cancel
Showing results for 
Search instead for 
Did you mean: 

Provisioning issue in new system

Former Member
0 Kudos

Dear Experts,

We have configured new system in GRC and all RFC connections are working properly.But when we are requesting roles for that system,after final approval, In audit log it is showing as " <Rolename> already assigned to <user id> in system < system>". But role is not assigned to the user in the selected target system.

I.e provisioning is not happening. Even auto provisioning is set .

Pls help me to resolve this issue.Need expert's solutions.

Thanks

KH

Accepted Solutions (0)

Answers (3)

Answers (3)

Arif1
Active Participant
0 Kudos

Hi,

Please run full sync.

Regards

Arif

Former Member
0 Kudos

It sounds like there is corrupt data within the GRAC* tables for role assignments or maybe the connector configuration is pointing back to an already existing system.

Try a Full sync for the Object Repository.

Is there any specific message within the SLG1 application logs?

Former Member
0 Kudos

I cannot see any error logs in SLG1.

Former Member
0 Kudos

Is this happening only with the role assignment? Are the user ids getting created in target system?

or is it that despite audit logs showing fine, nothing is happening at all i.e. no creation and no role assignment?

Former Member
0 Kudos

Hi Vivek,

Audit log is fine but no creation and no role assignment and instead in audit log, it shows " Role already exists to the user"

Thanks

KH

alessandr0
Active Contributor
0 Kudos

Hi Katrice,

SP level? Are you using CUA? Do you have run all the sync jobs accordingly?

Regards,

Alessandro

Former Member
0 Kudos

Hi Alessandro,

Here's the details.

Component Version : SAP NetWeaver 7.40 Version(GRC 10.1 )

Release                    : 7.40

SP-Level                   : 0004

Support Package      : SAPKB74004 .

AFAIK all sync. jobs are executed . Can you please let me know what will be the issue.

Thanks

KH

alessandr0
Active Contributor
0 Kudos

Dear Katrice,

strange and I don't know the issue. If you check the existing assignments for a user in GRC (e.g. in the access requests) does it show the role which you are going to assign? If yes, then you have to check the sync jobs.

Regards,

Alessandro