on 08-23-2016 4:48 PM
Hi All,
I have deleted few roles from my ECC system . We are using GRC 10.1 for provisioning the user access in production I would like to know how I can delete the same roles in or disable them in GRC , so the roles can not provisioned to any user.
In NWBC, go to Access Management workcenter. Then go to Role Maintenance quick link. This will open a role query. Locate the role in question. Hightlight and click open. You may need to click edit. Go to Provisioning tab, and set Allow Provisioning to N for all systems where the role has been deleted.
You can also DELETE the role from SAP Access Control by hightlight the role on the query screen and click Delete.
If you delete, then you will lose all change logs for the particular role in BRM.
Thanks
Kevin Tucholke
SAP America
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Pradeep,
in addition to what Kevin has already mentioned I suggest an easier step with the role status. Each role has a status and only a role with a productive status is available for provisioning. So rather than changing all the "Allow Provisioning" flags from YES to NO simply change the role status to a non-productive one (mostly Development or Test). You can also consider to implement a new role status like "DELETED". As Kevin mentioned, we do not recommend to delete the role, since you then lose the history.
Hope this helps.
Regards,
Alessandro
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.