I'm looking at the following security tasks after it was discovered during our testing that users had too much access. By their names, they appear to be narrowly defined. However, closer examination shows that TRX_PURCH_001* and TRX_PURCH_004* tread into other functions and appear to have both custodial and recording functions. Why would Microsoft give so much access to these tasks instead of just adding multiple tasks to a role? Especially when doing so causes a segregation of duties conflict? Thanks.
TRX_PURCH_001* - Enter purchase order transactions
-
Purchase Order Entry windows
-
Purchase Invoice Entry windows
-
Receivings Transaction Entry widows
TRX_PURCH_004* - Enter Receivings transactions
TRX_PURCH_005* - Enter/match Purchasing invoices
*This post is locked for comments
I have the same question (0)