We have added search box. Key in SAP issue keyword to search
TopBottom

Announcement: wanna exchange links? contact me at sapchatroom@gmail.com.

Re: [sap-security] How to restrict security admin to not able to change his own access

Posted by Admin at
Share this post:
Ma.gnolia DiggIt! Del.icio.us Yahoo Furl Technorati Reddit

Posted by cybong (Mr)
on Feb 25 at 3:03 AM
Mark this reply as helpfulMark as helpful
hi all/lee

you can go ahead with the authorization object �p_perner to restrict the access of one to change records�except his�own record.

________________________________
From: Lee Allen via sap-security <sap-security@Groups.ITtoolbox.com>
To: cybong <maran_chennai@yahoo.co.in>
Sent: Thu, 25 February, 2010 5:49:19 AM
Subject: RE: [sap-security] How to restrict security admin to not able to change his own access


Posted by Lee Allen (Senior Lead Analyst)
on Feb 24 at 9:10 PM Mark as helpful
In addition to any preventive control as you are inquiring, there must be a
detective control whereby all changes to access are reviewed, particularly
those with the ability to change access. To depend on only preventive
controls is not a best practice.

Warm regards,

The information transmitted is intended solely for the individual(s) or
entity to whom it is addressed and may contain confidential and/or
privileged material. Any review, retransmission, dissemination or other use
of or taking action in reliance upon this information by persons other than
the intended recipient is prohibited. If you have received this email in
error please contact the sender and delete the material from any computer.

From: sapsecurity247 via sap-security
[mailto:sap-security@Groups.ITtoolbox.com]
Sent: Wednesday, February 24, 2010 3:37 PM
To: Lee Allen
Subject: [sap-security] How to restrict security admin to not able to change
his own access

Posted by sapsecurity247
on Feb 24 at 3:39 PM

How to restrict security admin to not able to change his own access but able
to change others access. this can be acheived by restricting his user group
in S_USER_GRP, but he will not be able to change access for other users in
his group. i know the admins can be divided into two groups and can be
restricted not to change the users in their group. Is there any other
solution? please question me for more details.
__.____._
Copyright © 2010 Toolbox.com and message author.

Toolbox.com 4343 N. Scottsdale Road Suite 280, Scottsdale, AZ 85251

0 comments:

Post a Comment

T r a n s l a t e to your language