cancel
Showing results for 
Search instead for 
Did you mean: 

Removal of roles from GRC 10.1 from user access

former_member349600
Participant
0 Kudos

Hi All,

I have deleted few roles from my ECC system . We are using GRC 10.1 for provisioning the user access in production I would like to know how I can delete the same roles in or disable them in GRC , so the roles can not provisioned to any user.

Accepted Solutions (1)

Accepted Solutions (1)

kevin_tucholke1
Contributor
0 Kudos

In NWBC, go to Access Management workcenter.  Then go to Role Maintenance quick link.  This will open a role query.  Locate the role in question.  Hightlight and click open.  You may need to click edit.  Go to Provisioning tab, and set Allow Provisioning to N for all systems where the role has been deleted.

You can also DELETE the role from SAP Access Control by hightlight the role on the query screen and click Delete.

If you delete, then you will lose all change logs for the particular role in BRM.

Thanks

Kevin Tucholke

SAP America

alessandr0
Active Contributor
0 Kudos

Pradeep,

in addition to what Kevin has already mentioned I suggest an easier step with the role status. Each role has a status and only a role with a productive status is available for provisioning. So rather than changing all the "Allow Provisioning" flags from YES to NO simply change the role status to a non-productive one (mostly Development or Test). You can also consider to implement a new role status like "DELETED". As Kevin mentioned, we do not recommend to delete the role, since you then lose the history.

Hope this helps.


Regards,

Alessandro

former_member349600
Participant
0 Kudos

Thanks Alessandro for your answer.

Is there any way we can do change the provisioning status non productive only for hundred of roles at one shot.

I know through the file upload we can do that but not very sure if that will work.

Former Member
0 Kudos

Hi Pradeep,

    You can do that in 2 ways.

1. Through File Upload.

2. Through Role Update. Go to NWBC->Access Management->Role Mass Maintenance->Role Update.

Do let us know if you need more information.

Thanks,

Regards,

Fazil

Answers (0)