Quantcast
Channel: SCN : All Content - Governance, Risk and Compliance (SAP GRC)
Viewing all 5097 articles
Browse latest View live

UAR parameter 2004

$
0
0

Hi all,

While trying to configure UAR and setting parameter 2004 not able to get value 011 for UAR ; we are only getting options * and 009.

We are on GRC 10 SP11.

 

Thanks in advance

 

Vijaya


GRC AC 10 - risk analysis : No rules were selected

$
0
0

Hi,

 

In GRC AC 10, when I do a risk analysis (user level for example).

For each userid the result shown in the column action is "No rules were selected "

 

any idea ?

 

Thanks

Aurélien.

 

GRC 10: How do I create a new stage

$
0
0

Hi All,

May any one help me in creating a new stage in GRC 10?

So far I have seen and used GRAC_DEFAULT_STAGE only!

Regards,

Faisal

GRC AC 10: Emergency Access Management, Logon button is disabled (GRAC_SPM)

$
0
0

Hello Gurus,

I have configured Emergency Access Management in GRC AC 10.

GRC Box (SID) : GR1 client 100

Backend ERP system : D24 client 100

 

The FIREFIGHTER in GRC system : FFUSER1

Z_SAP_GRAC_SUPERUSER_MGMTUSER

Z_SAP_GRC_FN_BASE

Z_SAP_GRC_NWBC

 

In the Backend ERP system the FIREFIGHTER ID: ABC wants to access the FIREFIGHTER(FFUSER1)

Hence in NWBC (Setup >Superuser Assignment>Firefighter ID) the assignment is done.

ABC(FIREFIGHTER ID) <--->FFUSER1(FIREFIGHTER)

 

Now the User login the GRC system using FFUSER1 assigned following roles

Z_SAP_GRAC_SUPERUSER_MGMTUSER

Z_SAP_GRC_FN_BASE

Z_SAP_GRC_NWBC

Z_SAP_GRAC_SPM_FFID

 

and runs Transaction: GRAC_SPM

and he is able to see that ABC is assigned .

Now the user clicks on "Logon" and the status changes from green to "RED".

A new SAP screen opens asking credintials for Backend ERP system D24 client 100

The User enters his own Id : ABC and password and logs in.

Runs the necessary transactions and logs out using transaction: /nex

 

The session in GRC is still running and now the "LOGON button" is disabled , he comes out of that screen too.

 

When the user tries to login again using FFUSER1 to do more task , the "LOGON Button" is seen disabled.

and clicking the "unlock" button also doesn;t help.

 

When checked in SM04, no live session is reflected .

 

How can we "enable" the LOGON button in the transaction : GRAC_SPM for the same FIREFIGHTER (FFUSER1) assigned for Firefighter ID (ABC) ??

As it is now not possible to click "LOGON" button and the status is "RED".

 

Please let me know your opinion .

 

Thank You.

 

Regards,

Premjit

GRC 10 Documentation

$
0
0

Hi Experts

 

I want to start studying for GRC 10 but I don't have any documents on this subject, and there is not much out there in regards this tool so can anyone help me out with this. I am starting from the beginning so would like details please, my reason for this is I want to peruse the accreditation for GRC 10

 

I know there is a course on GRC 10 but at £2600 a pop I am in no position to spend this until I have something to go on first.

 

I look forward to your reply's

 

Thanks

 

Mark

GRC AC 10: Changing a description of a field in the application

$
0
0

Hello Gurus,

 

I would like to know is it possible to change the description of a field in the application (NWBC) in general?

and to be more specific, I'm looking to change the description of the field "Priority" in the create request main page (request details).

 

Please help,

Regards,

Michal.

GRC AC 10: Role Owner Agent

$
0
0

Hello Gurus,

 

I have a scenario which requires your help.

 

In the process of Role creation, I have the option of choosing in the owner field: Role content approver/ assignment approver.

I would like Both of them to be 2 different agents in the WF process.

 

My question is:

If I maintain 2 different users in the Role owner field, one of them will be a role content approver and the other will be an assignment approver,

when i choose the Agent ID: GRAC_RoleOwner in the WF process,

Which one of the 2 users will be the one that receives the request?

 

Do you know of a way to create an agent that will forward the WF to the Role content approver, and another agent that will forward to the assignment approver?

 

Appreciate all help,

 

Regards

Michal

maintaining actions directly in BRM AC10.0

$
0
0

Hello Experts,

 

Every time we are maintaining roles in AC BRM 10.0 and want to add / remove single transactions we are forces to move and work in the backend ECC system via transaction PFCG. We are only able to add functions directly in BRM.

 

Is there a way to maintain a role by adding / removing single transactions in it directly in BRM without moving to ECC PFCG?

