Access Enforcer Import Role Automation
We would like to automatically import roles from SAP.
We do know that you can use Role Expert which in itself can be used to automate the import. However, we still have to manually import into AE - even if RE is used as the role source.
Is there a way to periodically automate the import from either SAP or RE because it does not make sense to have to manuall import roles every time a new role is created in SAP.
Thanks
Actually, it does make sense.
One of the prime features of Access Enforcer is that you don't import all the roles, but just the ones you want users to be able to request.
For each of the roles, it's useful to put them into some kind of category (functional area, business process, sub-process), which makes handling for users a lot easier, and you have to assign approvers.
One way to do that is to use an Excel spreadsheet and manage the data there. Easy to use and update, and quick to upload into AE.
Kind regards,
Frank.
Similar Messages
-
Access Enforcer - REMOVE roles/existing roles inoperant
Hello
After some time using the capability to ADD and REMOVE roles when creating a request on Access Enforcer (using the option 'Existing Roles' to REMOVE), now Access back to the screen to ADD always that we try to access 'Existing Roles'.
So, the function to REMOVE roles are inoperant.
Any ideas what It cold be?Hi,
When you open a changing access request it's possible to add new roles and remove existing roles from the user, right?
However, the option to remove roles (which is accessed through the 'existing roles' button) is not working longer.
When that option is accessed, it's not showed anymore the current user's access: the screen returns to the add roles option.
I haven't found any setting for the feature to remove roles and still don't know how that option, previously used in other requests, is not working for anyone else.
Regards
Heverton Kesseler -
Access Enforcer(error in approving the request) and import roles
Dear all,
error in approving the request at security stage(last)
manager and role owner are successfully approved.
and also importing roles into access enforcer was not successful.
imortstatus : 0 roles imported of 28 records found.
please find the system log:
2008-09-05 13:01:34,625 [SAPEngine_Application_Thread[impl:3]_8] DEBUG com.virsa.ae.service.messaging.MessageFormatter : parseDesc : : INTO the method : desc :Please specify a file to import.paramNames :paramsMap :{FIELD_NAME=#_!FIELD_NAME#_!}
2008-09-05 13:01:34,625 [SAPEngine_Application_Thread[impl:3]_8] DEBUG com.virsa.ae.service.cache.AECacheUtil : getResourceBundle : : INTO the method : en
2008-09-05 13:01:34,625 [SAPEngine_Application_Thread[impl:3]_8] DEBUG com.virsa.ae.service.cache.AECacheUtil : getResourceBundle : : INTO the method : en
2008-09-05 13:01:34,625 [SAPEngine_Application_Thread[impl:3]_8] DEBUG com.virsa.ae.service.cache.AECacheUtil : getResourceBundle : : INTO the method : en
2008-09-05 13:01:34,625 [SAPEngine_Application_Thread[impl:3]_8] DEBUG com.virsa.ae.service.cache.AECacheUtil : getResourceBundle : : INTO the method : en
2008-09-05 13:01:34,625 [SAPEngine_Application_Thread[impl:3]_8] DEBUG com.virsa.ae.service.cache.AECacheUtil : getResourceBundle : : INTO the method : en
2008-09-05 13:02:28,234 [Thread-47] DEBUGIn Addition to my previous response:
I meant to include the following:
Some of the fields that need to be properly defined with attributes are:
System: must have the know SAP system defined here
Role Approver (i presently are using most of the roles without having need for approval; I created a user called NOAPPRV in AE)
Functional Area: need to have all the areas defined that roles will be assigned to
Company: I only have one company so that's an easy one
Some areas I presently do not use but found they must ne coded and coded properly:
ResponsibilityID: N/A (coded as is)
CommentsMandatory: NO (coded as is)
Parent Role Owner: NO
Business Process: NA (I believe I originally coded N/A and it did not like that)
Sub Process: NA (again N/A I believe error on me)
Reaffirm Period: presently I am using 0 (zero)
LastReaffirm: presently using 12/31/9999
Hope this helps a bit
I wanted to include an attachment with a sample of my Role Import spreadsheet but I'm not sure exactly how to do that; if I figure that out or someone can provide me the process I will include it
Jerry Synoga
Ryerson Inc.
