gt;BD51	 Maintain function modules (inbound)&lt;/P&gt;&lt;P&gt;BD52	 Activ.change pointer per chng.doc.it&lt;/P&gt;&lt;P&gt;BD54	 Maintaining Logical Systems&lt;/P&gt;&lt;P&gt;BD64	 Maintenance of Distribution Model&lt;/P&gt;&lt;P&gt;BD97	 Assign RFC dest. to Logical Systems&lt;/P&gt;&lt;P&gt;CK11	 Create Product Cost Estimate&lt;/P&gt;&lt;P&gt;DB01	 Analyze exclusive lockwaits&lt;/P&gt;&lt;P&gt;DB02	 Tables and Indexes Monitor&lt;/P&gt;&lt;P&gt;DB03	 Parameter changes in database&lt;/P&gt;&lt;P&gt;DB12	 DBA Backup Logs&lt;/P&gt;&lt;P&gt;DB6BACKHIST	 DB6: DBA Planning Calendar&lt;/P&gt;&lt;P&gt;DB6CLP	 DB6: Command Line Processor&lt;/P&gt;&lt;P&gt;DB6COCKPIT	 DB6: DBA Cockpit&lt;/P&gt;&lt;P&gt;DB6EXL	 DB6: Analyze Exclusive Lock Waits&lt;/P&gt;&lt;P&gt;DB6PERF	 DB6: DB2 UDB Cockpit Performance&lt;/P&gt;&lt;P&gt;DB6SPACE	 DB6: Space Analysis&lt;/P&gt;&lt;P&gt;FTXP	 Maintain Tax Code&lt;/P&gt;&lt;P&gt;KOSRLIST_PR	 Projects/Nets: Coll. Displ.SettRules&lt;/P&gt;&lt;P&gt;LBWE	 LO Data Ext.: Customizing Cockpit&lt;/P&gt;&lt;P&gt;LSMW	 Legacy System Migration Workbench&lt;/P&gt;&lt;P&gt;OS01	 LAN check with ping&lt;/P&gt;&lt;P&gt;OS03	 O/S Parameter changes&lt;/P&gt;&lt;P&gt;OS04	 Local System Configuration&lt;/P&gt;&lt;P&gt;OS05	 Remote System Cconfiguration&lt;/P&gt;&lt;P&gt;OS06	 Local Operating System Activity&lt;/P&gt;&lt;P&gt;OS07	 Remote Operating System Activity&lt;/P&gt;&lt;P&gt;OSS1	 Logon to SAPNet&lt;/P&gt;&lt;P&gt;OY05	 Factory calendar&lt;/P&gt;&lt;P&gt;RBDMIDOC	 Variant for RBDMIDOC&lt;/P&gt;&lt;P&gt;RSA7	 BW Delta Queue Monitor&lt;/P&gt;&lt;P&gt;RZ01	 Job Scheduling Monitor&lt;/P&gt;&lt;P&gt;RZ03	 Presentation, Control SAP Instances&lt;/P&gt;&lt;P&gt;RZ04	 Maintain SAP Instances&lt;/P&gt;&lt;P&gt;RZ10	 Maintain Profile Parameters&lt;/P&gt;&lt;P&gt;RZ11	 Profile Parameter Maintenance&lt;/P&gt;&lt;P&gt;RZ12	 Maintain RFC Server Group Assignment&lt;/P&gt;&lt;P&gt;RZ20	 CCMS Monitoring&lt;/P&gt;&lt;P&gt;SA38	 ABAP Reporting&lt;/P&gt;&lt;P&gt;SAINT	 Add-On Installation Tool&lt;/P&gt;&lt;P&gt;SALE	 Display ALE Customizing&lt;/P&gt;&lt;P&gt;SASAPIMG	 Call Up Project IMG&lt;/P&gt;&lt;P&gt;SBIW	 BIW in IMG for OLTP&lt;/P&gt;&lt;P&gt;SCON	 SAPconnect - Administration&lt;/P&gt;&lt;P&gt;SCOOLTOOL	 COOL Tools&lt;/P&gt;&lt;P&gt;SCOT	 SAPconnect - Administration&lt;/P&gt;&lt;P&gt;SCU0	 Customizing Cross-System Viewer&lt;/P&gt;&lt;P&gt;SCU3	 Table History&lt;/P&gt;&lt;P&gt;SE03	 Transport Organizer Tools&lt;/P&gt;&lt;P&gt;SE06	 Set Up Transport Organizer&lt;/P&gt;&lt;P&gt;SE12	 ABAP/4 Dictionary Display&lt;/P&gt;&lt;P&gt;SE13	 Maintain Technical Settings (Tables)&lt;/P&gt;&lt;P&gt;SE15	 ABAP/4 Repository Information System&lt;/P&gt;&lt;P&gt;SE18	 Business Add-Ins: Definitions&lt;/P&gt;&lt;P&gt;SE37	 ABAP Function Modules&lt;/P&gt;&lt;P&gt;S_TABU_DIS Display Tables (customize it to ztcode)&lt;/P&gt;&lt;P&gt;SCC4 (customize it to ztcode)&lt;/P&gt;&lt;P&gt;SE63	 Translation: Initial Screen&lt;/P&gt;&lt;P&gt;SE11	 ABAP Dictionary&lt;/P&gt;&lt;P&gt;SE11_OLD	 ABAP/4 Dictionary Maintenance&lt;/P&gt;&lt;P&gt;SE80	 Object Navigator&lt;/P&gt;&lt;P&gt;SE81	 Application Hierarchy&lt;/P&gt;&lt;P&gt;SE82	 Application Hierarchy&lt;/P&gt;&lt;P&gt;SE84	 R/3 Repository Information System&lt;/P&gt;&lt;P&gt;SE93	 Maintain Transaction Codes&lt;/P&gt;&lt;P&gt;SESSION_MANAGER	 Session Manager Menu Tree Display&lt;/P&gt;&lt;P&gt;SICF	 HTTP Service Hierarchy Maintenance&lt;/P&gt;&lt;P&gt;SM01	 Lock Transactions&lt;/P&gt;&lt;P&gt;SM02	 System Messages&lt;/P&gt;&lt;P&gt;SM04	 User List&lt;/P&gt;&lt;P&gt;SM12	 Display and Delete Locks&lt;/P&gt;&lt;P&gt;SM13	 Administrate Update Records&lt;/P&gt;&lt;P&gt;SM14	 Update Program Administration&lt;/P&gt;&lt;P&gt;SM20	 Security Audit Log Assessment&lt;/P&gt;&lt;P&gt;SM21	 Online System Log Analysis&lt;/P&gt;&lt;P&gt;SM28	 Installation Check&lt;/P&gt;&lt;P&gt;SM35	 Batch Input Monitoring&lt;/P&gt;&lt;P&gt;SM36	 Schedule Background Job&lt;/P&gt;&lt;P&gt;SM37	 Overview of job selection&lt;/P&gt;&lt;P&gt;SM37C	 Flexible version of job selection&lt;/P&gt;&lt;P&gt;SM38	 Queue Maintenance Transaction&lt;/P&gt;&lt;P&gt;SM49	 Execute external OS commands&lt;/P&gt;&lt;P&gt;SM50	 Work Process Overview&lt;/P&gt;&lt;P&gt;SM51	 List of SAP Systems&lt;/P&gt;&lt;P&gt;SM56	 Number Range Buffer&lt;/P&gt;&lt;P&gt;SM58	 Asynchronous RFC Error Log&lt;/P&gt;&lt;P&gt;SM59	 RFC Destinations (Display/Maintain)&lt;/P&gt;&lt;P&gt;SM61	 Backgroup control objects monitor&lt;/P&gt;&lt;P&gt;SM62	&lt;/P&gt;&lt;P&gt;SM63	 Display/Maintain Operating Mode Sets&lt;/P&gt;&lt;P&gt;SM64	 Trigger an Event&lt;/P&gt;&lt;P&gt;SM65	 Background Processing Analysis Tool&lt;/P&gt;&lt;P&gt;SM66	 Systemwide Work Process Overview&lt;/P&gt;&lt;P&gt;SM69	 Maintain External OS Commands&lt;/P&gt;&lt;P&gt;SMEN	 Session Manager Menu Tree Display&lt;/P&gt;&lt;P&gt;SMGW	 Gateway Monitor&lt;/P&gt;&lt;P&gt;SMLG	 Maint.Assign. Logon Grp to Instance&lt;/P&gt;&lt;P&gt;SMLT	 Language Management&lt;/P&gt;&lt;P&gt;SMQ1	 qRFC Monitor (Outbound Queue)&lt;/P&gt;&lt;P&gt;SMQ2	 qRFC Monitor (Inbound Queue)&lt;/P&gt;&lt;P&gt;SMQR	 Registration of Inbound Queues&lt;/P&gt;&lt;P&gt;SMQS	 Registration of Destinations&lt;/P&gt;&lt;P&gt;SMT1	 Trusted Systems (Display &amp;lt;-&amp;gt; Maint.)&lt;/P&gt;&lt;P&gt;SMX	 Display Own Jobs&lt;/P&gt;&lt;P&gt;SNL1	 Display NLS (character set, lang.)&lt;/P&gt;&lt;P&gt;SNOTE	 Note Assistant&lt;/P&gt;&lt;P&gt;SNRO	 Number Range Objects&lt;/P&gt;&lt;P&gt;SNUM	 Number Range Driver&lt;/P&gt;&lt;P&gt;SO00	 SAPoffice: Short Message&lt;/P&gt;&lt;P&gt;SO01	 SAPoffice: Inbox&lt;/P&gt;&lt;P&gt;SO02	 SAPoffice: Outbox&lt;/P&gt;&lt;P&gt;SO03	 SAPoffice: Private Folders&lt;/P&gt;&lt;P&gt;SO04	 SAPoffice: Shared Folders&lt;/P&gt;&lt;P&gt;SO05	 SAPoffice: Private Trash&lt;/P&gt;&lt;P&gt;SO07	 SAPoffice: Resubmission&lt;/P&gt;&lt;P&gt;SO23	 SAPoffice: Distribution Lists&lt;/P&gt;&lt;P&gt;SO50	 Rules for inbound distribution&lt;/P&gt;&lt;P&gt;SO99	 Put Information System&lt;/P&gt;&lt;P&gt;SOST	 Overview transmission requests&lt;/P&gt;&lt;P&gt;SP01	 Output Controller&lt;/P&gt;&lt;P&gt;SP12	 TemSe Administration&lt;/P&gt;&lt;P&gt;SPAD	 Spool Administration&lt;/P&gt;&lt;P&gt;SPAM	 Support Package Manager&lt;/P&gt;&lt;P&gt;ST01	 System Trace&lt;/P&gt;&lt;P&gt;ST02	 Setups/Tune Buffers&lt;/P&gt;&lt;P&gt;ST03	 Performance,SAP Statistics, Workload&lt;/P&gt;&lt;P&gt;ST03N	 R/3 Workload and Perf. Statistics&lt;/P&gt;&lt;P&gt;ST04	 DB Performance Monitor&lt;/P&gt;&lt;P&gt;ST05	 Performance trace&lt;/P&gt;&lt;P&gt;ST06	 Operating System Monitor&lt;/P&gt;&lt;P&gt;ST07	 Application monitor&lt;/P&gt;&lt;P&gt;ST10	 Table Call Statistics&lt;/P&gt;&lt;P&gt;ST11	 Display Developer Traces&lt;/P&gt;&lt;P&gt;ST14	 Application Analysis&lt;/P&gt;&lt;P&gt;ST22	 ABAP dump analysis&lt;/P&gt;&lt;P&gt;STAD	 Statistics display for all systems&lt;/P&gt;&lt;P&gt;STAT	 Local Transaction Statistics&lt;/P&gt;&lt;P&gt;SU01D	 User Display&lt;/P&gt;&lt;P&gt;SU03	 Maintain Authorizations&lt;/P&gt;&lt;P&gt;SU51	 Maintain Own User Address&lt;/P&gt;&lt;P&gt;SU52	 Maintain Own User Parameters&lt;/P&gt;&lt;P&gt;SU53	 Evaluate Authorization Check&lt;/P&gt;&lt;P&gt;SU55	 Call the Session Manager menus&lt;/P&gt;&lt;P&gt;SU56	 Analyze User Buffer&lt;/P&gt;&lt;P&gt;SUIM	 User Information System&lt;/P&gt;&lt;P&gt;S_BCE_68001285	 Transaction S_BCE_68001285&lt;/P&gt;&lt;P&gt;S_BCE_68001402	 With Unsuccessful Logons&lt;/P&gt;&lt;P&gt;S_BCE_68001418	 Act. Grps According to Complex Crit.&lt;/P&gt;&lt;P&gt;S_BCE_68001420	 Act. Grps According to Complex Crit.&lt;/P&gt;&lt;P&gt;S_BCE_68001429	 Transactions for User&lt;/P&gt;&lt;P&gt;TU02	 Parameter changes&lt;/P&gt;&lt;P&gt;USMM	 Customer measurement&lt;/P&gt;&lt;P&gt;WE02	 Display IDoc&lt;/P&gt;&lt;P&gt;WE05	 IDoc Lists&lt;/P&gt;&lt;P&gt;WE07	 IDoc statistics&lt;/P&gt;&lt;P&gt;WE08	 Status File Interface&lt;/P&gt;&lt;P&gt;WE09	 Search for IDoc in Database&lt;/P&gt;&lt;P&gt;WE20	 Partner Profiles&lt;/P&gt;&lt;P&gt;WE21	 Port definition&lt;/P&gt;&lt;P&gt;WE30	 Development IDoc Type&lt;/P&gt;&lt;P&gt;WE46	 IDoc administration&lt;/P&gt;&lt;P&gt;WE60	 Documentation for IDoc types&lt;/P&gt;&lt;P&gt;WE61	 Documentation for IDoc record types&lt;/P&gt;&lt;P&gt;WE63	 Documentation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;P&gt;Ashok&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jan 2009 07:06:23 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984978#M1161384</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-02T07:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Profiles for Basis Admins</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984979#M1161385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think idea here should be to understand the process more than giving actual values for such kind of posts. If, Lee were to make a role directly based on these tcodes what would be his justification as a security consultant for having provided these values.