Quantcast
Channel: SCN: Message List - Security
Viewing all articles
Browse latest Browse all 5338

Re: Role Comparisons

$
0
0

You could use Excel, concatenate and vlookup to run some comparisons on the AGR_1251 data for your old and new roles. But all you would be doing is replacing 50 small bad roles with 1 big bad role.

 

You've come across this requirement because the original roles were built badly, and effectively you're having to carry out a role redesign. In which case, the correct solution would be to:

 

1) Use ST01 traces to re-check what authorizations are required for each transaction - this way you know for sure that you know you are only adding relevant authorizations.

 

2) Update SU24 with the correct authorization proposals for those transactions. That way you have a link between each tcode and auths that it needs.

 

3) Add your transactions to the role menu so that the relevant auth objects and values are pulled through automatically. You will still have some open fields to maintain, but you'll know what values are needed from the trace files.

 

This will take you longer initially, but it is a more robust, longer lasting solution. There is no point in replacing one bad role design with another.


Viewing all articles
Browse latest Browse all 5338

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>