AC 10.1 Empty screen on User Level analysis

Hi all,
We have migrated our 5.3 Access Control System to 10.1 and all the post-installation steps are applied. We loaded the user and roles from our ERP System, created rules and generated them for our system. Parameter 1027 – Enable offline risk analysi is set to YES. We also ran the batch job for the risk analysis in Background (transaction GRAC_BATCH_RA). When we run the NWBC -> Access Management -> User Level for our System we get just an empty window – no error message, nothing. It doesn’t make a difference if we run it on action level, permission level with offline data or without, in foreground or background, the result is just an empty window. What might be the issue here ?
Thanks in advance
Bernd

Hello Bernd,
In GRC 10.1 there are a few new things. Can you tell which view you are running the report on? There are three in GRC 10.1; namely - Remediation view, Business View and Technical View. See screen below.
Most problems are on Remediation View (which is selected by default when you start running the RA). For traditional risk analysis report please run on the "Technical View" and see if you get results.
To fix the issue with the remediation view's blank screen please review following notes:
2040204 - Remediation View does not show up while running risk analysis
2035538 - Remediation view in Risk Analysis does not show any data
2099999 - Remediation View screen shows blank while Risk Analysis
Thanks
Sammukh

Similar Messages

  • Any way to have email address of the user in user level analysis report?

    Hi,
    Is their any way to get the users email address column in User Level Analysis report Result..??
    Any way or settings to add custom columns or the email address column in the displayed columns of the report ??

    Hi Pranjal
    If it's not an option to add the column from the screen you would need to look at customising the scren
    Below is an example for a different screen layout scenario
    Customizing Access Control Screens
    Regards
    Colleen

  • What is Execution Count in User Level Analysis?

    Hi,
    Can anyone through a light on that what is Execution Count Column means in User Level Analysis Report ,If it is the number of counts of the users execte the action then how we can discover or from when it counts the number of count ....??
    is it count from the starting of the user using that tcode or action?

    Hi Pranjal,
    Yes, Prashant is correct it counts from the first job run, but as it takes data from STAD, so the counting is actually as per the STAD data store setting.
    So if STAD store data for 4 days and if you run job in today it will count from 17.05.2014, make sure you have this job running regularly, if you miss this job run for more days than the retention period of STAD data, you may miss execution count for those days.
    Hope this clears your query.
    BR,
    Mangesh

  • Inconsistency Data between Role Level & User Level Risk Analysis

    Hi,
    When we run Role Level Risk Analysis for a role (Ex: XYZ), there is no SOD conflicts. But when we try to run the user level analysis, this role shows SOD conflicts. I mean, XYZ is assigned with other roles. Combination of other roles access may bring SOD conflict, thats fine, but here the challenge is role XYZ itself has SOD conflicts. The same does not appear when we run Role Level Risk Analysis!!
    How could this happen??
    Thanks,
    Karthik

    Hi Karthik,
    The role might be mitigated at role level.
    In RAR Anayze tool, click -More options to expand the selection options
    Chose "Exclude Mitigated Risks: No"

  • Issue in User Level Simulation in GRC 10.0

    Hello Every one,
    Before i Jump into the question, please find below the screen shot which tells about the B.P(Business process),Functions created in test system(GRC 10.0), where as the roles and corresponding users which have been created in back end system connecting to GRC 10.0.
    Now when i am trying to run a risk analysis on user TEST_RISK(TEST_ROLE_RISK role is assigned and pfa the authorizations in the role), i will be shown the Risk R001.
    Now i am trying to run user Level Simulation on the above user TEST_RISK and i am trying to simulate by adding a new role TEST_ROLE_RISK3 as shown in the below screenshot at Action level,Permission Level,Critical Action level ,Critical permission level.
    Even though i select the option, Risk from Simulation only, when i try to execute at action level , it is also showing me the risk which coming from the actual role assigned but not from the simulating one.
    Thanks and Regards,
    Naga.

