---
title: SAP Security Authorization for projects? No thanks!
description: Managing the SAP authorizations per project? Is it convenient? What should you know?
image: https://www.aglea.com/hubfs/Aglea/Imported_Blog_Media/SAP%20Security%20Project-Jun-14-2024-10-11-06-8489-AM.jpg
---

[linkedin](https://www.linkedin.com/company/292350?trk=vsrp_companies_res_name&trkInfo=VSRPsearchId%3A3373431891426179412478%2CVSRPtargetId%3A292350%2CVSRPcmpt%3Aprimary) [YouTube](https://www.youtube.com/c/AgleaSAPSecurity?sub_confirmation=1) [Twitter](https://twitter.com/AgleaItaly?lang=en)

[![Logo-Aglea-horsa-company](https://www.aglea.com/hubfs/Aglea/Aglea_November2018%20Theme/Images/Logo-Aglea-horsa-company.webp) ](https://www.aglea.com/en)

# SAP Security Authorization for projects? No thanks!

# SAP Security Authorization for projects? No thanks!

Posted by [Andrea Mazzolani (translation)](https://www.aglea.com/en/blog/author/andrea-mazzolani-translation) on Dec 16, 2022 12:00:00 AM

- [Tweet](https://twitter.com/share)

What does it mean? Do you have a uniform model to manage SAP Security or for each project you have to do it from scratch, wishing that it will be at least similar to the one already done, maybe from others in the past?

 

![SAP Security Project](https://www.aglea.com/hs-fs/hubfs/Aglea/Imported_Blog_Media/SAP%20Security%20Project-Jun-14-2024-10-11-06-8489-AM.jpg?width=500&name=SAP%20Security%20Project-Jun-14-2024-10-11-06-8489-AM.jpg)

 

Let's discover in this article if the centralized management SAP Security is better or worse. Are there one or multiple orchestra directors?

 

 

## SAP Security in your company

My idea is that in a company there should be a dedicated team that takes care of SAP security. Clearly the team depends from the company's dimension.

 

It can be made of one person that partially takes care of managing SAP authorizations and/or more in general the security other than other activities or a proper team of specific resources.

 

I think that the presence of people trained on the subject inside the company is essential. Sure I'm not expecting to find a guru on the subject in all realities. But at least he has to know the logics.

 

Delegating anything outside (including the covernance) is in my opinion unthinkable and risky. While it could be correct to outsource the system maintenance, meaning having an [AMS SAP Security](https://www.aglea.com/en/sap-security-ams) service.

 

If the supplier on duty proposes me something, I want to know what it's about in the short term and mainly in the long term. Will I have consequences on the choice made in the future? He's proposing something that solves a certain problematic but maybe it could cause difficulties in the future.

 

How is it possible to know or be critical (in a constructive way) if you don't know what you're talking about?

 

The same way I don't consider correct that the security is delegated to the various module functions. For example, the purchasing area and warehouse roles are managed by who takes care, in the IT, of the MM (Material Management) SAP module inside the company.

 

Why I think it's wrong:

- **Delegating everything outside the company,** including the model governance, can lead to a loss of know-how in the company on the topic ([but how to prepare to an AMS?](https://www.aglea.com/blog/sap-ams-come-prepararsi))
- **Also from the supplier point of view this is a problem**. I find myself at times explaining trivial concepts, to do anything, because the company lost any tipe of knowledge. This makes everything extremely complex and long to actuate. Including things that should be taken for granted.
- The applicative IT modules must manage the processes of competence and concentrate on their job. They can't also take care of SAP Security too. Sure, they're of great help and have to support the security but not substitute it. Why?
  
  Here are some examples:

 

## SAP Security for projects

Often a company thinks on the basis of projects, on new activities to carry out. But is it correct to do it for the SAP Security management too? I don't think so.

 

What do I mean?

 

During a SAP installation and configuration project in a company (also that was a project, more or less close in time) an authorization concept was defined. Let's not talk about if it was valid or not. Following that new project are born:

- Automatic warehouse management
- Activation of the CO-PA module
- Activation of the treasury
- Introduction of RPA logics
- Updating of the SAP S/4HANA system
- Etc...

 

These activities are often followed by internal staff but also by suppliers to who (when you remember to do it) you assign the management of authorizations, for that specific project.

 

I'm referring to that specific moment.

