SAP Security & GRC made easy

Emergency Access Management users include administrators, owners, controllers, and firefighters.

 The table below describes each role along with their corresponding delivered roles and authorizations.


Role TypeDescriptionDelivered Role
AdministratorAdministrators have full access to Emergency Access Management. They assign Firefighter IDs, manage data tables, run reports, and ensure the Reason Code table is up to date. They can also enable email notifications for Controllers.SAP_GRAC_SUPER_USER_MGMT_ADMIN
Note: In decentralized firefighting, administrators must create this role on relevant plug-in systems and assign authorization object /GRCPI/001 with ACTVT field value as 70 or *.
OwnerOwners assign Firefighter IDs to Firefighters and designate Controllers. They can view assigned Firefighter IDs but cannot assign them to themselves.SAP_GRAC_SUPER_USER_MGMT_OWNER
Note: For decentralized firefighting, owners must create this role on relevant plug-in systems and assign authorization object /GRCPI/001 with an empty ACTVT field value.
ControllerControllers oversee Firefighter ID usage by reviewing log reports and receiving email notifications on Firefighter ID logins.SAP_GRAC_SUPER_USER_MGMT_CNTLR
FirefighterFirefighters use Firefighter IDs to perform authorized tasks during emergency situations.SAP_GRAC_SUPER_USER_MGMT_USER
Note: For decentralized firefighting, Firefighters must have authorizations to use transactions /GRCPI/GRIA_EAM and SU53 on relevant plug-in systems.
Firefighter IDThe assigned role SAP_GRAC_SPM_FFID converts a user ID into a Firefighter ID, enabling remote logon.SAP_GRAC_SPM_FFID
Note: This role is applicable only for ID-based firefighting and requires authorization object S_RFC.

This version keeps the information structured, easy to read, and clear while retaining all critical details. Let me know if you need further refinements! 🚀

No comments:

Post a Comment