{"id":1575,"date":"2021-03-04T10:49:58","date_gmt":"2021-03-04T09:49:58","guid":{"rendered":"https:\/\/sast-solutions.com\/blog-en\/?p=1575"},"modified":"2021-03-23T08:59:34","modified_gmt":"2021-03-23T07:59:34","slug":"practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system","status":"publish","type":"post","link":"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/","title":{"rendered":"Practical tip: How you can avoid special roles and create new organizational levels in your SAP system based on an authorization field"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-1576 alignleft\" src=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Zeit-sparen-Sanduhr-300x226.jpg\" alt=\"Practical tip: How you can avoid special roles and create a new organizational level in your SAP system based on an authorization field\" width=\"300\" height=\"226\" srcset=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Zeit-sparen-Sanduhr-300x226.jpg 300w, https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Zeit-sparen-Sanduhr-1024x772.jpg 1024w, https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Zeit-sparen-Sanduhr-768x579.jpg 768w, https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Zeit-sparen-Sanduhr-1536x1158.jpg 1536w, https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Zeit-sparen-Sanduhr-800x600.jpg 800w, https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Zeit-sparen-Sanduhr.jpg 1920w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>In the standard SAP system, there are many authorization fields that are not declared as organizational levels, but instead characterized by special values. But the more authorization fields without organizational levels that contain organization-specific values like location or country, the larger the proportion of special roles grows.<\/p>\n<p>However, to achieve the greatest possible transparency in role administration and avoid unnecessary authorizations \u2013 not least with system security in mind \u2013 the creation of additional special roles should be avoided wherever possible.<\/p>\n<p><!--more--><\/p>\n<p>&nbsp;<\/p>\n<p>A practical example: One of our customers configured their system so that employees could only select from printers with a specific country code. These users also required access to other printers in other locations, however. This raises the question: How can you assign additional country codes without having to create a multitude of special roles?<\/p>\n<h2><strong>Add certain authorization fields to the organizational level <\/strong><\/h2>\n<p>When we look at the standard SAP system, we can see that only selected authorization fields are declared as organizational levels, such as the sales organization (VKORG), plant (WERKS), and so on. By assigning an organizational level to an authorization field, we can make sure that authorization fields are assigned identically in each authorization object.<\/p>\n<h2><strong>Absolute maintenance of organizational levels <\/strong><\/h2>\n<p>The report \u201cPFCG_ORGFIELD_CREATE\u201d can be used to define organizational levels for an authorization object. But be careful: the following reports are already obsolete in NetWeaver version 7.50 and later:<\/p>\n<ul>\n<li>PFCG_ORGFIELD_CREATE<\/li>\n<li>PFCG_ORGFIELD_DELETE<\/li>\n<li>PFCG_ORGFIELD_UPGRADE<\/li>\n<\/ul>\n<p>As a result, when you try to start the reports, the system issues the error message \u201cReport PFCG_ORGFIELD_* is obsolete\u201d. For more information, refer to the SAP Note <a href=\"https:\/\/apps.support.sap.com\/sap\/support\/knowledge\/en\/2625102\" target=\"_blank\" rel=\"noopener noreferrer\">2625102 &#8211; Report PFCG_ORGFIELD* is obsolete<\/a>.<\/p>\n<p>Excerpt from SAP transaction PFCG \u2013 authorization object S_BLOG, without organizational level:<\/p>\n<h2><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1577\" src=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik1_en.png\" alt=\"Practical tip: How you can avoid special roles and create a new organizational level in your SAP system based on an authorization field\" width=\"464\" height=\"263\" srcset=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik1_en.png 464w, https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik1_en-300x170.png 300w\" sizes=\"auto, (max-width: 464px) 100vw, 464px\" \/><\/h2>\n<h2><strong>How can you correctly maintain organizational levels now?<\/strong><\/h2>\n<p>To create custom organizational levels for the standard SAP system, call transaction SUPO \u2013 \u201cMaintain Organizational Levels\u201d. When the transaction starts, it displays an overview of all existing SAP standard organizational levels. To create or delete organizational levels, click the \u201cChange\u201d button.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1578\" src=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik2_en.png\" alt=\"Practical tip: How you can avoid special roles and create a new organizational level in your SAP system based on an authorization field\" width=\"957\" height=\"288\" srcset=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik2_en.png 957w, https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik2_en-300x90.png 300w, https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik2_en-768x231.png 768w\" sizes=\"auto, (max-width: 957px) 100vw, 957px\" \/><\/p>\n<p>You can control the insertion and deletion of rows using OK codes, which you enter in the command field:<\/p>\n<ul>\n<li>=CREA_OLVL to create a new organizational level<\/li>\n<li>=DELE_OLVL to delete an existing organizational level<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1579\" src=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Grafik-Mini.png\" alt=\"Practical tip: How you can avoid special roles and create