on 01-24-2014 8:52 AM
Hi Experts,
I have done all the Post-installation steps for GRC10 AC SP13 in our current GRC-Development system below is the snapshot which we have done till now.
CONFIGURATION IN IMG
Integration Framework
Access Controls Configuration relating to Connectors
Maintained Configuration Settings
-->Generated Rule Sets in SPRO(also did in NWBC)
-->Sync Jobs
--Auth Sync
--Repository Sync
--Action Usage Sync
--Role Usage Sync
All the jobs ended successfully without reporting any issues.
Also checked the below tables and everything is updated
GRACACTPERMSYS
GRACUSERCONN
GRACRLCONN
GRACACTRULE
After all this steps when i ran the risk analysis for the first time i didn't got any results.
Then i tried to search the roles by giving the inputs in the risk analysis at role level and then i found that there are no roles in the selection criteria
Iam able to see the Users when iam running through User level but no result.
But all the jobs were successful and also i can find the entries in the GRC table.
Please suggest your thoughts on this and let me know the inputs and were i went wrong.
Thanks,
Neeraj
Hi All,
Just wanted to update that the current Support pack is 12 not 13 sorry for the confusion.
Thanks,
Neeraj
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Neeraj,
As your connector has upper / lower characters and application tries to convert connector into upper case all the times, due to that data is not getting searched from GRC tables.
For user risk analysis, you need to maintain parameter "1022 - Connector for which Object Ids may be maintained case sensitive" with your exact connector id.
For Role level risk analysis, this will not be working. YOu have to convert your connector into upper case.
This is not only for role level risk analysis, upper case connector will help you in all the stages of GRC application. Most of the areas, connector name gets converted into Upper case. So creating a new connector with upper case will resolve your all future issues as well.
Thanks & Regards
Neeraj Manocha
Hi All,
Thanks for all your valuable inputs here, atlast SAP has provided a fix for this issue.
As the issue was with the connector naming convetion which was created in upper and lower case after creating a new connector with uppercase the issue got resolved.
Please check Neeraj Manocha reply for the detailed explanation regarding the connector issue.
Also i have raised a concern with SAP to provide a permanent fix for this as this is a potential risk which can be faced by others as well.
As Dilip was the first who has provided the hint for this issue marking his solution as correct.
Also like to thanks Neeraj Manocha for walking us through his detailed explanation.
Thanks,
Neeraj
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Neeraj,
Upload roles. Authorisations are in sync but not roles.
Have you tried to run risk analysis on SAP_all profile at authorisation level of analysis? Let us know the result pls
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Naveen,
Tried to run the risk analysis at profile level but still no luck.
One more weird thing what I am experiencing is when iam trying to search the profile/user from the search criteria by giving the system details I am not getting any result but when i am searching it without giving the system details then i am able to see the profile/user list in the drop down but for roles neither of the things is working.
Thanks,
Neeraj
Neeraj,
Did the roles import and export ?
Have you done rule generation?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Neeraj,
implement this notes 1824956 and 1817251 and also rum batch risk analysis job.
for role import you have to check confirguration paramenters.
Regards,
Visu
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks Guys for all your inputs, but still the issue is not resolved.
Please can someone provide any more suggestions.
Thanks,
Neeraj
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Neeraj,
try to apply this SAP Note:
1897975 - Role import does not show roles in the preview.
That should help.
Regards, Andrzej
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Neeraj,
Based on "Maintained Configuration Settings" screen you are not maintain Repository Path at 1052 and 3021 parameters.
Check in AL11-->Data Source--> Please check Repository Folders are available or Not.
If not Create Two folders in GRC Server and maintain Repository Path at 1052 and 3021 parameters.
It would be help to you.
Thanks,
Rajesh Srisailapu.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Neeraj,
In GRC 10 you need to upload the roles from backend system and maintain the role status as PRD to be able to available during access request creation.
So I doubt if that has to do something here also Check once and i am not sure though
Regards,
Madhu.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Madhu,
As of now we are only implementing ARA, ARM will be in our next scope.
I tried to import the roles also but it ended up in errors dont know if i have to provide all the details in the GRC 10 role import template as i only had role name and description so i have given the same and tried to import it but no luck.
Thanks,
Neeraj
User | Count |
---|---|
15 | |
3 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.