    Hi Naga,
    there are some notes which might help to fix the problem. Especially the first might fix your problem.
    http://service.sap.com/sap/support/notes/1895502
    http://service.sap.com/sap/support/notes/1953347
    Please let us know if it helped.
    Regards,
    Alessandro

  • Issue with Total Number of SODs at user level.

    Friends,
    Quick question -
    We are using GRC 5.3 Production on NT 20003 server. and back end systems are ECC 6.0
    1.We added the Additional Role to one of the business users in ECC 6.0
    2.We ran the FULL synch after adding this role in backend.
    Issue : The total number of SODs did not change for users, even though the SODs for this business users did increase about 300.
    Locations of Screen
    Informer Tab ->> Risk Violoations.
    Analysis Type -> Users
    Does anyone has any idea how this numbers get interpreted?
    The Total number of Violations for permission should increase, if user level SOD gets increased, as per our understanding.
    PT

    It should be in below sequence -
    1. Full or incremental sync for user/role/profile
    2. Full or incremental batch risk analysis for role/user/profile
    3. Management report
    The view you see is management report, which is based upon above jobs. FIrst jobs does high level sync like user/role/profile addition/deletion etc. Second job actually does risk analysis. Third one fills up the management view. If your batch risk analysis was run on  Aug 30 aug 10 and management report after completion of the same, the report will show the same data till you run these jobs again even there are many changes in backend authorization.
    Hope it clarifies your query.
    Regards,
    Sabita

  • Running Risk analysis at User Level(CC)

    Hi
    Please Clear my query, wat is the difference between running the risk analysis at userlevel Violation count by Risk and Violation count by Permission.
    violation count by Permission, the total number of violations are 377,569.
    Violation count by Risk,the total number of violations are 11,716.
    Thanks & Regards

    Hi Karuna,
    When you perform Risk Analysis at User level and choose violation count by Permission/Risk. Here are the details of each analysis:
    1. Violation Count by Risk
    This analysis will display the count of how many SOD risks associated with the users existing in each business process like FI, HR, MM, PR, SD.
    It will display as a bar graph or pie chart. If you choose each of the business processes and drill down to the particular SOD risk,P001 then you can display how many users have that risk, P001
    2. Violation Count by Permission
    This analysis will display the count of SOD violations at the action/permission level associated with the users existing in each business process.
    If you choose the conflicting functions inside each SOD risk, and then expand on the permission tab you will understand why the huge number of violations it is showing.
    In the Risk information screen, in Conflicting Functions, click the AP02 u2013 Process Vendor Invoices link to display the SAP transaction codes and the authorization objects. There are 26 different transactions in SAP to Process Vendor Invoices and another 185 authorization object values u2013 all come preconfigured out of the box.
    Choose the Permission tab. Expand Action F-42. Open an authorization object to show field values. By looking at all possible permutations of actions/permissions of one business function with all actions/permissions of the second business function, you can understand how the system arrives at the number of violations.
    Hope this will help you understand better.
    Regards,
    Kiran Kandepalli.

  • Risk Analysis at user level shows nothing in all 3 views though at role level shows risks of global rule set

    I am configuring ARA 10.1 for a ECC 6.0 plug in development system and facing this issue. Risk Analysis at user level shows no data  in all 3 views though at role level shows risks of global rule set. I am using Global rule set. I generated all risks/functions & using connector group as SAP_ECCS_LG not SAP_R3_LG.I activated common, R/3 & ECCS BC sets. Added integration scenario for AUTH. Run all 4 sync jobs multiple times successfully. My system already has decentralised EAM 10.1 implemented & even used in production as BAU. I have checked at both chrome & IE. The misleading thing is that RFC is also working fine & I can see risks in Risk Analysis at role level & risky roles are even assigned to valid users.GRC is at SP4 & accordingly is the ECC 6.0 plug in. Thanks in Advance. Please  consider it urgent.

