RE: [sap-security] Organizational levels in ECC 5.0
Posted by
Admin at
|
Share this post:
|
0 Comments
| | Posted by meconsulting on Feb 7 at 6:55 PM | |
I agree with Henrik, use derived roles it will cut down your maintenance and
complexity.
The concept you are talking about was used a lot pre-profile generator and
has the potential to create problems for you when you upgrade/apply hot
packs etc.
Mark
_____
From: henrikmadsen2 via sap-security
[mailto:sap-security@Groups.ITtoolbox.com]
Sent: Monday, 8 February 2010 7:49 AM
To: meconsulting
Subject: Re: [sap-security] Organizational levels in ECC 5.0
Posted by henrikmadsen2 (GRC
Consultant )
on Feb 7 at 6:20 PM
<http://it.toolbox.com/api/ContentVote/3289892/1/1/> Mark this reply as
helpfulMark as helpful
What you are talking about sounds like the split role concept, or enabler
roles. This can get very messy if you don't get it just right!
I would recommend using derived roles for this purpose. Much easier to
maintain in my opinion...
/henrik
On 8 February 2010 07:44, D_Gorby via sap-security <
sap-security@groups.ittoolbox.com> wrote:
>
> Posted by D_Gorby (SAP Security
> Analyst)
> on Feb 7 at 3:51 PM
>
> Kent,
>
> So I can put multiple objects which contain both the company code and
plant
> in the role which should limit the access in those areas.
>
> Thanks,
> D
>
> ---------------Original Message---------------
> From: D_Gorby
> Sent: Friday, February 05, 2010 5:15 PM
> Subject: Organizational levels in ECC 5.0
>
> > I'd like to create a role which contains just the org levels, I have
> multiple divisions and want to restrict by org levels yet have them have
the
> same roles. What's the best way to approach this?<br/>Thanks,
__.____._ complexity.
The concept you are talking about was used a lot pre-profile generator and
has the potential to create problems for you when you upgrade/apply hot
packs etc.
Mark
_____
From: henrikmadsen2 via sap-security
[mailto:sap-security@Groups.ITtoolbox.com]
Sent: Monday, 8 February 2010 7:49 AM
To: meconsulting
Subject: Re: [sap-security] Organizational levels in ECC 5.0
Posted by henrikmadsen2 (GRC
Consultant )
on Feb 7 at 6:20 PM
<http://it.toolbox.com/api/ContentVote/3289892/1/1/> Mark this reply as
helpfulMark as helpful
What you are talking about sounds like the split role concept, or enabler
roles. This can get very messy if you don't get it just right!
I would recommend using derived roles for this purpose. Much easier to
maintain in my opinion...
/henrik
On 8 February 2010 07:44, D_Gorby via sap-security <
sap-security@groups.ittoolbox.com> wrote:
>
> Posted by D_Gorby (SAP Security
> Analyst)
> on Feb 7 at 3:51 PM
>
> Kent,
>
> So I can put multiple objects which contain both the company code and
plant
> in the role which should limit the access in those areas.
>
> Thanks,
> D
>
> ---------------Original Message---------------
> From: D_Gorby
> Sent: Friday, February 05, 2010 5:15 PM
> Subject: Organizational levels in ECC 5.0
>
> > I'd like to create a role which contains just the org levels, I have
> multiple divisions and want to restrict by org levels yet have them have
the
> same roles. What's the best way to approach this?<br/>Thanks,
Copyright © 2010 Toolbox.com and message author.
Toolbox.com 4343 N. Scottsdale Road Suite 280, Scottsdale, AZ 85251
Toolbox.com 4343 N. Scottsdale Road Suite 280, Scottsdale, AZ 85251
Related Content
In the Spotlight
White Papers
In the Spotlight
Earn Recognition for Your Contributions at Toolbox for IT. Gain Points for Community Achievements
View this thread online
Manage group e-mails
Create an FAQ on this topic
Tell us what you think
Unsubscribe from discussion
Manage group e-mails
Create an FAQ on this topic
Tell us what you think
Unsubscribe from discussion