ERP Security and Access Controls for System Administrators Training Course
| Course code | SD-ES-019 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | ERP Systems |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
ERP administrators are expected to keep finance, procurement, supply chain and HR transactions available while preventing inappropriate access to sensitive records, configuration and privileged functions. That responsibility becomes difficult when role designs have grown organically, emergency access is unmanaged, identity data is inconsistent, and auditors cannot see why a user holds a particular entitlement. This course addresses the operational controls system administrators need to reduce excessive access without interrupting essential business processes.
Participants learn to translate business job responsibilities into least-privilege ERP roles, permissions and approval workflows. They examine role-based access control (RBAC), segregation-of-duties (SoD) conflicts, privileged-access administration, joiner-mover-leaver processes, access recertification, logging and evidence retention. Practical sessions cover security administration patterns in SAP S/4HANA Fiori and Oracle Fusion Cloud ERP, federation with Microsoft Entra ID, and the use of NIST SP 800-53 control families to structure control evidence and remediation priorities.
The programme is delivered through instructor-led technical briefings, guided configuration labs, access-review casework and team-based control design workshops. Participants work from a realistic ERP access model containing finance, purchasing and administrator roles, identify conflicts and weak controls, then design remediation. Each participant leaves with an ERP Security and Access Control Plan: a role-design matrix, SoD rule set, privileged-access workflow, review schedule, audit-evidence checklist and a 90-day implementation roadmap tailored to their own environment.
This course is designed for system administrators and security-focused ERP technical staff who already support production ERP services and need to make access administration defensible, repeatable and auditable.
Course objectives
By the end of this course, participants will be able to:
- Design least-privilege ERP roles using a job-function-to-permission matrix
- Map segregation-of-duties conflicts across procure-to-pay, record-to-report and user-administration processes
- Configure role-based access control concepts for SAP S/4HANA Fiori and Oracle Fusion Cloud ERP
- Implement joiner-mover-leaver access workflows with approval, provisioning and deprovisioning controls
- Administer privileged and emergency access using time-bound elevation, logging and approval procedures
- Build an access recertification campaign with reviewer assignments, attestation criteria and exception handling
- Collect audit evidence from access logs, role assignments, approvals and control-review records
- Produce an ERP Security and Access Control Plan with a 90-day remediation roadmap
Benefits of attending
For you
- Gain a repeatable method for converting business duties into defensible ERP access roles
- Build credibility with auditors by producing traceable access-review and remediation evidence
- Handle privileged and emergency access requests without relying on informal administrator workarounds
- Apply SAP and Oracle security concepts within a shared cross-platform control framework
- Leave with a portfolio-ready ERP Security and Access Control Plan for use in senior administration or IAM roles
For your organisation
- Reduces the likelihood of fraud-enabling segregation-of-duties conflicts in finance and procurement workflows
- Improves removal of stale and transferred-user access through defined joiner-mover-leaver controls
- Creates clearer approval and evidence trails for internal audit, external audit and compliance reviews
- Limits standing administrator privilege through time-bound emergency and privileged-access procedures
- Provides a prioritised 90-day remediation plan that focuses security effort on material ERP access risks
Target competencies
Who should attend
- ERP System Administrators — who provision accounts, manage roles and maintain production ERP environments
- ERP Security Administrators — who need to reduce excessive privileges and demonstrate control operation
- SAP Basis and Fiori Administrators — who administer SAP identities, authorisations and launchpad access
- Oracle Fusion Cloud ERP Administrators — who configure security consoles, job roles and data access
- Identity and Access Management Administrators — who integrate ERP applications with enterprise identity services
- IT Audit and Controls Analysts — who test access controls and require traceable evidence from ERP administrators
Requirements and prerequisites
Participants should have at least one year of experience administering, supporting or auditing an ERP application in a production setting. They should understand user accounts, groups, roles, permissions, authentication, approval workflows and basic change management. Familiarity with either SAP S/4HANA, SAP Fiori, Oracle Fusion Cloud ERP or a comparable enterprise platform is strongly recommended. Participants should also be comfortable reading access reports and discussing finance or procurement business processes. Prior programming, penetration-testing experience and formal audit certification are not required. The course explains platform-specific examples without assuming prior hands-on configuration experience in both SAP and Oracle.