a new organizational level in your SAP system based on an authorization field\" width=\"164\" height=\"36\" \/><\/p>\n<p>In \u201cChange\u201d mode, you can also add or remove organizational levels without OK codes by clicking the \u201cName of Org. Level\u201d field:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1580\" src=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik3_en.png\" alt=\"Practical tip: How you can avoid special roles and create a new organizational level in your SAP system based on an authorization field\" width=\"978\" height=\"190\" srcset=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik3_en.png 978w, https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik3_en-300x58.png 300w, https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik3_en-768x149.png 768w\" sizes=\"auto, (max-width: 978px) 100vw, 978px\" \/><\/p>\n<p><strong>Important information:<\/strong> To delete an authorization level, all authorization values with the authorization field must be deleted from all roles. There must not be any entry for it in the table AGR_1252.<\/p>\n<p>In the new row, you can now enter the name of the new organizational level and the existing authorization field. To finish, click \u201cSave\u201d and add the change to a transport request:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1581\" src=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik4_en.png\" alt=\"Practical tip: How you can avoid special roles and create a new organizational level in your SAP system based on an authorization field\" width=\"446\" height=\"217\" srcset=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik4_en.png 446w, https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik4_en-300x146.png 300w\" sizes=\"auto, (max-width: 446px) 100vw, 446px\" \/><\/p>\n<p>The responsible organizational level tables \u2013 USORG, USVAR, and USVART \u2013 are now updated automatically.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1582\" src=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik5_en.png\" alt=\"Practical tip: How you can avoid special roles and create a new organizational level in your SAP system based on an authorization field\" width=\"586\" height=\"255\" srcset=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik5_en.png 586w, https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Sonderrollen_Grafik5_en-300x131.png 300w\" sizes=\"auto, (max-width: 586px) 100vw, 586px\" \/><\/p>\n<p>Therefore, our goal is to raise certain authorization fields to the organizational level and then derive them.<\/p>\n<h2><strong>Sophisticated role management helps you save time and resources<\/strong><\/h2>\n<p>Crucial elements of role administration involve making it as transparent as possible and avoiding granting unnecessary authorizations, not least with system security in mind. With this approach, you can avoid having to define large numbers of special roles and also capture further positive effects by using the derivation principle throughout the system. The result: tremendous time savings in your role administration.<\/p>\n<p>If you would like more information about avoiding special roles or support with your role management, visit our <a href=\"https:\/\/sast-solutions.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">website<\/a> or <a href=\"mailto:sast@akquinet.de\" target=\"_blank\" rel=\"noopener noreferrer\">send us an e-mail<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1498\" src=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2020\/11\/Foto-Maxi.jpg\" alt=\"Maximilian Hauer (SAST SOLUTIONS)\" width=\"183\" height=\"204\" \/><br \/>\n<strong>Maximilian Hauer (SAP Authorizations Consultant, SAST SOLUTIONS)<\/strong><\/p>\n<p>&nbsp;<\/p>\n<h2>Further articles on the topic:<\/h2>\n<blockquote class=\"wp-embedded-content\" data-secret=\"QOFzZoG5hi\"><p><a href=\"https:\/\/sast-solutions.com\/blog-en\/2020\/11\/20\/role-adjustments-technical-sap-users-handle-authorizations-safely-effectively\/\">Role adjustments for technical SAP users \u2013 how to handle authorizations safely and effectively<\/a><\/p><\/blockquote>\n<p><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;Role adjustments for technical SAP users \u2013 how to handle authorizations safely and effectively&#8221; &#8212; SAST BLOG\" src=\"https:\/\/sast-solutions.com\/blog-en\/2020\/11\/20\/role-adjustments-technical-sap-users-handle-authorizations-safely-effectively\/embed\/#?secret=QOFzZoG5hi\" data-secret=\"QOFzZoG5hi\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<blockquote class=\"wp-embedded-content\" data-secret=\"M7MKxON1gn\"><p><a href=\"https:\/\/sast-solutions.com\/blog-en\/2018\/09\/25\/self-adjusting-authorizations-sasts-new-tool-intelligently-slims-down-sap-roles\/\">Self-Adjusting Authorizations: SAST SOLUTIONS&#8217;s new tool intelligently slims down SAP roles<\/a><\/p><\/blockquote>\n<p><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;Self-Adjusting Authorizations: SAST SOLUTIONS&#8217;s new tool intelligently slims down SAP roles&#8221; &#8212; SAST BLOG\" src=\"https:\/\/sast-solutions.com\/blog-en\/2018\/09\/25\/self-adjusting-authorizations-sasts-new-tool-intelligently-slims-down-sap-roles\/embed\/#?secret=M7MKxON1gn\" data-secret=\"M7MKxON1gn\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the standard SAP system, there are many authorization fields that are not declared as organizational levels, but instead characterized by special values. But the more authorization fields without organizational levels that contain organization-specific values like location or country, the larger the proportion of special roles grows. However, to achieve the greatest possible transparency in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[67,64,68,80],"class_list":["post-1575","post","type-post","status-publish","format-standard","hentry","category-sap-authorizations-grc","tag-identity-management","tag-role-management","tag-sap-authorizations","tag-sap-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Avoid special roles in the SAP system with your own organizational levels.