Quantcast
Channel: SCN: Message List - Security
Viewing all articles
Browse latest Browse all 5338

Re: How to switch a whole SAP system to be Display ONLY

$
0
0

Hi Colleen,

 

I totally agree that buidling a display role as equivalent for SAP_ALL does not work. I know this, because I tried and completely failed (see your linked post).

 

But in my opinion it also depends a little bit on the approach and what you really need. One must ask oneself if SAP_ALL with display restrictions is really needed, who requested it and what was the intention. Maybe it would be sufficient to provide a role containing all real display transactions of the SAP system.

 

If you are able to build a role based on transactions that are designed and known as display transactions, then this role would be acceptable. Otherwise SAP would have a big security problem with all its display transactions.

 

Maybe this role does not give you display access for the whole system, but from a business view most parts should be covered by it. It all depends on the chosen transaction set and the painful job to restrict all authorizations to display or set them to inactive if not possible.

 

Best regards

Stefan


Viewing all articles
Browse latest Browse all 5338

Trending Articles