cancel
Showing results for 
Search instead for 
Did you mean: 

CUP 5.3 Superuser Access Request Error

Former Member
0 Kudos

Dear Exparts,

I have a path u201CSuperuser Access Requestu201D with three stages* for assigning FF IDs to requesting users in CUP.

*

Stage1: Manager (Determinator: Manager)

Stage2: Superuser Owner (Determinator: Superuser Owner)

Stage3: Security Admin (Determinator: Security)

I have no problem assigning FF IDs to users through this path.

However, I have a problem when I tried to remove all FF IDs from a user (with an error message: Failed to process your request, Configuration Error, Approvers not found for SUPERUSER OWNER stage).

I kinda know that this is an error due to the fact that I am, in a request, removing all the FF IDs which are supposedly tied to superuser owners---Missing superuser owners causing this error.

Is there any way I can remove all FF IDs and still keep the user ID for day-to-day standard access?

PS: I have tried to create a detour path to the security admin stage in the case if no superuser owner is found. Unfortunately, this didnu2019t work since there is no such pre-defined condition as u201CNo Superuser Owneru201D in the detour path configuration.

Please help if you can.

Thanks,

HM

Accepted Solutions (0)

Answers (2)

Answers (2)

former_member366047
Contributor
0 Kudos

HM,.

How are you removing FFID's from users via CUP?

Michael,

Superuser provisioning via CUP actually assigns available FFID's to the user.

For more details on this functionality, please visit our AC5.3 Best Practice site at: http://help.sap.com/bp_grc53/GRC_US/HTML/index.htm

Not sure, but you might need your S-number to access.

Thanks!

Ankur

SAP GRC RIG

Former Member
0 Kudos

Ankur,

Yes, I am trying to remove the assigned FF ID from a user via CUP.

The CUP won't let me do it...

The system cannot find any superuser owner at the superuser owner stage since I am removing FF IDs to zero.

HM

former_member366047
Contributor
0 Kudos

HM,

What I was getting at is, there is no way to remove FFID's from a user via CUP. You will have to remove those FFID's in the backend SAP system.

Thanks!

Ankur

SAP GRC RIG

Former Member
0 Kudos

Ankur,

Probably so... I understood.

Thanks,

Hideo

Former Member
0 Kudos

Good day HM.

As far as I can recall, FF ID can only be asigned to a user via SPM Dashboard /VIRSA/ZVFAT, if it is configured to do so. The auto-provision feature on CUP allows for Role assignment, not SAP ID assignment.

I speak under correction as with GRC SP upgrades the feaure you are talking about might have been offered.

Regards,

Michael Hannie