<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAP_ALL usage in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-all-usage/m-p/5797214#M1311075</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; I want to know the main usage of SAP_ALL profile for RFC communications&lt;/P&gt;&lt;P&gt;&amp;gt; (other than Basis work).&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;No.. not needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Can it be used for all RFC/ALE ids in production systems ?&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No.. not needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Can SAP_ALL be a firefighter profile for dialog users (emergency&lt;/P&gt;&lt;P&gt;&amp;gt; access) ?&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes.. current audit scenario also tells not to use SAP_ALL for emergency users too..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Can SAP_ALL be given to Batch ids ?&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No.. not needed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Jun 2009 18:30:45 GMT</pubDate>
    <dc:creator>sdipanjan</dc:creator>
    <dc:date>2009-06-22T18:30:45Z</dc:date>
    <item>
      <title>SAP_ALL usage</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-all-usage/m-p/5797213#M1311074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to know the main usage of SAP_ALL profile for RFC communications&lt;/P&gt;&lt;P&gt;(other than Basis work).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can it be used for all RFC/ALE ids in production systems ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can SAP_ALL be a firefighter profile for dialog users (emergency&lt;/P&gt;&lt;P&gt;access) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can SAP_ALL be given to Batch ids ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jun 2009 18:27:20 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-all-usage/m-p/5797213#M1311074</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-22T18:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: SAP_ALL usage</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-all-usage/m-p/5797214#M1311075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; I want to know the main usage of SAP_ALL profile for RFC communications&lt;/P&gt;&lt;P&gt;&amp;gt; (other than Basis work).&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;No.. not needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Can it be used for all RFC/ALE ids in production systems ?&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No.. not needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Can SAP_ALL be a firefighter profile for dialog users (emergency&lt;/P&gt;&lt;P&gt;&amp;gt; access) ?&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes.. current audit scenario also tells not to use SAP_ALL for emergency users too..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Can SAP_ALL be given to Batch ids ?&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No.. not needed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jun 2009 18:30:45 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-all-usage/m-p/5797214#M1311075</guid>
      <dc:creator>sdipanjan</dc:creator>
      <dc:date>2009-06-22T18:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: SAP_ALL usage</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-all-usage/m-p/5797215#M1311076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Theoretically you can, but Dipanjan's answer is much more secure... &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think a License by Authority model would not sell very well, but would also be much more secure and authorizations would be more realistic for some of the user classes you have mentioned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jun 2009 19:40:44 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-all-usage/m-p/5797215#M1311076</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-22T19:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: SAP_ALL usage</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-all-usage/m-p/5797216#M1311077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I production system no user should have SAP_ALL profile except the OSS ids. If no specific role was created within the system for some particular access, SAP_ALL can be provided with limited validity.. but for audit issue, Security log(SM20 log) should be taken for that time period. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I would prefer to run ST01 trace against the user id to know the what authorizations are required to do the specific job.. Then proper role should be created as per requirement to avoid assignment of SAP_ALL profile. This new role can be used for emergency access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also for interface users also, assignment of SAP_ALL should be avoide.. Here also you should take trace against the interface user. In that case, you need to run the trace in both the systems where they are working. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But please note that running of trace may slow down the system performance.. So try to run trace when system load is minimum and try to run it only for the time when the user id is used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sandip.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jun 2009 13:11:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-all-usage/m-p/5797216#M1311077</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-06-23T13:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: SAP_ALL usage</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-all-usage/m-p/5797217#M1311078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This message was moderated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Jul 2009 20:43:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-all-usage/m-p/5797217#M1311078</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-07-19T20:43:22Z</dc:date>
    </item>
  </channel>
</rss>