Training methodology
The instructor uses short technical demonstrations followed by guided labs based on a multi-department ERP scenario. Participants analyse job roles, permission assignments, approval records and access logs; configure and test role-control decisions in SAP- and Oracle-oriented exercises; and work in teams to resolve realistic SoD and privileged-access cases. Daily debriefs connect technical settings to audit evidence and business process risk. On the final day, each participant converts lab findings into a documented access-control plan and receives structured instructor feedback on implementation priorities.
Course outline
Day 1: ERP access-risk foundations and role architecture
- ERP threat scenarios affecting finance, procurement and master data
- Identity, authentication, authorisation and data-access control layers
- Role-based access control and least-privilege design principles
- Business-role decomposition into tasks, permissions and data scope
- Standard, composite and inherited role patterns
- Access-risk registers and control-owner accountability
- NIST SP 800-53 access-control families applied to ERP operations
Workshop: Participants create a job-function-to-permission matrix for finance, purchasing and ERP administration roles and identify initial excessive-access risks.
Day 2: Segregation of duties and sensitive access
- Segregation-of-duties conflict patterns in procure-to-pay
- Segregation-of-duties conflict patterns in record-to-report
- Sensitive-access classification for vendor, bank and journal functions
- SoD rule-book structure, risk ratings and compensating controls
- Conflict detection using role, transaction and entitlement analysis
- Exception approval, expiry dates and compensating-control evidence
- Remediation options through role redesign, workflow and monitoring
Workshop: Using a supplied access extract, participants build an SoD conflict report, propose compensating controls and document remediation owners.
Day 3: ERP security administration and identity integration
- SAP S/4HANA Fiori catalog, business-role and space-page authorisation concepts
- Oracle Fusion Cloud ERP Security Console job roles and data roles
- Microsoft Entra ID federation, conditional access and group-claim considerations
- Joiner-mover-leaver provisioning workflow design
- Approval routing, role-request forms and access fulfilment records
- Service-account ownership, credential rotation and non-interactive access
- Data-access restrictions by legal entity, business unit and responsibility
Workshop: Participants design a joiner-mover-leaver workflow and role-request form for a new purchasing manager moving between business units.
Day 4: Privileged access, monitoring and audit evidence
- Privileged-account inventory and administrator role separation
- Emergency-access and firefighter account control procedures
- Time-bound elevation, approval and session-accountability requirements
- ERP access logging and event fields needed for investigation
- Access-review evidence, retention schedules and reviewer attestations
- Control testing procedures for user provisioning and deprovisioning
- Incident response actions for unauthorised ERP entitlement changes
Workshop: Participants investigate a simulated privileged-access incident and assemble an evidence pack containing logs, approvals, findings and corrective actions.
Day 5: Control operating model and implementation planning
- Periodic access recertification campaign design
- Reviewer population, attestation decisions and escalation rules
- Access-control metrics for stale accounts, exceptions and review completion
- Risk-based remediation prioritisation and treatment planning
- ERP security change control and release-management checkpoints
- Control ownership across ERP, IAM, security and business teams
- Ninety-day implementation roadmap and executive reporting format
Workshop: Participants complete and present an ERP Security and Access Control Plan containing their role matrix, SoD rules, privileged-access workflow, review calendar and 90-day roadmap.
Tools & standards covered
SAP S/4HANA Fiori, Oracle Fusion Cloud ERP Security Console, Microsoft Entra ID, NIST SP 800-53
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in ERP Systems
ERP Systems Fundamentals for Business Users Training Course
ERP initiatives often fail to deliver expected value because business users can complete transactions without understanding the upstream dat…
ERP Systems for Healthcare Supply Chain Teams Training Course
Healthcare supply chain teams work with products that cannot simply be treated as standard inventory. Implantable devices, pharmaceuticals, …
Microsoft Dynamics 365 Finance Training Course
Microsoft Dynamics 365 Finance implementations succeed or fail on the quality of financial design behind the configuration. Finance professi…
Epicor Kinetic Manufacturing Planning Training Course
Manufacturing planners using Epicor Kinetic must turn changing sales demand, inventory positions, supplier lead times and shop capacity into…