Big4Guy

Welcome to Big4Guy.com. Big4Guy is an online resource where I will share with you the latest news, insights, knowledge and some experiences as a Big 4 consultant. We will discuss some of the important issues which organisations are facing today in the areas of information security, security and controls in SAP R/3, Oracle Applications, J.D.Edwards, Peoplesoft and various other ERP's. You will also find information on latest complaince regulations like Sarbanes Oxley, Basel II and so on. Big4guy will also attempt to provide valuable resources for individuals interested in examinations the CISA, CISM, CISSP, PMP and various other security certifications considered essential for entry in any Big 4 accounting, auditing and consulting firms. You are invited to post your comments and viewpoints to posts here. I sincerely hope this online journal will be useful to everyone from a budding student to a professional in the accounting, auditing, management and consultancy professions.

Post details: Designing User Roles and Authorizations in SAP BW Made Easy

09/01/06

Permalink 05:57:04 am, Categories: SAP R/3, ABAP, 296 words   English (US)

Designing User Roles and Authorizations in SAP BW Made Easy

Providing users authorizations in SAP BW is a hot question for organizations implementing SAP Business Warehouse BW. Ideally, desigining authorizations should always begin with designing user roles in BW. Due to the inherent structure of many organizations, user roles need to be defined at the same level of detail as individual users. Such a design for user access within SAP BW requires a lot of maintenance. As an alternative, organizations can create a few roles and assign as many users to it as required. Though this approach is maintenance friendly, any changes to user roles may have an adverse impact on other users.

The transaction code used to provide authorizations in SAP BW is RSSM. Though the T-Code PFCG Profile Generator can also be used to provide authorizations. Authorization administration is much easier through transaction RSSM in case reporting authorizations are required to be attached to user roles.

SAP-BW-Authorizations-Roles-Design-Business-Warehouse

The best practice approach in providing authorizations in SAP BW is to design authorizations based on SAP BW meta-data objects. Roles can be defined to restrict user access to a particular query or InfoCube. The key is to keep the authorizations design role centric rather than user centric. This is because with user roles in SAP BIW, additional features such as portal integration and user menu specification become possible which cannot be done using user based authorization. To help secure access in SAP BW, I would suggest that restricting user access to a particular reporting query or transaction based on user menus. Normally, users are not sophisticated enough to guess transactions. They only play with what appears in the user access menu in front of them.

More on SAP R/3

SAP R/3 Auditor Authorizations
SAP BEx Analyzer Toolbar
SAP CATT Computer Aided Test Tool
SAP Basis Transaction Codes

Comments:

No Comments for this post yet...

Official Websites

Search

Google

Web Big4Guy.com

June 2008
Mon Tue Wed Thu Fri Sat Sun
<<  <   >  >>
            1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30

Misc

Syndicate this blog XML

What is RSS?