跳转至

Blueprint Access

Global Blueprint Enterprise Data Management Access Management Document Information Revision History Document Objective Provides an overview of the process area covered in this document and describes the Business Process Hierarchy (BPH) up to Level 4 (Activity). Describes key business requirements gathered during workshops with GAR Business Process Leads and key business users. Outline the solution and system design in SAP S/4HANA to address the business requirements in respective process areas. This document serves as the global blueprint template to be used as the basis for S/4HANA implementation project TAble of Contents 1 Business Process Overview 5 1.1 Background 5 1.1.0 Business Drivers 5 1.1.1 Current Challenges 5 1.2 Purpose 6 1.3 Objectives 6 1.4 Scope 6 1.4.0 In Scope 6 1.4.1 Out of Scope 6 1.5 Target Audience 7 1.6 Assumptions 7 1.7 Constraints 7 1.8 Authorization Principles 7 1.9 Security Design Goals 7 2 Key Design Decisions 8 2.1 Authorization Strategy 8 2.1.0 Purpose 8 2.1.1 Design Objectives 8 2.1.2 Authorization Model 8 2.1.3 Authorization Principles 8 2.2 Role Architecture 9 2.2.0 Role Categories 9 2.2.1 Design Principles 9 2.3 Function Role 9 2.4 Business Role 9 2.5 Business Role Catalog 10 2.6 Business Role Lifecycle 10 3 SAP Authorization Solution Blueprint 10 3.1 Authorization Architecture 10 3.2 Authorization Layer 10 3.3 Authorization Ownership 11 3.4 Authorization Flow 11 3.5 Responsibility Matrix (RACI) 11 3.6 Design Principles 11 4 Authorization Governance 12 4.1 Authorization Lifecycle 12 4.2 Joiner / Mover / Leaver (JML) 12 4.3 Periodic Access Review 12 4.4 Emergency Access Management 13 4.5 Privileged Access Management 13 4.6 Role Ownership 13 4.7 Role Change Management 13 4.8 Naming Governance 13 5 SAP GRC Integration 13 5.1 Overview 13 5.2 SAP GRC Components 14 5.3 Access Request Management (ARM) 14 5.4 Business Role Management (BRM) 14 5.5 Access Risk Analysis (ARA) 14 5.6 Emergency Access Management (EAM) 14 5.7 User Access Review 15 5.8 Mitigation Controls 15 5.9 Workflow 15 6 Future Architecture 15 6.1 Future Architecture Overview 15 6.2 SAP Fiori 15 6.3 SAP Business Technology Platform (BTP) 16 6.4 SAP Identity Authentication Service (IAS) 16 6.5 SAP Identity Provisioning Service (IPS) 16 6.6 Microsoft Entra ID Integration 16 6.7 Identity Federation 16 6.8 AI Readiness 16 7 Appendix 17 7.1 System Dictionary 17 7.2 Line of Business (LOB) Dictionary 17 7.3 Country Dictionary 17 7.4 Module Dictionary 17 7.5 Identifier Dictionary 17 7.6 Function Dictionary 17 7.7 Organization Dictionary 17 7.8 Business Role Catalog 17 7.9 Composite Role Catalog 17 7.10 Master Single Role Catalog 17 7.11 Derived Single Role Catalog 17 7.12 Business Role Matrix 18 Matrix mapping Business Roles to Composite Roles, Single Roles and business functions.Companion Documents 18 Business Process Overview Background As part of the SAP S/4HANA Transformation Program, the organization requires a standardized authorization framework capable of supporting global business operations while maintaining security, regulatory compliance, and operational efficiency.

Historically, authorization models have evolved independently across business units, resulting in inconsistent role structures, duplicated authorizations, excessive user privileges, and increased administrative effort. The migration to SAP S/4HANA provides an opportunity to redesign the authorization model using a standardized, scalable, and governance-driven approach aligned with SAP Best Practices and SAP Governance, Risk and Compliance (SAP GRC).

