cancel
Showing results for 
Search instead for 
Did you mean: 

Restrict RFC Connector in GRC

Former Member
0 Kudos

Hi Gurus,

We are currently working on a GRC10 implementation where we have some concerns with the access the RFC connector from GRC to ECC might have to sensitive information (particularly access to sensitive HR tables).  Is there a way to restrict via security the RFC ID's ability to access certain tables/information in ECC?  My understanding is that RFC connectors need to have SAP_ALL or automated business rules won't execute properly.  Is this correct?  Or can they be restricted.

Appreciate your thoughts and feedback! 

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

Hello Taylor,

RFC user id that is used to connect backend systems should never have SAP_ALL.

with that said, here are some authorizations that you can consider for the id that is used to communicate with the backend ECC system: you can find this info in the security guide