Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

SAP_ALL profile ?

Former Member
0 Kudos

hi there,

we have 4 users with a SAP_ALL and SAP_NEW Profile. (myself included)

now we had a audit where they forced us to NOT ALLOW using of manipulate data, which

means that it should NOT be allowed to use SE16N and changing data in debugging mode.

how can i achive this ? do i have to create a lot of roles for

1 ACCEPTED SOLUTION

Former Member
0 Kudos

SAP_ALL and SAP_NEW should not be assigned to any user in the production system....Although now there is no point in reiterating the same.

However please ensure that proper authorizations are set up in the system via roles so as to avoid audit issues.

The present scenario that you quote revolve around two objects ie. S_DEVELOP objtyp DEBUG and authorization to object S_TABU_DIS actvt Change.

There are many more restrictions on authorizations to ensure secure production environment.

10 REPLIES 10

jurjen_heeck
Active Contributor
0 Kudos

> how can i achive this ? do i have to create a lot of roles for

Yep. It doesn't have to be "a lot", but you'll have to create roles for the activities you need for your work.

0 Kudos

thats the BIG problem !

i am using SAP_ALL for almost 8 years now ! no problem with that ! and i STILL want to use it, but we are not allowed (as of law).

i am responsible for the whole sap ! we are only 3 people for SAP here, and we do EVERYTHING !!! basis, FI/CO, HR, programming ! there is nothing we are not using

reg, Martin

Former Member
0 Kudos

SAP_ALL and SAP_NEW should not be assigned to any user in the production system....Although now there is no point in reiterating the same.

However please ensure that proper authorizations are set up in the system via roles so as to avoid audit issues.

The present scenario that you quote revolve around two objects ie. S_DEVELOP objtyp DEBUG and authorization to object S_TABU_DIS actvt Change.

There are many more restrictions on authorizations to ensure secure production environment.

0 Kudos

as i said, we are using SAP_ALL for 8 years now. and there is NO(!) reason to change this expect the audit thing

well, is there a way to generate a role (or more roles) from SAP_ALL, and then change the roles ? that would be the easiest way for us.

reg, martin

0 Kudos

> well, is there a way to generate a role (or more roles) from SAP_ALL, and then change the roles ? that would be the easiest way for us.

Please use the forum search, this question has been asked several times before.

0 Kudos

i have used the search, even before my posting, but haven't found the right answer, sorry ;(

reg, martin

0 Kudos

The thread [How to remove SPRO from SAP_ALL profile|; will probabely get you going, even though the requirement isn't exactly the same.

0 Kudos

hi friends,

thanks for the links to other posts and so on, BUT: i stil haven't found anything for my specific question:

is it possible to generate ROLES out of SAP_ALL and SAP_NEW profile ?

reg, Martin

0 Kudos

Yes it is, and discussed before, but here goes:

Go to PFCG

Create an empty single role

Go directly to the authorizations tab

Go into the profile and

select template SAP_ALL

or

do not select a template and go to edit ->insert authorization -> from profile

If your SAP_ALL is recently regenerated there's no additional value in SAP_NEW.

0 Kudos

This is a way to get around SAP _ALL profile. But still its not recommeded.

Its only a matter of time your auditors pull you up - with a compare -all the ghosts are out !

Thanks