<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Limiting Role assignment in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/limiting-role-assignment/m-p/6860315#M1475633</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. I need to exclude assignment of certian roles. I  tried limiting it with the role name under S_USER_AGR object. here the hurdle is the names fo the roles are not standarised hence the problem of exclusion comes in. Another way was to limit it with transactions (S_USER_TCD) , so if I need to exclude the tcds ME21, 21N, ME22, ME51N, 52N, MIGO, ..any ideas ..newer ideas or do we just do it as per the old way of A*....wild card method ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;New ideas ?? inventions ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thannkx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 May 2010 20:12:46 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2010-05-18T20:12:46Z</dc:date>
    <item>
      <title>Limiting Role assignment</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/limiting-role-assignment/m-p/6860315#M1475633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. I need to exclude assignment of certian roles. I  tried limiting it with the role name under S_USER_AGR object. here the hurdle is the names fo the roles are not standarised hence the problem of exclusion comes in. Another way was to limit it with transactions (S_USER_TCD) , so if I need to exclude the tcds ME21, 21N, ME22, ME51N, 52N, MIGO, ..any ideas ..newer ideas or do we just do it as per the old way of A*....wild card method ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;New ideas ?? inventions ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thannkx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 May 2010 20:12:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/limiting-role-assignment/m-p/6860315#M1475633</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-05-18T20:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Role assignment</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/limiting-role-assignment/m-p/6860316#M1475634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A solid and consistent naming convention is beyond my doubt the best solution. You can also limit what the user can request using this approach (which is increasingly popular) as they are generally only skilled enough to look for roles and not authorization field values.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if you have to live with what you have, then there are exits available for the user administration - there you can "invent" to some extent and make it dependent on critical authorizations you define and conflicts (see report RSUSR008_009_NEW).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Last I heard the exits were converted to BADIs, but many customers are looking into GRC's CUP functionality and IdM workflows now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is in my opinion still a gem stone which can be used as a preventative or detective control if you set it up correctly. You are however on your own (with us... &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt; in this and do not have updated SAP defaults for all modules to build from.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is only critical authorizations and low-brainers you want to detect, then it is relatively easy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Julius&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 May 2010 21:26:17 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/limiting-role-assignment/m-p/6860316#M1475634</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-05-18T21:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting Role assignment</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/limiting-role-assignment/m-p/6860317#M1475635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you mean to say that you want to restrict your Security Administrators to assign specific roles to users or access of Security administrators should be restricted to manage a specific set of users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Anjan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 May 2010 07:01:29 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/limiting-role-assignment/m-p/6860317#M1475635</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-05-19T07:01:29Z</dc:date>
    </item>
  </channel>
</rss>

