Challenges in the implementation of an SAP authorization concept
Developing and implementing an authorization concept presents companies with major challenges on several levels:
- Time and resources required
Creating the concept at all levels is highly time-consuming, and its implementation is no less so. - Complexity
The complexity of the concept increases exponentially with the number of different roles and tasks in the company, as the dependencies also become more diverse. - Comprehensibility
A comprehensive concept can hardly be explained in simple diagrams and summaries; this is an inevitable consequence: - Need for training
All persons responsible for the concept and its implementation must be thoroughly trained; they must then also be given the opportunity on an ongoing basis to find out about changes and updates and implement them if necessary.
An authorization concept has major consequences for user administration in particular, as all work steps must be adapted to the requirements of the concept. Authorization profiles must match the existing roles and tasks in your company exactly.
However, practical experience in user and rights administration can also show that certain regulations of the authorization concept cause problems in day-to-day use. In this case, making changes to the concept may be necessary, which can entail time-consuming processes because all dependencies on other authorizations must also be checked. And then further training is sometimes required.
Ideally, an authorization concept should, therefore, be based on a thorough examination of the status quo and already take into account the approvals and work steps required in everyday use.