cancel
Showing results for 
Search instead for 
Did you mean: 

segregation of Basis/Admin duties

Former Member
0 Kudos

Our upper management ordered an audit of all roles in our ERP system. The company that audited us came up with a pretty extensive report that basically said a Basis Admin should not have the rights to both create transports and actually move transports. That's just one example. But there were many. Our Basis team is 4 people, yet their recommendations were to have close to 10 segreated duties that, in all my years(10+), have typically been performed by the same role. Clearly, this "report" that the auditor ran was pre-canned and scripted with little input on our specific company/environment. But I want to know - does anyone have any SAP published docs about recomendations on Basis roles and what transactions/duties they encompass?

Any comments on how similar audits at your own company might have gone?

Accepted Solutions (0)

Answers (2)

Answers (2)

Former Member
0 Kudos

Traditionally, I have seen Basis Admins have SAP_ALL and SAP_NEW in all systems except PROD. But in the SAP Best Practices for Security, Basis admins normally have a role set up that has pretty much everything they need. It does not normall include Security and most business transactions.

Former Member
0 Kudos

Basis admins should have all rights in the systems ,i never saw a basis admin having roles in his master record

admins have sap_all and sap_new