630-758-2021 -
Access Enforcer and Import Roles
Hi All,
I am having issues importing roles that have the exact same name across different systems. This makes it almost impossible to implement Access enforcer across Dev/QA and Production environments at once. I would have thought that AE uses the (System ID, role name) as the key for that particular table used.
Has anyone managed to find a workaround for this?
Cheers,
CuneytNevermind i have solved the problem.
-
Access Enforcer Role Import - Reaffirm period
Hello
What does the following terms mean;
last reaffirm
reaffirmperiod
We current upload roles into AE, with last reaffirm as current date, and reaffirmperiod of 60 which means 5 years.
Can someone please explain what these terms mean, because many roles have reaffirm periods that end in 2010.
ThanksHi Prakas,
Reaffirm period ( in months ) is the duration after which you would like the Approver of the Role ( Role Owner /Role Approver ) to get notified on which all user in SAP has access to that Role and Does he want to continue giving that role to them or wants to remove that Role from all of them or any one of them .
He would get the details on which Role requires Reaffrim at following location :
In AE 5.2 ; login with Role approver id ( eg ABC ) into AE .
In tab Access Enforcer > Reaffirm .
A list of All the roles of which ABC is apporver and which require re-affrim would display here.
ABC can now take approriate action by selecting the role name.
*Last reaffrim * is the date when the Role was Reaffrim /revisited/reassgined last.
In your scenario you have given Reaffrim period = 60 which means your Role Owner would get the Role in his Reaffrim inbox after 5 years .
This is not best practise . For security reason , SAP advices to keep the Reaffrim period to a maximum of 2 months.
I hope this answers your query .
Thanks
Jasmine -
Upload of role in Access Enforcer 5.2.
Hi All,
I need to upload roles in Access Enforcer from SAP ECC system. Actually i have uploaded the roles in Access Enforcer, but all unwanted roles have also got uploaded.
Now i need some way, first to clean entire uploaded roles & then upload selected roles.
Please suggest.
Thanks & Regards,
PravinHi Pravin,
Here are the steps:
1) Download all the roles into an excel spreadsheet:
Go to configuration -> Roles- Search roles -> Click on 'Export' button. This CUP, go to 'Search Roles'. Click on 'Search' button without providing any search criteria. This will return all the roles available in CUP. Now, click on Export button. CUP will export all the roles into Excel spreadsheet in the format which CUP understands.
2) Delete all the roles from CUP: Now, in the same screen as above, select all the roles and delete them.
3) Delete not needed roles from spreadsheet and upload it into CUP:
Now, delete all the unwanted roles from CUP and play with the spreadsheet to manipulate other parameters like role approvers, systems, business process etc and upload that spreadsheet into CUP.
Regards,
Alpesh
SAP GRC Manager (PwC) -
Error in accessing imported roles
Hi All,
I am facing a problem while i am accessing roles which are imported from one portal to another.These roles are already assigned to iviews.I created a new user into a portal and assigned a imported role to that user.So while i am logging to the portal as the specified user then the iview related to that role should be visible to the user.But i couldnt find anything except a blank iview with portal desktop.
Is there any changes which i need to do specially for the roles which are imported from a epa file?
Please put your suggessions.
Thanks you in advance.
ChaitaliI am facing a problem while i am accessing roles which are imported from one portal to another.These roles are already assigned to iviews.
Did you tranport the iviews and roles or just the roles ? Do you already have the iviews with the same object id and object prefix on the target portal ?
Just click on the imported role on the target portal and check if you can see those iviews attached to this role ?
Hope this helps.
Cheers,
Sunil
PS: Reward points for helpful answers. -
Access Enforcer - Role Reaffirmation
Hi,
Access Enforcer offers a role <-> user assignment reaffirmation after a defined period.
My question is, what happens if using the Remove or Hold button in the Role Reaffirm menu entry.
I tried removing the access, but all that happens is the user entry is marked as "Remove".
Should an automatic Request for the role removal be triggered or what's the purpose of these two options?
