10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (2024)

Administration

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (1)by Raghu Boddu

Emergency access management (EAM) stands out as one of the hero applications within the SAP Access Control suite, widely used for proficiently addressing emergency authorization needs.

This blog delves into the latest enhancements added to EAM with SAP and explores their practical applications.

Before diving into these novel functionalities, it's important to note that many of these features are available in the latest SP levels. Ensure your system is up to date by upgrading to a service pack level exceeding SP14. Notably, certain features are exclusively accessible in the most recent versions like SP23.

New EAM Parameters

Before we start, let’s quickly look at each of the newly added parameters for EAM.


10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (2)

These parameters can be enabled/disabled as per the business requirement. I recommend you go through the latest SAP documentation before implementing or using these parameters. Now let’s move on to looking at the new features in depth!

Dedicated/Single Usage of Firefighter ID

This interesting feature lets companies control which systems and users can have FFIDs assigned to them in dedicated mode. To find out more about how it works, check out my blog post titled "Parameter 4026: Changing How You Use the EAM Application in SAP GRC Access Control" at this link.

Set Ticket Selection to Mandatory in EAM Logon Pad

Parameter 4027, also known as "Set Ticket selection to mandatory in EAM Logon Pad," introduces a valuable enhancement by enabling the ticket selection drop-down and facilitating integration with an external ticket management solution. For detailed implementation instructions, refer to SAP Note 3061274, which outlines the necessary steps for leveraging this enhancement and enhancing the BADI.

Once implemented, parameter 4027 offers the flexibility to enable or disable this feature according to organizational requirements.

When the parameter is configured to "YES," firefighter users will notice a new dropdown menu within the Reason Code section of the Emergency Access Management Launchpad screen. This dropdown allows users to select the relevant ticket number from the integrated ticket management system. The selected data is then stored in a newly created table – GRACFFTICKET – ensuring traceability and auditability for future reference.

Adding Terms & Conditions in EAM Logon Pad

Two new SPRO parameters 4028 & 4029 have been introduced for Terms and Conditions. When maintained/enabled, The EAM Launchpad will have the Terms and Conditions button with a check box “I Accept the Terms and Conditions” that becomes a mandatory field for the user to accept the terms & conditions of the organization.

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (3)

With parameter 4028 (Absolute URL for Terms and Conditions in EAM Logon Pad), you can configure a URL linking to your organization's Terms and Conditions such as data privacy, non-disclosure, etc. Users logging into the FFID within the EAM Launchpad can review and acknowledge these terms. The URL can point to a webpage or a PDF file, opening in a new browser window upon clicking the terms and conditions button. If the parameter is left empty, the button won't appear. While the default value is empty, it's crucial to provide an absolute URL, especially when enabling parameter 4029.

Parameter 4029 (Set acceptance of Terms and Conditions mandatory in EAM Logon Pad) allows you to make acceptance of the terms and conditions mandatory for end users.

Firefighter Log Report Review External Key to Display Value

Until now the Firefighter log report review used to display a preconfigured value in the external key field. This field can now be configured with this enhancement.

To configure the external key to display value per your requirements, set or change SPRO parameter 4030. The SPRO parameter can be any character type value and you can use certain preconfigured variables as below:

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (4)

Here are a couple of examples for a better understanding of the values that can be maintained in parameter 4030:

When the parameter is set to "{$REQNO} -{$FFOBJECT} was used in{$CONNECTOR}” as shown…

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (5)

…then the request number/key will be displayed as shown:

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (6)

Another example for easy and better understanding is if the parameter is set to{$FFUSER_NAME} logged on as{$FFOBJECT} at{$LOGONTIME}”…

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (7)

…the output will be as follows:

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (8)

This parameter simplifies the way the external key is managed and helps a lot during the audit reviews. SAP Note 3331629 details more about this parameter and usage information.

FFID Assignment history

Table GRACFFUSERARC (Archive SPM Firefighter Assignment to FF ID/Roles) stores all FFID and FF Role assignments to users along with the assignment logs. Refer to SAP Notes 3105586, and 3105587.

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (9)

Additionally, you'll find the "Updated By" field, providing insight into whether the assignment was made through a workflow process or directly, which addresses one of the key audit requirements.

GRAC_FFSESSION – Session Reporting

The newly introduced transaction code GRAC_FFSESSION (Report GRAC_FIREFIGHTER_SESSIONS) allows you to view the session reports. This takes over the functionality of report GRAC_EAM_LOG_SYNC_TIMEBASED. Instead of the time-based report, you can now select and recollect the logs of sessions with this report. Refer to SAP Note 3253221, and 3326827.

