To make sure the correct people are granted access to powerful SAP authorizations, you can define a role that requires a manager’s approval for all access requests to those authorizations.
To create a restricted SAP Access role:
Launch Designer, and verify that your project is current.
To verify that your project is current, see Using the Compare Feature When Importing
in the Designer 3.0.1 for Identity Manager 3.6 Administration Guide.
In the Designer toolbar, click
> > to display the Provisioning view.In the Provisioning view, click
> > > .Right-click the
, then click .Use the following information to create the role:
Identifier: Specify a unique name for the role. In this example, it is Restrict SAP Access. The
and are populated with this name.Category: Select the
category.Trustees: Add the container that holds your user objects as a trustee of this role. When a user logs in to the Roles Based Provisioning Module, this role is displayed for them to access.
Click
to create the role.Click the
tab at the bottom of the new role.Select
to determine the type of approval process for granting access to the SAP resource.Select the approval type of
.When you select
, the request is sent to the approvers and the approvers must approve the request before it is granted. In this use case the approver is the users’ manager.Click the plus icon to add the approvers for the request. You can have one or more approvers.
To map the Restricted SAP Access role to the SAP resource:
Log in to the Role Mapping Administrator.
Select the Restricted SAP Access role.
Access the SAP system that you want to restrict access to in the Authorizations panel.
Select the roles in the SAP system that grant a user access to the resource and drag and drop them into the Mapping panel.
Click
to save and deploy the changes.The Restricted SAP access role is mapped to the SAP role, which is now available for the users to request through the Roles Based Provisioning Module. When the users request this resource, the manager is notified. The manager either approves or denies the request.