<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAP Security roles cleanup in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-roles-cleanup/m-p/12674601#M2016514</link>
    <description>&lt;P&gt;Hi Mansi,&lt;/P&gt;&lt;P&gt;With the number of single roles you describe, I propose to conduct a role consolidation project. The results can be beneficial for the S/4HANA transformation. The aim is to identify roles with significant overlap. For example, by:&lt;/P&gt;&lt;P&gt;- evaluating usage logs in production or of role test users in the test system&lt;/P&gt;&lt;P&gt;- comparison of AGR1251 to identify similar roles by the authorizations data&lt;/P&gt;&lt;P&gt;Also, you can find 3rd party add-on solutions to support simulation features and similar. &lt;/P&gt;&lt;P&gt;It's important to improve the role documentation during consolidation. In my experience, a role consolidation, many customers can reduce the number of roles by 20%+ without creating additional SoD or critical authorization threats. &lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
    <pubDate>Sun, 12 Mar 2023 15:05:04 GMT</pubDate>
    <dc:creator>marco_hammel2</dc:creator>
    <dc:date>2023-03-12T15:05:04Z</dc:date>
    <item>
      <title>SAP Security roles cleanup</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-roles-cleanup/m-p/12674599#M2016512</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
  &lt;P&gt;I am filing up for some one from SAP security in my team and my first assignment is to do security role cleanup. We have thousands of single roles(no composites in our system) and some of them are obsolete which can be removed without too much of thinking involved. But how to go about achieving a 'lean methodology' in security role management? Our intention is to have lesser roles than today and get ready for S4 HANA transition. We also want to take a fresh look at SoDs.&lt;/P&gt;
  &lt;P&gt;Appreciate if i can get access to any SAP documentation. Also. any pointers welcomed , that with S4 HANA transition planned , should we need to consider some perspectives along those lines?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 06:04:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-roles-cleanup/m-p/12674599#M2016512</guid>
      <dc:creator>mansipujari</dc:creator>
      <dc:date>2023-02-28T06:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: SAP Security roles cleanup</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-roles-cleanup/m-p/12674600#M2016513</link>
      <description>&lt;P&gt;My advice would be to meet and sit down with the project managers who will be implementing S4. The best way of achieving a lean security build methodology would be to get the project teams to map their business processes with the relevant Fiori apps and Tcodes. Only then can you design some nice clean and compliant Comp roles or even better again, specifically designed derived roles for the processes that are mapped. Trying to shoe horn in already existing ECC processes/roles into new roles for S4 can work but it would usually mean more SOD's and clean up whilst you start running the GRC analysis. The key is to get the business to agree to map their processes and to map those processes to the relevant Access Apps/Tcodes. &lt;BR /&gt;Good Luck.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2023 20:08:07 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-roles-cleanup/m-p/12674600#M2016513</guid>
      <dc:creator>former_member612251</dc:creator>
      <dc:date>2023-03-11T20:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: SAP Security roles cleanup</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-roles-cleanup/m-p/12674601#M2016514</link>
      <description>&lt;P&gt;Hi Mansi,&lt;/P&gt;&lt;P&gt;With the number of single roles you describe, I propose to conduct a role consolidation project. The results can be beneficial for the S/4HANA transformation. The aim is to identify roles with significant overlap. For example, by:&lt;/P&gt;&lt;P&gt;- evaluating usage logs in production or of role test users in the test system&lt;/P&gt;&lt;P&gt;- comparison of AGR1251 to identify similar roles by the authorizations data&lt;/P&gt;&lt;P&gt;Also, you can find 3rd party add-on solutions to support simulation features and similar. &lt;/P&gt;&lt;P&gt;It's important to improve the role documentation during consolidation. In my experience, a role consolidation, many customers can reduce the number of roles by 20%+ without creating additional SoD or critical authorization threats. &lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Sun, 12 Mar 2023 15:05:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-roles-cleanup/m-p/12674601#M2016514</guid>
      <dc:creator>marco_hammel2</dc:creator>
      <dc:date>2023-03-12T15:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: SAP Security roles cleanup</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-roles-cleanup/m-p/12674602#M2016515</link>
      <description>&lt;P&gt;Hi Mansi,&lt;/P&gt;&lt;P&gt;With the number of single roles you describe, I propose to conduct a role consolidation project. The results can be beneficial for the S/4HANA transformation. The aim is to identify roles with significant overlap. For example, by:&lt;/P&gt;&lt;P&gt;- evaluating usage logs in production or of role test users in the test system&lt;/P&gt;&lt;P&gt;- comparison of AGR1251 to identify similar roles by the authorizations data&lt;/P&gt;&lt;P&gt;Also, you can find 3rd party add-on solutions to support simulation features and similar. &lt;/P&gt;&lt;P&gt;It's important to improve the role documentation during consolidation. In my experience, a role consolidation, many customers can reduce the number of roles by 20%+ without creating additional SoD or critical authorization threats. &lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Sun, 12 Mar 2023 15:05:15 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-roles-cleanup/m-p/12674602#M2016515</guid>
      <dc:creator>marco_hammel2</dc:creator>
      <dc:date>2023-03-12T15:05:15Z</dc:date>
    </item>
  </channel>
</rss>

