Authorization_Check.xlsx
Analysis AU_AuthAssurance
The following Sheets are important:
- Conflicts
- All_IDs
- My_IDs
- User_AllowList
- Simulation
Analysis DetectiveAuthAssurance
The following Tabs are important:
- Conflicts_detective
- Activities
Conflicts
- Sheet is based on All_IDs and My_IDs
- Conflict -> a single authorization or a authorization-group of All_IDs or My_IDs is critical
- Only IDs that are listed in the Conflicts Sheet are included in the result
All_IDs
- Sheet lists all authorizations that have been defined in dab AnalyticSuite
- Only the authorizations listed in the Conflicts are taken into account
My_IDs
- Customer-specific authorizations can be defined
- For each authorization -> Required authorization objects and fields as well as the values must be defined
User_AllowList
- Users identified in the analysis run can be excluded
- A User can be excluded from one or more conflicts
- Alternatively, a User can be classified instead of excluded
- Furthermore, certain user types (e.g. Batch user) can be excluded
- A few examples are included in the Sheet for your reference
Simulation
- Simulate whether the user would appear if they had a certain authorization role
- Possibility to check whether the user would have an authorization conflict before assigning a role to a user
Conflicts_detective
- Sheet is used in the AU_DetectiveAuthAssurance analysis
- Selects all activities from the AU_P2P_Eventlog that contain the listed conflicts
- Conflict means that a group of activities is critical
Activities
- Sheet assigns numbers to the activities from AU_P2P_Eventlog
- The numbers are to be used for Conflicts_detective