This blueprint establishes the enterprise authorization strategy and serves as the governing document for the design, implementation, operation, and continuous improvement of SAP authorization management across all SAP landscapes. Business Drivers Current Challenges Inconsistent role naming conventions. Duplicate business roles across regions. Excessive authorization assignments. Manual access approval processes. Limited role lifecycle governance. High number of Segregation of Duties (SoD) conflicts. Inefficient access review processes. Complex role maintenance activities. Purpose The purpose of this SAP Authorization Blueprint is to establish the enterprise-wide authorization framework governing the design, implementation, administration, and lifecycle management of SAP authorization roles across the SAP S/4HANA landscape. It defines the authorization architecture, governance principles, role design standards, ownership model, and SAP GRC integration to ensure access is granted in a controlled, consistent, and auditable manner. Objectives Establish a standardized authorization framework. Define enterprise authorization governance. Implement Role-Based Access Control (RBAC). Support Least Privilege and Need-to-Know principles. Reduce Segregation of Duties (SoD) risks. Standardize SAP role architecture. Enable centralized role lifecycle management. Improve audit readiness. Support SAP GRC implementation. Support SAP Fiori authorization architecture. Scope In Scope SAP S/4HANA SAP Fiori SAP GRC Access Control SAP MDG SAP BTP SAP IAS SAP IPS Authorization Governance User Access Management Emergency Access Management Out of Scope Infrastructure security Operating system security Database administration Network security Non-SAP applications unless explicitly integrated Target Audience Assumptions SAP S/4HANA is the enterprise ERP platform. SAP GRC Access Control is implemented or planned. Role-Based Access Control (RBAC) is adopted. Business ownership is defined. Periodic access review is performed. Constraints SAP standard authorization capabilities. Regulatory requirements. Country-specific legal requirements. The authorization design shall comply with applicable legal, regulatory, and statutory requirements in each operating country. Where local legal or regulatory obligations require deviations from the global authorization framework, such deviations shall be documented, justified, approved, and governed in accordance with the established authorization governance process. Project implementation timeline. Existing legacy integrations. Authorization Principles Least Privilege Need-to-Know Role-Based Access Control (RBAC) Segregation of Duties (SoD) Defense in Depth Business Ownership Auditability Scalability Global Standardization with Local Compliance The global authorization framework shall remain standardized across all countries. Country-specific deviations shall only be permitted where required to comply with applicable legal, regulatory, or statutory obligations, and shall be documented and approved through the established authorization governance process Security Design Goals Prevent unauthorized access. Reduce excessive authorizations. Support standardization. Improve audit compliance. Support SAP GRC governance. Prepare for cloud identity integration. Key Design Decisions Authorization Strategy Purpose The SAP Authorization Strategy establishes the enterprise-wide principles for designing, implementing, governing, and maintaining authorization within the SAP S/4HANA landscape. The strategy ensures that user access is aligned with business responsibilities while maintaining confidentiality, integrity, availability, and compliance. The authorization framework shall be centrally governed, business-driven, risk-based, and standardized across all SAP environments. Design Objectives Establish a globally standardized authorization model. Support business process execution without compromising security. Implement Role-Based Access Control (RBAC). Enforce Least Privilege and Need-to-Know principles. Minimize Segregation of Duties (SoD) conflicts. Enable centralized governance through SAP GRC. Improve audit readiness and compliance. Authorization Model Authorization Principles Least Privilege Need-to-Know Role-Based Access Control (RBAC). Segregation of Duties (SoD) Central Governance Business Ownership Auditability Scalability Role Architecture The SAP authorization architecture adopts a layered role model to improve maintainability, reduce redundancy, and simplify user provisioning while separating business responsibilities from technical authorization objects. Role Categories Design Principles One business purpose per role. Minimal authorization scope. Reusable across business units. Free from unnecessary transactions. Business-owned and IT-administered. Version controlled and documented. Function Role A Function Role represents a specific business capability within a business process and groups related SAP transactions required to perform a single functional responsibility. Business Role A Business