SlideShare ist ein Scribd-Unternehmen logo
1 von 21
Downloaden Sie, um offline zu lesen
IRIS Authorizations/
     Security
User Administration

n   User Maintenance - defining a user has
    many components including the
    following:
    n   Basic User Data
    n   Defaults
    n   Parameters
    n   User Authorizations
n   Primary Transaction – SU01
n   Central User Administration
Basic User Data

n Name
n Initial Password
n Validity period of a user’s account
n User Group
n User Type
Types of R/3 Internal Users

n Dialog
n Batch Data Communication - BDC
n Background
n CPIC
User Defaults

n Logon language
n Default printer (local or network)
n Date and decimal formats
n Time Zone
Parameters

 Used to determine the default value for a
  field.

   • Parameter Id
   • Value
   • Description
Standard Parameter
Assignments
 KME   Z_UT   FI Account Assignment Model
 KPL   UT     Chart of Accounts
 MOL   10     Personnel Grouping
 PNI   US     Country Key
 UGR   10     HR User Group
 VKO   UT     Sales Organization
 BUK   UT     Company Code
 CAC   UT     Controlling Area
 EKO   UT     Purchasing Organization
 FIK   UT     FM Area
 FWS   USD    Curreny Unit
 FZ2   Z_UT   G/L Account Line Layout
 FZ5   Z001   Parking Document Line Layout
 FBZ   Z01    Posting Document Line Layout
Rules for Passwords

n   Minimum 6 characters
n   Not to begin with ‘?’ or ‘!’
n   Not to begin with any sequence of 3
    characters contained in the user name
n   Not to begin with 3 identical characters
n   Can not use ‘PASS’ or ‘SAP’
n   USR40 Password Lockout List
n   NOT Case-sensitive
n   Can change only once a day
n   Can not change to 5 previous passwords
USR40 – PW Lockout List
     *IRIS*
     *VOL*
     FIESTA*
     MOC*
     ORANGE*
     ROCKYTOP
     SMOKEY*
     TENN*
     UT*
User Authorizations

n Granted via Activity Groups/Roles
  and/or Profiles
n Assigned to user master records to
  provide access to R/3 functionality
Activity Groups
n Created via the Profile Generator
  (PFCG)
n Serve as containers for user menus
  and authorization objects and values
n Used to generate authorization
  profiles
Authorization Profiles
n Generated from assignments made
  to Activity Groups in the Profile
  Generator (PFCG)
n Assigned to users via Activity Group
  Assignment
n Some high-level profiles, such as
  SAP_ALL, can be assigned directly to
  users
Relationship of Activity
Groups and Profiles

                 User


 Activity Group                           Profile


                           Authorization Object
 Detailed Authorizations


                             Authorizations
Profile Generator

n Menu – User Menu
n Task Assignment – associate
  workflow task for “potential agents”
n Authorizations – assign
  authorization objects and generate
  profiles
n Users
UT Activity Groups/Roles
n   Departmental Roles
    n   Departmental Specialist
    n   Departmental Management
    n   Funds Centers
n   Campus Office Roles
    n   For example, CBO’s, Personnel Specialists
n   Central Office Roles
    n   For example, Accounts Payable/Controller’s
        Office
n   Project Team/Support Roles
Composite Roles
       UT_DEPT_ADMIN_SPEC_CMP     CBO

         UT_DEPT_ADMIN_SPEC_CO    Controller

                            GL
Dept                       AP      CBO

Mgmt                       MM      AP

                           FM    CBO
                                 Controller
                                 Budget Office
UT Roles – Breakdown

Departmental        Campus Level       Central
Functional Role     Functional Role    Functional Role
Campus data role    Campus data role
Funds center role
Relationship to Workflow
n   Security
    n    Provides the ability for a user to perform an
        action
n   Workflow
    n    Routes the document to the appropriate
        person
    n   Performs background processing for some
        functionality
n   User must have both security and
    workflow to act upon work items
Workflow
Roles/Assignments
n   Departmental Reviewer
    n   Reviews documents before approver
n   Departmental Approver
    n   Provides the departmental approval for
        documents
n   Other special workflows
    n   Journal vouchers, CBO level approvals,
        HR/security processes
Useful Transaction Codes
SU01D       Display Users
User Reports - Tools-->Administration-->User Administration-->Information System
ZAPPS       Display Approvers/Workflow Responsibilities
ZSUBS       Workflow Substitutes Report
ZWIRPT      Workflow Work Item Aging Report
SWI5        Workload Analysis
SM04        Current Users Logged in on "App Server"
AL08        Current Users Logged in on System
PFCG        Profile Generator
PP01        Display Workflow Responsibilities
FM5S        Display Fund
FM2G        Funds Center Hierarchy
Security System Settings
n Password reset – 62 days
n Logon screen - disappears after 3
  unsuccessful logon attempts
n User ID lock – after 6 unsuccessful login
  attempts
n Automatic logout - after 8 hours of
  inactivity

