Skip to Content

Role assignment / content approver residue remains in GRC

Dear Friends, Even if role assignment or content approver is deleted from GRC, activate directory and user master data of all systems ( deleted ) ARQ notifications are sent to email id and are getting captured in audit logs as one of the approvers.

Points to note: -

- ID's are not present in GRC

- ID's are not present in Active Directory

- ID's are not present in any SAP Systems

Is this a Synchronization issue between GRC and Active Directory. How can we confirm if it's synchronized or not ( Auth, Repo and Act Synch are already completed ) ?

Are there any additional steps in GRC which need to be performed apart from

- Deletion of ID as Assignment approver @ Role Mass Update.

- Deletion of ID as Role owner @ Access Control Owner and un - checking as Role Owner

- Un assignment of AC roles

Do we have a table were we can go and check if role assignment / content approver residue still remains ?

Please let us know.

- Thanks

Add comment
10|10000 characters needed characters exceeded

  • Get RSS Feed

1 Answer

  • Feb 19, 2018 at 06:15 AM


    You can check table GRACROLEAPPRVR for cross checking for role approver residue.

    If above table shows correct data, you might want to check the MSMP configurations if approval agents are fixed there itself.

    Please provide screen captures if possible.

    Kind regards,


    Add comment
    10|10000 characters needed characters exceeded