SAP Knowledge Base Article - Public

3753665 - MDF data export includes own data despite RBP exclude-self configured

Symptom

  • MDF Data Export includes records for the exporting user even when Role-Based Permissions (RBP) are configured to exclude self (that is, exclude granted users from having the same access to themselves) for a custom MDF object.
  • There is a requirement to export custom MDF object data without including the exporting user’s own data. However, during export, entries related to the exporting user still appear in the output file.
  • Administrators expect to export secured MDF object data while ensuring that their own records are excluded, but the export file continues to display their data (for example, their user ID in the externalCode field).

 

"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."

Environment

SAP SuccessFactors HCM suite

Reproducing the Issue

  1. Configure a custom MDF object
  2. Assign RBP roles that:  exclude granted users from having same access to themselves
  3. Confirm in the RBP troubleshooting tool that the exporting user is excluded from the target population.
  4. Run an MDF Data Export for the object.
  5. Observe that the exported file still includes records associated with the excluded user (for example, their id appears in externalCode).

    Cause

    By design, MDF Data Export does not enforce record-level permissions unless explicitly enabled. Therefore, exports return all records regardless of RBP target population or exclude-self settings.

    Resolution

    1. In Admin Center, go to Configure Object Definitions.
    2. Select the custom MDF object and set Secured = Yes (if not already).
    3. In Admin Center, go to Manage Data
    4. Open Object Configuration and select the same MDF object.
    5. Enable “Record-Level Permission Check on Export” (set to Yes).
    6. Save the configuration and re-run the MDF Data Export to confirm that only permitted records are included based on RBP.

    See Also

    Keywords

    mdf data export, record-level permission, rbp, exclude self, target population, export includes self, object-level permissions, metadata framework, permission check on export, custom mdf object, externalCode, promotion recommendation, expected behavior, security configuration, data export permissions, Enable Record-Level Permission Check on Export , KBA , LOD-SF-MDF-IMP , Import and Export Issues , Problem

    Product

    SAP SuccessFactors Platform all versions