    Hi,
    Assign ECC connector to SAP_ECCS_LG group.
    Run the programs GRAC_PFCG_AUTHORIZATION_SYNCand GRAC_REPOSITORY_OBJECT_SYNC) in full synch mode(this might take time so better do this in background). Better do it sequentially.Check the logs of the jobs in SLG1 just to ensure everythings fine.
    Run ARA for a specific user and mention the connector for faster output. Ensure this user has the role with risks.Also as explained earlier check the GUID against user id in table GRACUSERROLE and using GRACROLE you can find out the technical name of the role updated in the table. This should be same as the backend role.
    Then run ARA and while doing so please ensure the selection screen doesnt have any unwanted default inputs. If followed correctly , this should be of help.  I am assuming the role analysis yielded correct risks as configured since this would mean that connector have correct actions and basic config is in place.
    Regards,
    Vivek

  • MSS Status overview displays empty screen

    Hi
    We are configring the MSS PCR under the Team workset.
    Under PCR when the option for Status Overview for Personnel Change Requests  are clicked, I get an empty screen.
    Is there any additional configurations required?
    We are using EP7.0, ECC6.0 (nw2004s)
    Thanks for your help
    Regards
    Madhu

    Hi Ulrike,
    I replicated exactly the steps your described but do not see the same system behaviour. On my system, just after creating the cart, in the section 'Approval status details for selected item', the status is 'No user decision'.
    I searched notes and messages and found nothing related to this issue.
    Can you send me screenshots showing exactly the steps you followed just to make sure I am following same steps in the replication.
    Cheers,
    Siobhan

  • How to mitigate control at User levels

    Hello Friends,
    Can anyone send me step by step process documentation on how to mitigating control at user levels? I have already run the risk analysis ( Global Conflict roles analysis/risk analysis). So I do have all detail information like control ID , management approver and description,etc.
    It will be highly appreciated on any guidence on this.
    Regards,
    Suvi

    Hi,
    Please follow the below steps to mitigate user.
    1.  once you get the all details ( Mitigation control id, approver id and Monitor id), then select/click on the RAR Mitigation tab-> click on the Mitigated User option->search.
    There is one page is open and then click on ADD button at the bottom of the screen. once you click on add option it will ask the Mitigation control id, user id, Risk id etc... once filled the all required filelds and save. Now successfully applied the moitihation control to the particler user.
    Regrads,
    Arjuna.

  • Single registeration form to capture different user levels

    Hi there,
    I am currently working on a business catalyst website project and I have a trouble defining different user levels on single registeration form. Here is the detail of what I am looking for.
    I have a registeration form on the site and we have two types of users, one is student and the other is professor. My client wants to just keep one form with tick boxes at bottom of the form i.e Create my account as a Student & Create my account as a Professor. So clicking on any one will process the registeration for the selected user level. (If I select Create my account as a Student, the form should register me as a Student or wise versa)
    I am not sure if business catalyst offers this feature or any possiblity to achieve it. Could anyone pls give me some help on this?
    Thank you in Advance,
    Anand

    Yes , the T-Codes give same results in diff. users when they were being executed seperately.
    When I am executing all those using my program the following things happen
    1-  Those tcode working fine and producing same result as if they were being run independeltly in my user-id.
    2-  The productiong order is getting locked in CO02 and variance are also getting calculated in my user-id.
    3- When  I am running same program in other user-id, I am always getting formatting erros for T-code KGI2 for the fileds
      CODIA-AUFNR and RAKUF-FROM.
    4- I have used  ALFA routine  to convert AUFNR as its being used in that KGI2 screen in similar way.
    5- I have used NUMC format for FROM and condense its value before passing in to KGI2 screen.
    6- While executing BDC  I am passing following options.
      wa_opt-dismode = 'N'.
      wa_opt-updmode = 'A'.
      wa_opt-cattmode = ' '.
      wa_opt-defsize =  ' '.
      wa_opt-racommit = ' '.
    I have tried several combinations for these options, but didnt work.
    SOS.

