Security risk: Users able to see data from other companies

Security risk: Users able to see data from other companies

We are using SAP 4.6c on a single instance. We have one controlling area with multiple companies. We have a problem where a user in one company can have access to the data of other companies. This problem presents itself in FI, CO and MM. We want to resolve the issues by adding authorization controls, but have failed. Is there any solution that you can recommend to solve the issue?

    Requires Free Membership to View

    When you register, you will start receiving targeted emails from my award-winning team of editorial writers. Our goal is to keep you informed on the hottest topics and biggest challenges faced by SAP professionals today.

    Hannah Smalltree, Editorial Director

    By submitting your registration information to SearchSAP.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSAP.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

By design CO is controlled by Controlling Area for almost all processing actions. You can control the display and some activities around reporting, budget planning and master data maintenance using the cost center hierarchy. If this hierarchy mirrors your company code structure it may serve your purposes. MM controls are based on plants, purchasing organizations and purchasing groups. Plants are typically set up for one company code so adding all the plants for one company to a user's role may mirror your company code security. FI organizational security is based on company code.

This was first published in June 2008