User Authorizations in SAP S/4HANA Cloud

Поділитися
Вставка
  • Опубліковано 11 вер 2024
  • S4HCKS22 - SAP S/4HANA Cloud Knowledge Snippet
    For the full post please visit the corresponding post at
    pascalrenet.com...
    For those of you that want to jump right to a topic, I have below indicated the time markers:
    Introduction to authorizations in SAP S/4HANA Cloud - how things hang together 00:45
    The apps to work with to manage roles 01:30
    From authorization to user and everything in between 03:00
    A concrete example - Setting it up in the system 10:22
    Topic round offs 36:00

КОМЕНТАРІ • 50

  • @garycalverley6988
    @garycalverley6988 4 роки тому +2

    Very good information, thanks. Admittedly I had you on speed x2 setting for the bits I already knew but I thought it was really well done.

    • @pascalrenet
      @pascalrenet  4 роки тому

      Thank you for the comment. Admittedly, it was published 2+ years ago when there was quasi no information available. Probably needs an update.

  • @Noor-Assamawat
    @Noor-Assamawat Місяць тому

    Great video, very helpful, much appreciated.

  • @devendrapalav7004
    @devendrapalav7004 2 роки тому +2

    Superb Video. got clear understanding of Cloud Auth.

    • @pascalrenet
      @pascalrenet  2 роки тому

      Thank you for the great comment! Glad to hear it gave you clarity.

    • @devendrapalav7004
      @devendrapalav7004 2 роки тому

      @@pascalrenet in SAP S/4HANA Cloud how can we check SOD risk?

  • @DrBaseemMayhoub
    @DrBaseemMayhoub 2 роки тому +1

    A great method of explanation ...really appreciate your kind effort to produce such this helpful video

    • @pascalrenet
      @pascalrenet  2 роки тому

      Thank you very much for such a nice comment, and glad to read you found this helpful!

  •  3 роки тому +1

    It's very enlightening and clear. Thank you

  • @sivad805
    @sivad805 5 років тому +1

    Excellent Pascal..thank you for your detailed explanation..

    • @pascalrenet
      @pascalrenet  5 років тому

      Thank you for the comment. Always nice to hear that it is helpful!

  • @TheGarry420
    @TheGarry420 6 років тому +1

    Thanks for your snippets. really helpful

    • @pascalrenet
      @pascalrenet  6 років тому

      Thank you - happy to hear they are helping!

  • @praveenkongara
    @praveenkongara 3 роки тому +1

    Excellent... Very Much Helpful.

  • @Cylo243
    @Cylo243 Рік тому +1

    Perfect video. Thank you

  • @rameshgurram2935
    @rameshgurram2935 3 роки тому +1

    Great information.. Thank you so much :)

  • @wvansluisveld3011
    @wvansluisveld3011 3 роки тому +1

    Excellent video. What would have made this even more useful is if (1) you would have explained what is a good way to export all this info (incl restriction details) in order to perform an effective access review (2) what does the SoD check button do that is shown there and (3) are there any tools available (similar to GRC, CSI) that help with reviewing the appropriateness of access rights more automatically.

    • @pascalrenet
      @pascalrenet  3 роки тому

      Thanks for the note and comment. Whilst this video was uploaded in 2018, some things have remained and some have changed. The SOD (Segregation Of Duty) button has disappeared, roles need to be downloaded/uploaded to be moved between systems and I am not aware of tools such as GRC (not to say they do not exist/are available).

    • @wvansluisveld3011
      @wvansluisveld3011 3 роки тому

      @@pascalrenet how I understand it SAP has a product available called IAG that brings many GRC features to the cloud. I'm trying to figure out how this works as it is all relatively new. Then again many companies dont have IAG yet and they would still need to manage their accesses.

  • @k4621
    @k4621 3 роки тому +1

    Thank you!

  • @krln586
    @krln586 3 роки тому +1

    Hi pascal, I see that you have completely done this role configuration from fiori but this authorization assignment could be easily done via sap gui rite. Please correct me if I am wrong. Is it that while integrating with cloud we should follow this process ??

    • @pascalrenet
      @pascalrenet  3 роки тому

      Hi sumithra. In this particular, I was using an SAP S/4HANA Cloud (Essentials - fka, Multi-Tenant), which can only be accessed via a web browser, hence the Fiori Launchpad. If you are looking at SAP S/4HANA Extended or Private Cloud Edition, then yes, the access is via GUI.

  • @vvishal4
    @vvishal4 2 роки тому +1

    Hi Pascal, what would be the process to allow Approval rights to a User, say, for example Sales orders?

