When you assign a role to a user, you don't select a legal entity for that assignment.
As a result, a combination of assigned roles can violate an enhanced segregation of duties (SoD) rule in one or more legal entities. This isn't visible at the time of assignment.
This becomes relevant when an enhanced segregation of duties rule is scoped to specific legal entities (see also: Set up segregation of duties rules (enhanced)). Use Validate enhanced SoD rules to check a user for enhanced segregation of duties conflicts. The validation covers all legal entities the user has access to.
Complete the following procedure to validate enhanced segregation of duties conflicts for a user.
Steps
Click Security management.
Click the Users tab.
In the list, click the link of the desired user record.
Click Validate enhanced SoD rules.
All active enhanced segregation of duties rules are evaluated against the user's current role assignments. For each rule, its legal entities are compared with the legal entities the user can access.
Notes
For a rule assigned to:
All organizations, the validation is done regardless of the legal entities the user has access to.
Specific organizations, validation is only done for legal entities that are part of the rule's assignment. The user must also have access to these legal entities.
Review the results.
When validation is finished, a message as shown with the results:
If conflicts are detected, the message shows each detected conflict with the user, legal entity, and enhanced segregation of duties rule. It also shows the two conflicting securable objects and their types.
If no conflicts are found, a message indicates that the roles for the user comply with the enhanced segregation of duties rules.