cancel
Showing results for 
Search instead for 
Did you mean: 

GRC and LDAP

Former Member
0 Kudos

Dear all.

Maybe this topic is already treat at some thread however i didn't find it.

I would like to implement the following scenario:

All the users that are going to use the SAP GRC application; that is to say the responsible of modifying roles, of creating access request, etc...once they access through the SAP GUI to GRC, the GRC must check the User ID and the password against the LDAP instead of checking against the information stored at the SU01 of the GRC itself.

  • So is this possible?
  • If so, is it possible through the SPRO point "Maintain Data Souces Configuration" and the following guide?

How to Configure LDAP connector - Governance, Risk and Compliance - SCN Wiki

Regards and thanks

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Hi Sara,

The LDAP connector described in the guide is to use the end user login page, in order to create access request or password self service, etc. But is not a single sign on for make all other thing you mentioned.

Regards,

Former Member
0 Kudos

Hi Claudio.

What you mean for the rest of the things?

  • Are you saying that is impossible to authenticate against LDAP through SAP GUI?
  • The only way to authenticate against the LDAP is through this End User Link?
  • I have access through the end user link and as you mention, there i am able to create Access Request. As you said i haven't seen the possibility to modify roles but could it be possible to add this link? That is toy say to add the link for the Business Role Management (BRM) submodule?

Regards.

Former Member
0 Kudos

Hi Sara,

  • Yes, is impossible, you need to create users in GRC for main functionality.
  • Yes, is only for end user logon purpose.
  • I can not tell you this because I never did it. But I think you need a GRC user to BRM functionality.

Regards,

Answers (1)

Answers (1)

former_member193066
Active Contributor
0 Kudos

Hello

As stated earlier by you and Claudio..

You need End user logon and data source to be LDAP for authentication.

Regards,

Prasant

Former Member
0 Kudos

Prasant.

So all my bullets indicated before are right?

  • Are you saying that is impossible to authenticate against LDAP through SAP GUI?
  • The only way to authenticate against the LDAP is through this End User Link?
  • I have access through the end user link and as you mention, there i am able to create Access Request. As you said i haven't seen the possibility to modify roles but could it be possible to add this link? That is toy say to add the link for the Business Role Management (BRM) submodule?

regards.

former_member193066
Active Contributor
0 Kudos

Yes..

but for BRM you need to have master record.

hence you have to go through nwbc.

Regards,

Prasant