Weitere ähnliche Inhalte

Andere mochten auch (7)

Haqiqat-e-Wahdatul Wajud
Haqiqat-e-Wahdatul WajudHaqiqat-e-Wahdatul Wajud
Haqiqat-e-Wahdatul Wajud
 
Tareekat-e-Tawhidia
Tareekat-e-TawhidiaTareekat-e-Tawhidia
Tareekat-e-Tawhidia
 
Sufism - The True Spirit of Islam
Sufism - The True Spirit of IslamSufism - The True Spirit of Islam
Sufism - The True Spirit of Islam
 
Momin Magzine April 2012
Momin Magzine April 2012Momin Magzine April 2012
Momin Magzine April 2012
 
Momin Magzine May 2012
Momin Magzine May 2012Momin Magzine May 2012
Momin Magzine May 2012
 
Debug1214
Debug1214Debug1214
Debug1214
 
How To Improve Your Communication Skills
How To Improve Your Communication SkillsHow To Improve Your Communication Skills
How To Improve Your Communication Skills
 

Ähnlich wie Sap security for audit seminar1

SAP-Security-Madhu
SAP-Security-MadhuSAP-Security-Madhu
SAP-Security-Madhu
Madhu Sharma
 
Mitul Jain SAP GRC Security
Mitul Jain SAP GRC SecurityMitul Jain SAP GRC Security
Mitul Jain SAP GRC Security
mitul jain
 
sap basis 2.5 yr exp. resume
sap basis 2.5 yr exp. resumesap basis 2.5 yr exp. resume
sap basis 2.5 yr exp. resume
kul deepak
 
Ritesh Kumar Sap Secuirty & Grc new 2
Ritesh Kumar Sap Secuirty & Grc new 2Ritesh Kumar Sap Secuirty & Grc new 2
Ritesh Kumar Sap Secuirty & Grc new 2
Ritesh Kumar
 
sai kanisetty
sai kanisettysai kanisetty
sai kanisetty
sai k
 
sai kanisetty
sai kanisettysai kanisetty
sai kanisetty
sai k
 
07 a 01templates
07 a 01templates07 a 01templates
07 a 01templates
tflung
 
Event Management System Document
Event Management System Document Event Management System Document
Event Management System Document
LJ PROJECTS
 
Anil kumar sap security and grc consultant
Anil kumar sap security and grc consultantAnil kumar sap security and grc consultant
Anil kumar sap security and grc consultant
Anil Kumar
 
Anil kumar sap security and grc consultant
Anil kumar sap security and grc consultantAnil kumar sap security and grc consultant
Anil kumar sap security and grc consultant
Anil Kumar
 

Ähnlich wie Sap security for audit seminar1 (20)

Day5 R3 Basis Security
Day5 R3 Basis   SecurityDay5 R3 Basis   Security
Day5 R3 Basis Security
 
SAP-Security-Madhu
SAP-Security-MadhuSAP-Security-Madhu
SAP-Security-Madhu
 
Mitul Jain SAP GRC Security
Mitul Jain SAP GRC SecurityMitul Jain SAP GRC Security
Mitul Jain SAP GRC Security
 
Iterative itsm implementation using TeamDynamix
Iterative itsm implementation using TeamDynamixIterative itsm implementation using TeamDynamix
Iterative itsm implementation using TeamDynamix
 
sap basis 2.5 yr exp. resume
sap basis 2.5 yr exp. resumesap basis 2.5 yr exp. resume
sap basis 2.5 yr exp. resume
 
Ritesh Kumar Sap Secuirty & Grc new 2
Ritesh Kumar Sap Secuirty & Grc new 2Ritesh Kumar Sap Secuirty & Grc new 2
Ritesh Kumar Sap Secuirty & Grc new 2
 
Oracle Fusion Applications Navigation and Roles
Oracle Fusion Applications Navigation and RolesOracle Fusion Applications Navigation and Roles
Oracle Fusion Applications Navigation and Roles
 
165373293 sap-security-q
165373293 sap-security-q165373293 sap-security-q
165373293 sap-security-q
 
Introduction on sap security
Introduction on sap securityIntroduction on sap security
Introduction on sap security
 
