cancel
Showing results for 
Search instead for 
Did you mean: 

Risk Analysis Issue in Template Based Access Requests

madhusap
Active Contributor
0 Kudos

Hi All,

We have set parameter 1071 as YES to make risk analysis run up on request submission.

We also have multiple instances of parameter 1023 with values 02, 03 and 04 (Permission, Critical Action and Critical Permission level)

We have 2 types of requests

1. Normal Access Request

2. Template Based Access Request

1. During Normal Access request submission, risk analysis is running up on submission and once the request goes to approvers after SUBMISSION,

approvers are able to see risk analysis at all 3 levels (Permission, Critical Action and Critical Permission level).

Based on those results, they are mitigating the access and Approve/Rejecting the roles.

2. During Template based Access request submission, risk analysis is running up on submission and once the request goes to approvers after SUBMISSION,

approvers are able to see risk analysis only for 2 levels Critical Action and Critical Permission level). Permission Level risks are not showing up and also

report type "Permission Level" is not even coming in the drop down list.

As per our understanding even though permission Level analysis report has "No Violations", request should show "Permission Level" report type in the drop down in the same way as shown in Normal Access Requests

We also observed that for few requests, even though there are permission Level violations, they were not shown in the request and hence the approver approved the request and user got roles which had violations.

Anyone faced similar issue, please share if you have any suggestions.

Regards,

Madhu

Accepted Solutions (0)

Answers (1)

Answers (1)

madhusap
Active Contributor
0 Kudos

Hi All,

We have found that if there are "No Violations" then that particular report type is not shown in drop down. But we have "Show All Objects" in risk analysis parameter enabled so report should show up in dropdown even though there are "No Violations" with message "No Violations Found".

We raised this to SAP and will update the thread once we get the answer

Regards,

Madhu