Skip to Content
author's profile photo Former Member
Former Member

GRC AC 10 EAM - Distiguish between a firefighter id and a regular user id logon by looking at it


I have a requirement where users want to see a change in SAP screen( color/warning/note) while using a firefighter id.

Reason behind the requirement is that some users are not logging off after using the firefighter id and by mistake using the firefighter id as their own user id for their day to day jobs.

We are conducting training sessions for users but wanted to check if anyone has worked on the same requirement before .

I know SAP GUI settings to get different color codes for development, staging and production sap system but we can not use this for firefighter id globally.


Add a comment
10|10000 characters needed characters exceeded

Assigned Tags

Related questions

2 Answers

  • Posted on Jun 02, 2014 at 06:48 AM

    Dear Mark,

    so far there is no possibility to give colors or warnings when logged on via firefighter. I have the same problem in my organization and assume others do have the same.

    To avoid that a user does his daily work with the firefighter we have limited the access rights of the firefighter. Basically a user who has a firefighter has authorized "missing" transactions in the firefighter and does not have the access to his daily work authorization.

    This isn't the perfect solution but as work around it serves its purpose.



    Add a comment
    10|10000 characters needed characters exceeded

    • Former Member

      Hello Alessandro,

      Thanks for your reply.

      I think then here I will stress on user training on firefighter usage. We have tried to restrict the firefighter id access by giving exceptional T codes but to give access to a specific business process sometimes we have to include the non sensitive T codes that user have in their own ids as well.


  • author's profile photo Former Member
    Former Member
    Posted on Jun 02, 2014 at 06:56 AM

    Hello Mark,

    I guess you are not using SSO for normal ID login in different systems.

    But I am curious because in my organization it's different.

    One thing : We have SSO and second thing user's have very limited access under normal ID.

    even if users are logging in using GUI. Throug GRC_EAM , it will take them to UI and from there user's sees the FF ID's ?

    Is that not the case here ?


    Munish Kumar

    Add a comment
    10|10000 characters needed characters exceeded

    • Hi Mark

      Yes training is the way to go but it is an issue faced a lot when users forget which account to use. You are right - like all design - there is that balance between time, cost, effort and functionality.

      Good luck on it

      If your question has been answered here, please close the thread out



Before answering

You should only submit an answer when you are proposing a solution to the poster's problem. If you want the poster to clarify the question or provide more information, please leave a comment instead, requesting additional details. When answering, please include specifics, such as step-by-step instructions, context for the solution, and links to useful resources. Also, please make sure that you answer complies with our Rules of Engagement.
You must be Logged in to submit an answer.

Up to 10 attachments (including images) can be used with a maximum of 1.0 MB each and 10.5 MB total.