<\/title>\n<meta name=\"description\" content=\"A high number of special roles can compromise your system security. We show you how to collect and derive authorization fields at the organizational level.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Avoid special roles in the SAP system with your own organizational levels.\" \/>\n<meta property=\"og:description\" content=\"A high number of special roles can compromise your system security. We show you how to collect and derive authorization fields at the organizational level.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/\" \/>\n<meta property=\"og:site_name\" content=\"SAST BLOG\" \/>\n<meta property=\"article:published_time\" content=\"2021-03-04T09:49:58+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-03-23T07:59:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Zeit-sparen-Sanduhr.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1447\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"securityblog\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Avoid special roles in the SAP system with your own organizational levels.\" \/>\n<meta name=\"twitter:description\" content=\"A high number of special roles can compromise your system security. We show you how to collect and derive authorization fields at the organizational level.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Zeit-sparen-Sanduhr.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"securityblog\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/2021\\\/03\\\/04\\\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/2021\\\/03\\\/04\\\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\\\/\"},\"author\":{\"name\":\"securityblog\",\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/#\\\/schema\\\/person\\\/cd70e3749cca136a7e8a37dc1d3cfc26\"},\"headline\":\"Practical tip: How you can avoid special roles and create new organizational levels in your SAP system based on an authorization field\",\"datePublished\":\"2021-03-04T09:49:58+00:00\",\"dateModified\":\"2021-03-23T07:59:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/2021\\\/03\\\/04\\\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\\\/\"},\"wordCount\":629,\"publisher\":{\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/2021\\\/03\\\/04\\\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/Zeit-sparen-Sanduhr-300x226.jpg\",\"keywords\":[\"Identity Management\",\"Role Management\",\"SAP Authorizations\",\"SAP Security\"],\"articleSection\":[\"SAP Authorizations &amp; GRC\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/2021\\\/03\\\/04\\\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\\\/\",\"url\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/2021\\\/03\\\/04\\\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\\\/\",\"name\":\"Avoid special roles in the SAP system with your own organizational levels.\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/2021\\\/03\\\/04\\\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/2021\\\/03\\\/04\\\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/Zeit-sparen-Sanduhr-300x226.jpg\",\"datePublished\":\"2021-03-04T09:49:58+00:00\",\"dateModified\":\"2021-03-23T07:59:34+00:00\",\"description\":\"A high number of special roles can compromise your system security. We show you how to collect and derive authorization fields at the organizational level.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/2021\\\/03\\\/04\\\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/2021\\\/03\\\/04\\\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/2021\\\/03\\\/04\\\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\\\/#primaryimage\",\"url\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/Zeit-sparen-Sanduhr.jpg\",\"contentUrl\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/Zeit-sparen-Sanduhr.jpg\",\"width\":1920,\"height\":1447,\"caption\":\"Practical tip: How you can avoid special roles and create a new organizational level in your SAP system based on an authorization field\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/2021\\\/03\\\/04\\\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Practical tip: How you can avoid special roles and create new organizational levels in your SAP system based on an authorization field\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/#website\",\"url\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/\",\"name\":\"SAST BLOG\",\"description\":\"SAP Security &amp; Compliance\",\"publisher\":{\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/#organization\",\"name\":\"SAST BLOG\",\"url\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/sast-solutions-logo.png\",\"contentUrl\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/sast-solutions-logo.png\",\"width\":358,\"height\":155,\"caption\":\"SAST BLOG\"},\"image\":{\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/sast-solutions.com\\\/blog-en\\\/#\\\/schema\\\/person\\\/cd70e3749cca136a7e8a37dc1d3cfc26\",\"name\":\"securityblog\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Avoid special roles in the SAP system with your own organizational levels.","description":"A high number of special roles can compromise your system security. We show you how to collect and derive authorization fields at the organizational level.