The native SAP authorization model is complex, with its own particularities and pitfalls. SAP's native transaction objects can combine to allow access in unforeseen ways, and SAP wildcards in SAP authorization objects are a powerful but often insecure feature.
IDEAS Access Risk Controls for SAP includes specific controls the check the use of these SAP features and scans for unintended access and security consequences. Compliance managers can define policies for secure SAP role design and these are enforced by Access Risk Controls for SAP.
Compliance Controls for SAP leverages IDEAS' native activity-based SoD model, SoD domains, what-if analysis, and integrated access risk remediation, bringing all the advantages of IDEAS access governance to SAP applications.