 

Here, if there isn't a common and shared model (especially with a supplier) there's the risk of creating n authorization models inside the system. One per object.

 

Sometimes I hear people say: The roles named ZTR* are the ones created during the treasury project. The roles that begin with ZCOMP* where COMP stands for the name of the company are the ones made at the beginning of the project. And so on.

 

Will this work? Not in my opinion.

 

There must be only one orchestra director for SAP Security. Regardless of the projects that are being carried out by the company.

****

 Topics: [consulenza sap security](https://www.aglea.com/en/blog/tag/consulenza-sap-security), [consulenti sap security](https://www.aglea.com/en/blog/tag/consulenti-sap-security), [progetti security sap](https://www.aglea.com/en/blog/tag/progetti-security-sap)

### Subscribe Here!

### Blog Aglea, cosa puoi trovare?

Ogni mercoledì pubblichiamo articoli, interviste e documenti relativi alla security SAP.

Cosa puoi trovare:

- Suggerimenti su come mettere in sicurezza i sistemi SAP
- Come fare a … (How To)
- Checklist
- Gli errori comuni che spesso vengono fatti in ambito Security SAP
- Interviste con esperti del settore
- Chi è AGLEA quale è la nostra vision security SAP

### Recent Posts

### Post By Topic

- [SAP Security (12)](https://www.aglea.com/en/blog/tag/sap-security)
- [SAP GRC (11)](https://www.aglea.com/en/blog/tag/sap-grc)
- [pfcg (8)](https://www.aglea.com/en/blog/tag/pfcg)
- [gdpr (7)](https://www.aglea.com/en/blog/tag/gdpr)
- [SAP GDPR (5)](https://www.aglea.com/en/blog/tag/sap-gdpr)
- [Segregation of duties (5)](https://www.aglea.com/en/blog/tag/segregation-of-duties)
- [governance (5)](https://www.aglea.com/en/blog/tag/governance)
- [sod (5)](https://www.aglea.com/en/blog/tag/sod)
- [SAP ECC (4)](https://www.aglea.com/en/blog/tag/sap-ecc)
- [audit sap (4)](https://www.aglea.com/en/blog/tag/audit-sap)
- [auditing (4)](https://www.aglea.com/en/blog/tag/auditing)
- [sap consulenza security (4)](https://www.aglea.com/en/blog/tag/sap-consulenza-security)
- [sap password (4)](https://www.aglea.com/en/blog/tag/sap-password)
- [HANA (3)](https://www.aglea.com/en/blog/tag/hana)
- [SAP HR (3)](https://www.aglea.com/en/blog/tag/sap-hr)
- [UI logging (3)](https://www.aglea.com/en/blog/tag/ui-logging)
- [rfc security (3)](https://www.aglea.com/en/blog/tag/rfc-security)
- [sap cyber security (3)](https://www.aglea.com/en/blog/tag/sap-cyber-security)
- [sap hana (3)](https://www.aglea.com/en/blog/tag/sap-hana)
- [sap_all (3)](https://www.aglea.com/en/blog/tag/sap_all)
- [security audit log (3)](https://www.aglea.com/en/blog/tag/security-audit-log)
- [sicurezza sap (3)](https://www.aglea.com/en/blog/tag/sicurezza-sap)
- [su53 (3)](https://www.aglea.com/en/blog/tag/su53)
- [HANA Security (2)](https://www.aglea.com/en/blog/tag/hana-security)
- [ISO (2)](https://www.aglea.com/en/blog/tag/iso)
- [Profiles (2)](https://www.aglea.com/en/blog/tag/profiles)
- [SAP FIORI Security (2)](https://www.aglea.com/en/blog/tag/sap-fiori-security)
- [SAP audit (2)](https://www.aglea.com/en/blog/tag/sap-audit)
- [Secure programming (2)](https://www.aglea.com/en/blog/tag/secure-programming)
- [UCON (2)](https://www.aglea.com/en/blog/tag/ucon)
- [UI Masking (2)](https://www.aglea.com/en/blog/tag/ui-masking)
- [access management (2)](https://www.aglea.com/en/blog/tag/access-management)
