https://raw.githubusercontent.com/ajmaradiaga/feeds/main/scmt/topics/Security-qa.xmlSAP Community - Security2025-05-15T08:01:38.489271+00:00python-feedgenSecurity Q&A in SAP Communityhttps://community.sap.com/t5/enterprise-resource-planning-q-a/how-to-check-when-the-last-execution-of-a-transaction-took-place/qaq-p/14036668How to check when the last execution of a transaction took place2025-03-07T10:20:00.757000+01:00SAPSupporthttps://community.sap.com/t5/user/viewprofilepage/user-id/121003<P>There is a need to know how to find the last execution of a specific transaction code in the system.</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B>2025-03-07T10:20:00.757000+01:00https://community.sap.com/t5/technology-q-a/security-vulnerability-in-sap-crystal-reports-for-eclipse-java-sp31-cve/qaq-p/14037138Security Vulnerability in SAP Crystal Reports for Eclipse (JAVA) SP31 - CVE-2024-217422025-03-07T17:40:42.576000+01:00neilpayne-1https://community.sap.com/t5/user/viewprofilepage/user-id/1196220<P>Hello</P><P>Regarding Crystal report for eclipse (java) - SP31;</P><P>Looks like there is vulnerability <STRONG>CVE-2024-21742</STRONG> in file:</P><P><STRONG>lib/xmlconnector.jar/lib/apache-mime4j-core-0.8.9.jar</STRONG></P><P>version 0.8.10 and beyond does not have this vulnerability:<BR /><A href="https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-core" target="_blank" rel="nofollow noopener noreferrer">https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-core</A><BR /><BR />CVE details:<BR />Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages.</P><P>Can someone confirm if this is effected by this CVE, and if so can this be a hotfix or new service pack?</P><P>Thank you!</P>2025-03-07T17:40:42.576000+01:00https://community.sap.com/t5/technology-q-a/is-there-a-way-to-compare-multiple-roles-between-systems/qaq-p/14046926Is there a way to compare multiple Roles Between Systems?2025-03-17T11:24:49.019000+01:00Stavros_Myhttps://community.sap.com/t5/user/viewprofilepage/user-id/1704372<P>I am trying to find if the roles in our Development client are consistent with the Production client.</P><P>If I use the comparison tool found in SUIM (tcode: S_BCE_68001777) I can only select one role at a time. </P><P>I tried to create an ECATT script by I cannot bypass the log in to production step required by the transaction</P><P>Any ideas?</P>2025-03-17T11:24:49.019000+01:00https://community.sap.com/t5/technology-q-a/mass-maintenance-of-pfcg-role-menus/qaq-p/14048138Mass maintenance of PFCG role menus2025-03-18T09:14:23.388000+01:00dexner44https://community.sap.com/t5/user/viewprofilepage/user-id/861559<P>Hello all,</P><P>I want to delete transactions out of role menus via a mass maintenance. The known PFCGMASSVAL seems to be suitable only for authorization data, and not for entries in the role menu.</P><P>Does anyone have an idea if it is possible to do a mass maintenance of PFCG role menu entries?</P><P> </P><P>Thanks in advance and best regards</P><P>Daniel</P>2025-03-18T09:14:23.388000+01:00https://community.sap.com/t5/enterprise-resource-planning-q-a/how-to-connect-to-gcp-storage-bucket-provided-with-handover-files-to/qaq-p/14056319How to connect to GCP Storage Bucket provided with Handover files to transfer Backup to SAP Rise2025-03-25T19:13:17.684000+01:00marcusbragahttps://community.sap.com/t5/user/viewprofilepage/user-id/5892<P><STRONG>How to connect to GCP Storage Bucket provided by SAP with Handover files to transfer Backup to SAP Rise</STRONG></P><P>The purpose of this blog is to demonstrate how to connect to the GCP Bucket with the credentials provided by SAP via sharepoint through the files Handover "<sid><prefix-customer>_BROWNFIELD_CREDENTIALS.docx".</P><P>In this demonstration we will use an operating system SUSE Linux Enterprise Server 15 SP5.</P><P> </P><P><STRONG>Example of a file "<sid><prefix-customer>_BROWNFIELD_CREDENTIALS.docx".</STRONG></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="marcusbraga_0-1742913667481.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/242248iE9338D9EF6B60787/image-size/medium?v=v2&px=400" role="button" title="marcusbraga_0-1742913667481.png" alt="marcusbraga_0-1742913667481.png" /></span></P><P> </P><P><STRONG>Creating the .JSON file</STRONG></P><P>Start by creating a .JSON file with the information contained in the file "_BROWNFIELD_CREDENTIALS.docx"</P><P>Copy the contents of the "<STRONG>JSON File Details</STRONG>" contained within the characters<STRONG> { }</STRONG>.