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/","og_locale":"en_US","og_type":"article","og_title":"Avoid special roles in the SAP system with your own organizational levels.","og_description":"A high number of special roles can compromise your system security. We show you how to collect and derive authorization fields at the organizational level.","og_url":"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/","og_site_name":"SAST BLOG","article_published_time":"2021-03-04T09:49:58+00:00","article_modified_time":"2021-03-23T07:59:34+00:00","og_image":[{"width":1920,"height":1447,"url":"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Zeit-sparen-Sanduhr.jpg","type":"image\/jpeg"}],"author":"securityblog","twitter_card":"summary_large_image","twitter_title":"Avoid special roles in the SAP system with your own organizational levels.","twitter_description":"A high number of special roles can compromise your system security. We show you how to collect and derive authorization fields at the organizational level.","twitter_image":"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Zeit-sparen-Sanduhr.jpg","twitter_misc":{"Written by":"securityblog","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/#article","isPartOf":{"@id":"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/"},"author":{"name":"securityblog","@id":"https:\/\/sast-solutions.com\/blog-en\/#\/schema\/person\/cd70e3749cca136a7e8a37dc1d3cfc26"},"headline":"Practical tip: How you can avoid special roles and create new organizational levels in your SAP system based on an authorization field","datePublished":"2021-03-04T09:49:58+00:00","dateModified":"2021-03-23T07:59:34+00:00","mainEntityOfPage":{"@id":"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/"},"wordCount":629,"publisher":{"@id":"https:\/\/sast-solutions.com\/blog-en\/#organization"},"image":{"@id":"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/#primaryimage"},"thumbnailUrl":"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Zeit-sparen-Sanduhr-300x226.jpg","keywords":["Identity Management","Role Management","SAP Authorizations","SAP Security"],"articleSection":["SAP Authorizations &amp; GRC"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/","url":"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/","name":"Avoid special roles in the SAP system with your own organizational levels.","isPartOf":{"@id":"https:\/\/sast-solutions.com\/blog-en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/#primaryimage"},"image":{"@id":"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/#primaryimage"},"thumbnailUrl":"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Zeit-sparen-Sanduhr-300x226.jpg","datePublished":"2021-03-04T09:49:58+00:00","dateModified":"2021-03-23T07:59:34+00:00","description":"A high number of special roles can compromise your system security. We show you how to collect and derive authorization fields at the organizational level.","breadcrumb":{"@id":"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/#primaryimage","url":"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Zeit-sparen-Sanduhr.jpg","contentUrl":"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/Zeit-sparen-Sanduhr.jpg","width":1920,"height":1447,"caption":"Practical tip: How you can avoid special roles and create a new organizational level in your SAP system based on an authorization field"},{"@type":"BreadcrumbList","@id":"https:\/\/sast-solutions.com\/blog-en\/2021\/03\/04\/practical-tip-avoid-special-roles-create-new-organizational-level-in-sap-system\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sast-solutions.com\/blog-en\/"},{"@type":"ListItem","position":2,"name":"Practical tip: How you can avoid special roles and create new organizational levels in your SAP system based on an authorization field"}]},{"@type":"WebSite","@id":"https:\/\/sast-solutions.com\/blog-en\/#website","url":"https:\/\/sast-solutions.com\/blog-en\/","name":"SAST BLOG","description":"SAP Security &amp; Compliance","publisher":{"@id":"https:\/\/sast-solutions.com\/blog-en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sast-solutions.com\/blog-en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/sast-solutions.com\/blog-en\/#organization","name":"SAST BLOG","url":"https:\/\/sast-solutions.com\/blog-en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sast-solutions.com\/blog-en\/#\/schema\/logo\/image\/","url":"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/sast-solutions-logo.png","contentUrl":"https:\/\/sast-solutions.com\/blog-en\/wp-content\/uploads\/2021\/03\/sast-solutions-logo.png","width":358,"height":155,"caption":"SAST BLOG"},"image":{"@id":"https:\/\/sast-solutions.com\/blog-en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/sast-solutions.com\/blog-en\/#\/schema\/person\/cd70e3749cca136a7e8a37dc1d3cfc26","name":"securityblog"}]}},"_links":{"self":[{"href":"https:\/\/sast-solutions.com\/blog-en\/wp-json\/wp\/v2\/posts\/1575","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sast-solutions.com\/blog-en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sast-solutions.com\/blog-en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sast-solutions.com\/blog-en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sast-solutions.com\/blog-en\/wp-json\/wp\/v2\/comments?post=1575"}],"version-history":[{"count":8,"href":"https:\/\/sast-solutions.com\/blog-en\/wp-json\/wp\/v2\/posts\/1575\/revisions"}],"predecessor-version":[{"id":1607,"href":"https:\/\/sast-solutions.com\/blog-en\/wp-json\/wp\/v2\/posts\/1575\/revisions\/1607"}],"wp:attachment":[{"href":"https:\/\/sast-solutions.com\/blog-en\/wp-json\/wp\/v2\/media?parent=1575"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sast-solutions.com\/blog-en\/wp-json\/wp\/v2\/categories?post=1575"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sast-solutions.com\/blog-en\/wp-json\/wp\/v2\/tags?post=1575"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}