- [authorization concept (2)](https://www.aglea.com/en/blog/tag/authorization-concept)
- [autorizzazioni sap (2)](https://www.aglea.com/en/blog/tag/autorizzazioni-sap)
- [consulenti (2)](https://www.aglea.com/en/blog/tag/consulenti)
- [corso (2)](https://www.aglea.com/en/blog/tag/corso)
- [e-learning (2)](https://www.aglea.com/en/blog/tag/e-learning)
- [password policy (2)](https://www.aglea.com/en/blog/tag/password-policy)
- [patch (2)](https://www.aglea.com/en/blog/tag/patch)
- [programmazione sicura (2)](https://www.aglea.com/en/blog/tag/programmazione-sicura)
- [quality (2)](https://www.aglea.com/en/blog/tag/quality)
- [rfc (2)](https://www.aglea.com/en/blog/tag/rfc)
- [ruoli (2)](https://www.aglea.com/en/blog/tag/ruoli)
- [sap access control (2)](https://www.aglea.com/en/blog/tag/sap-access-control)
- [sap custom (2)](https://www.aglea.com/en/blog/tag/sap-custom)
- [sap etd (2)](https://www.aglea.com/en/blog/tag/sap-etd)
- [sap gui (2)](https://www.aglea.com/en/blog/tag/sap-gui)
- [sap query (2)](https://www.aglea.com/en/blog/tag/sap-query)
- [sap security guidelines (2)](https://www.aglea.com/en/blog/tag/sap-security-guidelines)
- [sap siem (2)](https://www.aglea.com/en/blog/tag/sap-siem)
- [sap standard role (2)](https://www.aglea.com/en/blog/tag/sap-standard-role)
- [sap super user (2)](https://www.aglea.com/en/blog/tag/sap-super-user)
- [sap vulnerability (2)](https://www.aglea.com/en/blog/tag/sap-vulnerability)
- [se16 (2)](https://www.aglea.com/en/blog/tag/se16)
- [security ams (2)](https://www.aglea.com/en/blog/tag/security-ams)
- [siem (2)](https://www.aglea.com/en/blog/tag/siem)
- [soar (2)](https://www.aglea.com/en/blog/tag/soar)
- [supporto sap ams (2)](https://www.aglea.com/en/blog/tag/supporto-sap-ams)
- [test system (2)](https://www.aglea.com/en/blog/tag/test-system)
- [threat detection (2)](https://www.aglea.com/en/blog/tag/threat-detection)
- [upgrade (2)](https://www.aglea.com/en/blog/tag/upgrade)
- [312 (1)](https://www.aglea.com/en/blog/tag/312)
- [ABAP (1)](https://www.aglea.com/en/blog/tag/abap)
- [AI (1)](https://www.aglea.com/en/blog/tag/ai)
- [CVA (1)](https://www.aglea.com/en/blog/tag/cva)
- [DPO (1)](https://www.aglea.com/en/blog/tag/dpo)
- [FIORI Security (1)](https://www.aglea.com/en/blog/tag/fiori-security)
- [HANA Roles (1)](https://www.aglea.com/en/blog/tag/hana-roles)
- [PFCG SAP transaction (1)](https://www.aglea.com/en/blog/tag/pfcg-sap-transaction)
- [SAP Cloud Security (1)](https://www.aglea.com/en/blog/tag/sap-cloud-security)
- [SAP Consulting (1)](https://www.aglea.com/en/blog/tag/sap-consulting)
- [SAP DLP (1)](https://www.aglea.com/en/blog/tag/sap-dlp)
- [SAP Fraud Management (1)](https://www.aglea.com/en/blog/tag/sap-fraud-management)
- [SAP IDM (1)](https://www.aglea.com/en/blog/tag/sap-idm)
- [SAP LOG (1)](https://www.aglea.com/en/blog/tag/sap-log)
- [SAP Security Documentation (1)](https://www.aglea.com/en/blog/tag/sap-security-documentation)
- [SAP Table (1)](https://www.aglea.com/en/blog/tag/sap-table)
- [SAP Transactions (1)](https://www.aglea.com/en/blog/tag/sap-transactions)
- [SPOOL (1)](https://www.aglea.com/en/blog/tag/spool)
- [Security Analyzer (1)](https://www.aglea.com/en/blog/tag/security-analyzer)
- [Statistiche security SAP (1)](https://www.aglea.com/en/blog/tag/statistiche-security-sap)
- [Trace autorizzazioni SAP (1)](https://www.aglea.com/en/blog/tag/trace-autorizzazioni-sap)