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Every company would have its own unique policy for authorizing Basis consultants.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some may want the consultants to be authorized with relevant tasks like system admin or database admin or security admin or user admin seperately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While some may want these tasks to combined by one group of consultants.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also want to provide the display access to all functional tcodes to the security roles as it may be needed more often or not to solve the authorization issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would rather stick to the security policy of my company and the job rrequirements of the consultant when designing these roles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jan 2009 07:24:15 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984979#M1161385</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-02T07:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Profiles for Basis Admins</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984980#M1161386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; I would rather stick to the security policy of my company and the job rrequirements of the consultant when designing these roles.&lt;/P&gt;&lt;P&gt;I couldn't agree more. Unfortunately OP doesn't want to go through the design process and there happened to be a spoonfeeder around....... Oh, well, some companies will get the quality they deserve.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@Ashok: Please do not spoonfeed in this forum. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@Lee: As far as basis roles are concerned, my basis admins will only be authorized to do their work if they can specify what they need. That makes creating the basis roles an ongoing design and build process for a few months with a tailormade result.&lt;/P&gt;&lt;P&gt;The process of trial and error does make them mad at occasions but the worst thing I've ever had to do was threaten them to tell their boss they cannot tell me what their job is about. Worked like a charm &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jan 2009 08:57:20 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984980#M1161386</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2009-01-02T08:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Profiles for Basis Admins</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984981#M1161387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; ... they cannot tell me what their job is about. &lt;/P&gt;&lt;P&gt;Must remember that one... &lt;SPAN __jive_emoticon_name="wink"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for bringing some sanity to this thread.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jan 2009 10:28:09 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984981#M1161387</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-02T10:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Profiles for Basis Admins</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984982#M1161388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the responses.  Actually, I'm a basis guy and I have seen such a different discrepency with Basis roles in every company, I just wanted to get some feedback from all of you to see your thoughts on security for Basis.  Many companies I go to just take the sap_all profile and take away the authorities they don't want basis people to have and other companies start with a limited transaction set and make the basis guys tell them what other access they need (which can be frustrating).  I just wanted to keep a good list so that when I get asked that question at various clients I can give them a good answer. