cancel
Showing results for 
Search instead for 
Did you mean: 

AC 10 MSMP Workflow

Former Member
0 Kudos

Hello Experts,

We are just trying to configure the basic components of Access Control on AC 10.

We have configured PSS and when we are trying to configure workflow for access requests we are running into issues.

I Just wanted to check what I configured makes sense.

We only need basic functionality.

1.User Lock,Unlock ---Where the only Approver is Manager ( We have configured LDAP so the system picks up manager details for the user)

2.Next is Validity Extension where we don't want any stage but the users can change their validity date just by submitting request and request is auto approved (Auto Provisioning has been configured)

3.We need Change Acct(For Adding of new roles)

4.We need New Acct(For creating new acct and also adding roles in same step)

I see that the major difference w.r.t. 5.3 to 10 is that in 5.3 we have different kind of Request types and we can have different initiators but in 10 we have a process id (Access Request) which pretty much covers above 1-4 etc and we have a single standard initiator(If we want more we need to use BRF+)

So Initially I configured in such a way that the request only goes to manager and it is approved .Here I had to use the system name and it worked fine.

Then I configured second stage of role owner approval and then when i add system and role it was erroring out so i just added the role and did a change acct and it worked fine.Don't know why it wasn't taking system and role together(could be because the role already has system name and maybe it didn't want redundant values)

So after configuring second stage when I tried to use it for user lock/unlock it is erroring out as obviously it doesn't like taking just system name.

My Config settings based on MSMP workflow.

1. Process ID -- SAP_GRAC_ACCESS_REQUEST

2. Rule ID-GRAC_AC_INITIATOR(Rule Result --GRAC_DEFAULT_RESULT)

5.Maintain Paths-GRAC_DEFAULT_PATH

Maintain Stages- GRAC_MANAGER,GRAC_ROLEOWNER

sorry for such a long post but I am at my wit's end as I am so near yet so far from the solution.

Thanks

Uday

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Hi Uday,

Scenario's defined by you can't be acheived using standard MSMP. You need to define the BRF rules using transaction BRF+.

BRF + is simple, will help you in configuring the approver based on the request type.

Regards

Rajan Arora

Former Member
0 Kudos

Thanks Rajan but i don't know if anyone of you had encountered this or is is a bug .We are on AC 10 SP4 and when i am trying to save my Access request workflow it gives this error message.

Error when trying to activate a new version 00000027 for process SAP_GRAC_ACCESS_REQUEST.

Is there a restriction that the version shouldn't be beyond 26 or something..

Answers (1)

Answers (1)

Former Member
0 Kudos

Hi Uday,

Hope you are well. The workflow seems to be configured as I would have expected, utilising the SAP delivered stages and agent. Before proceeding, would it be possible to check if you have actually imported and configured the roles via Business Role Management (BRM)? Ensure you have assigned an approver against the roles also.

Good luck and let us know what you find.

Former Member
0 Kudos

Hi Kuashal,

I had imported only 1 role using role import from access mgmt.I am not using ERM.

I also found out yesterday that the error i was getting gave me a new description

Incorrect path and stage class entry for process SAP_GRAC_ACCESS_REQUEST

Error when generating a new version 000027 for process SAP_GRAC_ACCESS_REQUEST

and also when i try to activate other process id's it works fine but only for this process id i am getting an error.

logged an OSS message .

Will get back with any reply