2016 Mar 12 6:13 AM
Our company never had anyone to manage the roles of the users. When user request access to certain transactions, we simple just added the transaction in one of the roles we thought it would fit the best based on description.
At this point , multiple roles for that user have the same authorization objects.
I got a request to restrict the transaction based on a cost center. Restricting the authorization object on K_CCA for the role that contains the transaction doesn't work because K_CCA can be found in other roles for the user. We can restrict all the K_CCA objects we find for that user in all the roles but this doesn't seem to be the right solution or is it?
what is the best solution for such scenraios? Should be restructure roles so all the transactions that use the same authorization objects are under the same role? or create a program enhancment and programmatically set a authorization based on user and cost center?
any ideas would be welcomed
thanks
2016 Mar 14 9:55 AM
Hi Juan,
As a temporary fix (considering the current request has some fixed ETA), i would recommend to update the all the roles of user which contain this auth object but this can cause issue to other users having common roles hence you need to check this beforehand.
As a long term solution to make whole security task easy, its highly recommended to make your SAP roles consistent and adaptive to further subsequent changes.
Thanks
Our company never had anyone to manage the roles of the users. When user request access to certain transactions, we simple just added the transaction in one of the roles we thought it would fit the best based on description.
At this point , multiple roles for that user have the same authorization objects.
I got a request to restrict the transaction based on a cost center. Restricting the authorization object on K_CCA for the role that contains the transaction doesn't work because K_CCA can be found in other roles for the user. We can restrict all the K_CCA objects we find for that user in all the roles but this doesn't seem to be the right solution or is it?
what is the best solution for such scenraios? Should be restructure roles so all the transactions that use the same authorization objects are under the same role? or create a program enhancment and programmatically set a authorization based on user and cost center?
any ideas would be welcomed
thanks
2016 Mar 12 8:58 AM
I would highly recommend to restructure the authorization concept. Implementing of enhancements is definetely not the right way.
2016 Mar 12 10:56 AM
Depending on if you want to keep digging your grave or you want to clean up the mess.In other words I agree with Michael.
Cheers
2016 Mar 14 9:55 AM
Hi Juan,
As a temporary fix (considering the current request has some fixed ETA), i would recommend to update the all the roles of user which contain this auth object but this can cause issue to other users having common roles hence you need to check this beforehand.
As a long term solution to make whole security task easy, its highly recommended to make your SAP roles consistent and adaptive to further subsequent changes.
Thanks
2016 Mar 14 2:33 PM
Santosh,
Thanks for help.
What is the correct why to structure the authorization object?what do you mean by consistent?
The way I see it, multiple authorization objects will always be shared in multiple roles because transaction have multiple authorization objects.
2016 Mar 16 3:31 AM
Hi Juan,
You need to define all your roles as per any recommended role design policy such as based on user's position/job description. Multiple roles will share the common authorization objects provided multiple JDs have some common activities among them.
Hope this helps
Thanks
| User | Count |
|---|---|
| 3 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |