on 07-30-2013 7:23 PM
Hello Experts,
Wonder whether you can help? I am trying to get the User Access Review (UAR) setup in our development system for testing. I done the steps listed below, but still cannot see any tasks under Compliance Certification Review\Request Review when logged in as a Security lead, or in role owner’s inbox if I set the Admin Review Required to NO.
Here is what I have done so far:
1. Assigned an owner to a test role
2. Assigned a coordinator to the role owner
3. In IMG set UAR Review : 2006 to Role Owner
4. 2007 to YES (Admin Review required)
5. Initiated MSMP workflow SAP_GRAC_USER_ACCESS_REVIEW
6. Scheduled and executed a job for “Generate data for access request UAR review” for the test role. Job completes successfully.
7. When I login as a Security Lead and I check under “Request Review”, no tasks appears.
I added a Default Stage to Maintain Path section in SAP_GRAC_USER_ACCESS_REVIEW workflow and set Current Approvers for the Notifications. Still no notifications either.
What am I missing? Appreciate any guidance.
Hi Sonny,
please make sure that the following job's have run before running the job "Generate data for UAR Review"
GRAC_ROLEREP_ROLE_SYNC | Synchronizes all roles in the repository. |
GRAC_ROLEREP_USER_SYNC | Synchronizes all users, and roles used by these users. |
GRAC_ACTION_USAGE_SYNC | Retrieves the action usage for users. |
GRAC_ROLE_USAGE_SYNC | Retrieves the role usage. |
Thanks & Regard
Japneet Singh
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Japneet,
Thanks for your response. I do have these jobs scheduled and they are completing successfully.
Job | Spool | Job | Sched. start date | Sched. start time |
GRAC_ACTION_USAGE_SYNC | SAMASO | Released | 02.08.2013 | 0:01:03 |
GRAC_BATCH_RISK_ANALYSIS | SAMASO | Released | 03.08.2013 | 5:00:00 |
GRAC_PFCG_AUTHORIZATION_SYNC | SAMASO | Released | 01.08.2013 | 17:30:00 |
GRAC_REPOSITORY_OBJECT_SYNC | SAMASO | Released | 01.08.2013 | 20:30:00 |
GRAC_ROLE_USAGE_SYNC | SAMASO | Released | 02.08.2013 | 1:30:00 |
GRAC_ROLEREP_ROLE_SYNC | SAMASO | Released | 04.08.2013 | 1:00:00 |
GRAC_ROLEREP_USER_SYNC | SAMASO | Released | 04.08.2013 | 3:00:00 |
GRAC_SPM_LOG_SYNC_UPDATE | SAMASO | Released | 01.08.2013 | 9:00:00 |
GRAC_SPM_WORKFLOW_SYNC | SAMASO | Released | 01.08.2013 | 13:00:00 |
GRFNMW_BATCH_EMAIL_REMINDER | SAMASO | Released | 01.08.2013 | 18:00:00 |
ACTION_USAGE and ROLE_USAGE_SYNC jobs are running daily. The other two ROLEREP jobs you mentioned are running weekly over the weekend. Does that make a difference?
Thanks for you help,
Sonny
Hi Lenovo
We were able to resolve the UAR issue for Sonny. Are you having the issue still? For Sonny scenario, we had several things changed. A few points for you to consider:
- Role status needs to be set to PRODUCTION (in BRM, open role, additional details tab, provisioning menu, Role status drop down.)
- make sure you have request type configure and active for UAR in SPRO
- make sure you have range number for GRACREQNO active
- when you run the background job for generating UAR data, make sure you enter the system in the criteria, as well as other things like role etc.
hope this helps!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.