SAP Knowledge Base Article - Public

2089450 - Users able to proxy in as others (whom they don't have proxy rights for)

Symptom

  • How to restrict proxy permissions for a user?
  • Usernames which do not exist in Account Holder List can be found in the pull-down list when try to do proxy and the proxy can be done successfully.
  • After doing proxy, the account holder’s name will display in Account Holder List

Environment

  • BizX Platform

Resolution

  • If the user has Proxy Management permissions, then by default, the user can proxy as anyone and you won’t be able to restrict or remove certain users.
  • Any domain admin has access to every user in their domain.
  • The user names listed in proxy management page are ones for whom the user has already proxied into.
  • To restrict the target group of users, the admin's target group has to be made smaller.

Keywords

KBA , sf proxy management , sf proxy issues , LOD-SF-PLT , Foundational Capabilities & Tools , How To

Product

SAP SuccessFactors HCM Core all versions