ERP Security and Access Controls for System Administrators Training Course

5 days ERP Systems Certificate on completion
Course codeSD-ES-019
Duration5 days
LevelIntermediate to Advanced
CategoryERP Systems
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

ERP administrators are expected to keep finance, procurement, supply chain and HR transactions available while preventing inappropriate access to sensitive records, configuration and privileged functions. That responsibility becomes difficult when role designs have grown organically, emergency access is unmanaged, identity data is inconsistent, and auditors cannot see why a user holds a particular entitlement. This course addresses the operational controls system administrators need to reduce excessive access without interrupting essential business processes.

Participants learn to translate business job responsibilities into least-privilege ERP roles, permissions and approval workflows. They examine role-based access control (RBAC), segregation-of-duties (SoD) conflicts, privileged-access administration, joiner-mover-leaver processes, access recertification, logging and evidence retention. Practical sessions cover security administration patterns in SAP S/4HANA Fiori and Oracle Fusion Cloud ERP, federation with Microsoft Entra ID, and the use of NIST SP 800-53 control families to structure control evidence and remediation priorities.

The programme is delivered through instructor-led technical briefings, guided configuration labs, access-review casework and team-based control design workshops. Participants work from a realistic ERP access model containing finance, purchasing and administrator roles, identify conflicts and weak controls, then design remediation. Each participant leaves with an ERP Security and Access Control Plan: a role-design matrix, SoD rule set, privileged-access workflow, review schedule, audit-evidence checklist and a 90-day implementation roadmap tailored to their own environment.

This course is designed for system administrators and security-focused ERP technical staff who already support production ERP services and need to make access administration defensible, repeatable and auditable.

Course objectives

By the end of this course, participants will be able to:

  • Design least-privilege ERP roles using a job-function-to-permission matrix
  • Map segregation-of-duties conflicts across procure-to-pay, record-to-report and user-administration processes
  • Configure role-based access control concepts for SAP S/4HANA Fiori and Oracle Fusion Cloud ERP
  • Implement joiner-mover-leaver access workflows with approval, provisioning and deprovisioning controls
  • Administer privileged and emergency access using time-bound elevation, logging and approval procedures
  • Build an access recertification campaign with reviewer assignments, attestation criteria and exception handling
  • Collect audit evidence from access logs, role assignments, approvals and control-review records
  • Produce an ERP Security and Access Control Plan with a 90-day remediation roadmap

Benefits of attending

For you

  • Gain a repeatable method for converting business duties into defensible ERP access roles
  • Build credibility with auditors by producing traceable access-review and remediation evidence
  • Handle privileged and emergency access requests without relying on informal administrator workarounds
  • Apply SAP and Oracle security concepts within a shared cross-platform control framework
  • Leave with a portfolio-ready ERP Security and Access Control Plan for use in senior administration or IAM roles

For your organisation

  • Reduces the likelihood of fraud-enabling segregation-of-duties conflicts in finance and procurement workflows
  • Improves removal of stale and transferred-user access through defined joiner-mover-leaver controls
  • Creates clearer approval and evidence trails for internal audit, external audit and compliance reviews
  • Limits standing administrator privilege through time-bound emergency and privileged-access procedures
  • Provides a prioritised 90-day remediation plan that focuses security effort on material ERP access risks

Target competencies

ERP role designSoD conflict analysisPrivileged access controlAccess recertificationAudit evidence collectionIdentity lifecycle governance

Who should attend

  • ERP System Administrators — who provision accounts, manage roles and maintain production ERP environments
  • ERP Security Administrators — who need to reduce excessive privileges and demonstrate control operation
  • SAP Basis and Fiori Administrators — who administer SAP identities, authorisations and launchpad access
  • Oracle Fusion Cloud ERP Administrators — who configure security consoles, job roles and data access
  • Identity and Access Management Administrators — who integrate ERP applications with enterprise identity services
  • IT Audit and Controls Analysts — who test access controls and require traceable evidence from ERP administrators

Requirements and prerequisites

Participants should have at least one year of experience administering, supporting or auditing an ERP application in a production setting. They should understand user accounts, groups, roles, permissions, authentication, approval workflows and basic change management. Familiarity with either SAP S/4HANA, SAP Fiori, Oracle Fusion Cloud ERP or a comparable enterprise platform is strongly recommended. Participants should also be comfortable reading access reports and discussing finance or procurement business processes. Prior programming, penetration-testing experience and formal audit certification are not required. The course explains platform-specific examples without assuming prior hands-on configuration experience in both SAP and Oracle.

Training methodology

The instructor uses short technical demonstrations followed by guided labs based on a multi-department ERP scenario. Participants analyse job roles, permission assignments, approval records and access logs; configure and test role-control decisions in SAP- and Oracle-oriented exercises; and work in teams to resolve realistic SoD and privileged-access cases. Daily debriefs connect technical settings to audit evidence and business process risk. On the final day, each participant converts lab findings into a documented access-control plan and receives structured instructor feedback on implementation priorities.

