Application Development and Automation Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

Table DD09L question

Former Member
0 Likes
4,577

Hello, in the SAP environment I am reviewing, in the DD09L table, table logging is NOT enabled for certain business tables. If a user has SAP_ALL, could that user process a payment to a vendor, then delete the table record in BKPF and BSEG, and the table change would NOT be recorded? Thanks!

1 ACCEPTED SOLUTION
Read only

Former Member
0 Likes
3,001

Hi

If you find out table logging is not enabled you can enable the same from SE16 -> Table name-> Change -> technical Setting ..

It will raise a TR generate that tr and TRansaport the same into othe environments as per the requirement .

Secondly with the help of SAP All Profile a user can perform all as SAPall it self denotes full authorization to the entire system ..

As per the audit point no one should havse SAP_All Authorization

Regards

Shilpa

2 REPLIES 2
Read only

Former Member
0 Likes
3,001

DD09L is a different concept to application logs.

Yes they could delete from the BSEG with SAP_ALL, but it would cause a mess (inconsistency) which an auditor would find very easily.

Cheers,

Julius

Read only

Former Member
0 Likes
3,002

Hi

If you find out table logging is not enabled you can enable the same from SE16 -> Table name-> Change -> technical Setting ..

It will raise a TR generate that tr and TRansaport the same into othe environments as per the requirement .

Secondly with the help of SAP All Profile a user can perform all as SAPall it self denotes full authorization to the entire system ..

As per the audit point no one should havse SAP_All Authorization

Regards

Shilpa