With this transaction code, administrators can find the login status of the FFID, as shown in this figure:

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (10)

The "Login Status" field serves as a useful indicator to track the status of each request. Moreover, additional fields are available for various reporting purposes, enhancing the system's capability for detailed analysis and reporting.

Risk Analysis for the FFID in Access Request

Thanks to the enhancement introduced in SAP Note 3295064, it's now possible to conduct risk analysis for FFIDs within the access request feature. A new checkbox has been added to the access request form, allowing users to include the associated risks of the FFID. Simply activate the checkbox to enable this functionality during the request process by setting the parameter 1038 (Consider FF Assignments in Risk Analysis) to YES as shown:

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (11)

NOTE: This enhancement is provided by default in GRC 12, Support Package Level 21. In case you are on an older SP level and wish to implement, refer to SAP Note 3295064 to implement manual corrections.

Once the parameter is set to YES, users will see a new check box “Include FFID” in the access request page.

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (12)

It enables users to perform Risk Analysis for FFID and the FFUSER during the creation and approval of Access Requests, showcase the SoD risks associated with both users.

The "Include FFIDs" checkbox is also enabled within the "Access Risk Analysis" work item in the access management tab. It facilitates risk analysis and simulation at user, role, profile, and HR object levels.

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (13)

FF Logon Pad Changes

Previously, the firefighter session was aligned with the user's session using the firefighter ID in the backend system. It commenced upon the user's login with the firefighter ID and concluded upon logout, as detected by specific processes.

However, there's been a change: the firefighter session is now independent of the user's session with the firefighter ID. This means that the firefighter user can initiate multiple consecutive sessions with different firefighter IDs within a single firefighter session.

To commence a firefighter session, the user simply clicks the logon button and concludes it by clicking the new logoff button in the Firefighter Logon Pad. Initially, the reason code screen must be completed, but thereafter, any action can be categorized as additional activity.

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (14)

After the firefighter session is closed, the firefighter IDs will be automatically locked. They will remain in this locked state until a user session is initiated, at which point they will be unlocked and available for use again.

GRAC_SPM_MAINTENANCE

The firefighter session concludes when the user selects the logoff button in the Firefighter Logon Pad. Subsequently, another user can only access the same firefighter ID once the previous user has successfully logged out. To address instances where users may forget to log out, it's advisable to schedule a background job to automatically force a logout of these firefighter sessions. SAP recommends scheduling the report GRAC_SPM_MAINTENANCE to run at regular intervals, with a suggested frequency of every 10 minutes. This proactive approach helps ensure the security and integrity of firefighter sessions within the system.

GRAC_FFID_EXPIRE_REMINDER

The “GRAC_FFID_EXPIRE_REMINDER” program is designed to provide reminders for the firefighter IDs (FFIDs) that are close to expiring. It serves as a proactive measure to alert owners and controllers about FFIDs approaching their expiration date, allowing them to take timely action to renew or extend the validity of these IDs. By running this program, organizations can ensure the continuity of firefighter access while maintaining compliance with security policies and regulations.

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (15)

The period is set to 15 days by default, with the owner option checked. Administrators can customize notifications to be sent to either owners or controllers.

However, the notification will be triggered only when the firefighter “valid from” and “valid to” difference (days) is greater than the given date in the program.

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (16)

Upon executing the program, administrator can see the notifications triggered to the owners/controllers in the Logs.

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (17)

The owner/controller will receive an email on their email ID containing a link that redirects to the maintenance screen of NWBC and the FFIDs can be reviewed and extended as needed.

Conclusion

In conclusion, EAM remains a pivotal application within SAP Access Control, crucial for managing emergency authorization needs effectively. This blog post has explored the latest enhancements introduced in EAM, offering practical insights into their implementation and utilization.

The features detailed in this blog not only streamline operations but also increase security and auditability, empowering organizations to mitigate risks effectively and maintain regulatory compliance.

10 Enhanced EAM Firefighter Features in SAP Access Control 12.0 (2024)

FAQs

What is firefighter access in SAP? ›

In SAP source system we have what we call a firefighter role where we can assign access so that a developer for example could have temporary access to production in order to troubleshoot a problem. All firefighter access has an expiration date and is logged for auditor purposes.

What are the components of GRC Access Control 12? ›

The components of SAP GRC Access Control are:
  • Access Request Management.
  • Role Management.
  • Emergency Access Management.
  • Segregation of Duties (SoD) Analysis.
  • Risk Analysis.
  • Access Violation Management.
  • Compliance Management.
  • Audit Management.