    • @pascalrenet
      @pascalrenet  2 роки тому +1

      Hi - check the script associated with scope item BD9 - Sale from stock -> rapid.sap.com/bp/#/browse/scopeitems/BD9 it has all the instructions

  • @mohitshrivastava07
    @mohitshrivastava07 5 років тому

    Wonderfully explained.. thanks for the tutorial ..

    • @pascalrenet
      @pascalrenet  5 років тому

      Thank you for taking the time comment - glad you got something out of it.

  • @sarabg8825
    @sarabg8825 2 роки тому +1

    Great

  • @sindhugunasekar2615
    @sindhugunasekar2615 3 роки тому

    Hi Pascal, is there a way to transport roles rather than download and upload in 2102 release?

  • @srani7253
    @srani7253 6 років тому +1

    Nice one .. Easy to understand. What to learn S4 Hana could from basis .. please assist thanks

  • @pradeepmanitripathi3120
    @pradeepmanitripathi3120 5 років тому +1

    Nice and informative content

    • @pascalrenet
      @pascalrenet  5 років тому +1

      Thank you ! Watch for an update some time before the 1908 release !

  • @sumanthapa5891
    @sumanthapa5891 3 роки тому +1

    Hii pascal, Is there a way to to have authorization
    based on region or country ??

    • @pascalrenet
      @pascalrenet  3 роки тому +1

      Hi Suman. Thanks for the comment. If you mean can you restrict a user to access ALL the data in the system based on a region or country, the answer is no. You have to remember that the authorisations are determined by authorisation objects that are directly dependent on the objects for which you are trying to set a restriction. For example, it would not make sense to use the Purchase Organisation to restrict in what Plant you can create a production order ! So, it could be that in some cases a region or country code can be used for authorisation but that will not be the case for all authorisations. Hope this helps.

    • @sumanthapa5891
      @sumanthapa5891 3 роки тому +1

      @@pascalrenet Thanks for ur explanation

  • @krln586
    @krln586 3 роки тому

    Adding to my previous question, so when we use cloud, we do security administration using Business role in Fiori Apps library but when its just on-premise and fiori, we do administration using SAP GUI..

    • @pascalrenet
      @pascalrenet  3 роки тому

      Your latter comment would also apply to SAP S/4HANA Cloud Extended or SAP S/4HANA Cloud PE (Private Cloud Edition)

  • @gioesravan
    @gioesravan 2 роки тому

    good one

  • @jak1312
    @jak1312 4 роки тому

    Hi Pascal, is there a way to transport roles rather than download and upload?

    • @pascalrenet
      @pascalrenet  4 роки тому +1

      Hi. No unfortunately this is not possible.

  • @sindhugunasekar2615
    @sindhugunasekar2615 3 роки тому +1

    Dear Pascal,
    Wonderful video for the beginners:) Thanks a lot for sharing this video.
    We have nearly 50 master business roles to be created in S/4 HANA Cloud and derived roles are expecting to be nearly 1000+ roles ( 50*21 = 1050). We are facing challenges in creating all these 1000+ derived roles manually in the system as it is time-consuming and involves the manual creation of roles.
    I have already gone through the blog Mass Maintenance of Business Roles in SAP S/4HANA Cloud, but again this suggestion also leads to creating more number of files as the same as the number of derived roles.
    Does anyone come across this situation? Do we have any provision to automate or doing mass derived roles creation in the S/4 HANA cloud system?
    Thanks
    Sindhu

  • @rajc03
    @rajc03 4 роки тому

    Do you know of any report/table in SAP S4 to show the relationship between role and catalog? - similar as in ECC was AGR_1251

    • @pascalrenet
      @pascalrenet  4 роки тому

      Check the IAM Information System app for what is setup specifically in your system, or check the Fiori Apps library (list view - which tells you the standard catalog to role relationship for an app)

  • @plabansahoo7592
    @plabansahoo7592 3 роки тому

    Thanks for the good video. Is the same business role viewable through PFCG. If the business role is the same as PFCG role, then i think if the role has been restricted at auth. object level, but not at level of restrictions, then the role will follow according to auth. object level. Am i right.

    • @pascalrenet
      @pascalrenet  3 роки тому

      Thanks for the comment. Not sure I fully understand your comment. However this recording is specific to S/4HANA Cloud Essentials (Multi tenant) and PFCG is not available there. That said, yes if you were to compare, yes a role created in the app 'Maintain Business Roles' in cloud, would be viewable via PFCG if this were an on-prem flavour. A role is made up of catalogs, that are themselves linked to 'authorisation objects' that are used to restrict the data a user can see or create/modify.

  • @nadeemdilber
    @nadeemdilber 4 роки тому

    Excellent 5 stars