SAP Knowledge Base Article - Public

2088807 - Restrict Users to Proxy in as Super Users in RBP - BizX Platform

Symptom

    Restrict users from proxying other users in terms of Admin rights.

    Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental.

    Environment

    SuccessFactors BizX Platform

    Resolution

    1. Make sure you remove each of the users from the role to which proxy permissions have been granted:
      1. For example: Role "RoleTEST" has proxy permissions granted
      2. Group "GroupTEST" has this role (RoleTEST) associated with it and UserTEST belongs to GroupTEST"
      3. Then you need to either remove UserTEST from the group GroupTEST and/or remove proxy permissions from the role RoleTEST.
    2. Create a role "SuccessFactors Admin 2ndary", give the permissions as follows:
      1. Proxy management and any other permission as desired
      2. Also "Proxy" permissions only to view – Please see below the screenshot

    1.png

    1.  Create two groups following these steps:
      1. The group should include only secondary administrators (who should not be able to proxy in as super admins)
      2. Assign the role we created to the group above​
      3. Create another group “all except admin”, make sure in the Group Members people pool you include everyone. But in the people pool to exclude, make sure you add the super admins as shown below:

    4.png

    1. Assign the same role (SuccessFactors Admin 2ndary) to this group as well:

    5.png

    1. Setting target population to the role "SuccessFactors Admin 2ndary" as follows:

    6.png

     

    7.png

    Keywords

    proxy, restrict, user, super, admin , KBA , sf admin tools , sf how to , sf rbo , sf user , sf restrict , LOD-SF-PLT-PRX , Proxy , How To

    Product

    SAP SuccessFactors HCM Core all versions