Question: Hi,
I am in a finance module in an organization. Our auditors have pointed out that 7 users have been attached SAP_ALL profile. When i went to the BASIS guy, he tells its not a risk because all 7 users are not dialog users....can somebody comment on that..
Regards,
Marja
Answer:
All depends. How many dialog or communication users have S_BATCH_NAM with one of the non-dialog users in the name field? These users effectively have SAP_ALL.
How many of these user ids are attached to communication users that have a password stored in transaction SM59 (or an external sideinfo file) in any of your systems.
I am afraid your bais guy is a total naif about security.
Answer:
Guest is correct, the SAP_ALL users may not be dialog users but there is a reasonable likelyhood that they can be used by people with certain auths.
If you want to fool the auditors, rename the SAP_ALL profile to something different. Most won't pick this up, however I don't recommend this course of action.
Answer:
& make sure the non dialog user's password is not easily guessable even though they cannot be logged on directly in SAP.
If the password is easily guessable they can be used via Excel / Bapis etc.
Answer:
No user should have SAP_ALL perminantly attached, Even SAP*. There are too manu back doors that let you use that access. ( i.e Reference user, USRBF2, UST04 etc.)
Answer:
Hi Guys,
Thanks a million for your replies. I will take it up wit the basis guy, but since he talks in tehnical lingo, can you please help me with ( in a bit non-techie language) regarding how and in what circumstances a dialog user can access non-dialog iD. that would be of great help.
Thanks & Regards
Marja
Answer:
1. Scheduling jobs in SM36 and/or SM37. Not all reports regurgitate data come do things.
2. potentiall SM35.
3. Reference user field in SU01 ( the error message is configurable)
4. Direct table manipulation of USRBF2, UST04 via SE30, SE37, SE38 to name a few.
And the list goes on...
Answer:
Do you have WORKFLOW implemented and the user is non-dialog and has SAP_ALL?
Answer:
Non-dialog users can also execute functionality via RFC and make use of the SAP_ALL.
How to Earn Rs.25000 every month in internet without Investment?
SAP_ALL, not for dialog users
Labels:
Sap Basis Faqs
Subscribe to:
Post Comments (Atom)
topics
-
▼
2007
(1406)
-
▼
November
(1359)
- Free Download SAP FI Certification study pdf books
- Implementing SAP R/3 on OS/400
- Update SAP Kernel in UNIX based
- Security Audit Log (BC-SEC).pdf
- Security Audit Log.pdf
- Securities,pdf
- Secure Store & Forward / Digital Signatures (BC-SE...
- Secure Network Communications (BC-SEC-SNC)
- Free download use ful T-codes
- I did not find any OSS notes appropriate for my pr...
- How to apply OSS notes number?
- What is OSS Notes number?
- Where can i access SAP OSS?
- WHAT IS OSS
- Disaster Recovery Plan to Restore Production System
- Steps to Install SAP Note in sap
- Difference Between SAP Notes and Support Package
- Question : Subject : Support packages testing
- Five Different "User Type"
- How to solve the Time Zone Definition Problems?
- Setting the User Decimals Format
- Schedule Manager
- Various Important SAP Basis T-Code
- Trace Functions in sap
- System Trace: Error Analysis in sap
- System Trace(ST01) in sap
- Roles and Authorizations Used in Background Proces...
- Deleting Multiple Spool Requests Simultaneously in...
- Logging and Tracing in spool
- Print and Output Management in spool
- Background Job Monitoring Monitor in CCMS
- Monitoring the Database Using the Alert Monitor
- Monitoring the Operating System Using the Alert Mo...
- Monitoring Memory Management Using the Alert Monitor
- Method Dispatching Monitor in CCMS
- Remote Application Server Status Monitor in CCMS
- GRMG Self-Monitoring Monitor in CCMS
- CCMS Selfmonitoring Monitor for System-Wide Data i...
- Logfile Monitoring Monitor in CCMS
- Logon Load Balancing Monitor in CCMS
- Transaction-Specific Dialog Monitor in CCMS
- Workload Collector Monitor in CCMS
- System Errors Monitor in CCMS
- System Configuration Monitor in CCMS
- Syslog Monitor in CCMS
- Spool System Monitor in CCMS
- Security Monitor in CCMS
- Performance Overview Monitor in CCMS
- Operating System Monitor in CCMS
- Filesystems Monitor in CCMS
- Entire System Monitor in CCMS
- Monitoring the Enqueue Service in CCMS
- Dialog per Application Server Monitor in CCMS
- Dialog Overview Monitor in CCMS
- Database Monitor in CCMS
- Transactional RFC and Queued RFC Monitor in CCMS
- Communications Monitor in CCMS
- Buffers Monitor in CCMS
- Background Job Monitoring Monitor(CCMS)
- Background Processing Monitor(CCMS)
- Availability and Performance Overview Monitor (CCMS)
- SAP CCMS Monitor Templates Monitor Set
- Creating and Changing a Monitoring Pause(CCMS)
- Creating and Changing Monitoring Rules(CCMS)
- Configuring Availability Monitoring(CCMS)
- Update Repositories(CCMS)
- Displaying Central Performance History Reports(CCMS)
- Displaying Report Properties
- Scheduling and Executing a Report
- Variables in Group Names
- Creating a Report Definition(CCMS)
- Maintaining Collection and Reorganization Schemata...
- Maintaining Collection and Reorganization Schemata...
- Creating and Editing a Calendar Schema(CCMS)
- Creating and Editing a Day Schema
- Customizing the Alert Monitor(CCMS)
- Resetting MTEs and Alerts(CCMS)
- Reorganizing Completed Alerts(CCMS)
- Display Completed Alerts(CCMS)
- Automatically Complete Alerts(CCMS)
- Completing Alerts(CCMS)
- Starting Methods (CCMS)
- Processing Alerts(CCMS_
- Displaying the Technical View: Central Performance...
- Displaying the Technical View: Threshold Values(CCMS)
- Displaying the Technical View: Status Autoreaction...
- Displaying the Technical View: Status Data Collector
- Displaying the Technical View: Method Allocation
- Displaying the Technical View: Info on MTE
- Display Types and Views of the Alert Monitor(CCMS)
- Properties of Status Attributes (CCMS)
- Properties of Performance Attributes(CCMS)
- Properties of Log Attributes (CCMS)
- General Properties of Monitoring Tree Elements(CCMS)
- Properties of Monitoring Objects and Attributes
- Elements of the Alert Monitoring Tree
- Alert Monitoring Tree(CCMS)
- Monitors(CCMS)
- Monitor Sets (CCMS)
- Elements of the Alert Monitor (CCMS)
-
▼
November
(1359)
No comments:
Post a Comment