on 02-17-2018 8:07 AM
Dear Friends, Even if role assignment or content approver is deleted from GRC, activate directory and user master data of all systems ( deleted ) ARQ notifications are sent to email id and are getting captured in audit logs as one of the approvers.
Points to note: -
- ID's are not present in GRC
- ID's are not present in Active Directory
- ID's are not present in any SAP Systems
Is this a Synchronization issue between GRC and Active Directory. How can we confirm if it's synchronized or not ( Auth, Repo and Act Synch are already completed ) ?
Are there any additional steps in GRC which need to be performed apart from
- Deletion of ID as Assignment approver @ Role Mass Update.
- Deletion of ID as Role owner @ Access Control Owner and un - checking as Role Owner
- Un assignment of AC roles
Do we have a table were we can go and check if role assignment / content approver residue still remains ?
Please let us know.
- Thanks
Hello,
You can check table GRACROLEAPPRVR for cross checking for role approver residue.
If above table shows correct data, you might want to check the MSMP configurations if approval agents are fixed there itself.
Please provide screen captures if possible.
Kind regards,
Yashasvi
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
User | Count |
---|---|
15 | |
3 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.