Thanks,
DanielaI answered the question myself.
Hold will keep the role in the queue to reaffirm.
Remove will automatically remove the role from the user once all user-role assignments have either been affirmed or removed. -
Access Enforcer/ CUP - Export/ Import?
Hi, I wanted to know if there is a export functionality in the access enforcer/CUP (GRC v 5.2)?? I wanted to export the workflows and other items I have created outside the current environment and import it to a different environment. Is this actually possible??
Thanks,
KenHi,
You can go to configuration -> initial system data and select the checkboxes in front of the data you want to export. Click on export button and save the file. Now, you can import this data by going to same place in the other CUP system and import the file with 'clean and insert' option.
Regards,
Alpesh -
CUA still necessary/recommended with Access Enforcer?
Hello forum members,
we are planning to implement SAP GRC Access Control for one of our clients. There are 5 R/3 Systems in the landscape, one of them a HR System. Currently there is no CUA in place an all users and roles are maintained separately in each system. Now with the introduction of GRC Access Control there is the question, if we should at the same time also have a CUA introduced or if it is better to directly provision the Users and Roles from Access Enforcer to the target systems.
What are the pros/cons to have a CUA in between? Does Access Enforcer also provide overview on all users in all system and the assigned roles?
Thanks for your replies.This is a question that I'm asked all the time. For some environments, using CUA with AE is really nice. For other environments, it's just not feasible to have CUA as the security authorisation strategies are too inconsistent across systems.
For example:
a. There are three systems (ECC, BI, and SRM) implemented with a consistent top-down (job) approach to defining roles. So, a AP clerk will receive the 'AP Clerk' role in ECC, 'AP Clerk' role in BI, and 'AP Clerk' role in SRM (for simplicity). Obviously, the roles are different as they are for different systems, but the point is, it is easy to categorise the authorisations for a particular job across each of the systems. If security is consistent like this, then CUA can be implemented and the three single roles for the three systems can be grouped together in a cross-system composite role called 'AP Clerk'. When AE is implemented over the top of this, a user only has to request the 'AP Clerk' role (composite). AE performs the workflows, risk analysis etc and then finally passes the request to CUA, which then provisions out to the other two systems. Very easy from a user point of view as they only have to request one role, which is their job.
b. If however due to inconsistency between the systems, it is not feasible to group access into cross-system composites, it may just be better to go with AE without CUA. In this scenario, a user must request the applicable roles from each of the three systems. It is more flexible, but a little more difficult for the end user.
I normally spend quite a bit of time developing the Access Controls strategy during the blueprint phase of the implementation just to make sure that I'm coming up with the optimal design. A bit of prototyping helps also! -
Can access enforcer be implemented with going through the SOD check.
Hi All,
I have couple of questions regarding Access enforcer:
1. Can Access enforcer be implemented with going through the SOD check?
2. Can we provision roles for the project team using Access Enforcer (without having a million SOD conflicts which need to be cleared)?
I would really appreciate any insight on these questions.
Thankshttps://websmp103.sap-ag.de/~form/sapnet?_FRAME=OBJECT&_HIER_KEY=501100035870000015092&_HIER_KEY=601100035870000206624&_HIER_KEY=601100035870000212731&_HIER_KEY=601100035870000210510&_HIER_KEY=701100035871000519581&_SCENARIO=01100035870000000202&#HOME
-
Do anybody know where I can find information about Access Enforcer? What I'm interested in is what steps are required to implement the application for user automation.
Try these sites....
http://www.virsa.com/products/access_enforcer.php
http://www.sap.com/solutions/grc/accessandauthorization/index.epx
HB -
Restricting access for import manager and syndicator
Hi All,
I wanted to know whether is there any way on how we can restrict the access to import manger and syndicator.
I have one scenario whether user needs to be given the access to data manager only but not to other components.It is ok if they are able to open but should not be able to import or syndicate.
Please help in this
Thanks
NitinHi Nitin,
No i get your point Nitin,I said if a unwanted user logs into Import manager he can try to add/modify/replace record,this can be stopped if he is not given the rights.For this go to Console,Admin table and goto Roles and set rights and privileges on that.
whenever a user logs into Import Manager he has to give his user id and password,and from there we can control this.