</P><P>Example:</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="marcusbraga_1-1742914711062.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/242256iA56ACC0C1CD409D3/image-size/medium?v=v2&px=400" role="button" title="marcusbraga_1-1742914711062.png" alt="marcusbraga_1-1742914711062.png" /></span></P><P>Paste into a notepad and save with the extension .json</P><P>Example:</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="marcusbraga_2-1742915154747.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/242267iBEB49A14FEC56082/image-size/medium?v=v2&px=400" role="button" title="marcusbraga_2-1742915154747.png" alt="marcusbraga_2-1742915154747.png" /></span></P><P> </P><P>Create a directory on the operating system from where you will transfer the backup and save the generated .json file. You can use the same directory for the next download and installation activities of the gsutil tool that will use this .json.</P><P> </P><P><STRONG>Installing of GSUTIL</STRONG></P><P>Use this official documentation: <A href="https://cloud.google.com/storage/docs/gsutil_install?hl=pt-br#linux" target="_blank" rel="noopener nofollow noreferrer">https://cloud.google.com/storage/docs/gsutil_install?hl=pt-br#linux</A></P><P>Switch to the folder you created in the previous step with the command "cd".</P><P>Download: </P><PRE>curl -O https://dl.google.com/dl/cloudsdk/channels/rapid/downloads/<SPAN class="">google-cloud-cli-linux-x86_64.tar.gz</SPAN></PRE><P>Extract:</P><PRE>tar -xf <SPAN class="">google-cloud-cli-linux-x86_64.tar.gz</SPAN></PRE><P>Installing:</P><PRE>./google-cloud-sdk/install.sh</PRE><P>You can use the default options during installation, in my case it was like this:</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="marcusbraga_4-1742916533702.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/242287iEC27FF5D5F0F35C6/image-size/medium?v=v2&px=400" role="button" title="marcusbraga_4-1742916533702.png" alt="marcusbraga_4-1742916533702.png" /></span></P><P>Log out and start a new session for the changes to take effect.</P><P> </P><P><STRONG>Register with the account contained in the .json</STRONG></P><P>Use the command below changing it to the path of your .json file, you will have a result similar to the image.</P><P>gcloud auth activate-service-account --key-file=/gsutil/gcp-key1.json</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="marcusbraga_6-1742922543436.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/242302i3CFF4BBC621DFA89/image-size/medium?v=v2&px=400" role="button" title="marcusbraga_6-1742922543436.png" alt="marcusbraga_6-1742922543436.png" /></span></P><P> </P><P><STRONG>Validate access to GCP Storage Bucket</STRONG></P><P>Use the ls command to list the directories on your account.</P><P>Examples:</P><P>gsutil ls gs://sahecXXXtransferXXX01/</P><P>After the first copy just adjust the path to list sub directories</P><P>gsutil ls gs://sahecXXXtransferXXX01/HD4-21032025</P><P> </P><P>In my case, I did not identify the account name, I had to ask the Project Lead because this information was not included in the brownfield file.</P><P>The list of bucket names should be returned with the command</P><PRE>gcloud<SPAN class=""><SPAN> </SPAN></SPAN>storage<SPAN class=""><SPAN> </SPAN></SPAN>ls<SPAN class=""><SPAN> </SPAN></SPAN><SPAN class="">--project</SPAN><SPAN class="">=</SPAN>my-project</PRE><P>In the example below, I am listing the remote directory with a backup copy that I made.</P><P>Next, I will pass the command to execute a copy.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="marcusbraga_7-1742922985190.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/242304i23A3170878563A7D/image-size/medium?v=v2&px=400" role="button" title="marcusbraga_7-1742922985190.png" alt="marcusbraga_7-1742922985190.png" /></span></P><P> </P><P><STRONG>Copying your backup to GCP Bucket Storage</STRONG></P><P>Run the command "gsutil -m cp -r SOURCE gs://TARGET/"</P><P>Example:</P><P>gsutil -m cp -r SOURCE-FOLDER-OF-YOUR-BACKUP gs://saheXXXtransferXX01/</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="marcusbraga_8-1742923951889.