Role represents a complete job responsibility assigned to an employee and aggregates one or more Composite Roles. Business Role Catalog The Business Role Catalog shall maintain Business Role ID, Name, Description, Business Owner, Composite Roles, Organizational Scope, Status, Version, Effective Date, and Last Review Date. Business Role Lifecycle Request Assessment Design Approval Build Testing Deployment Monitoring Periodic Review Retirement SAP Authorization Solution Blueprint Authorization Architecture The SAP Authorization Architecture defines the logical security framework for controlling access to SAP S/4HANA applications. The architecture separates business responsibilities from technical authorization components to ensure scalability, consistency, and governance across all SAP environments. Authorization Layer Presentation Layer – SAP GUI and SAP Fiori. Application Layer – SAP S/4HANA business applications. Authorization Layer – PFCG roles, authorization objects and values. Governance Layer – SAP GRC Access Control. Authorization Ownership Authorization Flow Access Request submitted through SAP GRC ARM. Business Manager approval. Role Owner approval. SoD analysis using SAP GRC ARA. SAP Security provisions approved roles. User access validation. Periodic access review. Role retirement when no longer required. Responsibility Matrix (RACI) Design Principles Business-driven authorization design. Least Privilege and Need-to-Know. Role-Based Access Control (RBAC). Segregation of Duties (SoD) compliance. Reusable and standardized role design. Central governance with local organizational restrictions. Full auditability and traceability. Authorization Governance Authorization Lifecycle All SAP authorization roles shall follow a controlled lifecycle to ensure consistent governance, auditability, and compliance throughout their existence. Business Request Assessment Design Approval Build Testing Deployment Periodic Review Modification Retirement New Account / Role Change / Account Termination New Account Grant minimum required access, Approved by Manager and Role Owner Access Modification (Transfer / Position Change) Adjust access based on new responsibilities, Remove obsolete roles before assigning new roles Account Deactivation (Resignation / Termination) Revoke all SAP access immediately, Disable accounts and archive records Periodic Access Review Business Role Owners shall perform periodic access reviews at least quarterly or according to corporate policy to verify that assigned access remains appropriate. Validate business necessity. Identify excessive access. Review Segregation of Duties conflicts. Remove obsolete authorizations. Document review evidence for audit. Emergency Access Management Emergency access shall be managed through SAP GRC Emergency Access Management (EAM) using Firefighter IDs. Emergency access must be time-bound, approved, monitored, and reviewed. Formal approval before activation. Automatic activity logging. Mandatory log review. Immediate deactivation after completion. Privileged Access Management Privileged access shall be restricted to authorized administrators and technical support personnel. Privileged roles shall be monitored continuously and protected by strong authentication and approval workflows. Role Ownership Role Change Management All role changes require formal change requests. Business impact assessment shall be completed. SoD analysis shall be performed before deployment. Testing is mandatory before production transport. Changes shall be documented and version controlled. Naming Governance Role names shall comply with the approved SAP Role Naming Convention Standard to ensure consistency, traceability, and maintainability. Use standardized prefixes. Include business function and organizational identifiers. Avoid abbreviations not defined in the enterprise dictionary. Maintain uniqueness across all SAP environments. SAP GRC Integration Overview SAP Governance, Risk and Compliance (SAP GRC) provides the governance framework for managing user access, business roles, segregation of duties, emergency access, and periodic access reviews across the SAP S/4HANA landscape. The integration ensures that authorization processes are standardized, auditable, and aligned with enterprise security policies. SAP GRC Components Access Request Management (ARM) All SAP access requests shall be initiated through SAP GRC ARM. Requests shall follow predefined workflows and require approval from the Requestor's Manager, Business Role Owner, and SAP Security where applicable. Business justification is mandatory. SoD analysis shall be executed before provisioning. Only approved requests may be provisioned. All request activities shall be retained for audit. Business Role Management (BRM) Business Roles shall be designed, approved, version-controlled, and maintained through SAP GRC BRM to ensure consistency and governance across all business units. Central Business Role catalog. Formal approval workflow. Role version history. Periodic role review. Access Risk Analysis (ARA) SAP GRC ARA shall