<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PFCG Authorization Updates in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-updates/m-p/10239289#M1828150</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To reorganize the work inside our SAP team, we are in discussion for who should be responsible for functions (MM,FI,CO,HR,Sales) PFCG authorization modifications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please; advise the best practice from SAP, who can better handle functions (MM,FI,CO,HR,Sales) PFCG authorization modifications, the BASIS&lt;/P&gt;&lt;P&gt;team or the function consultants?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Fawzy Ibrahim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 13 Apr 2014 18:08:10 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2014-04-13T18:08:10Z</dc:date>
    <item>
      <title>PFCG Authorization Updates</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-updates/m-p/10239289#M1828150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To reorganize the work inside our SAP team, we are in discussion for who should be responsible for functions (MM,FI,CO,HR,Sales) PFCG authorization modifications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please; advise the best practice from SAP, who can better handle functions (MM,FI,CO,HR,Sales) PFCG authorization modifications, the BASIS&lt;/P&gt;&lt;P&gt;team or the function consultants?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Fawzy Ibrahim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Apr 2014 18:08:10 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-updates/m-p/10239289#M1828150</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-04-13T18:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: PFCG Authorization Updates</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-updates/m-p/10239290#M1828151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Fawzy&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;
&lt;P&gt;the BASIS&lt;/P&gt;
&lt;P&gt;team or the function consultants?&lt;/P&gt;
&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd say the security team &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.sap.com/718/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whoever you choose, ensure they are actually trained and knowledgeable of PFCG/SU24/general security. Splitting role maintenance across several teams can create inconsistent role build.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basis might know how to click and tick boxes (or at least a step ahead of 'just assign sap_all') but they need to understand what the authorisations are for and how to appropriately restrict for functional requirements. Both may know how to build but do they understand how to interpret a misleading authorisation failure check in a trace?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best practise is to choose someone who is competent&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Colleen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Apr 2014 21:56:26 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-updates/m-p/10239290#M1828151</guid>
      <dc:creator>Colleen</dc:creator>
      <dc:date>2014-04-13T21:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: PFCG Authorization Updates</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-updates/m-p/10239291#M1828152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Accountable are the MM, FI, CO, HR, SALES etc. business process owners. They should initiate all role changes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Responsible for the actual changes in the system normally is the security team.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2014 08:16:00 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-updates/m-p/10239291#M1828152</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-04-14T08:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: PFCG Authorization Updates</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-updates/m-p/10239292#M1828153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;SPAN class="j-post-author"&gt;&lt;STRONG&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="610732" data-username="fawzy.ibrahim" href="https://answers.sap.com/people/fawzy.ibrahim"&gt;Fawzy Ibrahim&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp; ,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="j-post-author"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="j-post-author"&gt;Is it means that, in each module there will be different BASIS people? Like the responsible to MM users cannot change SD users authentication? If yes then, there is a good solution.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="j-post-author"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="j-post-author"&gt;You need to group the users module wise. Then assign the BASIS peoples to maintain those particular group only(Using authorization object &lt;/SPAN&gt;S_USER_GRP&lt;SPAN class="j-post-author"&gt;). Please have a try. If you face problem let me know&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="j-post-author"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="j-post-author"&gt;Asad&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2014 08:31:17 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-updates/m-p/10239292#M1828153</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-04-16T08:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: PFCG Authorization Updates</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-updates/m-p/10239293#M1828154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Fawzy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the company you work for/contract for has to adhere to SOX compliancy, then you definitely do not want the Basis folks doing security. This is for the security team to define the authorizations, modifications, roles, etc, related to SAP Security. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro_emoticon jive_macro jive_emote" src="https://community.sap.com/718/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2014 20:06:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/pfcg-authorization-updates/m-p/10239293#M1828154</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2014-04-16T20:06:21Z</dc:date>
    </item>
  </channel>
</rss>

