<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query regarding Critical Authorizations in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/query-regarding-critical-authorizations/m-p/5298942#M1222116</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users having this access can maintain tables which are sensitive i.e. system tables and etc. Hence deloitte points out the same in audit findings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please coordinate with the respective business process owners before removing the access. The best way is to tell all the users having access, and request the business process owners to point out the genuine or few users who can have this access. Later you can remove access to rest of users. If your client's policy doesn't allow this access for any one, then you can simply inform and delete the access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gowrinadh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Mar 2009 13:31:32 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-03-10T13:31:32Z</dc:date>
    <item>
      <title>Query regarding Critical Authorizations</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/query-regarding-critical-authorizations/m-p/5298941#M1222115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As part of audit review we have identified below of the critical authorizations were given to all users across the organization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;CTBA-Customizing: Table maintenanceu2019&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;u2018CTBS-Customizing   : Table maintenance all basic tablesu2019&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;through SUIM, I have generated the report of all users having these authorizations. I'm not sure what these critical objects does actually?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now i would like to know what will be the effect on access rights of the users if I remove the above two critical authorizations from the roles? and How we could remove the critical authorizations from roles?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Vinod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Mar 2009 09:01:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/query-regarding-critical-authorizations/m-p/5298941#M1222115</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-03-10T09:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: Query regarding Critical Authorizations</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/query-regarding-critical-authorizations/m-p/5298942#M1222116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users having this access can maintain tables which are sensitive i.e. system tables and etc. Hence deloitte points out the same in audit findings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please coordinate with the respective business process owners before removing the access. The best way is to tell all the users having access, and request the business process owners to point out the genuine or few users who can have this access. Later you can remove access to rest of users. If your client's policy doesn't allow this access for any one, then you can simply inform and delete the access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gowrinadh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Mar 2009 13:31:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/query-regarding-critical-authorizations/m-p/5298942#M1222116</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-03-10T13:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Query regarding Critical Authorizations</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/query-regarding-critical-authorizations/m-p/5298943#M1222117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have never seen the need for these authorisations in NORMAL roles, so i think you can delete them from all roles!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Mar 2009 14:06:13 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/query-regarding-critical-authorizations/m-p/5298943#M1222117</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-03-10T14:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: Query regarding Critical Authorizations</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/query-regarding-critical-authorizations/m-p/5298944#M1222118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assited and clarifed user doubts on duplicate profiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for all assistance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Apr 2009 11:50:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/query-regarding-critical-authorizations/m-p/5298944#M1222118</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-04-21T11:50:03Z</dc:date>
    </item>
  </channel>
</rss>