be used to identify Segregation of Duties (SoD) conflicts and critical access risks before user provisioning and during periodic compliance reviews. Real-time SoD analysis. Simulation before role assignment. Risk reporting dashboard. Mitigation assignment where justified. Emergency Access Management (EAM) Emergency access shall be managed using Firefighter IDs. Emergency access shall be temporary, approved, monitored, logged, and reviewed after each usage. Named owner for each Firefighter ID. Time-bound activation. Mandatory log review. Immediate revocation after completion. User Access Review Business Role Owners shall periodically review user access using SAP GRC User Access Review capabilities to ensure that assigned access remains appropriate. Quarterly review cycle. Removal of obsolete access. Evidence retained for audit. Mitigation Controls Where SoD conflicts cannot be removed due to legitimate business requirements, mitigation controls shall be documented, approved, and periodically reviewed. Documented control owner. Compensating control description. Review effectiveness at defined intervals. Workflow Access Request Submission Manager Approval Business Role Owner Approval SoD Analysis (ARA) SAP Security Provisioning User Notification Periodic Access Review Audit and Compliance Reporting Future Architecture Future Architecture Overview The future SAP authorization architecture shall support hybrid and cloud-based identity services while maintaining centralized governance, standardized role management, and regulatory compliance across all SAP platforms. SAP Fiori SAP Fiori authorization shall be based on Business Roles, Business Catalogs, Spaces, and Pages. Role design shall align with enterprise business functions and reuse existing authorization concepts where possible. Business Role driven design. Reuse of Business Catalogs. Standardized Fiori launchpad content. Central governance of Fiori roles. SAP Business Technology Platform (BTP) SAP BTP shall extend SAP S/4HANA capabilities while leveraging centralized identity and authorization services. Access to BTP applications shall follow the same governance model as core SAP applications. SAP Identity Authentication Service (IAS) SAP IAS shall provide centralized authentication, Single Sign-On (SSO), and Multi-Factor Authentication (MFA) for SAP cloud solutions. Single Sign-On (SSO). Multi-Factor Authentication (MFA). Corporate identity integration. SAP Identity Provisioning Service (IPS) SAP IPS shall automate user provisioning and deprovisioning between identity providers and SAP cloud applications, reducing manual administration and improving lifecycle governance. Microsoft Entra ID Integration Microsoft Entra ID shall serve as the enterprise identity provider where applicable, providing federation, lifecycle integration, conditional access, and centralized authentication. Identity Federation Identity Federation shall establish trusted authentication relationships between enterprise identity providers and SAP platforms to provide a seamless user experience while maintaining centralized security controls. AI Readiness The future authorization architecture shall support AI-assisted governance capabilities, including access analytics, anomaly detection, role mining, and intelligent access recommendations, subject to organizational approval and governance. Role mining. Access analytics. Anomaly detection. Risk prediction. Intelligent access recommendations. Appendix System Dictionary Reference list of SAP systems, landscapes, environments, and system identifiers used throughout the authorization framework. Line of Business (LOB) Dictionary Defines supported Lines of Business and their mapping to SAP modules and business processes. Country Dictionary Lists country codes, regional deployment scope, and organizational assignment standards. Module Dictionary Reference of SAP modules including FI, CO, MM, SD, PP, PM, QM, PS, EWM, TM, GRC, MDG, BW, BTP and Fiori. Identifier Dictionary Defines enterprise identifiers such as Company Code, Plant, Sales Organization, Purchasing Organization, Storage Location, Profit Center, Cost Center and Controlling Area. Function Dictionary Defines standard business functions and corresponding authorization responsibilities. Organization Dictionary Reference of organizational elements used as authorization organizational levels. Business Role Catalog Master inventory of approved Business Roles including role ID, owner, description, status, version and effective date. Composite Role Catalog Catalog of Composite Roles and associated Single Roles. Master Single Role Catalog Repository of Master Roles used as templates for Derived Roles. Derived Single Role Catalog Repository of organizationally restricted Derived Roles. Business Role Matrix Matrix mapping Business Roles to Composite Roles, Single Roles and business functions.Companion Documents SAP Authorization Naming Convention Standard SAP Role Development Standard SAP Authorization Role Catalog SAP User Access Management SOP SAP Emergency Access SOP SAP GRC Rulebook