Project Manager, Lead Business Analyst, Scrum Master
Project Manager, Lead Business Analyst, Scrum MasterProject Manager, Lead Business Analyst, Scrum Master
Project Manager, Lead Business Analyst, Scrum Master
 
sai kanisetty
sai kanisettysai kanisetty
sai kanisetty
 
sai kanisetty
sai kanisettysai kanisetty
sai kanisetty
 
Iia los angeles sap security presentation
Iia  los angeles  sap security presentation Iia  los angeles  sap security presentation
Iia los angeles sap security presentation
 
07 a 01templates
07 a 01templates07 a 01templates
07 a 01templates
 
Event Management System Document
Event Management System Document Event Management System Document
Event Management System Document
 
Vithya r 4+yrs exp as400
Vithya r 4+yrs exp as400Vithya r 4+yrs exp as400
Vithya r 4+yrs exp as400
 
Anil kumar sap security and grc consultant
Anil kumar sap security and grc consultantAnil kumar sap security and grc consultant
Anil kumar sap security and grc consultant
 
Anil kumar sap security and grc consultant
Anil kumar sap security and grc consultantAnil kumar sap security and grc consultant
Anil kumar sap security and grc consultant
 
User Requirements, Functional and Non-Functional Requirements
User Requirements, Functional and Non-Functional RequirementsUser Requirements, Functional and Non-Functional Requirements
User Requirements, Functional and Non-Functional Requirements
 
Catherine Ner-Nacional
Catherine Ner-NacionalCatherine Ner-Nacional
Catherine Ner-Nacional
 

Mehr von Amit Gupta (8)

Loans-Management-ECC-6.pptx
Loans-Management-ECC-6.pptxLoans-Management-ECC-6.pptx
Loans-Management-ECC-6.pptx
 
BP_KPIs_process.ppt
BP_KPIs_process.pptBP_KPIs_process.ppt
BP_KPIs_process.ppt
 
GR_Clearing_Key_v2.1.0.pdf
GR_Clearing_Key_v2.1.0.pdfGR_Clearing_Key_v2.1.0.pdf
GR_Clearing_Key_v2.1.0.pdf
 
SAP Org Stracture Overview.pptx
SAP Org Stracture Overview.pptxSAP Org Stracture Overview.pptx
SAP Org Stracture Overview.pptx
 
GRANISH.pdf
GRANISH.pdfGRANISH.pdf
GRANISH.pdf
 
COPA-1-0.pptx
COPA-1-0.pptxCOPA-1-0.pptx
COPA-1-0.pptx
 
TDS_194QWebinar.pdf
TDS_194QWebinar.pdfTDS_194QWebinar.pdf
TDS_194QWebinar.pdf
 
Sap security for audit seminar
Sap security for audit seminarSap security for audit seminar
Sap security for audit seminar
 

Kürzlich hochgeladen

Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
ZurliaSoop
 

Kürzlich hochgeladen (20)

NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
 
SOC 101 Demonstration of Learning Presentation
SOC 101 Demonstration of Learning PresentationSOC 101 Demonstration of Learning Presentation
SOC 101 Demonstration of Learning Presentation
 
Google Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptxGoogle Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptx
 
Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)
 
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptxOn_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
 
Sociology 101 Demonstration of Learning Exhibit
Sociology 101 Demonstration of Learning ExhibitSociology 101 Demonstration of Learning Exhibit
Sociology 101 Demonstration of Learning Exhibit
 
Philosophy of china and it's charactistics
Philosophy of china and it's charactisticsPhilosophy of china and it's charactistics
Philosophy of china and it's charactistics
 
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxBasic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
 
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
 
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
 
Understanding Accommodations and Modifications
Understanding  Accommodations and ModificationsUnderstanding  Accommodations and Modifications
Understanding Accommodations and Modifications
 
latest AZ-104 Exam Questions and Answers
latest AZ-104 Exam Questions and Answerslatest AZ-104 Exam Questions and Answers
latest AZ-104 Exam Questions and Answers
 
Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)
 
This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.
 