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jan 2009 16:07:17 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984982#M1161388</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-09T16:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Profiles for Basis Admins</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984983#M1161389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can I chime in on this topic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I started late on my current project the entire Basis team had sap_all. They were well into realization and experiencing a lot of problems with system stability, data corruption and people stepping on each other's toes by making changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I fought like heck to remove sap_all from every Basis member. We  had pretty good Basis roles set up by our SI. Yes there were transactions missing but the deal I offered was simple:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I''m taking sap_all away effective immediately. You will never see it again. However, I'm going to give you these roles and promise you that if and when you find a transaction missing, I will immediately add it. Day, night, on vacation whatever, I will stop what I am doing and make sure you have what you need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It frustrated some of our Basis admins to the point of insanity but we now have rock solid, position and task based roles. Oh yeah, most of our problems have gone away now. Personally I thought it was only fair to make myself available for immediate assistance since I was removing their crutch - that's all sap_all was for us.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think well designed Basis roles work better than just giving out sap_all like Halloween candy. By removing sap_all and assigning them true Basis roles we have also eliminated potential audit issues with SoDs. No longer can our lead Basis guru create users at will. The deal again is that if a user is needed (system, service etc) that I am available via phone for emergencies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My personal opinion is that if you are going to take away sap_all be willing to go the extra mile to ensure the team does have the tools they need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Todd&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Jan 2009 03:57:30 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984983#M1161389</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-10T03:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Profiles for Basis Admins</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984984#M1161390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; Can I chime in on this topic?&lt;/P&gt;&lt;P&gt;Thanks for chiming in, even although the thread is closed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I enjoyed reading your post and agree with you - if nothing else has been done, then you need to support the transision to a based-on-need-role as a "tool", otherwise it will fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other very usefull tools are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Provide a password vault and/or Single-Sign-On solution --&amp;gt; these folks often has many systems and clients to administrate, and their authority might be less of an immediate risk than the way they manage their passwords.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Give them an emergency user procedure (as this ball typically ends up in basis's court to solve) --&amp;gt; long before Virsa FireFighter there were ways of doing this. If you know what you are doing, you can implement one on your own in only a few days with about 30 lines of code in the right place, and a bit of carefull config. Carefull config should be in place anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my experiences, if you provide security solutions and explain the risks which are being mitigated, only unreasonable or unknowledgable people will resist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for adding your insight!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Julius Bussche on Jan 12, 2009 12:54 AM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Jan 2009 20:12:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984984#M1161390</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-10T20:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Profiles for Basis Admins</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984985#M1161391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the start!