Skip to Content
avatar image
Former Member

GRC ARM - Issue when "Retain" Role

Dear all,

I have a issue when I try to retain a role.

The Audit log in the request shows :

  • Role ZTOTO in system -SYSID- is approved for action 'Retain' with validity 19.05.2015-20.05.2016
  • Auto provisioning activity at end of request at Path Z_CHANGEACCOUNT and Stage Z_ADMINISTATOR_STAGE
  • Role ZTOTO is not retained for user Z10_REQUEST for system -CUA-
  • Error in End of Path, Escape for 'Auto Provisioning Failure' not Enabled, Ending Path 'Z_CHANGEACCOUNT'
  • Post-request activities reported problems; check logs for details
  • Approval path processing is finished, end of path reached
  • Request is closed

I don't understand why it works for action "add" and "remove" and not for "retain"...

I have a CUA system and I am in GRC 10.0

SAP_BASIS 702 0014 SAPKB70214 SAP Basis Component

GRCPINW V1000_700 0016 SAPK-10316IN GRCPINW SAP GRC NW Plug-in

Could you help me please?



Add comment
10|10000 characters needed characters exceeded

  • Follow
  • Get RSS Feed

3 Answers

  • May 19, 2015 at 10:15 AM


    can you share the provisioning log and SLG1?

    Thanks and regards,


    Add comment
    10|10000 characters needed characters exceeded

    • Former Member Baithi Srinivas


      Thanks for your help Baithi but the role validity date is NOT Changed in my system... so it's not the same issue than in this SAP Note.

      The logs shows that it doesn't work ... and the role is not change.

      For "assign" and "remove" actions, systems works and assigns or removes roles without no issues and the logs are corrects.

      It doesnt work only for "Retain" action


  • avatar image
    Former Member
    Jun 22, 2015 at 07:58 AM

    Somebody can help me ?


    Add comment
    10|10000 characters needed characters exceeded

  • avatar image
    Former Member
    Aug 26, 2015 at 10:14 AM

    Dear all

    I still have the same issue.

    Additional information:

    - CUA is used only for user provisioning and not for role

    - I don't have filled the SPRO > Access Control > User Provisioning > Maintain CUA settings

    - All works fine for "Remove" and "Assign" actions

    Somebody has an idea to help me? if no, I will open an ticket to SAP.

    Thanks and regards,

    Add comment
    10|10000 characters needed characters exceeded