Forbidden password

What is your password?

***123
abc***
welcome****
***hello
qwerty**
love
dragon
password@**

 

 

Usually max people set their password like  above …if any of you set passwords as above then you are in Risk…………

In SAP its very dangerous RISK because its matter of cores in business.To stop making easy to guess passwords SAP introduce this concept called forbidden password.Let us see the setup of forbidden password/Illegal password with screenshots.

Table USR40 is used to store the restricted passwords. It  is also referred as exception list of passwords.Simply we set up some well-known passwords in USR40 to avoid use of these passwords. We can restrict password as Texts/numbers/special characters……It allows users to define strong passwords to avoid misuse /hacking from intruders. This is part of Authentication Security.

 

  • Go to SM30

 Enter USR40 and click and Maintain.

  •  Click New Entries

  • Enter passwords . 

  • Select save

  • Once select the save option new window will prompt to create Transport request.

create TR with require details and save .

 now we have done the set up.

If user uses the forbidden password then user gets an error as “password is in exceptional”.

 For password rules click here  login password parameters

 Any doubts feel free to contact me.

2 comments:

Unknown said...

Hi ,

Thanks for sharing knowledge.please keep post some more documents in sap security

Anonymous said...

I really like looking through a post that will
make people think. Also, thank you for permitting me to comment!


my homepage; how to get free gems in clash of Clans