Scope filters for Authorizations Insight for SAP

Authorizations Insight for SAP allows you to select the following filters to define your analysis scope:

  • Exclusions

    The option Analyze all data will analyze all objects, including objects excluded from rules. If you do not want excluded violating objects to be analyzed,  select the option Do not analyze excluded data .

  • Analysis Filter

    Select either users or roles to be analyzed or select the All option to analyze both users and roles.

  • Locked/Unlocked Users

    Select the option Analyze locked users if you want locked users included in your analysis. If you are scheduling an Incremental Analysis, it is recommended that you select the option Analyze locked users.

  • Valid Expired Users

    Select the option Analyze expired users if you want your analysis to include expired users. If you are scheduling an Incremental Analysis, it is recommended that you select the option Analyze expired users.

  • Expired User-Role Assignments

    Select the option Analyze expired user-role assignments if these assignments are to be included in your analysis.

  • Future User-Role Assignments

    Select the option Analyze future user-role assignments if future role assignments are to be considered in your analysis.

Note:  You can set limits for role violations and user violations through Analysis Settings. When this limit is reached during analysis, no more violations will be generated.

Scenarios in case of different time zones

After scoping the data using these filters, the actual data that is analyzed may vary if ERP server and the Infor Risk & Compliance application server are in different time zones.

For example, consider that the Infor Risk & Compliance application server is in India and ERP server is in US. In such cases the following scenarios may occur:
  • Users or user-role assignments valid in ERP may not participate in the analysis
  • Users or user-role assignments expired in ERP may undergo an analysis.

Consider a user is assigned a role in the ERP and the role assignment expiry date is 12th June 2012. Perform an analysis on 13th June 8.00 am IST (which is 12th June 10.30 PM EST).

As per the application server time zone, the user-role assignment is expired and will not be participate in the analysis (unless explicitly selected the scoping filter to analyze expired assignments), whereas the user-role assignment is actually valid in ERP.