Compliance rules that are violated generate rule violations. Rule violation exceptions can be granted or denied.
Compliance rules that are violated generate rule violations. Rule violation exceptions can be granted or denied.
You can display rule violations that you can approve. In doing so, you can additionally display rule violations that already have an approval decision.
To display rule violations
In the menu bar, click Compliance > Rule violations.
This opens the Rule Violations page and displays all the rule violations that are still subject to approval.
(Optional) To control which rule violations are displayed, perform the following actions:
Click (Filter).
In the Filter Data side panel, enable the relevant filter options.
Click Apply filter.
(Optional) To display details of a rule violation, click the appropriate rule violation.
Mitigating controls can be assigned to rule violations to reduce the risk of rule violations.
NOTE: You can assign only mitigating controls that are also assigned to the compliance rules that are violated.
NOTE: You can only assign mitigating controls to a rule violation if your system is configured appropriately. Otherwise, the mitigating controls assigned to the compliance rule are automatically assigned to every other related rule violation.
To assign mitigating controls to a rule violation
In the menu bar, click Compliance > Rule violations.
On the Rule Violations page, click the rule violation to which you want to assign mitigating controls.
In the View Rule Violation Details side panel, click the Mitigating Controls tab.
On the Mitigating Controls tab, click Assign mitigating controls.
In the drop-down, select the mitigating control that you want to assign to the rule violation.
(Optional) To assign other mitigating controls, click (Assign mitigating control).
Click Save.
Identities that have access to certain critical SAP functions, may violate compliance rules and can pose a significant security threat. You can analyze and determine these identities in order to prepare countermeasures.
You can display rule violations of identities that violate compliance rules containing SAP functions. For each identity, you can find out which compliance rule was violated and which SAP function was involved in the rule violation. If a compliance rule with a high rating has been violated by an SAP function with a high rating, you must act immediately.
To display rule violations of identities with critical SAP functions
In the menu bar, click Compliance > Rule violations.
On the Rule Violations page, click (Filter).
In the Filter data side panel, select the Compliance rules containing SAP function instances check box.
Click Apply filter.
This displays all the rule violations of compliance rules containing SAP functions.
(Optional) To determine whether a rule violation was caused by the role or the instance, perform the following:
Click the relevant rule violation.
In the View Rule Violation Details side panel, click the SAP Functions tab.
On the SAP functions tab, in the SAP user account drop-down, select the SAP user account you want to analyze.
Perform one of the following actions:
To display details about rule violations of roles and profiles, click By role
To display details of SAP functions and transactions, click By ability.
TIP: To display the objects grouped by SAP function instance or SAP transaction, click Group and then SAP function instance or SAP transaction.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Termini di utilizzo Privacy Cookie Preference Center