Tatlong Kwento ni Lola basyang-1.pdf arts
Tatlong Kwento ni Lola basyang-1.pdf artsTatlong Kwento ni Lola basyang-1.pdf arts
Tatlong Kwento ni Lola basyang-1.pdf arts
 
Exploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptx
Exploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptxExploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptx
Exploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptx
 
21st_Century_Skills_Framework_Final_Presentation_2.pptx
21st_Century_Skills_Framework_Final_Presentation_2.pptx21st_Century_Skills_Framework_Final_Presentation_2.pptx
21st_Century_Skills_Framework_Final_Presentation_2.pptx
 
On National Teacher Day, meet the 2024-25 Kenan Fellows
On National Teacher Day, meet the 2024-25 Kenan FellowsOn National Teacher Day, meet the 2024-25 Kenan Fellows
On National Teacher Day, meet the 2024-25 Kenan Fellows
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptx
 
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
 

Sap security for audit seminar1

  • 2. User Administration n User Maintenance - defining a user has many components including the following: n Basic User Data n Defaults n Parameters n User Authorizations n Primary Transaction – SU01 n Central User Administration
  • 3. Basic User Data n Name n Initial Password n Validity period of a user’s account n User Group n User Type
  • 4. Types of R/3 Internal Users n Dialog n Batch Data Communication - BDC n Background n CPIC
  • 5. User Defaults n Logon language n Default printer (local or network) n Date and decimal formats n Time Zone
  • 6. Parameters Used to determine the default value for a field. • Parameter Id • Value • Description
  • 7. Standard Parameter Assignments KME Z_UT FI Account Assignment Model KPL UT Chart of Accounts MOL 10 Personnel Grouping PNI US Country Key UGR 10 HR User Group VKO UT Sales Organization BUK UT Company Code CAC UT Controlling Area EKO UT Purchasing Organization FIK UT FM Area FWS USD Curreny Unit FZ2 Z_UT G/L Account Line Layout FZ5 Z001 Parking Document Line Layout FBZ Z01 Posting Document Line Layout
  • 8. Rules for Passwords n Minimum 6 characters n Not to begin with ‘?’ or ‘!’ n Not to begin with any sequence of 3 characters contained in the user name n Not to begin with 3 identical characters n Can not use ‘PASS’ or ‘SAP’ n USR40 Password Lockout List n NOT Case-sensitive n Can change only once a day n Can not change to 5 previous passwords
  • 9. USR40 – PW Lockout List *IRIS* *VOL* FIESTA* MOC* ORANGE* ROCKYTOP SMOKEY* TENN* UT*
  • 10. User Authorizations n Granted via Activity Groups/Roles and/or Profiles n Assigned to user master records to provide access to R/3 functionality
  • 11. Activity Groups n Created via the Profile Generator (PFCG) n Serve as containers for user menus and authorization objects and values n Used to generate authorization profiles
  • 12. Authorization Profiles n Generated from assignments made to Activity Groups in the Profile Generator (PFCG) n Assigned to users via Activity Group Assignment n Some high-level profiles, such as SAP_ALL, can be assigned directly to users
  • 13. Relationship of Activity Groups and Profiles User Activity Group Profile Authorization Object Detailed Authorizations Authorizations
  • 14. Profile Generator n Menu – User Menu n Task Assignment – associate workflow task for “potential agents” n Authorizations – assign authorization objects and generate profiles n Users
  • 15. UT Activity Groups/Roles n Departmental Roles n Departmental Specialist n Departmental Management n Funds Centers n Campus Office Roles n For example, CBO’s, Personnel Specialists n Central Office Roles n For example, Accounts Payable/Controller’s Office n Project Team/Support Roles
  • 16. Composite Roles UT_DEPT_ADMIN_SPEC_CMP CBO UT_DEPT_ADMIN_SPEC_CO Controller GL Dept AP CBO Mgmt MM AP FM CBO Controller Budget Office
  • 17. UT Roles – Breakdown Departmental Campus Level Central Functional Role Functional Role Functional Role Campus data role Campus data role Funds center role
  • 18. Relationship to Workflow n Security n Provides the ability for a user to perform an action n Workflow n Routes the document to the appropriate person n Performs background processing for some functionality n User must have both security and workflow to act upon work items
  • 19. Workflow Roles/Assignments n Departmental Reviewer n Reviews documents before approver n Departmental Approver n Provides the departmental approval for documents n Other special workflows n Journal vouchers, CBO level approvals, HR/security processes
  • 20. Useful Transaction Codes SU01D Display Users User Reports - Tools-->Administration-->User Administration-->Information System ZAPPS Display Approvers/Workflow Responsibilities ZSUBS Workflow Substitutes Report ZWIRPT Workflow Work Item Aging Report SWI5 Workload Analysis SM04 Current Users Logged in on "App Server" AL08 Current Users Logged in on System PFCG Profile Generator PP01 Display Workflow Responsibilities FM5S Display Fund FM2G Funds Center Hierarchy
  • 21. Security System Settings n Password reset – 62 days n Logon screen - disappears after 3 unsuccessful logon attempts n User ID lock – after 6 unsuccessful login attempts n Automatic logout - after 8 hours of inactivity