- [User Access Management (1)](https://www.aglea.com/en/blog/tag/user-access-management)
- [aglea (1)](https://www.aglea.com/en/blog/tag/aglea)
- [audit (1)](https://www.aglea.com/en/blog/tag/audit)
- [authorization model (1)](https://www.aglea.com/en/blog/tag/authorization-model)
- [biometric (1)](https://www.aglea.com/en/blog/tag/biometric)
- [chatGPT (1)](https://www.aglea.com/en/blog/tag/chatgpt)
- [codice sicuro SAP (1)](https://www.aglea.com/en/blog/tag/codice-sicuro-sap)
- [consulenti sap security (1)](https://www.aglea.com/en/blog/tag/consulenti-sap-security)
- [consulenza sap security (1)](https://www.aglea.com/en/blog/tag/consulenza-sap-security)
- [crittografia SAP (1)](https://www.aglea.com/en/blog/tag/crittografia-sap)
- [custom transactions (1)](https://www.aglea.com/en/blog/tag/custom-transactions)
- [cyber security (1)](https://www.aglea.com/en/blog/tag/cyber-security)
- [data loss prevention (1)](https://www.aglea.com/en/blog/tag/data-loss-prevention)
- [data privacy (1)](https://www.aglea.com/en/blog/tag/data-privacy)
- [documentazione sap security (1)](https://www.aglea.com/en/blog/tag/documentazione-sap-security)
- [emergency users (1)](https://www.aglea.com/en/blog/tag/emergency-users)
- [gxp (1)](https://www.aglea.com/en/blog/tag/gxp)
- [identity management system (1)](https://www.aglea.com/en/blog/tag/identity-management-system)
- [idm (1)](https://www.aglea.com/en/blog/tag/idm)
- [log sap (1)](https://www.aglea.com/en/blog/tag/log-sap)
- [mail security sap (1)](https://www.aglea.com/en/blog/tag/mail-security-sap)
- [microsoft (1)](https://www.aglea.com/en/blog/tag/microsoft)
- [parameter sap (1)](https://www.aglea.com/en/blog/tag/parameter-sap)
- [processi security (1)](https://www.aglea.com/en/blog/tag/processi-security)
- [profili (1)](https://www.aglea.com/en/blog/tag/profili)
- [profili sap (1)](https://www.aglea.com/en/blog/tag/profili-sap)
- [progetti security sap (1)](https://www.aglea.com/en/blog/tag/progetti-security-sap)
- [quotazione borsa (1)](https://www.aglea.com/en/blog/tag/quotazione-borsa)
- [rfc destination (1)](https://www.aglea.com/en/blog/tag/rfc-destination)
- [role translation (1)](https://www.aglea.com/en/blog/tag/role-translation)
- [s_tabu_dis (1)](https://www.aglea.com/en/blog/tag/s_tabu_dis)
- [s_tabu_nam (1)](https://www.aglea.com/en/blog/tag/s_tabu_nam)
- [s_tabu_rfc (1)](https://www.aglea.com/en/blog/tag/s_tabu_rfc)
- [sap FIORI (1)](https://www.aglea.com/en/blog/tag/sap-fiori)
- [sap btp (1)](https://www.aglea.com/en/blog/tag/sap-btp)
- [sap data masking (1)](https://www.aglea.com/en/blog/tag/sap-data-masking)
- [sap dati personali (1)](https://www.aglea.com/en/blog/tag/sap-dati-personali)
- [sap developer (1)](https://www.aglea.com/en/blog/tag/sap-developer)
- [sap earlywatch (1)](https://www.aglea.com/en/blog/tag/sap-earlywatch)
- [sap grc 12 (1)](https://www.aglea.com/en/blog/tag/sap-grc-12)
- [sap grc tables (1)](https://www.aglea.com/en/blog/tag/sap-grc-tables)
- [sap gui history (1)](https://www.aglea.com/en/blog/tag/sap-gui-history)
- [sap gui security (1)](https://www.aglea.com/en/blog/tag/sap-gui-security)
- [sap gxp compliance (1)](https://www.aglea.com/en/blog/tag/sap-gxp-compliance)
- [sap ilm gdpr (1)](https://www.aglea.com/en/blog/tag/sap-ilm-gdpr)
- [sap license auditing (1)](https://www.aglea.com/en/blog/tag/sap-license-auditing)
- [sap logon (1)](https://www.aglea.com/en/blog/tag/sap-logon)
