Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

what roles should be assigned to HR and SD peoples.

Former Member
0 Kudos

Hi all,

I have a doubt in security. what roles should be assigned to HR and SD,MM people instead of assigning SAP_ALL and SAP_NEW. I want to restrict all the people giving SAP_ALL and SAP_NEW. How to assign the roles to them and how to authorize them. Plz can anybody tell me clearly the steps for this.

Thanks & Regards

Karunakar Reddy

5 REPLIES 5

jurjen_heeck
Active Contributor
0 Kudos

Basically what you're asking is a step by step guide to role design and implementation. This is an often asked and seldom answered question on this forum (and other forums) because it is not a simple question and not a light task.

Best start by asking your functional teams' members which transactions they need and start from there.

You can also have a look at the standard roles delivered by SAP. Maybe some could suit your needs.Try to find out which ones do, copy those and work from there.

If you want more information from us please tell us:

1 What have you done so far to acquire knowledge on the SAP authorization concept?

2 For who do you want to build roles? Developers, functional consultants, key-users, endusers?

3 Is this on a development environment or a complete landscape?

4 What is your job role in the project/company?

Jurjen

0 Kudos

Hi,

I want to assign the roles to developers, functional consultants and endusers in a landscape. Can u plz tell me. What roles should be given to Technical consultants and what roles to Functional consultants. How to identify the roles which role is for which consultants. Plz tell me clearly. I am new to security. We are developing the new landscape and we want to restrict all the consultants from accessing other transaction codes. Technical consultants should be given their related transaction codes and they should not be allowed to acess other transaction codes. Similarly for functional consultants. But i want to know what transaction codes and roles should be assigned to all these technical and functional consultants. Can u plz help me out.

Regards

Karunakar Reddy

0 Kudos

Karunakar

Jurjen has told you what you need to do & has included some very relevant questions.

I suggest that if you are not comfortable with this then you enlist the help of an experienced security consultant who will be able to undertake this action. No-one here is going to give you a list of tx which may or may not be relevant to your implementation.

1. Ask your project team what tx then need

2. Build the roles

3. Get them to test them

4. Fix the bugs

5. Repeat steps 3&4 until fixed

0 Kudos

I guess what people are trying to say is that SAP security is not some simple pre-canned and defined thing that you can just say definitively that SD people get this, MM this, and HR this.

Every organization is completely different, their needs are different, and their risks are different. I'm afraid that you will need to refer to all of the other suggestions in this thread and work for there. Even if you start your development by using specific module chucks from the menu there are lots of hidden security, basis, development, and other transactions under even the functional modules that you will likely not want to give your functional team.

Former Member
0 Kudos

Best thing is to creat new role for each module in PFCG.

In pfcg enter authorization from "start menu" (option at the left)

Select the relevant sub tree from easy access access menu...

and save the role ...