We have added search box. Key in SAP issue keyword to search

Announcement: wanna exchange links? contact me at sapchatroom@gmail.com.

Re: [sap-security] PFCG_UPDATE_ALL_ROLES in Production

Posted by Admin at
Share this post:
Ma.gnolia DiggIt! Del.icio.us Yahoo Furl Technorati Reddit

Reply from wilderlatino on Jun 27 at 10:56 AM
It's making a change in PRD so audit will not like this. Transport roles from dev.

---------------Original Message---------------
From: sheffeld
Sent: Tuesday, June 27, 2017 9:55 AM
Subject: PFCG_UPDATE_ALL_ROLES in Production

The primary con is that you can remove an end user's access for the role
being generated, while they are using it.

The primary pro is that end user's may not have access to the
authorizations in a role requiring generation until the role has been

My preference (and what has been considered a best practice) is to run
program PFCG_TIME_DEPENDENCY on a periodic basis in Production. The
timing would depending upon the frequency of transports with
role/authorization object/field/transaction modifications being promoted
to Production. Look for the period of least end user logins and then
coordinate with your Basis team to choose a time or times with the least
amount of traffic.


Reply to this email to post your response.
Manage Settings | Unsubscribe | Create FAQ | Send Feedback
© 2017 Ziff Davis, LLC. and message author.
Ziff Davis, LLC. 28 E 28th Street New York, NY 10016

Mark as helpful
View this online
Ask a new question
In the Spotlight
Have a technical question? Need to find IT solutions? Ask your peers in the Toolbox for IT community.



Post a Comment

T r a n s l a t e to your language