Course outline

Day 1: ERP access-risk foundations and role architecture

  • ERP threat scenarios affecting finance, procurement and master data
  • Identity, authentication, authorisation and data-access control layers
  • Role-based access control and least-privilege design principles
  • Business-role decomposition into tasks, permissions and data scope
  • Standard, composite and inherited role patterns
  • Access-risk registers and control-owner accountability
  • NIST SP 800-53 access-control families applied to ERP operations

Workshop: Participants create a job-function-to-permission matrix for finance, purchasing and ERP administration roles and identify initial excessive-access risks.

Day 2: Segregation of duties and sensitive access

  • Segregation-of-duties conflict patterns in procure-to-pay
  • Segregation-of-duties conflict patterns in record-to-report
  • Sensitive-access classification for vendor, bank and journal functions
  • SoD rule-book structure, risk ratings and compensating controls
  • Conflict detection using role, transaction and entitlement analysis
  • Exception approval, expiry dates and compensating-control evidence
  • Remediation options through role redesign, workflow and monitoring

Workshop: Using a supplied access extract, participants build an SoD conflict report, propose compensating controls and document remediation owners.

Day 3: ERP security administration and identity integration

  • SAP S/4HANA Fiori catalog, business-role and space-page authorisation concepts
  • Oracle Fusion Cloud ERP Security Console job roles and data roles
  • Microsoft Entra ID federation, conditional access and group-claim considerations
  • Joiner-mover-leaver provisioning workflow design
  • Approval routing, role-request forms and access fulfilment records
  • Service-account ownership, credential rotation and non-interactive access
  • Data-access restrictions by legal entity, business unit and responsibility

Workshop: Participants design a joiner-mover-leaver workflow and role-request form for a new purchasing manager moving between business units.

Day 4: Privileged access, monitoring and audit evidence

  • Privileged-account inventory and administrator role separation
  • Emergency-access and firefighter account control procedures
  • Time-bound elevation, approval and session-accountability requirements
  • ERP access logging and event fields needed for investigation
  • Access-review evidence, retention schedules and reviewer attestations
  • Control testing procedures for user provisioning and deprovisioning
  • Incident response actions for unauthorised ERP entitlement changes

Workshop: Participants investigate a simulated privileged-access incident and assemble an evidence pack containing logs, approvals, findings and corrective actions.

Day 5: Control operating model and implementation planning

  • Periodic access recertification campaign design
  • Reviewer population, attestation decisions and escalation rules
  • Access-control metrics for stale accounts, exceptions and review completion
  • Risk-based remediation prioritisation and treatment planning
  • ERP security change control and release-management checkpoints
  • Control ownership across ERP, IAM, security and business teams
  • Ninety-day implementation roadmap and executive reporting format

Workshop: Participants complete and present an ERP Security and Access Control Plan containing their role matrix, SoD rules, privileged-access workflow, review calendar and 90-day roadmap.

Tools & standards covered

SAP S/4HANA Fiori, Oracle Fusion Cloud ERP Security Console, Microsoft Entra ID, NIST SP 800-53

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand how users, roles, permissions and approval workflows operate in an enterprise application, ideally through at least one year of ERP support or administration. You do not need to be an SAP security specialist, Oracle security specialist or certified auditor.

No production-system access is required. The course uses instructor-provided scenarios, configuration examples and access datasets based on SAP S/4HANA Fiori and Oracle Fusion Cloud ERP security models.

A laptop capable of joining the live online lab environment and working with spreadsheets and PDF documents is recommended for both classroom and online delivery. No specialist local software installation is required before the course.

It is best suited to ERP system administrators, ERP security administrators, SAP Basis or Fiori staff, Oracle Fusion administrators and IAM practitioners supporting ERP applications. IT auditors also benefit when they need to understand how technical access controls are designed and evidenced.

This course concentrates on the operational controls that govern identities, roles, sensitive access, SoD, recertification and privileged administration after an ERP system is in service. It does not teach end-to-end ERP business configuration or broad network and endpoint security.

You can use the supplied templates to review role assignments, document SoD conflicts, formalise emergency access and plan an access recertification cycle. You also leave with a completed access-control plan that can be adapted for your organisation's ERP estate.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in ERP Systems

5 Days Certificate

ERP Systems Fundamentals for Business Users Training Course

ERP initiatives often fail to deliver expected value because business users can complete transactions without understanding the upstream dat…

5 Days Certificate

ERP Systems for Healthcare Supply Chain Teams Training Course

Healthcare supply chain teams work with products that cannot simply be treated as standard inventory. Implantable devices, pharmaceuticals, …

5 Days Certificate

Microsoft Dynamics 365 Finance Training Course

Microsoft Dynamics 365 Finance implementations succeed or fail on the quality of financial design behind the configuration. Finance professi…

5 Days Certificate

Epicor Kinetic Manufacturing Planning Training Course

Manufacturing planners using Epicor Kinetic must turn changing sales demand, inventory positions, supplier lead times and shop capacity into…