 

Kind Regards,

Shira


CUP Connector Test failing as SLD Connector

$
0
0

Hi,

 

I am working with GRC 5.3 and have changed the password of RFC User maintained in Connector in Configuration Tab of CUP.

 

Problem is when I am updating the new password in Connector the Connection Test is failing.

 

It's successful, when I un-check the option of SLD Connector.

 

With option SLD Connector checked the connection test fails, previously it was fine. The issue is coming after I changed the password in backend and updating it in CUP Connectors in configuration Section.

 

Can anyone help please.

 

 

Thanks

Aditi

ARQ - >> Error while inserting the request reason

$
0
0

Hi,

 

We have just upped the GRC10 SP to 10 and have the following error on the access request.

 

>> Error while inserting the request reason

 

Has anyone had this error after doing the SP lift?

 

Regards, Mel Button 

GRC AC 10.0 - Post-Installation : Issue in Task Specific Customization with Plug-ins

$
0
0

Hello All,

 

While i am trying to activate standard task TS 76308013 using the t-code PFTC, I am getting the following error while i am selecting assign agents -> maintain option.

 

Interface implementation IF_WORKFLOW does not exist.

 

Please let me know what I need to do to proceed further.

 

 

Regards

Deepak M

SAP GRC - BRM

$
0
0

Hi Friends,

 

Can anyone share me a configuration & post installation steps of BRM....

 

thanks!

SSM - GRC integration issue

$
0
0

Hello, SAP experts,

 

I have an issue while configuring SSM-GRC integration. Both SSM and GRC have version 10.0.

 

We have successfully installed and configured our SSM environment, also installed GRC and followed all required SSM-GRC configuration steps as provided in the SSM administration manuals.

 

After that we have made some initial configurations in GRC like setting Org Structure, Objectives, Activities, Risks etc and set-up SSM scheduler to import all GRC data into SSM via SSM administration web portal.

 

The problem is that GRC Scorecard KPIs section of SSM administration / Connectors tab is still empty and no GRC data is provided inside SSM system. In SSM administration / Connectors / GRC Scorecard KPIs we can select the PAS model then the org dimension (which is filled with data) but after selecting the org dimension no GRC related data is displayed.

 

I have a suspicion that our GRC system might be incompletely configured for the SSM-GRC integration. If this is the case what are the basic GRC configuration requirements for the SSM-GRC integration to work?

 

Thank you for help and support.

 

 

Best regards,

Donatas

MSMP Notification Settings > Missing Notification Event: END_OF_REQUEST

$
0
0

Hello everybody,

 

While configuring MSMP Notification Settings to send an email to the end user with credentials the Notification Event "END_OF_REQUEST" is not in the list. As a reference for this context, see details on Note: 1588079.

 

-Current system: GRC 10 SP12

 

-SPRO Configuration: Access Control-> User Provisioning -> Maintain provisioning Settings -> Maintain Global Provisioning Configuration and change the Send Password under EMAIL status to YES.

 

-(1) MSMP Workflow Configuration:

     Process Global Settings > Notification Settings:

     -Notification Event: END_OF_REQUEST

     -Template ID: GRAC_AR_CLOSE

     -Recipient ID: GRAC_USER

 

-(5) Maintain Paths > Notification Settings > Notification Event:

     -Approved

     -Escalation

     -Forward

     -New_Work_Item

     -Rejected

     -Return

 

 

Your guide on how to get the missing Notification Event: "END_OF_REQUEST" will be appreciated!

 

Regards,

Gustavo

New Request Type - Terminate Account

$
0
0

Hi All,

 

Is it possible to Create a New Request Type with actions CHANGE_ACCOUNT, LOCK_USER in GRC 10 and name it as Terminate Account? If that is possible i can maintain User Defaults with UserGroup as "DELETE" or "TERMINATE" for this Terminate account request type. We are not using IDM or HR Triggers for terminating the users. We would like to do it through GRC request manually. I know all the companies make use of HR Triggers or Centralized IDM system for this purpose, but we want to do this manually. So is it possible to create new request type with my requirements? Or Is there any other way to do it?

 

Regards,

Madhu.


Using GRAC_DETOUR_SODVIOL_NO_ROLOWN Routing Rule

$
0
0

Hi Guru's -

 

Can someone explain to how to use this Routing Rule or what the point of it is?

