cancel
Showing results for 
Search instead for 
Did you mean: 

GRC 10 Firefighter ID Request restriction

Former Member
0 Kudos

Hi,

We are implementing GRC 10 decentralised Firefighter.

I have an issue to restrict the Firefighter ID selection when an End User raise a new access request.

Given a scenario, our GRC is connected to 3 SAP systems (PQVCLNT100, PTKCLNT100 & PTLCLNT100). When an existing User (FF_TESTPTL) from system PTLCLNT100 raise a new access request, he able to select the FireFighter ID from other systems (PQVCLNT100, PTKCLNT100) beside system PTLCLNT100. After selected the FFIDs from different System, he able to submit the FFID request.

The user only exist in system PTLCLNT100, logically this user should only able to submit the FFID from PTLCLNT100 system. However, the system did not restrict the FFID selection based on system it allows the user to submit the FFID request from other systems.

Well, I've restricted some connector objects,but the result still the same.

Can anyone assist on this? Thank you.

Refer below screenshot as sample.

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

Hi Rachel,

I think there are security objects to restrict the FF ID selection. Can you check with the following objects:

- GRAC_FFOWN

- GRAC_SYS

Hope it helps.

Kind regards,