What is new in SAP GRC 12? ›

GRC 12.0 NEW FEATURES FOR AC SOLUTIONS IN BRIEF

Can run risk analysis for FIORI, new FIORI rule set -- Rule set for risk analysis integration with Fiori Apps on S/4HANA On-premise systems. GRC 12.0 now allows to use on Mobile devices as it is SAP Persona based personalisation application.

What is the use of EAM in GRC? ›

SAP GRC EAM is a powerful tool for balancing the need for emergency access with security and compliance requirements. By carefully planning, configuring, and monitoring EAM, organizations can maintain control over sensitive systems while ensuring the ability to respond effectively to critical situations.

What is fire fighting access? ›

fire fighting access level means the highest level that a fire appliance ladder may be brought against a building for purposes of fire fighting and evacuation; Based on 11 documents.

What is a firefighter user type? ›

A Firefighter identity is a special type of user account in an SAP system that provides temporary privileged access to other user accounts. It is used in emergency situations such as a system crash or an urgent issue that needs to be addressed immediately.

What is the difference between GRC 10 and GRC 12? ›

GRC 12: Leverages the power of SAP HANA (in-memory database), leading to faster performance, especially regarding risk analysis and reporting. Compatibility with S/4HANA systems is a crucial advantage. GRC 10.1: Offers some integration capabilities but with a greater focus on on-premise systems.

What are the key activities under SAP GRC access control? ›

SAP GRC Access Control consists of the following modules:
  • Access Risk Analysis (ARA)
  • Emergency Access Management (EAM)
  • Bussiness Role Management (BRM)
  • Access Request Management (ARM)
  • User Access Review (UAR)

What are the 4 key themes of SAP GRC? ›

  • SAP GRC- Focus on the Enterprise Risk and Compliance pillar.
  • SAP GRC- Focus on the Identity and Access Governance pillar.
  • SAP GRC- Focus on the International Trade Management pillar.
  • SAP GRC- Focus on the Cybersecurity, Data Protection and Privacy pillar.

How to configure firefighter in SAP? ›

Configure the Firefighter ID Role Name. You assign this role to user accounts to create Firefighter IDs. In Customizing, open the activity Maintain Configuration Settings, under Governance, Risks, and Compliance Access Control. For parameter 4010, enter the user-defined role name, for example, SAP_GRAC_EAM_FFID.

What does EAM mean in SAP? ›

Enterprise asset management (EAM) incorporates the management and maintenance of physical assets owned by a company throughout the entire lifecycle of an asset, from capital planning, procurement, installation, performance, maintenance, compliance, risk management, through to asset disposal.

How to check firefighter logs in SAP GRC? ›

How to Find the Pending Fire fighter logs that are pending with FF Controller for approval with in particular time frame in GRC 10.
  1. In the system GRC system execute the transaction SE16. ...
  2. In the system GRC system execute the transaction SE16.
Jan 5, 2015

What is emergency access in SAP? ›

Emergency Access Management provides a centralized console in the SAP Access Control system. Through the console, you, as a firefighter can log on to different systems for firefighting. Therefore, you don't have to log on to individual client systems to do a firefighting.

How do I access FFID in SAP? ›

Firefighter login into GRC system or plugin system and using GRAC_EAM or /GRCPI/GRIA_EAM transaction respectively. After SP21 Log Off button is explicitly provided to end the FF session. This helps in recording the exact time of FFID log off.

What is the difference between firefighter owner and controller? ›

The FireFighter ID Owner determines the appropriate assignment for the Firefighter ID. The FireFighter Controller for that FFID is notified when it is used. The FireFighter User actions are logged and reviewed by FireFighter Controller or Delegate when the Firefighter logs out.

How do I assign a firefighter ID in SAP? ›

Configure the Firefighter ID Role Name. You assign this role to user accounts to create Firefighter IDs. In Customizing, open the activity Maintain Configuration Settings, under Governance, Risks, and Compliance Access Control. For parameter 4010, enter the user-defined role name, for example, SAP_GRAC_EAM_FFID.

References

Top Articles
Latest Posts
Article information

Author: Tyson Zemlak

Last Updated:

Views: 6082

Rating: 4.2 / 5 (43 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Tyson Zemlak

Birthday: 1992-03-17

Address: Apt. 662 96191 Quigley Dam, Kubview, MA 42013

Phone: +441678032891

Job: Community-Services Orchestrator

Hobby: Coffee roasting, Calligraphy, Metalworking, Fashion, Vehicle restoration, Shopping, Photography

Introduction: My name is Tyson Zemlak, I am a excited, light, sparkling, super, open, fair, magnificent person who loves writing and wants to share my knowledge and understanding with you.