Symptom
Business users with the role are able to view individual customer despite access restrictions being configured to limit read and write access.
Environment
SAP Cloud for Customer
Reproducing the Issue
- Log in with the user which the restriction rule is being configured to limit read and write access
- Navigate to the individual customer section and search for ID
- Observe that the user is able to view this individual customer despite the configured access restrictions.
Cause
If an individual customer has a 1015 (00000000000000000000000000000000) ACL entry and the business partner (in this case is the individual customer) has two role: Customer and Contact Person ,every user (independent how the restrictions are tailored) has access to the individual customer + contact person.
Resolution
- Navigate to the Data Protection and Privacy work center.
- Select the "Personal Data Removal" option.
- Query all business partners and locate customer ID.
- Identify the contact person role associated with the customer ID.
- Remove the contact person role if it is not required.
- Save the changes and verify whether the access restriction is now functioning as expected.
Keywords
access restriction, individual customer, business role, homeless, ACL entry, contact person role, restriction rule, Account, unrestricted access, Data Protection and Privacy work center, personal data removal. Account, Business partner. , KBA , LOD-CRM-ACC-PRI , Private Account (Customers) , LOD-CRM-ACC , Account , Problem
SAP Knowledge Base Article - Public