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/242306i2EEE52BD1244C3BE/image-size/medium?v=v2&px=400" role="button" title="marcusbraga_8-1742923951889.png" alt="marcusbraga_8-1742923951889.png" /></span></P><P>After the copy is complete, you can list the files again with the command:</P><P>gsutil ls gs://sahecXXXtransferXXX01/HD4-21032025/</P><P>The -m parameter is used to copy files in parallel,<BR />more details about advanced parameters can be found at this official link: <A href="https://cloud.google.com/sdk/gcloud/reference/storage/cp" target="_blank" rel="noopener nofollow noreferrer">https://cloud.google.com/sdk/gcloud/reference/storage/cp</A></P><P>In the example above, the 237GB copy took 2 hours, the speed will depend on the upload speed of your internet connection.</P><P>In the same example, I performed a HANA backup with a 20GB Split. This helps in case of a very large file failure so that you don't have to reprocess everything from the beginning.</P><P> </P><P> </P><P>After finishing, you just need to request a copy of the GCP Bucket backup to the /Migration directory, which is probably mounted on your Skeleton system database server. To do this, open the Service Request with the "Download Data from Cloud to Block Storage" template, providing details of the source and destination such as SID, hostname, IP, source and destination path.</P><P> </P><P> </P>2025-03-25T19:13:17.684000+01:00https://community.sap.com/t5/technology-q-a/last-logon-date-not-updated-in-sap-in-usr02-table/qaq-p/14058386Last Logon date not updated in SAP in USR02 table.2025-03-27T09:09:40.153000+01:00SAPSupporthttps://community.sap.com/t5/user/viewprofilepage/user-id/121003<P>Hi SAP,</P><P>we have encountered an Audit issue where user when login in from SAPGUI, users login is getting recorded properly in USR02 table. <BR />But when users are login in from Fiori or salesfore, etc. the login Records are not updating in table, though the users are having same SAP id.</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B>2025-03-27T09:09:40.153000+01:00https://community.sap.com/t5/technology-q-a/remove-authorization-value-from-multiple-authorization-objects/qaq-p/14060009Remove authorization value from multiple Authorization objects2025-03-28T12:17:20.548000+01:00SAPSupporthttps://community.sap.com/t5/user/viewprofilepage/user-id/121003<P>Dear Team</P><P>we want to remove authorization value i.e. 23 from multiple "Authorization object" from multiple roles at a time</P><P> </P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B>2025-03-28T12:17:20.548000+01:00https://community.sap.com/t5/technology-q-a/required-guidance-to-expose-rest-api-externally/qaq-p/14060533Required Guidance to Expose REST API Externally2025-03-29T05:07:09.708000+01:00Hemachandiranhttps://community.sap.com/t5/user/viewprofilepage/user-id/1707834<P>Dear SAP Support Team,<BR />We need to create and host two secure APIs in SAP to integrate with Bank for authentication and transaction processing. These APIs will facilitate automated authentication and transaction status updates between SAP and Bank, ensuring seamless, secure, and efficient communication.</P><P><STRONG><U>Business Requirement:</U></STRONG></P><P><STRONG><U>Bank requires two endpoints:</U></STRONG></P><P><STRONG>Authentication API</STRONG> – Bank will send an authentication request to SAP, which should validate the credentials and return an authentication token. This token will then be used for further API interactions, eliminating the need for manual username/password entry.</P><P><STRONG>Late Return Payment Status API</STRONG> – Bank will send encrypted status updates for late return payments via HTTPS. SAP must decrypt the request, validate the data, update the transaction status, and send a response.</P><P>These APIs must be externally accessible, enforce strong security mechanisms, and comply with banking and SAP security standards.</P><P><STRONG><U>Technical Requirements:</U></STRONG></P><P><STRONG>Authentication Mechanism:</STRONG> The API should support automatic authentication and prevent unauthorized access. SBI should be able to call the authentication URL securely without requiring manual login like API URL.</P><P><STRONG>Encryption & Security:</STRONG> Data should be encrypted in transit and at rest. Authentication and late return status updates should be processed securely using encryption, signature verification, and request integrity validation.