cancel
Showing results for 
Search instead for 
Did you mean: 

SAP_GRAC_USER_ACCESS_REVIEW

sonny_samarak
Explorer
0 Kudos

Hello Experts,

Wonder whether you can help? I am trying to get the User Access Review (UAR) setup in our development system for testing. I done the steps listed below, but still cannot see any tasks under Compliance Certification Review\Request Review when logged in as a Security lead, or in role owner’s inbox if I set the Admin Review Required to NO.

Here is what I have done so far:

1.       Assigned an owner to a test role

2.       Assigned a coordinator to the role owner

3.       In IMG set UAR Review : 2006 to Role Owner

4.       2007 to YES (Admin Review required)

5.       Initiated MSMP workflow SAP_GRAC_USER_ACCESS_REVIEW

6.       Scheduled and executed a job for “Generate data for access request UAR review” for the test role. Job completes successfully.

7.       When I login as a Security Lead and I check under “Request Review”, no tasks appears.

I added a Default Stage to Maintain Path section in SAP_GRAC_USER_ACCESS_REVIEW workflow and set Current Approvers for the Notifications. Still no notifications either.

What am I missing? Appreciate any guidance.

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Hi Sonny,

please make sure that the following job's have run before running the job "Generate data for UAR Review"

GRAC_ROLEREP_ROLE_SYNC

 

Synchronizes all roles in the repository.

 

GRAC_ROLEREP_USER_SYNC

 

Synchronizes all users, and roles used by these users.

 

GRAC_ACTION_USAGE_SYNC

 

Retrieves the action usage for users.

 

GRAC_ROLE_USAGE_SYNC

 

Retrieves the role usage.

Thanks & Regard

Japneet Singh 

sonny_samarak
Explorer
0 Kudos

Hi Japneet,

Thanks for your response. I do have these jobs scheduled and they are completing successfully.

JobSpoolJobSched. start dateSched. start time
GRAC_ACTION_USAGE_SYNCSAMASOReleased02.08.20130:01:03
GRAC_BATCH_RISK_ANALYSISSAMASOReleased03.08.20135:00:00
GRAC_PFCG_AUTHORIZATION_SYNCSAMASOReleased01.08.201317:30:00
GRAC_REPOSITORY_OBJECT_SYNCSAMASOReleased01.08.201320:30:00
GRAC_ROLE_USAGE_SYNCSAMASOReleased02.08.20131:30:00
GRAC_ROLEREP_ROLE_SYNCSAMASOReleased04.08.20131:00:00
GRAC_ROLEREP_USER_SYNCSAMASOReleased04.08.20133:00:00
GRAC_SPM_LOG_SYNC_UPDATESAMASOReleased01.08.20139:00:00
GRAC_SPM_WORKFLOW_SYNCSAMASOReleased01.08.201313:00:00
GRFNMW_BATCH_EMAIL_REMINDERSAMASOReleased01.08.201318:00:00

ACTION_USAGE and ROLE_USAGE_SYNC jobs are running daily. The other two ROLEREP jobs you mentioned are running weekly over the weekend. Does that make a difference?

Thanks for you help,

Sonny

0 Kudos

Hi Sonny,

I am looking at your message, you need to specify the UAR request type for Process id SAP_GRAC_USER_ACCESS_REVIEW. Thanks. Luciana,

Former Member
0 Kudos

hi Sonny

I have got same issue in our individual system. For sync job, SAP suggest to running them sequentially. and you have to make sure the next job is start runing after the last one completed.

we have one system still facing on this issue, therfore, I'm not sure if it is helpful for you,

0 Kudos

Hi Lenovo

We were able to resolve the UAR issue for Sonny. Are you having the issue still? For Sonny scenario, we had several things changed. A few points for you to consider:

- Role status needs to be set to PRODUCTION (in BRM, open role, additional details tab, provisioning menu, Role status drop down.)

- make sure you have request type configure and active for UAR in SPRO

- make sure you have range number for GRACREQNO active

- when you run the background job for generating UAR data, make sure you enter the system in the criteria, as well as other things like role etc.

hope this helps!

Answers (0)