CSI tools Facebook CSI tools Twitter CSI tools LinkedIn CSI tools Instagram
  • Home
  • Newsroom
    • Awards
    • Events
    • Press Releases
    • Publications
  • Software
    • By Solution
      1. Access Risk Management
      2. Access Request Management
      3. Privileged Access Management
      4. Access Role Management
      5. SAP License Audit
      6. Mass User Maintenance
    • Tools
      1. CSI Authorization Auditor
      2. CSI Automated Request Engine
      3. CSI Emergency Request
      4. CSI Role Build & Manage
      5. CSI Mass User Maintenance
      6. CSI Integrate & Collaborate
    • Pathlock
    • Legacy Tools
    • Pathlock Cloud: The Successor of CSI tools
  • Customer Center
  • Community
    • CSI tools Forum
    • Meta's Blog
    • Tech Updates
    • Training
  • About
    • Contact
    • Jobs
    • Partners
      • Become a Partner
    • References
    • Testimonials
    • Sustainability
  • Login

CSItools MetaBlogHeader2018 20180518 v03

  • You are here:  
  • Home
  • Meta's Blog Home
  • What are the pros and cons of converting authorization fields to organizational levels?

What are the pros and cons of converting authorization fields to organizational levels?

Details
Published: Wednesday, 14 August 2019 14:27

If business requires, it's possible in SAP to promote non-organizational authorization fields to organizational fields. This can be done using PFCG_ORGFIELD_CREATE. However, upon use it is possible that you receive the message that the program has become obsolete. To counter this, SAP has delivered a new transaction: SUPO/SUPO_SEL (see note 2625102). Once done in DEV, you will need to do this in QAS and PROD, and do the field conversion as well because the conversion is NOT transportable.

Please note, there is a CON in promoting to organizational level: If the field is an "authorization group" type of field, and used by (for example) 4 authorization objects, you should check that you are using all 4 with the same values for the groups (most often this is not the case, and promoting will lead to inconsistencies and problems in maintenance). For example, the authorization groups for programs and tables are not good candidates for organizational levels as they are not scalable in this way. Central customer, customer and GL account groups are not good candidates either because they are being used by multiple objects throughout your SAP role concept.

However, there is a solution!

Would you like to restrict authorization fields that are being used by multiple authorization objects? This can be done! With CSI Role Build & Manage you can derive all roles with appropriate values, even if the authorization fields that it needs to be derived on, are not stated as organizational values.

This means that if you would like to derive roles with account types, vendor account groups, authorization groups for only one specific authorization object, it’s possible in CSI RBM. Define the values in the central codification document and CSI RBM will build these roles for you:

CSItools Codification blog

It's a PRO that there's no need to promote organization levels first. Just document all your values that deriving should take into account into one central codification sheet. All roles will be derived with the correct values.

CSI RBM has comparison features available to find inconsistencies between your role concept's design, and the role concept that is being used in your SAP system, which results in no more inconsistencies in the role setup.

Interested how you can speed up role building in an automated and compliant way? Let's schedule a demo session! Send us a message at info@csi-tools.com. 

 

Let's get personal

Let's get personal, request a demo!

Blog Archive

  • The Power of Workflow
  • The NIST framework for SAP Access Security
  • Who has access to your business critical and sensitive SAP data?
  • What are the pros and cons of converting authorization fields to organizational levels?
  • Security risks of Robotic Processing Automation (RPA) in SAP
  • Privileged Access Management
  • The Secure Habits for Securing SAP systems
  • SAP User Licenses
  • Access Certification
  • Implementing compliancy for SAP environments
  • Protection of personal data for GDPR within SAP
  • (SOx) Governance, Risk and Compliance with CSI tooling
  • SAP support packages keeping me busy
  • Role building with (non) organizational values in SAP
  • CSI Authorization Auditor instead of manual control
  • Reverse Engineering for the SAP security concept
  • How to perform critical authorizations and SoD checks in SAP systems
  • Who is doing what in your SAP system?
  • Fine tuning your GRC filter set with Custom transactions
  • Display roles - are they really display only?
  • User type reference not always taken into account
  • SAP Special Users

Get in touch

Pathlock Benelux
Support Direct
Link to the support portal https://support.pathlock.com

To gain access to the new support portal, please contact us at customersupport@pathlock.com

Tel. +32 16 308 008

Address
Kempische Steenweg 303/200
B-3500 Hasselt, Belgium

Via phone
Tel: +32 16 308 000

Last Updates

  • Pathlock Cloud: The Successor of CSI tools
  • Pathlock named Market Leader for Zero Trust by Cyber Defense Magazine

Solutions

  • SoD and Risk analysis - CSI Authorization Auditor
  • Compliant Provisioning - CSI Automated Request Engine
  • Emergency Access Management - CSI Emergency Request
  • Compliant Role and Mass User Management - CSI Role Build & Manage
  • Extract SAP data - CSI Data Xtractor
  • CSI Integrate & Collaborate

©1997-2025 Pathlock Benelux. All rights reserved. - Privacy Policy  - Cookie Policy - Code of Ethical Conduct - Sitemap