- [sap patch (1)](https://www.aglea.com/en/blog/tag/sap-patch)
- [sap security blog (1)](https://www.aglea.com/en/blog/tag/sap-security-blog)
- [sap security teal (1)](https://www.aglea.com/en/blog/tag/sap-security-teal)
- [sap sos (1)](https://www.aglea.com/en/blog/tag/sap-sos)
- [sap splunk (1)](https://www.aglea.com/en/blog/tag/sap-splunk)
- [sap sso (1)](https://www.aglea.com/en/blog/tag/sap-sso)
- [sap tabelle custom (1)](https://www.aglea.com/en/blog/tag/sap-tabelle-custom)
- [sap tdms (1)](https://www.aglea.com/en/blog/tag/sap-tdms)
- [sap_all_only_view (1)](https://www.aglea.com/en/blog/tag/sap_all_only_view)
- [se16n (1)](https://www.aglea.com/en/blog/tag/se16n)
- [secpol (1)](https://www.aglea.com/en/blog/tag/secpol)
- [secure coding sap (1)](https://www.aglea.com/en/blog/tag/secure-coding-sap)
- [secure operation map (1)](https://www.aglea.com/en/blog/tag/secure-operation-map)
- [security awareness (1)](https://www.aglea.com/en/blog/tag/security-awareness)
- [security bridge (1)](https://www.aglea.com/en/blog/tag/security-bridge)
- [sentinel (1)](https://www.aglea.com/en/blog/tag/sentinel)
- [sicurezza codice ABAP (1)](https://www.aglea.com/en/blog/tag/sicurezza-codice-abap)
- [sicurezza dei dati sap (1)](https://www.aglea.com/en/blog/tag/sicurezza-dei-dati-sap)
- [slaw (1)](https://www.aglea.com/en/blog/tag/slaw)
- [social engineering (1)](https://www.aglea.com/en/blog/tag/social-engineering)
- [sost (1)](https://www.aglea.com/en/blog/tag/sost)
- [sql (1)](https://www.aglea.com/en/blog/tag/sql)
- [su25 (1)](https://www.aglea.com/en/blog/tag/su25)
- [super utenti sap (1)](https://www.aglea.com/en/blog/tag/super-utenti-sap)
- [system users (1)](https://www.aglea.com/en/blog/tag/system-users)
- [tabelle (1)](https://www.aglea.com/en/blog/tag/tabelle)
- [tabelle SAP grc access control (1)](https://www.aglea.com/en/blog/tag/tabelle-sap-grc-access-control)
- [ticket management system (1)](https://www.aglea.com/en/blog/tag/ticket-management-system)
- [training (1)](https://www.aglea.com/en/blog/tag/training)
- [transazioni sap (1)](https://www.aglea.com/en/blog/tag/transazioni-sap)
- [userid (1)](https://www.aglea.com/en/blog/tag/userid)
- [usmm (1)](https://www.aglea.com/en/blog/tag/usmm)
- [ust04 (1)](https://www.aglea.com/en/blog/tag/ust04)
- [zero trust security (1)](https://www.aglea.com/en/blog/tag/zero-trust-security)

[See all](https://www.aglea.com/en/blog/sap-security-authorization-per-progetti-no-grazie#)

## [SAP Security Blog AGLEA RSS Feed](https://www.aglea.com/blog/rss.xml)

Aglea s.r.l. P. IVA: IT 03868780960 - 2026  | Copy | [Note legali](https://cdn2.hubspot.net/hubfs/4422290/Aglea_November2018%20Theme/Pdfs/Privacy-policy-AGLEA.pdf)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Andrea Mazzolani (translation)",
    "url" : "https://www.aglea.com/en/blog/author/andrea-mazzolani-translation"
  },
  "dateModified" : "2024-06-14T10:13:55.075Z",
  "datePublished" : "2022-12-15T23:00:00.000Z",
  "headline" : "SAP Security Authorization for projects? No thanks!",
  "image" : [ "https://www.aglea.com/hubfs/Aglea/Imported_Blog_Media/SAP%20Security%20Project-Jun-14-2024-10-11-06-8489-AM.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.aglea.com/en/blog/sap-security-authorization-per-progetti-no-grazie",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject"
    },
    "name" : "Horsa S.p.A."
  }
}
```