Can someone help to understand
1. the difference between firefighter user / controller / owner and what role does each play. Can the owner and controller be the same ? Usually, what is the scenario?
2. For planning access, should it be sufficient to realize the different players as :
user a,b,c,d,e: firefighter users (sap users who will be assigned on ad-hoc basis by owner)
user f,g: FF controllers (project managers and security team)
user i: FF owner (module lead)
3. Following roles are provided by SAP.
These roles are provided as examples and customer roles need to be created based on their authorizations.
In the AC system:
Firefighter user: SAP_GRAC_SUPER_USER_MGMT_USER
Firefighter controller: SAP_GRAC_SUPER_USER_MGMT_CNTLR
Firefighter owner: SAP_GRAC_SUPER_USER_MGMT_OWNER
In the target system: Firefighter ID SAP_GRAC_SPM_FFIDWhat does customer role refer to ? I understand that I will need to create FFIDs with appropriate authorizations in the target system but will I have to assign the role SAP_GRAC_SPM_FFID to it in addition ? What other roles will need to be applied in relation to FF access?
Thanks,
Help others by sharing your knowledge.
AnswerRequest clarification before answering.
Hi Jay,
While the SAP terminology is self explanatory ,the meaning of FF Owners ,IDs and Controllers differ from Organization to Organization.In General, I would define them as follows in a lucid language :
Owner : Takes complete ownership of a FFID in target system . Owner is responsible for assigning FFIDs to responsible business / support users (firefighters ) . Owner is also responsible for making sure that FFIDs are not abused.
Controller : Reviews log and is able to interpret the log in a pure business sense . He is generally a business process owner .
I have seen that Owner and Controller for an FFID can be same .but this again depends on the compliance requirement of an organization
In GRC AC 10.0 , an FFID can have the same owner and controller but an owner/controller cannot assign the FFID to him/herself. This is SAP's way of preventing abuse.
Reward points if my answer was useful.
Best Regards,
Vishal Padiyar
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Jai,
My answers for your questions are as below.
1)
the difference between firefighter user / controller / owner and what role does each play. Can the owner and controller be the same ? Usually, what is the scenario?
Please check the below link to understand the concept
[http://help.sap.com/saphelp_grcac10/helpdata/en/16/404938695540b398a5e76fe8cfb067/content.htm]
2)
or planning access, should it be sufficient to realize the different players as :
user a,b,c,d,e: firefighter users (sap users who will be assigned on ad-hoc basis by owner)
user f,g: FF controllers (project managers and security team)
user i: FF owner (module lead)
It depends on how your customer requires them. Have a meeting with the customer people responsible (Business Process Owners, IT people etc.) and discuss the open points you have.
3)
These roles are provided as examples and customer roles need to be created based on their authorizations.
In the AC system:
Firefighter user: SAP_GRAC_SUPER_USER_MGMT_USER
Firefighter controller: SAP_GRAC_SUPER_USER_MGMT_CNTLR
Firefighter owner: SAP_GRAC_SUPER_USER_MGMT_OWNER
In the target system: Firefighter ID SAP_GRAC_SPM_FFID
What does customer role refer to ?
Customer Role refers to the roles you need to create for the SAP customer/client you are working for.
I understand that I will need to create FFIDs with appropriate authorizations in the target system but will I have to assign the role SAP_GRAC_SPM_FFID to it in addition ?
You need to create FFIDs in the AC system not the target system. and add the role SAP_GRAC_SUPER_USER_MGMT_USER along with the appropriate authorization. Also add this role to the firefighter User. In the target system (ERP system) you need to assign the role SAP_GRAC_SPM_FFID to the firefighter ID.
What other roles will need to be applied in relation to FF access?
This much is ok. No more roles required to add relation to FF access?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
If I'd create the FFID in AC system,
You need to create FFIDs in the AC system not the target system. and add the role SAP_GRAC_SUPER_USER_MGMT_USER along with the appropriate authorization.
how will I assign the roles in the target system ?
In the target system (ERP system) you need to assign the role SAP_GRAC_SPM_FFID to the firefighter ID.
Hi Jay,
You have to create Fire-fighter ID on Backend system as service user and assign role SAP_GRAC_SPM_FFID (or copy this role to Z role and assign to FF ID)
Ensure that you maintain SAP_GRAC_SPM_FFID role in SPRO -~GRC-----Access control- maintain configuration setting----
SPM PAramID 4010
then run synchronize job..
In AC system you have FF User assign role "SAP_GRAC_SUPER_USER_MGMT_USER" , for Owner assign role "SAP_GRAC_SUPER_USER_MGMT_OWNER" and for controller assign role "SAP_GRAC_SUPER_USER_MGMT_CNTLR".
Ensure that you maintain owner and controller on NWBC through tab access management.
Regards,
Dear Venkat,
as this thread is closed I suggest to to open a new one with your question/problem.
Basically I can also answer the question if this is all you want to know:
- Firefighter ID : the user id which is defined as firefighter. This user account is type of service.
- Firefighter : we call the user who is using a Firefighter ID as Firefighter.
If you need more please open a new thread with your question.
Thanks and regards,
Alessandro
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.