cancel
Showing results for 
Search instead for 
Did you mean: 

Mass RAR Rule Set Changes

Former Member
0 Kudos

My integrator is telling me that there is no way to complete a mass update to the authorizations/restrictions in our RAR rule set (AC 5.3.) That is, at the recommendation of our external auditor, we added additional transactions to existing rules but failed to activate the company code restrictions to ignore display only access and therefore, I am receiving a significant number of SODs which are false positives.

I find it hard to believe that there is no easy way to activate the company code authorization objects (and others) for the additional transactions in the rule set. The integrator is telling me that this has to be done one by one. Please tell me that there is an easier way.

Apologies if this is a repeat; if this topic is out there, could someone point me in the right direction?Thank you in advance!

Thank you in advance!

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

Is there any easy way? Depends on what you think is easy

For mass updates to function I will typically use the: Configuration -> Rule Upload feature. To perform an update to an authorization object, you would use the 'Function Authorization' selection.

To upload the function you'd want to use the file formats from the 9 upload files SAP provides for the ruleset. If I recall correctly, function uploads will overwrite the existing function so it is important that your upload file contains all existing function data + the additional auth objects you want to activiate.

As with any text file manipulation and download/upload or export/import features into GRC you want to be particulary careful with formatting and attention to detail. Probably a good idea to take a backup of the rules if this is your first time working with the ruleset files.

Former Member
0 Kudos

Hi,

You can try as per the above suggestion by tweaking the text files of rule set and re-upload them for the changes. But you need to be extra careful while tweaking as even a space will effect the rule set and may not get uploaded correctly.

If the functions are very few and you know the t-codes to which the objects to be enabled it is better to use mass maintenance functionlity for each function. This is not so painful like going to each function and making changes line by line for each t-code at permissions.

There are options of add, change and delete of permissions& actions under mass maintenance which can be used to change in the function. We did like this only for enabling few customized document type restrictions to the t-codes and were successful.

Best Regards,

Srihari.K