<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Please help on SA38 in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/please-help-on-sa38/m-p/7058334#M1502972</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; I am trying to understand what this access would allow and whether there is any audit risk with having this access. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be able to run programs is a high risk. In some programs there are additional authorization checks. Therefore ability to run a program does not directly mean that you can really use it. But there are many programs without authorization checks. Usually, the custom reports lack authorization checks. As it was mentioned there is no reason to add access to SA38 to normal user in production environment. If some users think they need to run particular program and there is no transaction assigned to it then the best practice is to assign custom transaction code to this program and use give users access to this transaction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Jul 2010 23:25:08 GMT</pubDate>
    <dc:creator>mvoros</dc:creator>
    <dc:date>2010-07-26T23:25:08Z</dc:date>
    <item>
      <title>Please help on SA38</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/please-help-on-sa38/m-p/7058329#M1502967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried searching on this forum, but could not find an answer to my question.  I am an auditor and I have been assigned the following access at my company:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;T-Code: SA38&lt;/P&gt;&lt;P&gt;S_PROGRAM: SUBMIT&lt;/P&gt;&lt;P&gt;Authorization: *&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on my limited understanding, this access would give me access to execute programs.  Is that correct?  Is there any restrictions that would prevent me from running any programs?  For example, if the program is assigned to custom t-code, would I also need access to that t-code to run the program? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to understand what this access would allow and whether there is any audit risk with having this access.  Appreciate any information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jul 2010 05:00:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/please-help-on-sa38/m-p/7058329#M1502967</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-07-26T05:00:03Z</dc:date>
    </item>
    <item>
      <title>Re: Please help on SA38</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/please-help-on-sa38/m-p/7058330#M1502968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SA38 is assigned to users who just want to execute the report and no source code access is reuired.&lt;/P&gt;&lt;P&gt;You can execute almost all the programs via this tsb until and unless there are specific checks/authorizations assigned to few objects .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jul 2010 05:14:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/please-help-on-sa38/m-p/7058330#M1502968</guid>
      <dc:creator>Sandeep_Panghal</dc:creator>
      <dc:date>2010-07-26T05:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Please help on SA38</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/please-help-on-sa38/m-p/7058331#M1502969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This message was moderated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jul 2010 05:22:49 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/please-help-on-sa38/m-p/7058331#M1502969</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-07-26T05:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: Please help on SA38</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/please-help-on-sa38/m-p/7058332#M1502970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tcode SA38 is used to run programs or reports in SAP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When SA38 added to a role menu the following objects gets added&lt;/P&gt;&lt;P&gt;S_PROGRAM and authorization groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the S_PROGRAM object contains the following values&lt;/P&gt;&lt;P&gt;SUBMIT         - allows one to run a program.&lt;/P&gt;&lt;P&gt;BTCSUBMIT  - allows the user to Schedule a background job for the execution of a program.&lt;/P&gt;&lt;P&gt;VARIANT     - allows user to maintain variants for the program.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;K.Tharani.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jul 2010 05:30:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/please-help-on-sa38/m-p/7058332#M1502970</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-07-26T05:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Please help on SA38</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/please-help-on-sa38/m-p/7058333#M1502971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;T-Code: SA38&lt;/P&gt;&lt;P&gt;S_PROGRAM: SUBMIT&lt;/P&gt;&lt;P&gt;Authorization: *&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on my limited understanding, this access would give me access to execute programs. Is that correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any restrictions that would prevent me from running any programs?&lt;/P&gt;&lt;P&gt;You can restrict on auth group, instead of *   (mention only those auth group, that user want to execute.&lt;/P&gt;&lt;P&gt;Note : There r many programs which don't have auth group. You can assign them using RSCSAUTH prg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; For example, if the program is assigned to custom t-code, would I also need access to that t-code to run the program? &lt;/P&gt;&lt;P&gt;Not needed. it is good way to map all custom report to custom tcodes, so that we will have addtional check on  S_Tcode .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to understand what this access would allow and whether there is any audit risk with having this access. Appreciate any information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most of the users dont need access to SE38 &amp;amp; SA38&lt;/P&gt;&lt;P&gt;Mostly in production system we dont give access to SE38 &amp;amp; SA38 also. On case to case issue we can assign firghter role.  auditors happy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jul 2010 20:56:51 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/please-help-on-sa38/m-p/7058333#M1502971</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-07-26T20:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: Please help on SA38</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/please-help-on-sa38/m-p/7058334#M1502972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; I am trying to understand what this access would allow and whether there is any audit risk with having this access. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be able to run programs is a high risk. In some programs there are additional authorization checks. Therefore ability to run a program does not directly mean that you can really use it. But there are many programs without authorization checks. Usually, the custom reports lack authorization checks. As it was mentioned there is no reason to add access to SA38 to normal user in production environment. If some users think they need to run particular program and there is no transaction assigned to it then the best practice is to assign custom transaction code to this program and use give users access to this transaction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jul 2010 23:25:08 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/please-help-on-sa38/m-p/7058334#M1502972</guid>
      <dc:creator>mvoros</dc:creator>
      <dc:date>2010-07-26T23:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Please help on SA38</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/please-help-on-sa38/m-p/7058335#M1502973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks to everyone that responded.  This was helpful forum.  Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jul 2010 16:52:05 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/please-help-on-sa38/m-p/7058335#M1502973</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-07-28T16:52:05Z</dc:date>
    </item>
  </channel>
</rss>