</P><P><STRONG>External Hosting Considerations:</STRONG> The URLs must be accessible externally with proper security controls.</P><P><STRONG>Token Management:</STRONG> The authentication API should generate a secure token that SBI can use for further API requests to SAP.</P><P><STRONG>Logging & Monitoring:</STRONG> All incoming API requests should be logged for audit purposes, and SAP should monitor API activity to detect anomalies.</P><P><STRONG>Authentication API Flow:</STRONG></P><P>BANK→ [HTTPS Request] → SAP (Authentication URL)</P><P>SAP → [Validate Credentials] → Internal Authentication Logic</P><P>SAP → [Generate Auth Token] → Internal Token Storage</P><P>SAP → [HTTPS Response with Token] →BANK</P><P>BANK → [Use Token for API Calls] → SAP Transactions</P><P><STRONG>Late Return Payment Status API Flow:</STRONG></P><P>BANK→ [HTTPS Request with Encrypted Data] → SAP (Late Return API URL)</P><P>SAP → [Decrypt Request] → Internal Processing</P><P>SAP → [Validate & Update Payment Status] → SAP Database</P><P>SAP → [HTTPS Response: Status Updated] →BANK</P><P>We need to securely expose two REST-based APIs in SAP for integration with SBI Bank using JSON over HTTPS. These APIs will handle authentication and transaction status updates.</P><OL><LI>Authentication API – Bank calls this API for authentication, and SAP responds with an authentication token.</LI></OL><OL><LI>Late Return Status API – Bank calls this API with encrypted late return payment status updates, which SAP decrypts, processes, and acknowledges.</LI></OL><P>Technical Details:</P><P>Data Format: JSON</P><P>Protocol: REST (HTTPS)</P><P>Authentication: Client certificate authentication (mutual TLS) and token-based authentication</P><P>Security: TLS 1.2/1.3, digital signature verification, IP whitelisting</P><P>SSL Certificate: Signed by a trusted CA (not self-signed)</P><P>Hosting: SAP should securely expose the APIs externally for Bank access</P><P><STRONG>Request for Support:</STRONG></P><P>1.What are the recommended SAP-supported approaches for hosting secure REST-based APIs?</P><P>2.Which SAP authentication mechanisms align best with mutual TLS and token-based authentication?</P><P>3.What SAP components and configurations are recommended for secure REST API exposure?</P><P>Looking forward to your expert guidance.</P>2025-03-29T05:07:09.708000+01:00https://community.sap.com/t5/technology-q-a/duplicate-role-deletion-from-users/qaq-p/14062273Duplicate role deletion from Users.2025-03-31T17:43:12.856000+02:00SAPSupporthttps://community.sap.com/t5/user/viewprofilepage/user-id/121003<P>Dear Expert,</P><P>we have GRC System with our Production (SSP) system. as per the requirement users are aplly role from GRC System, but some most of the roles are duplicate in the system, is there any way to delete duplicate roles from the user automatically, there should be condition if the same roles are there if one roles are expired, can be delete, i.e. duplicate role need to verify and then delete old one, which is expired. if validity period of this role is expired, then role should be deleted.</P><P>please guide us can we do this on monthly basis from any background job which will be automated in GRC or in the system.</P><P>Thanks</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B>2025-03-31T17:43:12.856000+02:00https://community.sap.com/t5/financial-management-q-a/restrict-the-quot-release-quot-and-quot-pay-quot-button-in-the-app-quot/qaq-p/14063986Restrict the "Release" and "Pay" button in the App "Make Bank transfers"2025-04-02T11:42:30.132000+02:00Inchara_BKhttps://community.sap.com/t5/user/viewprofilepage/user-id/1827014<P>Hi All,</P><P>I need to Restrict the "Release" and "Pay" button in the App "Make Bank transfers" in S/4 Hana Public cloud system. I don't see the restriction type related to this in the catalog.</P><P>Please advise me on the possible solution for this.