8.1 Explaining Security Flashcards
(27 cards)
SAC provides basic user mgmt, which lets you do 3 thins with role assignment
- create
- delete
- change
what user management and authentication mechanism does SAC use
SAP Cloud Identity Management
What is another way to import user data for security
CSV file
importing users from an active directory server is supported (TF)
false
what 3 fields are required for security
User ID
Last Name
Email
what is the role of a Manager of a user
to approve the users requests for self-service role
can user ID be changed once it’s created
no
what is used to link a SAML identity in an external SAML ID provider
X509 user mapping
what are the pre-delivered standard application roles (12)
- system owner
- admin
- modeler
- planner/reporter
- viewer
- BI admin
- BI content creator
- BI content viewer
- SAP BTP Content Creator
- SAP BTP Content Viewer
- Boardroom creator
- Boardroom viewer
What privileges does a System Owner have
- full privileges
- only 1 user can be assigned this role
What privileges does a Admin have
- full privileges
- can access all functions
- has data read access
What privileges does a Modeler have
- modeling privileges
- full access to all models and dims
What privileges does a Planner/Reporter have
- planning and reporting
- data access granted seperately
What privileges does a Viewer have
- planning read only
- no privileges to change anything
What privileges does a BI admin have
- full privileges
- can access all functions
- has data read access
What privileges does a BI content creator have
- content creator
- create BI content and models
What privileges does a BI content viewer have
- bi read only
no privileges to change anything
What privileges does a SAP BTP Content Creator have
- access SAP BTP as a datasource
What privileges does a SAP BTP Content Viewer have
- view BTP content
What privileges does a Boardroom Creator have
- can create boardrooms
What privileges does a Boardroom viewer have
- view all boardrooms
Describe the team concept
- a team is a group of users
- a user can belong to multiple teams
- a role can be assigned to a team, and all users in the team inherit the role
Describe the workflow for assigning privileges to users (4)
> create users
create teams
create roles
assign the roles/users to teams
how do you indirectly assign a role to a user
- assign user to team A
2. assign role to team A