Showing posts with label PFCG. Show all posts
Showing posts with label PFCG. Show all posts

Creating Derived Roles in SAP Security

Creating Derived Roles in SAP Security

Derived roles :
1.   Derived roles refer to roles that already exist.  The derived roles inherit the menu structure and the functions included (transactions, reports, Web links, and so on) from the role referenced or simply you can call as Parent Role.  A role can only inherit menus and functions if no transaction codes have been assigned to it before.
2.  These are used to define to handle the security at organization levels.
3     These are created for administrative purpose to minimize the maintenance.
4.   Derived roles specify the division or unit for which the security can be provided.
5.    Derived roles are inherited from parent role/ single role/ generic role differed by there organization levels.
6.     Derived roles are also called as child roles.
7.   The higher-level role passes on its authorizations to the derived role as default values which can be changed afterwards.  Organizational level definitions are not passed on. They must be created a new in the inheriting role. User assignments are not passed on either.
8.     Derived roles are an elegant way of maintaining roles that do not differ in their functionality (identical menus and identical transactions) but have different characteristics with regard to the organizational level.
9.   The menus passed on cannot be changed in the derived roles.  Menu maintenance takes place exclusively in the role that passes on its values. Any changes immediately affect all inheriting roles.
10. You can remove the inheritance relationship, but afterwards the inheriting role is treated like any other normal role. Once a relationship is removed, it cannot be established again.
11.   In derived roles, menus are fixed.
12.   These are created in PFCG
13.   In versions earlier than 4.6 c, derived roles are also called as Derived Activity Groups DAGS.
 
 
 
 
 
 





 

Composite Roles in SAP Security

Composite Roles in SAP Security


Composite roles:
1.   A composite role is a container with  several different roles. For reasons of clarity, it does not make sense and is therefore not allowed to add composite roles to composite roles. Composite roles are also called roles.
2.     It is used to simplify the administration.
3.    Composite roles do not contain authorization data. If you want to change the authorizations (that are represented by a composite role), you must maintain the data for each role of the composite role.
4.     It only groups the roles, but menus can be compressed.
5.  Creating composite roles makes sense if some of your employees need authorizations from several roles. Instead of adding each user separately to each role required, you can set up a composite role and assign the users to that group.
6.   The users assigned to a composite role are automatically assigned to the corresponding (elementary) roles during comparison.
7. Composite roles are identified by customer naming conventions only.
1.    These are created in PFCG.
2.  These are earlier called as CAGS(Composite Activity Groups).
3.    Example for Composite Role. Here the role name, “BASIS Role” is defined as Composite Role

           




·         The menu tree of a composite role is, in the simplest case, a combination of the menus of the roles contained. When you create a new composite role, the initial menu tree is empty at first. You can set up the menu tree by choosing Read menu to add the menus of all roles included. This merging may lead to certain menu items being listed more than once. For example, a transaction or path contained in role 1 and role 2 would appear twice.
·         If the set of roles contained in a composite role changes, the menu tree is also affected. In such a case, you can completely rebuild the menu tree or process only the changes. If you choose the latter option, the Profile Generator removes all items from the menu which are not contained in any of the roles referenced.
·         It is possible (and often necessary) to change the menu of a composite role at any time. You adjust these menus in the same way as the menus for roles (see above).