cancel
Showing results for 
Search instead for 
Did you mean: 

Delete all existing roles

Former Member
0 Kudos

Hello,

we 're using the GRC Provisioning Framework (with IDM 7.1 SP4 and GRC 5.3 SP10_1) and want to delete all existing roles from a user bevor we set new roles to him.

Is there a general command to do this or have the existing roles to be known?

Thanks,

Carsten

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Hello Carsten

Are you talking about privileges or business roles?

Also: Take note: If a user looses all roles, he will be deleted form the target system!

But you can delete all roles with a ToIdentityStore pass with .

Former Member
0 Kudos

Hello Christian,

thanks for the quick answer. I'm talking about privileges.

In the To Identity Store, is it enough to set:

MSKEYVALUE -


%MSKEYVALUE%

MXREF_MX_PRIVILEGE -


Or do I have to set all existing roles behind the (like priv:grc:xxxx)?

Thanks,

Carsten

Former Member
0 Kudos

Yes, this would do it.

But as I said, this removes all privileges from a users.

If the user has no more privileges on a target system, he will be deleted.

Maybe you test that with a test user first, to see how IDM reacts in your situation.

Former Member
0 Kudos

I have one last Question before I'll test it.

Will the SAP Privilege Framework or the GRC Privilege Framework delete the privileges?

Thanks,

Carsten

Former Member
0 Kudos

The SAP Framework.

Former Member
0 Kudos

Many Thanks!

But is it also possible to delete privileges via GRC Provisioning Framework?

Best Regards,

Carsten

Answers (0)