If he tries to import records,it will fail.also if he tries to modify map,it wil fail too.
To get a clearer picture try doing it for one user and run this scenario.
An excerpt froim reference guide:
"The groups and functions displayed in the Name column are listed in Table 89; access privileges for each function are directly editable in the Functions pane"
record - Add records
Modify records
Modify checked out records
Delete records
Merge records
Merge checked out records
Protect records
Unprotect records
Check out records
Check out new records
Check in owned records
Roll back owned records
Check in non-owned records
Roll back non-owned records
Modify join permissions for non-owned records
Consolidation and distribution - Add import maps
Modify import maps
Delete import maps
Add syndication maps
Modify syndication maps
Delete syndication maps
Enable key mappin
You can control these setting privileges in Console.
thanks,
Ravi -
CUA vs. Access Enforcer
Can anyone explain the need for implemented both CUA and Access Enforcer?
We are currently upgrading to ECC6.0 and implementing the GRC tools(5.2) and CUA With the distributed access provisioning available in Access Enforcer, I am trying to determine the benefit of implementing CUA .Hi Patrick
1) In this scenario the only benefit with CUA i can see is
a) Password reset
b) locking and unlocking the user.
2) If you use GRC AC in landscape, it is not at all recommended to assign roles, profiles using CUA. This can lead to high level compliance /regulatory issues.
3) If you are implementing new CUA, then i would recommend to go for NW Identity Management Solution. Advantages are
1) User provisioning for SAP and non-SAP system
2) can be integrated with GRC for Risk analysis and remediation.
3) Password Management also possible.
https://www.sdn.sap.com/irj/sdn/nw-identitymanagement
regards
Anand.M -
Risk Analysis Error - Access Enforcer
Hi Experts,
I am getting error while running risk analysis in Access Enforcer and the error is
<b>Risk analysis failed: Exception in getting the results from the web service : Service call exception; nested exception is: java.lang.Exception: Incorrect content-type found 'text/html'
</b>
We are using seperate RFC IDs for Access Enforcer connector and Comlaince Calibrator connector.
Please help me.
Thanks&Regards,
VijayReddy,
The user must indeed be created in the UME as a Compliance Calibrator user.
I don't know exactly which role he should be assigned, usually I indicate there my CC admin user-id and password.
When you see it is working with that user-id, you can try to re-fine the roles.
Some more info regarding what needs to be set in the URI in case the one I inducated in my previous answer is not working:
"There are two selectable versions of Compliance Calibrator. If you select 5.0 Web Service, three additional fields appear (URI, UserName, and Password). For the URI field, you need to navigate to the SAP NetWeaver Web Application Server Home page > Web Services Navigator > CCRiskAnalysisService > WSDLs > Standard link of Document, where you will see a list of all web services in the server. Select the desired URI address. If you select Compliance Calibrator 4.0, there is no need to connect to a URI address."
Karim
Maybe you are looking for
-
Trying to insert a single row in a table based on NOT EXIST
Hi, I have a procedure where i am doing an insert into the table say create table ABC(PK number, valu varchar2(10)); insert into ABC values(1,'hi'); Now my problem is that this procedure may be run several times so if a PK already exists, it should n
-
Spotlight and Finder related problems
Lately Spotlight hasn't been too keen on finding things in my drive, most notably applications. Once or twice, I experienced problems with Finder while this was occurring, so I relaunched Finder and everything began working properly. But lately I hav
-
I have two iMac's one running 10.6.8 and the other 10.8.2 What Apeture program should I purchase?
-
I reaaally hate how anti-procrastination apps like ColdTurkey don't work for apple products, because what's the point of restricting internet usage on the computer when you can just access it from your apple device? There's no point in using the pare
-
Correspondance for customer statements F.27
Dear all I am trying to select a standard form to print customer statements but it is not working. I think it is something not correct in customising. Can anyone send me the steps to do this please. Also when using F.27 I cannot print all the selecte