<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict Authorization in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184383#M1199969</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Julius,&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; The thing is he is able to access a lot of other restricted Tcodes, not just SCC4. I just wanted to know if there are any loopholes that we, as security admins should do to block these loopholes.&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;Which release are you on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming it is 6.40 or higher, go to tcode SUIM (or report RSUSR002) "Users by Complex selection criteria" and run it for Object 1 = 'S_DEVELOP' Activity = '16' ObjectType = 'FUGR'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do any of the users turn up?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, where are you getting this information from that they are (successfully) starting tcode SCC4? Are they also using it (making changes)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Feb 2009 20:42:50 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-02-12T20:42:50Z</dc:date>
    <item>
      <title>Restrict Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184377#M1199963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have taken all precautions to restrict authorizations to users in a system, still some of them are able to execute SCC4. I think there is some report/function using which you can execute transactions which you do not have access to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could some one please tell me the name of that report and how I can restrict it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2009 05:58:07 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184377#M1199963</guid>
      <dc:creator>former_member759680</dc:creator>
      <dc:date>2009-02-12T05:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184378#M1199964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gautam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check whether user is having access to display all tcodes, if so you need to take the tcode from s_tcode object from that role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check in SUIM tcode &amp;gt;&amp;gt;&amp;gt; transactions executable for user and check whether this tcodes exits or not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2009 06:14:49 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184378#M1199964</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-02-12T06:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184379#M1199965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make sure param rec/client is set to ALL, and check tocde SCU3 for changes to table T000.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ALL = all clients... the changes can be made from other clients...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2009 06:21:50 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184379#M1199965</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-02-12T06:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184380#M1199966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Julius,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The thing is he is able to access a lot of other restricted Tcodes, not just SCC4. I just wanted to know if there are any loopholes that we, as security admins should do to block these loopholes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2009 06:26:52 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184380#M1199966</guid>
      <dc:creator>former_member759680</dc:creator>
      <dc:date>2009-02-12T06:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184381#M1199967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check whether users has any super role access? If so, then he will be able to access all the T-codes. &lt;/P&gt;&lt;P&gt;You can create a role and add only those T-codes he/she needs acces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Geetha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2009 08:45:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184381#M1199967</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-02-12T08:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184382#M1199968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; Check whether users has any super role access? If so, then he will be able to access all the T-codes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Super role? What should that be? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd suggest to do a complete user compare for the user, and afterwards have a look in SU01 to see which profiles are actually linked to the user. Make sure those are only the profiles belonging to your roles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2009 08:56:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184382#M1199968</guid>
      <dc:creator>jurjen_heeck</dc:creator>
      <dc:date>2009-02-12T08:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184383#M1199969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Julius,&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; The thing is he is able to access a lot of other restricted Tcodes, not just SCC4. I just wanted to know if there are any loopholes that we, as security admins should do to block these loopholes.&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;Which release are you on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming it is 6.40 or higher, go to tcode SUIM (or report RSUSR002) "Users by Complex selection criteria" and run it for Object 1 = 'S_DEVELOP' Activity = '16' ObjectType = 'FUGR'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do any of the users turn up?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, where are you getting this information from that they are (successfully) starting tcode SCC4? Are they also using it (making changes)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2009 20:42:50 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184383#M1199969</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-02-12T20:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict Authorization</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184384#M1199970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK - I'll join this thread.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you know it's not a SAP_ALL profile - do the following to check the offending role/roles:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Go to SU01-&amp;gt;Roles and copy all the roles assigned to the user.&lt;/P&gt;&lt;P&gt;2. Go to SE16-&amp;gt;AGR_1251-&amp;gt;ROLES-&amp;gt; paste all the roles, OBJECT-&amp;gt; enter S_TCODE, VALUE-&amp;gt; enter SCC4 then Execute.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should display all the roles that gives access to  SSC4.  You can even do ranges on the value like S* to T*.  You can also run PFCG and click on transaction and enter SCC4, roles having that tcode will be displayed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good Luck!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Feb 2009 00:23:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restrict-authorization/m-p/5184384#M1199970</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-02-13T00:23:35Z</dc:date>
    </item>
  </channel>
</rss>

