cancel
Showing results for 
Search instead for 
Did you mean: 

User authentication & User Detail Data Source

former_member193066
Active Contributor
0 Kudos

Hello All,

I have few queries.

I have GRC 10.1 with SP08.

My GRC system is connected to LDAP and HR System.

I Have maintained user authentication data source as LDAP and User details data source as HR.

I have maintained SAP ID of users in LDAP physical attribute and HR system infotype 0105 and subtype 0001.

when a user logs in it automatically changes the user id, where is mapped ,thats what expected.

but Managers id is still domain id, it does not pick manager ID from LDAP physical attribute.

again my user details data source is HR system, if a user log on using his SAP ID then it fetches details from HR system, but when user log on using domain id it does not go to HR system.

my requirement was user can log on using Domain account and details should be fetched from HR system.

Regards,

Prasant

Accepted Solutions (0)

Answers (2)

Answers (2)

Former Member
0 Kudos

Make path ID for HR connector as B012 in Connector setting.

SPRO GRC parameters set to YES for below:

2050 - Enable Real time LDAP Search for Access Request User

5023 - Consider details from multiple data sources for missing user

details in access requests

Even then if it doesnt work then apply below notes:

1756290 - Incorrect Manager picked if employee itself is a manager

1949721 - GRC is pulling incorrect manager from HR system

2137424 - GRC ARQ : Manager details are not getting pulled for External users

2077724 - GRC ARQ 10.0: Incorrect Manager id showing for the HR data source



former_member193066
Active Contributor
0 Kudos

i had 2 hr and 3 ldap, and ids are stored in different places, i had to go for customization, issue has been solved long back.

thanks for the help.

regards,

prasant

Former Member
0 Kudos

Hi Prashant,

Please let me know what exactly  this domain id you are referring to ?

If I get your requirement correctly- that basically Managers  who are there in LDAP can login with their LDAP account and their details should be fetched from SAP HR  or any other HR system?

Regards

Pradeep

former_member193066
Active Contributor
0 Kudos

Hello Pradeep,

User login to end user URL using domain account,his SAP ID is populated in user id feild,

but his user details are fetched from LDAP, where as it should come from HR system,

as we maintain SAP ID in HR system as well.

Regards,

Prasant

Former Member
0 Kudos

Hi Prashant,

Please provide the screenshots to see the issue in detail if possible.

Regards

Pradeep

former_member193066
Active Contributor
0 Kudos

Hello Pradeep,

Issue is user details are not coming from HR system. but its coming from LDAP.

example; if i login using my domain account,

its shows my user id as ABC, but manager details all are coming from LDAP.

if i make change from self to other and type ABC and hit enter twice then it pulls details from HR system.

Regards,

Prasant

Former Member
0 Kudos

Hi Prashant,

So if I understand it correctly manager details also should be pulled from HR system and not from LDAP.

So basically you want during Access Request creation ,Userid  get  pulled  from LDAP  but all the other data/information  should be pulled from HR system ?

Regards

Pradeep