cancel
Showing results for 
Search instead for 
Did you mean: 

Display All

said_shepl
Participant
0 Kudos

Hi Expert,

    Please we want to create a role have all transaction but with display activity only.

Regards

Said Shepl

Accepted Solutions (1)

Accepted Solutions (1)

divyanshu_srivastava3
Active Contributor
0 Kudos

You need sap_all with display attributes.

refer

Regards

Colleen
Advisor
Advisor
0 Kudos

If recommending a document it would be worth reading the comments.. the display role didn't restrict

divyanshu_srivastava3
Active Contributor
0 Kudos

Well, the link was just an reference and not suggested to download and import. The idea was to set sap_all with non-execute right.

Thanks for bringing this to everyone.

Colleen
Advisor
Advisor
0 Kudos

Hi Divyanshu

Is your background security?

There have been quite a few conversations around the ability to actual build such a role and under what circumstances it is valid. Your comment reads like a link only response when the better question would have been "Why do you need such a role"?

If this role is for Production then I would be concerned. I get your point is that you need to obviously restrict access. However, the article your link to without any context does not provide the risks or things to consider. Hence, my comment on this thread.

As the person asking the question has already marked your question as "correct" there is now probably another system out there that will be inadequately restricted and team under the false impression they have followed security guidelines and managed their risk.

In future, if you are going to give such advise in the from of a link only it would be worth providing more context. Your comment implied you were provide the solution and not an example.

@Said Shepal - if you are still following this thread, what do you want a SAP_ALL display role for? I recommend you read the comments in the document linked to you to see the risks as it is not an easy item to achieve (unless you revoke SE* transactions to prevent program execution and go through all of the 80k+ transactions).

Regards

Colleen

said_shepl
Participant
0 Kudos

Hi Colleen,

    firstly, this role for audit team, I know that you are want to secure this role as much as possible, because of this t revoke some transaction SE* to prevent program execution already.

Regards

Said Shepl

Colleen
Advisor
Advisor
0 Kudos

Hi Said Shepl

If this is for production and for audit, I highly recommend you design the role like any other end users and obtain requirements. Then drive the role build all through transaction codes.

If you are allowing full display then grant them the end user reporting transactions, audit logs and SE16 (hate to suggest granting this) table access. That should meet their requirements. You don't need to provide a cut down version of SAP_ALL

Regards

Colleen

Answers (0)