Skip to Content

SAP_GRAC_SUPER_USER_MGMT_USER IS MISSING IN PFCG

Hello,

Currently I am Implementing GRC 10.1 AC in my company. i have to create a FFID and looks like sap_grac_super_user_mgmt_user role is missing in PFCG, because of that Firefighter (GRC system) is not communicating with FFID (Backend system).

Please help

Add a comment
10|10000 characters needed characters exceeded

Related questions

2 Answers

  • Best Answer
    Posted on Nov 18, 2014 at 03:45 AM

    Hi Feroz,

    You need to perform lot of configuration activities in both GRC and Target systems apart from creating FF ID. Please follow all the steps mentioned in the below guides and let us know if you face any issues.

    Step 1: Create Firefighter ID:

    Create a user account in transaction SU01 with user type “S” to be used as a Firefighter ID in target SAP production system

    Assign the appropriate roles to the Firefighter ID

    A user exit should be implemented (see SAP Note 1545511) to restrict users from logging in to the Firefighter ID through the SAP GUI.

    Step 2: Import Firefighter ID to GRC:

    Run “Repository Object Synch” background job in GRC => SPRO => Governance, Risk and Compliance => Access Control => Synchronization Jobs”

    Step 3: Assign Firefighter Owner:

    Assign an Owner to the Firefighter ID.

    NOTE: Before assigning owners please create owners SU01 record in GRC system and mark the person as Firefighter Owner in NWBC => Setup => Access Owners => Access Control Owners

    Step 4: Assign Firefighter Controller:

    Assign a Controller to the Firefighter ID.

    NOTE: Before assigning Controllers please create controllers SU01 record in GRC system and mark the person as Firefighter controllers in NWBC => Setup => Access Owners => Access Control Owners

    For Centralized Firefighting Follow below guide

    Configure Emergency Access (EAM) in GRC 10

    For De-centralized Firefighting Follow below guide

    De-centralized EAM GRC 10.0

    Regards,

    Madhu.

    Add a comment
    10|10000 characters needed characters exceeded

  • author's profile photo Former Member
    Former Member
    Posted on May 14, 2015 at 07:39 PM

    Hi Firoz,

    How did you find the role SAP_GRAC_SUPER_USER_MGMT in GRC?

    I guess we need to assign thsi role to end user in target systems(I am using Decentralize EAM) but teh role is not vailiable in GRC as well as a result when I assign FFID to user it is not shwoing in FF cockpit of target systems.

    Hwo did you resolve this?

    Thanks,

    Trinetra

    Add a comment
    10|10000 characters needed characters exceeded

Before answering

You should only submit an answer when you are proposing a solution to the poster's problem. If you want the poster to clarify the question or provide more information, please leave a comment instead, requesting additional details. When answering, please include specifics, such as step-by-step instructions, context for the solution, and links to useful resources. Also, please make sure that you answer complies with our Rules of Engagement.
You must be Logged in to submit an answer.

Up to 10 attachments (including images) can be used with a maximum of 1.0 MB each and 10.5 MB total.