cancel
Showing results for 
Search instead for 
Did you mean: 

SAP IDM - GRC Integration Scenario Query

Former Member
0 Kudos

Hello Experts

I want to understand if the following scenario is possible or not. Or if any alternate is available. Please share your thoughts..

Current Situation:

SAP IDM 7.2, SP9, Patch 11, in use with SAP Provisioning Framework 2 and GRC Provisioning Framework 2

SAP GRC Access Control 10.1

Both systems installed, configured and connected (web service connection works well)

Desired scenario:

Business Roles will be requested for assignment in IDM. For each privilege that is contained in the Business Role, IDM will trigger the Risk Analysis task and GRC will perform a risk analysis (privilege grouping not yet defined).

If the GRC risk analysis does not discover a risk, IDM will continue the assignment process of the privileges (or rather Business Role) following the approval workflow defined in IDM.

If the GRC risk analysis discovers a risk, IDM will trigger the AC Validation task and GRC will create a validation request. This request has to be mitigated in GRC. The result will be handed over to IDM and will there be processed accordingly.

Problem:

In IDM only one task from the GRC Provisioning Framework 2 can be triggered when a privilege will be requested for assignment. In our case it’s the “AC Validation – Risk Analysis only” task:

…and the “AC Validation” task:

Using the “Risk Analysis only” task processes the pending value object right after receiving the GRC response. This prevents us from post-processing or modifying the pending value object. The assignment will directly be assigned or rejected.

That means we can either have a risk analysis only OR we’ll have a GRC AC validation request for any privilege assignment request! This is not the foreseen scenario. We want to perform a risk analysis for eacht privilege assignment and if a risk is detected in GRC, a mitigation request shall be started in GRC.

Question:

How can this problem be solved? Is the desired scenario feasible?

Thanks a lot in advance.

Regards,

Krishna.

Accepted Solutions (0)

Answers (2)

Answers (2)

jaisuryan
Active Contributor
0 Kudos

Hi Krishna,


I suppose AC Validation – Risk Analysis only" should suffice your requirement from IDM side.


IDM prepares risk analysis request, submits the request to GRC and process the output of risk analysis.


Rest to be config'd in SAP GRC side. GRC should receive the request from IDM, performs risk analysis and creates request for remediation and send out of request to IDM. Did you check with your SAP GRC Consultant if workflows and WS are correctly configured in GRC side?


Kind regards,

Jai

Former Member
0 Kudos

http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/70a537eb-b486-3110-30a7-a5ec24222...Hi Krishna,

You can refer to the guide below - section 1.2.1 Landscape configuration scenarios : AC validation also perform risk analysis but specifically used in the case of distributed provisioning. AC validation - Risk Analysis only is recommended to be used for centralized provisioning. Both tasks can be used alternatively and will perform risk analysis in AC.