<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restricting Tcode using Roles in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935029#M1891843</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jalina,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can try below option. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/jiveimages/651210" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Shakthi Raj Natarajan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 23 Feb 2015 13:37:43 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2015-02-23T13:37:43Z</dc:date>
    <item>
      <title>Restricting Tcode using Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935026#M1891840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear BW Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to create a role to restrict of accessing TCODE : STMS_IMPORT and STMS in Production system. I can able to create a role by adding S_TCODE. While creating the role, inclusion is available but exclution is not available. I want to create a role by restricting tcode STMS and STMS_import. How to achieve this. Please help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2015 06:57:16 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935026#M1891840</guid>
      <dc:creator>former_member184624</dc:creator>
      <dc:date>2015-02-23T06:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting Tcode using Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935027#M1891841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jalina,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently, what is the role of the user you are referring? Why don't you edit his or copy his current role and remove the STMS_IMPORT and STMS in S_TCODE?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Loed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2015 07:49:32 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935027#M1891841</guid>
      <dc:creator>Loed</dc:creator>
      <dc:date>2015-02-23T07:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting Tcode using Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935028#M1891842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. For the Current role, I have given access to all Tcode. I just want to restrict STMS_IMPORT. I cannot include all the TCODES in the current role. Please suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2015 13:11:01 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935028#M1891842</guid>
      <dc:creator>former_member184624</dc:creator>
      <dc:date>2015-02-23T13:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting Tcode using Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935029#M1891843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jalina,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can try below option. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/jiveimages/651210" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Shakthi Raj Natarajan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2015 13:37:43 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935029#M1891843</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2015-02-23T13:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting Tcode using Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935030#M1891844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a Basis/Security question and should ideally be posted in that SCN space. Security folks are better placed to answer this. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2015 04:03:17 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935030#M1891844</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2015-02-24T04:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting Tcode using Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935031#M1891845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jalina,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; I wonder why would you even give access to all T codes in S_TCode, which is quite dangerous. Instead, try giving access to those T codes which is required by the user. And in case the user needs access to some critical transactions, then you may either suggest the user to use FF ID or may be you can give him/her access on temporary basis. I do not see a point in adding '*' in S_Tcode. Also I dont think it is SOX complaint.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mohamed Fazil &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2015 06:34:18 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935031#M1891845</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2015-02-24T06:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting Tcode using Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935032#M1891846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;All transaction codes in production !! You might to review the security design and give them what is needed versus give all and then restrict on few. &lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Feb 2015 13:58:24 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935032#M1891846</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2015-02-28T13:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting Tcode using Roles</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935033#M1891847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jalina&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;SPAN style="color: #333333; font-size: 12px;"&gt;but exclution is not available&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px;"&gt;SAP Security role authorisation concept does not cater for exclusion values or ranges&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px;"&gt;If you are not a security person, I recommend you look at the ADM940 or help.sap.com for Authorisations Concept or discuss your requirements with your Security contact.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 12px;"&gt;Colleen&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Mar 2015 07:17:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/restricting-tcode-using-roles/m-p/10935033#M1891847</guid>
      <dc:creator>Colleen</dc:creator>
      <dc:date>2015-03-05T07:17:04Z</dc:date>
    </item>
  </channel>
</rss>