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And while yes, my companies needs are probably different.  I prefer to start as close to correct as possible and remove and add access as needed.  My company can't wait on me to do weeks of analysis for 6 users for them to get started.  So boo hoo to the "spoon feed" comments.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Jan 2009 15:33:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984985#M1161391</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-23T15:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: Profiles for Basis Admins</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984986#M1161392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you use the SAP Standard roles as the basis of rest of your build then?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Jan 2009 16:48:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984986#M1161392</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-23T16:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: Profiles for Basis Admins</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984987#M1161393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only implementation I have been security architect on is HCM.  Our GBS team has to put together process documents before we do implementation testing.  I looked through the Process documents for each transaction used and derived what object values to use based on the text of the process.  We have several cycles of testing which of course found some missing object values and reports not previously on their process documents.(Not many &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;) So in essence for the end user roles I started with 0 and added as needed.  However, I had close to 6 months to do this process.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am now being asked to find a way to reduce Basis's access for all systems and if I could have it done yesterday.  Which is why I was looking through here to see if someone had a more efficient way of doing this.  Specifically for Basis, I would rather take broad approach and remove slowly instead of taking a narrow approach and add as requested.  (This is for their FireFighter access anyway.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Jan 2009 21:36:30 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984987#M1161393</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-23T21:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Profiles for Basis Admins</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984988#M1161394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Waldon, I take your point about the basis access, personally I find this as much as a minefield as the end user access and with the potential to cause more grief.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Jan 2009 22:41:52 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984988#M1161394</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-01-23T22:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: Profiles for Basis Admins</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984989#M1161395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Lee,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't recall who the poster was - maybe third from the top - gave a list of  many, many transactions but,&lt;/P&gt;&lt;P&gt;you don't need all of them. There are many you do need. As a Basis Admin. in my shop, we don't have authority for the IDOC transactions ie. WExx and I haven't needed them. Applications support and Developers use them here. Also, your security team should be the ones controling what transactions a given role has authority to. Some have given you links within the SAP site(s). Stick with SAP recommendations and not third party links. A while back our security team was trying to be more SOX compliant and took some transactions away but we demonstrated the need for them so we got them back. Good luck.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Mar 2009 18:28:08 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/profiles-for-basis-admins/m-p/4984989#M1161395</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-03-12T18:28:08Z</dc:date>
    </item>
  </channel>
</rss>