  • Empty screen at starting webclient

    hi *,
    we're getting an empty screen, when starting the crm2007 webclient. by empty i mean that the skin is loaded, i can recognize the L-structure, the back-button is also visible and at the position where in standard skin normally used to appear a picture there is only written 'Hello, I am empty      Hello, I am empty'... but there ain't no navigation bar or functional links...
    any suggestions?
    regards, tom

    Ho Thomas,
    Could you please try the following:
    a) On SAP standard menu -> right click on 'Favorites' folder -> select 'Add Other Objects' -> select 'BSP Application' from pop-up -> enter BSP Application = CRM_UI_FRAME, Description = Log-on Page and Start Page = default.htm -> save
    b) Double-click on Log-on Page (favorites folder) -> enter USER = CRM USER (example: CRMUSER01), enter Password = xxxxx ->
    should display your business role specific new CRM WEB UI
    Please note that you have to try 5/6 times - if you are activating CRM WEB UI for the first time due to the default time out session. You can  monitor the process in SM50...
    Once again, I strongly suggest you to check the link which I forwarded to you to make sure that all the steps have been taken care...
    Still, you are having the problem - please don't hesitate to let me know...
    Cheers,
    Peter J.

  • ESS: empty screen

    Hello,
    I'm just implementing ESS on an EP6 / ECC 6 (both on the highest av. service pack)
    If I start ESS in the portal I see the homepage framework properly but if I click an an application group f.e. time management I get only empty screens.
    Can anybody help please?
    Thanks
    Eric
    P.S.:
    I have imported the necessary packages ESS and XSS and deployed (they are shown in in the Content Manager).
    I have configured the JCos and tested them successfully.
    In the HR System I have an user with unlimited rights and an attached personal id.
    I use the Homepage Framework from client 000

    Hi Eric
    As I understand
    1. You can view the home page tab (overview) where there are links to areas like time management, personal data etc.
    2. when you select time management you view blank page.
    if above is correct then
    1. check the if there are services and resources attached properly in the home page frame work.
    2. What is the ERP(R3) authorization given to the user with which you are using to access ESS.
    We had a similar issue which was due to ERP authorization. Please ask your security consultant to activate and attach SAP_ESSUSER_ERP05 role to your user.
    PLEASE MAKE SURE YOU GENERATE THE ROLE BEFORE ACTIVATING.
    We have been able to resolve such issues before. Do reply.
    regards
    Barin
    Edited by: Barin Desai on Apr 15, 2009 1:04 PM

  • How to prevent error message for material description in MDG material detail screen, when user click on check action

    Dear Experts,
    I have a requirement for making material description as non mandetory in change request view of mdg material screen.
    I have done that using field usage in get data method of feeder classes, but still message is displaying.
    This message 'Material description is mandatory is displaying with check action only, but not with save or submit after i anhance field property as not mandetory.
    How to prevent error message for material description in MDG material detail screen, when user click on check action.
    Thanks
    Sukumar

    Hello Sukumar
    In IMG activity "Configure Properties of Change Request Step", you can completely deactivate the reuse area checks (but will then loose all other checks of the backend business logic as well).
    You can also set the error severity of the checks from Error to Warning (per CR type, not per check).
    Or you provide a default value for the material description, e.g. by implementing the BAdI USMD_RULE_SERVICE.
    Regards, Ingo Bruß

  • Make all the forms at a user level or responsibility level to be read only

    Hi,
    Please suggest me to make all the forms at a user level or responsibility level to be read only. So that when a particular user logs in, he gets all the form in read only mode or at a particular responsibility all the forms are read only so that we can attach this responsibility to the user for the same purpose.
    Any ideas will be highly appreciated.

    check this blog,
    http://www.oracleappshub.com/11i/oracleapps-responsibility-vs-sap-functions/
    Re: How to change OM responsibility as read-only in oracle applications 11i
    read only responsibility-user

Maybe you are looking for