</P><P>Regards,</P><P>Inchara BK</P>2025-04-02T11:42:30.132000+02:00https://community.sap.com/t5/enterprise-resource-planning-q-a/inactive-objects-to-be-maintained-from-su24-without-deleting-within-the/qaq-p/14064936Inactive Objects to be maintained from SU24 without deleting within the role2025-04-03T09:26:56.836000+02:00ChethanBShttps://community.sap.com/t5/user/viewprofilepage/user-id/1497676<P>Dear All,</P><P>We are facing a condition were we need to remove Inactive objects within the role. You can suggest us to delete or maintain it from SU24 with check indicator "NO". But either of the case is not acceptable and wanted to find if there is any new way for this. </P><P>For more clarification: We maintain an object S_SECPOL for SU01 in SU24 for Security team and added in Role1. But the same object might not be necessary for Basis (in rare Basis user maintenance access) and added in Role 2 with S_SECPOL inactive. </P><P>In this case for Role 2 we are not supposed to inactive S_SECPOL object either we cannot maintain check no for same transaction SU01 in SU24 as it might effect Role 1.</P><P>If there is any alternate, please suggest me.</P><P><a href="https://community.sap.com/t5/c-khhcw49343/Security/pd-p/49511061904067247446167091106425" class="lia-product-mention" data-product="1143-1">Security</a> </P>2025-04-03T09:26:56.836000+02:00https://community.sap.com/t5/technology-q-a/in-ias-if-user-is-non-admin-then-he-is-not-able-to-see-the-privacy-policy/qaq-p/14065347In IAS, if user is non-admin then he is not able to see the Privacy Policy document or Terms of use2025-04-03T12:58:03.404000+02:00bhaskarnahttps://community.sap.com/t5/user/viewprofilepage/user-id/687982<DIV class=""><DIV class=""><DIV class=""> </DIV><SPAN>In IAS, once a user (non-admin - usertype='employee') accept the consent, he is not able view it in IAS console., If IAS doesn't allow non-admin to view it in IAS console then is there a way(URL/api) thru which BTP application can pull this content from IAS and show it?</SPAN></DIV></DIV><DIV class=""><DIV class=""><P>if we still want to let tenant users to revoke the accepted consent the only option with IAS is to load a new version so that, all users start seeing it and either accept/deny. It is sounding complex!!! </P><P><STRONG>SAP IAS is handling authentication and consent management today</STRONG>, but it does<SPAN> </SPAN><STRONG>not expose APIs for users to view or revoke consent</STRONG>, switching to<SPAN> </SPAN><STRONG>SAP Enterprise Consent and Preference Management (ECPM)</STRONG><SPAN> </SPAN>means we will need to<SPAN> </SPAN><STRONG>manually enforce consent collection</STRONG><SPAN> </SPAN>within your BTP application.</P><H3 id="toc-hId-1836501961">what is the overall guideline?</H3></DIV></DIV>2025-04-03T12:58:03.404000+02:00https://community.sap.com/t5/enterprise-resource-planning-q-a/doubts-with-table-usr40/qaq-p/14067397doubts with table USR402025-04-06T00:35:27.832000+02:00samuel2023https://community.sap.com/t5/user/viewprofilepage/user-id/861366<P>Greetings, dear friends<BR />I have a question: If wildcards are added to the USR40 table, would they directly impact existing users in the system? For example,<BR />if an existing user has a password with the newly added wildcards, would they be forced to change their password?<BR />Thank you.</P>2025-04-06T00:35:27.832000+02:00https://community.sap.com/t5/technology-q-a/hi-all-quot-error-quot-quot-ias-authentication-is-not-ias-it-is-xsuaa/qaq-p/14068052Hi all "error": "IAS authentication is not 'ias'. It is: xsuaa. implementing the Build apps.2025-04-07T09:31:10.096000+02:00tirumalahttps://community.sap.com/t5/user/viewprofilepage/user-id/1413048<P>Hi all </P><P>I am developing an sap build app mobile application. I had done all the <SPAN class="">Instances and Subscriptions to my project. when I go to sap build lobby and to open the project, getting error that </SPAN></P><PRE><STRONG> "error": "IAS authentication is not 'ias'. It is: xsuaa.</STRONG></PRE><P>in btp cockpit security->users-> i found custom IAS tenent and checked all are ok but still getting the same error can any one help me to out.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tirumala_0-1744010787151.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/247520iDCA31C4325434BB5/image-size/medium?v=v2&px=400" role="button" title="tirumala_0-1744010787151.png" alt="tirumala_0-1744010787151.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tirumala_1-1744010920265.