cancel
Showing results for 
Search instead for 
Did you mean: 

GRC AC 10 CUP: Provisioning for GRC System Itself

Former Member
0 Kudos

Hello Gurus,

As we are aware that to perform "firefighter" task , the ERP(Plugin) user should exist in GRC system also.

Hence if a user who does not exist in GRC , he has to be created in GRC system first and then he can use CUP form to request for "SUPER USER ACCESS".

So my question here is , can i create a "RFC" pointing to GRC system itself and can it be used to "provision" users in GRC system Itself !!

Has anyone done it earlier ??

Rather than creating the user manually in GRC system.

Regards,

Victor

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Victor,

Once you install ERP plugin's on GRC it will act like any other backend system i.e. you can use it for provisioning on GRC system also.I haven't performed this on my end but I heard it in the training i attended back in Jan with SAP.

Uday

Answers (1)

Answers (1)

Former Member
0 Kudos

Hi Victor,

Yes you can and yes you should, to enable the SPM user ID's to be provisioned in GRC 10.0. I have done this on a few implementations already and it works fine.

You treat the GRC system as any other system and create an entry to itself in SM59 etc and configure it like all the other target system connectors to be used by the GRC system. As pointed out in the previous post, ensure the GRC PlugIn is installed on the GRC system itself.

Ensure you have assigned all the integration scenarios (AUTH, PROV, SUPMG etc) to the conenctor also.

all the best

Former Member
0 Kudos

Hello Kaushal/Uday,

Please note i have not installed : GRC Plugins (GRCPINW & GRCPIERP ) as GRC add-on is present on the system GRCFND_A.

Is it mandatory to have the plugin also installed on the GRC server to make this functionality work ??

I did the necessary configurations in SPRO after creating an RFC to the GRC system itself.

I have configured it as follows

1) Connection type: SAP

Assigned to the same connector group as SAP ECC (other ECC systems)

2) Maintain Connector setting : I selected application type as :015 (GRC)

3) Assigned all scenarios like AUTH, PROV,SUPMG etc.

Then i ran all the Authorization sync

but all the jobs ran in error seen in transaction : SLG1

Job1 : Authorization Sync (Error in GRDCLNT400; Reason Error in RFC; 'Function module "/GRCPI/GRIA_AUTH_G)

Job2 : Profile Sync (Error in RFC; 'Function module "/GRCPI/GRIA_PROF_GET_RANGES" not')

Job3 : Role Sync (Error in RFC; 'Function module "/GRCPI/GRIA_ROLE_GET_RANGES" not')

Job4: User Sync (Error in RFC; 'Function module "/GRCPI/GRIA_USR_GET_RANGES" not f')

Thanks in advance.

Regards,

Victor

Former Member
0 Kudos

Victor,

The plug in is mandatory, hence you got all those errors. Install and configure the plugin's first on the GRC system then try all the steps above again.