TIP OF THE DAY: LIMIT VISIBILITY TO CERTAIN FINANCIAL YEARS

Posted by Klea Duro on Feb 10, 2023, 12:00:00 AM

For many companies using SAP (if not all of them) it is absolutely normal to 'undergo' inspections by external entities. Especially for the auditing of balance sheet data.

 

 

A common practice is to enable everything to the auditors. And from the perspective of maximum transparency it could certainly make sense. But is it possible to evaluate or reason differently? Continue reading...

Read More

TIP OF THE DAY: SAP AUTHORIZATION PFUD USER COMPARISON

Posted by Klea Duro on Feb 3, 2023, 12:00:00 AM

Did you know that there is a feature called "User Comparison" in SAP? Even in S/4HANA?

 

 

But what is it for and why in some cases might there be errors?

Read More

SAP DEFAULT PASSWORD

Posted by Fabio Mambretti on Jan 27, 2023, 12:00:00 AM

Did you know that there are "special" SAP users whose credentials are known, public?

This is not an SAP oversight; it is something known and familiar. Especially in the initial setup processes of the system, utilities are activated that should be secured immediately thereafter. But what are they and what should you do?

Read More

Topics: password policy, sap super user, sap password, cyber security, userid

Tip of the day: SAP User Parameters

Posted by Fabio Mambretti on Jan 20, 2023, 12:00:00 AM

In this series of articles we discuss the "tip" of the day. That is, real cases of requests received in counseling. 

Today we discuss "is it worth using user parameters to manage permissions?" What are the advantages and disadvantages?

Read More

Topics: parameter sap, SAP GRC, SAP IDM, sap gui

SAP Roles and Profiles, what are they?

Posted by Fabio Mambretti on Jan 13, 2023, 12:00:00 AM

In the day-to-day these terms are often used as synonyms , but they're actually not

They can be confused and often it's not clear whether it's correct to talk about SAP profiles or roles. Let's try to underline the differences between these two terms, by starting from the past!

Read More

Topics: sap security blog, authorization model, authorization concept, HANA Roles, Profiles

SAP GRC Access Control Tables

Posted by Andrea Mazzolani (translation) on Jan 6, 2023, 12:00:00 AM

Which are the tables of the SAP GRC Access Control product useful to know (out of the existing 2500)?

Read More

Topics: sap grc tables, tabelle SAP grc access control

SE16 in SAP

Posted by Fabio Mambretti on Dec 30, 2022, 12:00:00 AM

For some SE16 may be an unknown acronym. For others it is the "bread and butter." It is a SAP transaction remarkably familiar to administrators. And often not only them, unfortunately.

 

 

 

But what is it used for? How many versions of it are there? How do you use it and what are the risks involved?

We discuss  it in this article!

Read More

Topics: se16n, se16, SAP Security, supporto sap ams, sap query, SAP GDPR

SAP Security Optimization Service (SOS)

Posted by Andrea Mazzolani (translation) on Dec 23, 2022, 12:00:00 AM

Did you ever hear about it? What does it do?

 

 

How does it work and what are the attention points of this tool?

Read More

Topics: sap earlywatch, secure operation map, sap sos

SAP Security Authorization for projects? No thanks!

Posted by Andrea Mazzolani (translation) on Dec 16, 2022, 12:00:00 AM

What does it mean? Do you have a uniform model to manage SAP Security or for each project you have to do it from scratch, wishing that it will be at least similar to the one already done, maybe from others in the past?

 

 

Let's discover in this article if the centralized management SAP Security is better or worse. Are there one or multiple orchestra directors?

Read More

Topics: consulenza sap security, consulenti sap security, progetti security sap

SAP SCP/BTP for external, how to do it?

Posted by Andrea Mazzolani (translation) on Dec 9, 2022, 12:00:00 AM

It's always more common to see hybrid sceneries, meaning On-premise and on cloud systems. Or just on cloud.

 

 

In these systems too, obviously, it's necessary to activate these policies used in on-premise systems.

 

But what accesses should you supply? Especially to who still isn't part of this organization?

Read More

Topics: sap btp, SAP Cloud Security

Yes Subscribe!

Blog Aglea, what you could find out?

Every Friday a new post, interview or content related to SAP Security.

  • Tips on how to design SAP Security
  • How to
  • Checklist
  • Common error and pitfall on security SAP
  • Interview with experts
  • Who we are and Aglea vision on SAP Security

Recent Posts

Post By Topic

See all