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/247521iA6A9DE222036BF56/image-size/medium?v=v2&px=400" role="button" title="tirumala_1-1744010920265.png" alt="tirumala_1-1744010920265.png" /></span></P><P> </P><P> </P>2025-04-07T09:31:10.096000+02:00https://community.sap.com/t5/technology-q-a/how-to-find-where-odata-service-is-coming-from-in-the-catalog/qaq-p/14068340How to find where OData service is coming from in the catalog.2025-04-07T13:15:03.150000+02:00MichaelHealy779https://community.sap.com/t5/user/viewprofilepage/user-id/175376<P>Hi, <BR /><BR />I have an OData service called R3TR IWSV UI_JOURNALENTRY_OTA_O2 0001 which I can see is being pulled into a catalog that I have built for display purposes, so no change access is permitted. This Odata is bringing in 01/02 access for F_MANDATE but the issue is I cannot find which App is bringing this into the catalog, as this needs to be removed or changed in SU24....but I cannot seem to figure out how to actually find where its originating from. I have checked the catalog for clues on the "Action" but all of the actions are listed as "Display". There are too many apps to start removing 1 by 1 to see which app is populated the S_SERVICE value. <BR /><BR />Can someone provide some way of finding this? I have tried to check a way of mapping the application resource to S_SERVICE but sadly I came up empty. </P>2025-04-07T13:15:03.150000+02:00https://community.sap.com/t5/technology-q-a/issue-with-ga-sap-s-4hana-users-not-visible/qaq-p/14069148Issue with GA SAP S/4HANA - Users Not Visible2025-04-08T09:13:28.146000+02:00Feras_https://community.sap.com/t5/user/viewprofilepage/user-id/1418073<P>Dear SAP community,</P><P>i have recieved an answer of a ticket: </P><P><EM>"To check developers, you need to install SAP Note 3333812 in your development environment and execute that report."</EM></P><P>This was helpful, but I can only see 4 developers listed, whereas the SAP measurements show that we have 9 developer licenses in the system.</P><P>Could you please clarify this discrepancy?<BR />Additionally, could you provide more detailed guidance on how to identify the other users holding developer licenses?</P><P>Thanks in advanced </P><P>Best regards, </P><P>Feras </P>2025-04-08T09:13:28.146000+02:00https://community.sap.com/t5/technology-q-a/deploy-idm-component-on-po-system/qaq-p/14073408Deploy IDM component on PO system2025-04-11T12:02:07.311000+02:00SAPSupporthttps://community.sap.com/t5/user/viewprofilepage/user-id/121003<P>Dear SAP,<BR /><BR />Do we need license to deploy IDM component on PO (Process Orchestration) system? We have PO license.<BR /><BR />Regards<BR /><BR /></P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B>2025-04-11T12:02:07.311000+02:00https://community.sap.com/t5/technology-q-a/how-to-bypass-the-saml2-idp-selection-screen-for-sap-netweaver-abap/qaq-p/14075573How to bypass the SAML2 IdP selection screen for SAP NetWeaver ABAP2025-04-14T16:20:34.793000+02:00SAPSupporthttps://community.sap.com/t5/user/viewprofilepage/user-id/121003<P>Hi,</P><P>Is it possible to bypass the SAML IDP selection page? </P><P>How do you ensure the SAML2 IDP is automatically selected? </P><P>Thanks and Best Regards.</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B>2025-04-14T16:20:34.793000+02:00https://community.sap.com/t5/technology-q-a/tool-to-secure-hana-instances-as-per-sap-checklists/qaq-p/14089500Tool to secure HANA instances as per SAP checklists2025-04-29T14:56:26.367000+02:00VincentBerghttps://community.sap.com/t5/user/viewprofilepage/user-id/2108807<P>Hello, I just wanted to get the word out that there is a free and open-source tool available to help securing HANA instances as per the SAP provided checklists. This should make it a whole lot easier with staying compliant and making sure that your HANA databases are configured as per SAP's recommended advice.</P><P>More information can be found at the introductory blogpost at: <A href="https://www.anvilsecure.com/blog/introducing-hanalyzer.html" target="_blank" rel="nofollow noopener noreferrer">https://www.anvilsecure.com/blog/introducing-hanalyzer.html</A>.</P><P>If this is not the right forum then please accept my apologies and let me know what forum this should be posted in.</P>2025-04-29T14:56:26.367000+02:00https://community.sap.com/t5/technology-q-a/segragation-of-roles-based-on-organizational-values/qaq-p/14096867Segragation of roles based on Organizational values2025-05-09T06:54:20.391000+02:00RafaMarjhttps://community.sap.com/t5/user/viewprofilepage/user-id/2113566<P>Hello!</P><P>How do you analyze/ check on the organizational values/ levels if the two businesses of the client are segragated? Any insights/comments will be much appreciated.</P><P>Thank you.</P>2025-05-09T06:54:20.391000+02:00