cancel
Showing results for 
Search instead for 
Did you mean: 

Password notification should not be with user id information

Former Member
0 Kudos

Hi,

We are configuring GRC Access Enforcer for our company and we are able to do auto provisionoing succesfully. But, a small issue is that, after user provisioning is happened, system generates a PAssword mail notificaiton to the user along with

System details

User id

Password

There are two issues here:

1. As per the company policy, the user should not recieve both user id and pasword in a same mail.

2. As per the company policy, the password generates by GRC should match to certain policy..like, the password should be with character, 1 digits and 1 special characters. But, GRC generates a password like the below, which is against our company policy.

Password: rhdjd]P7

Any solution for the above two issues?

Regards

Anandm

Accepted Solutions (0)

Answers (2)

Answers (2)

Former Member
0 Kudos

Hi,

As per your first query, it is not possible to send the user id and password in different mail as this is not designed in CUP.

The mails are hard-coded which will sent both userid and password together in a mail.

Regards,

Shweta

Former Member
0 Kudos

Hello Anandam,

2. As per the company policy, the password generates by GRC should match to certain policy..like, the password should be with character, 1 digits and 1 special characters. But, GRC generates a password like the below, which is against our company policy.

-> To make this requirement possible you would have to enforce this at SAP backend system level. The password policy enforced in the system where the provisioning is going to be done is taken by CUP. If the same is enforced in the backend system A then CUP will use the policy maintained in SAP System A and generate password according to that.

Regards,

Varun

Former Member
0 Kudos

How to enforce this policy works?

Former Member
0 Kudos

Hi,

That would be a SAP Basis or SAP Security question. You can define your password policy in SAP and CUP (AE) will follow this policy. There is no configuration required in CUP.

You won't be able to change the password notification email as it is hard coded.

Regards,

Alpesh

Former Member
0 Kudos

In that case, how come the user id and password informations comes in a separate mail while the user provisioning is happening. Why not the same concept apply for password self-service