Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

Strategy adopted in creating Master role

Former Member
0 Kudos

Hello SAP Security Gurus,

Please let me know if the startegy i have adopted to create master role in my current project is wrong or right

I have  created master role with transaction added in the menu tab, and have maintained the object values accordingly,for Organisational values i have maintained value as * in master roles, example co code as *.These master roles will not get assigned to users in prod system, only derived will be assigned

I have derived the roles from master roles, which inherited the object values etc and have mantained organisational values for that derived role accordingly example co code as 1000 etc.

is this a wrong practice per SAP or is this the correct approach, your advice is much appriciated.

Thanks

Uttam

1 ACCEPTED SOLUTION

Former Member
0 Kudos

Hi,

If master roles are not to be assigned then leave the org levels blank.  If they are then accidentally assigned the user will not get full organisational access.

If you need an "all access" variant then create one as a derived role.

Cheers

1 REPLY 1

Former Member
0 Kudos

Hi,

If master roles are not to be assigned then leave the org levels blank.  If they are then accidentally assigned the user will not get full organisational access.

If you need an "all access" variant then create one as a derived role.

Cheers