SAP Access Control


What is SAP Access Control?

Improper access is a major security threat to SAP and other enterprise systems. The issue only gets worse as employees increasingly access their relevant applications remotely and on varying, often personal, devices. The goal of SAP Access Control is to ensure the right people are using the right software from the right device. It also helps track access information in case it needs to be reported later for compliance purposes or assessed for risk.

SAP Access Control’s key functions include:

  • Risk analysis
  • User provisioning
  • Monitoring privileges
  • Certifying authorizations
  • Integration with enterprise systems
  • Role definition and maintenance

Key SAP Access Control Considerations for SAPinsiders

What is SAP Access Control?

Improper access is a major security threat to SAP and other enterprise systems. The issue only gets worse as employees increasingly access their relevant applications remotely and on varying, often personal, devices. The goal of SAP Access Control is to ensure the right people are using the right software from the right device. It also helps track access information in case it needs to be reported later for compliance purposes or assessed for risk.

SAP Access Control’s key functions include:

  • Risk analysis
  • User provisioning
  • Monitoring privileges
  • Certifying authorizations
  • Integration with enterprise systems
  • Role definition and maintenance

Key SAP Access Control Considerations for SAPinsiders

  • Quantify how improving user access and identity management impacts the bottom line. Most governance, risk, and compliance (GRC) organizations surveyed for our recent User Access and Identity Management for SAP S/4HANA report are facing budget constraints. That can make it hard to invest in software like SAP Access Control, but you can build the business case by finding those areas where unauthorized access can be costly. Added costs can come from cyberattacks, fraud, compliance-related fines, and rework to address audit issues. The cybersecurity threats are real — over a quarter of respondents noted having an access-related security breach in our April 2021 Securing the SAP Landscape Against Cyber Threats report.
  • Audit your user access landscape. First, gain an understanding of which users are accessing which systems and why. Then, survey your users and identify which roles need which systems. These steps can help you be more efficient in integrating your access across your technology footprint.
  • Integrate user access and identity management across your technology stack as part of your migration. Respondents to our latest User Access and Identity Management survey who worked for leading organizations were much more likely to integrate user access and identity management as part of digital transformation and integrate identity management across their heterogeneous application landscapes. These actions can help you optimize investment in software like SAP Access Control and create a holistic user access and identity management strategy.
  • Centralize user access and identity processes to maximize your next technology investment. Centralizing user access and identity management can provide benefits that reduce risk, enable compliance, and make securing your systems easier. However, you must first unify the process by which you identify users and grant access to systems, no matter the business area or solution. That will make any technological investment more valuable when implemented.

75 results

  1. Mass Maintenance of Mitigation Control Owners and Risk Owners in SAP Access Control 10.1

    Reading time: 6 mins

    Sergei Peleshuk provides an overview of SAP BW/4HANA and key considerations to think about when making the decision to migrate. This content is for SAPinsider Monthly Subscription, SAPinsider Annual Subscription, and SAPinsider Premium Annual Subscription members only.Log In Join Now

  2. Speed Up Repository Object Synchronization with a New BAdI

    Reading time: 7 mins

    Learn about a Business Add-In (BAdI) that is a new feature introduced in SAP Access Control 10.0 (Support Package 24) and 10.1 (Support Package 15) for customizing the way the standard Repository object synchronization program works. Users on lower Support Packages can implement SAP Note 2307792 to have this feature. This content is for SAPinsider…

  3. Past-to-Present SAP Access Management Best Practices

    Reading time: 13 mins

    What do you do when what used to be acceptable is no longer adequate? How efficiently is your organization managing SAP ERP access and role-design? How pleased are your auditors with the control and reporting you offer? How pleased are your users with the processes they have to follow to get and retain access? How…...…

  4. A Walk Through Ticketing Functionality in SAP Access Control 10.1

    Reading time: 8 mins

    The integration of data and processes among different SAP systems has always been challenging and expensive in development. You can dramatically reduce the development effort in system integration by exploring the generic presentation of functions/methods and the generic presentation of parameters in a generic Remote Function Call (RFC). Key Concept Ticketing functionality gives role designers…...…

  5. Live from SAPinsider Studio: Customer Panel on ERP Maestro

    GRC practitioners Carol Chapman of American National Insurance and Kevin Lester of Dominion Diamond Corp share how their companies realized enormous benefits through ERP Maestro. The conversation occurred during the Financials/GRC 2017 conference held in Las Vegas, Nevada. Topics covered include: • The challenges each company was facing around SAP access controls • How ERP…...…

  6. Live from SAPinsider Studio: American Outdoor Brands GRC Initiative Leads to Improved Controls

    Joshua Lowy, Head of Internal Audit at American Outdoor Brands, shares how American Outdoors Brand deployed SAP Access Control and implemented an SoD waiver form. The conversation occurred during the Financials/GRC 2017 conference held in Las Vegas, Nevada. Topics covered include: How access roles are kept clean for users with separate responsibilities How existing SoD…...…

  7. Relaxo Footwears Takes Huge Strides to Improve SAP User Management

    Reading time: 12 mins

    Relaxo Footwears Limited -- the largest footwear manufacturer in India -- produces roughly 600,000 pairs of shoes each day, which are sold through 900 distributors promoting 11 brands and 300 retail outlets in 125 cities across the country. Since implementing SAP Apparel and Footwear in 2009, Relaxo has more than doubled its SAP licenses, and…

  8. Live from SAPinsider Studio: The Last Mile of SoD Management

    Susan Stapleton, Vice President of the Customer Advisory Office at Greenlight, shares what the last mile of SoD management entails and provides advice on how to get there. The conversation occurred during the Financials/GRC 2017 conference held in Las Vegas, Nevada. Topics covered include: • What was involved in the previous miles that led up…...…

  9. The Never-Ending Opportunities with SAP Projects

    Reading time: 6 mins

    Every SAP project brings with it tremendous opportunities as well as challenges, not only for your organization at large, but especially for you as a member of the SAP project team. As I look back at my 40+ years of experience, both as a leader within a large global corporation as well as President and…

  10. American Outdoor Brands Takes Aim at a New Beginning

    Reading time: 6 mins

    American Outdoor Brands Corporation (AOBC) is experiencing the beginning of a new business direction. Originally the well-known firearms company Smith and Wesson, recent success has led AOBC to rapid acquisitions, expansion into new markets, and a rebranding that reflects its broadened focus. But in order to continue this growth, AOBC needed a new IT infrastructure…