 

Based on the description, it sounds like this rule is supposed to check to see if the Access Request contains an SoD violation AND has roles associated with No Role Owner. Here is out the description reads in the MSMP Workflow:

 

SOD violation and no roleowner chained routing rule ( Process Type : SAP_GRAC_AR)

 

I have not seen any other threads on this so I assume that it is not utilized much, but I have a workflow design where I want to perform a check just like what is being implied in the routing rule. If the combination of roles has and SoD AND one or more of the roles does not have a Role Owner, I'd like to route the request to a different Path. However, when I try to implement this routing rule in the "Maint Route Mapping" stage, I get two options of either a Rule Result of "NO_ROLE_OWNER" OR "SODVIOL_DETOUR_PATH"

 

To me this seems redundant since there are two other Routing Rules "GRAC_MSMP_ROUTE_NO_ROLEOWNER" & "GRAC_MSMP_DETOUR_SODVIOL" which perform the exact same function and produce the same two Rule Results.

 

The description of this routing rule is misleading because to me in the description when it says "Chained Routing Rule", it implies that it will check for both conditions....

 

Can anyone provide feedback on how to use this Routing Rule and if it can be used the way that I'm suggesting?

 

It seems redundant to have the rule setup this way, but I believe I may not be using it right.... any feedback would be greatly appreciated.

 


Add/delete function in BRM

$
0
0

Hello,

Error below appears when we link our roles to a GRC function (add/delete function button->select function-> select OK-> error message)

 

2013-11-18_150906.png

Also,

  • the transactions do not appear in the action tab, except if we switch to the PFCG mode. Even in this case, the transactions are not sync with the backend role

 

Did I miss something?

 

Thanks,

Julien

SoD action alerts are not being pulled from tables to dashboard

$
0
0

Our Firma Is already done with the migration project from GRC 5.3 to GRC V10.0 and we obtained good results ,excpect that SoD alerts dasboard could not be updated since golive as of, 30.11.2013. The information was pulled succesfuly once after we applied the following notes:

 

1878803 -  Conflicting and critical alerts report showing no data

1888094 - Alerts are not generated for critical actions

 

The next SAP Notes related to MIME configuration were reviewed in the productive system:

1946390 - How to resolve Unified Rendering issues on GRC Systems:

 

1686073 - Complete data is not visible in Dashboard Pie chart

1600319 - No Message for Empty Dashboard

 

 

All the MIME configuration was correct, however we need to enter the transaction SE80 to review it. According with the SAP Note: 18023 – Jobs EU_INIT, EU_REORG and EU_PUT. When you start transaction SE80 (Repository Browser) for the first time, the three EU jobs are automatically created and, if the user has sufficient authorizations, released: EU_INIT (single start), EU_REORG (periodically each night), and EU_PUT (periodically each night). Among other task this jobs completely rebuild the indexes. All customer-defined programs (selection according to the naming convention) are analyzed and indexes are created that are used in the ABAP Workbench for the where-used lists of function modules, error messages, reports, and so on. These indexes are automatically updated in dialog mode.

 

Following  these activities, the sync jobs: GRAC_ACTION_USAGE_SYNC, GRAC_SPM_LOG_SYNC_UPDATE and GRAC_ALERT_GENERATION (in that order) were scheduled   again without favorable results.  Ultimatelly  we  recorded  a SAP OSS msg and the recommendation was to apply the following  SAP notes:

 

1866795 Dashboard reports should drilldown for current period only

1898931 Drilldown not working in access request dashboard reports

1931837 Connector name with & causes issue in Dashboard reports

 

At the time I´m writing this, the problem persist and I will appreciate your expertice and recommendations.

Best Regards,

Victor Sarabia

GRC Technical Manager

 

 

 

UAR Data Generation Job and User Groups

$
0
0

Hi Experts,

 

In UAR Data Generation Job step number 2(select variants), when i select a particular connector, the User Group option does not show the correct user groups from that connector.

 

Attached a screenshot of the screen for your reference

 

Regards,

Jaravuy

Data Source Creation in SAP GRC PC 10.0

$
0
0

Hi,

 

 

I am trying to created Data Source in SAP GRC PC 10.0. I have completed the configuration with respect to the connector for ECC application server.

 

On the Object field tab I have selected the sub scenario as Configurable.

Connection Type is SAP System

Main I try to select the main collector I do not see the connector for ECC Application.

 

For connector I have made following setting:

 

1. Create Connector - Created Connection in ABAP Connectors Area

 

2. Maintain Connectors and Connection Types: Connection Type Created is SAP

                                                                 Connector Definition is as follows:

Target Connector - Test

Connection Type - SAP

Source Connector - Test

Logical Port - Test

 

3. Maintain Connection Setting:Integration Scenario is AM (Automatic Monitoring)

Scenario Connection link is as Test (target Connector) - SAP (Connection Type) - SAP System (Connection Type Text)

 

After doing all above I am not able to see the Target Connector Test in the drop down list for connectors in Data Source creation screen.

 

 

Am i missing some configuration setting because of which Test Connector is not shown in the drop down list?

 

 

Please help me on this error.

 

 

 

Regards

JSM

Viewing all 5097 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>