on 03-12-2015 6:17 PM
Hello Everyone,
I am completely new to GRC and we have got a new request and here are the details,
We are on GRC 10.0 and there was some kind of a mass role update done on our GRC production system which has removed a role for a group of users in ECC PRD.
So, If I need to add that role back to the user how do I do it from GRC? I know it can be done directly from ECC PRD, but I have heard from clients that it should not be done directly on ECC.
So Please help me out with any suggestions/solutions.
Regards,
Nikil
Thank you for your response Faizal and Madhu. And thanks for making me understand the process.
Is there a way to directly assign the role without sending it to approver? Also, What happens after the role is approved? How is it assigned to users in GRC?
Regards,
Nikilesh
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Nikilesh,
Once the request is approved roles will be auto provisioned to the user in target system. This depends on your provisioning settings.
Anyways since you are new to GRC, I can suggest you to go through different links, blogs and documents available in SCN to understand the functionality and I also suggest to go for GRC 300 training to understand the module better and if possible practice in your sandbox for learning.
If you are directly assigning the roles with out any approvals then there is no compliance being followed and GRC is a security and SOD audit tool to make sure that there is proper audit trial and system is risk free.during all user and role changes.
Regards,
Madhu.
Hi Madhu,
As you said i do need to go through documents on GRC security and I will do that.
But, my question is, is it possible to push a role from GRC to ECC without going through approval? I am trying this scenario on our Sandbox server just to make sure it works.
Thanks in advance.
Regards,
Nikilesh
Hi Nikilesh,
Go to NWBC Page --> Access Management --> Access Request Creation -->Access Request. PFB the screen.
In the new screen that opens, select 'Multiple' under Request For and select the Business Process and the mandatory fields that appear. And add the users below as shown.
After this go to User Access and click on Add->Role. You will see a search pop up. Search for the Role by giving the correct search criteria and add the role. Once this is done, review and submit. Ask the appropriate approvers to approve the same. But make sure that the role is imported before you search it here. Let us know if you face any difficulty.
Regards,
Fazil
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Nikilesh,
If it is the same role which is removed from all users then you can use Request For "MULTIPLE" option and can raise grc requests which goes for approvals based on your workflow paths and once approved user roles will be restored back.
You can check lot of discussions and blogs in this space to understand more about MULTIPLE request type for users.
Regards,
Madhu.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.