Tables, Roles, Profiles and Authorizations in SAP

Posted by Fabio Mambretti on Apr 15, 2022 12:00:00 AM

Which are the main Security SAP Tables for SAP Roles and Profiles?

SAP contains hundreds of thousands of tables. In some cases the direct access to these tables allows one to retrieve data faster. Below a list of tables for each defined area:

  • SAP Roles
  • SAP Profiles
  • Users
  • Authorizations
  • Authorization objects
Read More

Topics: SAP ECC, sap standard role, Profiles, SAP Table

SAP Role and User Administration: what are the metrics?

Posted by Marta Ortona on Apr 8, 2022 12:00:00 AM

 

How does one know if you have set up a good authorization concept in SAP??

 

What are the metrics and how to best exploit them? Does a SAP Security Score exist? 

Read More

Topics: User Access Management, autorizzazioni sap, sap custom, Statistiche security SAP

Who are the owners of the Governance and Security area?

Posted by Fabio Mambretti on Apr 1, 2022 12:00:00 AM

Why is that all the decisions taken following authorization assignments requests fall under the IT department?

Read More

Topics: Segregation of duties, sap access control

SAP Field Masking

Posted by Fabio Mambretti on Mar 25, 2022 12:00:00 AM

For reasons of internal policies or regulations it may be necessary to make some data inside of SAP anonymous. There are many ways to do this. The first elements we need to consider are:

  • Which data needs to be anonymous
  • In which systems/environments
  • Which users to authorize
  • How to monitor the compliance of the created segregation
Read More

Topics: SAP GDPR, UI logging, UI Masking

SAP Upgrades. Authorizations are always neglected, why?

Posted by Fabio Mambretti on Mar 18, 2022 12:00:00 AM

 

SAP updates are frequent. SAP releases feature updates to its products but also new features or patch security.

 

Read More

Topics: patch, pfcg, su25, upgrade, HANA

Consultants with production environment access? 5 actions to remember!

Posted by Marta Ortona on Mar 11, 2022 12:00:00 AM

 

Is it really possible that external consultants do not have any access to SAP production systems? 

 

Clearly there are various case studies, occasional or ongoing consultants, for example for maintenance contracts.

 

Is it really necessary to release an access to the production systems even in this last case? Can we control what happens and why it is requested?

Read More

Topics: pfcg, gdpr, sap_all, sod, SAP GRC, consulenti

How does Segregation of Duties help protect your company data?

Posted by Fabio Mambretti on Mar 4, 2022 12:00:00 AM

How does segregation of duties help protect your company data?

 

Read More

Topics: ISO, sod, SAP Security, governance

How to export data from SAP?

Posted by Fabio Mambretti on Feb 25, 2022 12:00:00 AM

Here's why it's important to check how data is exported and by who it's spread

How do you monitor the data exported from SAP ECC?

 

Many users must be formally authorized in order to do that as part of their job. It’s however of great importance, especially in a GDPR framework, to monitor how and who exports data in a non-authorized way from the SAP system.

How do you do that? Let’s see some paid methods and others included in the SAP business suite

Read More

Topics: gdpr, security audit log, SAP Security, SAP HR, SAP ECC, UI logging, UI Masking

Change management SAP Security

Posted by Marta Ortona on Feb 18, 2022 12:00:00 AM

Are you an auditor? Or an IT manager who wants to monitor the data of his own SAP systems? 

 

Is it possible to assign privileges without leaving traces or almost?

 

 

That’s why you need to know what are the potential risks in the SAP system and how you can mitigate them!

 

 

Read More

Topics: ABAP, programmazione sicura, sicurezza codice ABAP

How do you surpass the 312 profiles limit in SAP?

Posted by Fabio Mambretti on Feb 11, 2022 12:00:00 AM

In SAP there is/was a limit on the number of profiles that can be assigned to a user. Historically this limit of 300 and then 312 has been kept to stop the assignment of too many authorizations to users.

 

 

Does this limit persist?

Read More

Topics: pfcg, SAP Security, profili, ust04, SAP ECC, 312

Yes Subscribe!

Blog Aglea, what you could find out?

Every Friday a new post, interview or content related to SAP Security.

  • Tips on how to design SAP Security
  • How to
  • Checklist
  • Common error and pitfall on security SAP
  • Interview with experts
  • Who we are and Aglea vision on SAP Security

Recent Posts

Post By Topic

See all