CUA and SU10: unexpected deletion in all child systems

Hi,
I am facing with a problem with SU10 and CUA.
I have updated a lot of users with SU10 in CUA. For 20 users in a child system, I first add a new role, everything is fine. Then I perform a remove of a old role (I know that the end date will be changed), everything is fine except for one user. All roles were removed from all systems where the user is defined ! However, when I look in each child systems, it is not the case, the roles are well present except in the child sytem for which I do the remove.
This problem occurs twice, for different users. It is a real problem because we have to adapt a lot of users.
I have reinstalled the 'missing' roles with SCUG and with the change document for users but it can be a workaround because I have discovered this by chance. I can imagine check all users after each run of SU10.
Hope someone can help me.
Regards

Hi Olivier,
that sounds like you are facing the problem corrected with sap note #1117530......
The removal shows up only at the next change of a user, the actual deletion of role assignements because of the copy might have happend already some time ago.....
b.rgds, Bernhard

Similar Messages

  • I have many duplicate contacts on my iphone and want to delete them all at once and sync with my mac that has the contacts correct.  Is there a way to delete them all from my iphone?

    I have many duplicate contacts on my iphone and want to delete them all and start over by syncing to my mac's address book.  Is there a way to delete the contacts all at once?  I started icloud and the iphone caused duplicates there also. 

    I have exactly the same problem on my ipad. It is happening on only some contacts but, as with you, when I delete one of the contacts on the ipad, the second ipad contact and the contact on the imac are also deleted. This is even the case when I have differentiated the two contacts on the ipad and can see the one I have deleted on the ipad is not the same one as is then deleted on the imac.

  • Push SAP passwords to all child systems

    Hi,
    I use IDM 8.0 to connect a CUA.
    Has anybody been able to push IDM password to CUA and all child systems (ECC, BI, SAP Portal, Solution Manager...) ?
    I can only change password on the CUA but not on the child systems the users have access to.
    When I change a user password in IDM, I can see in SAP logs that the password is changed in the CUA (if the user has access to the CUA, which is not the case for all the users) but instead of changing the user password in the child systems it only try to unlock it (which is useless).
    Any help ?
    Thanks,
    Ben

    For your information, looks like it was a bug corrected in IdM 8.0 patch 8.
    I didn't try it so I can't confirm it works now.
    Ben

  • TS3276 Is it possible to delete mail from your iPhone and it be deleted from all your Apple devices?

    I would like to delete mail from all my Apple devices in one go rather than having to access each individually and then read/delete on each, is this possible? I have a Mac Book Pro an iPad mini and an iPhone 5.
    Any help would be gratefully received.
    Regards,
    Andy

    It depends on the email you use, if you have a provider that only allows POP then it is not possible. If your provider supports Imap or Exchange then it is.
    Who is your email provider?

  • Deletion doent reflect child system

    Hi All,
    We have deleted a composite role from CUA,but to our suprise single role still exist in child system. How to delete these now?
    We have tried to re-distrubute the idoc- unsuccessful
    We cant use PRGN_COMPRESS_TIMES  as CUA is conneted.
    Any help will be appreciated.
    Thank you,
    Sri

    Hi,
    What is the status of the Idocs in Central system and Child systems? Are they processed properly? If yes and still you see the Single Roles in the child system then do the following:
    1. Check the Composite role first in the child system (and in central also if it is existing there too). If the role is not ok to see then first take of it.
    2. Do a text comparison in the Central system for the Respective Child system(s) and save the user once more by getting into change mode.  Now check whether the roles are gone or not.
    3. if the single roles are still there then assign the composite role once more and save and then remove it again. Check the SCUL status for the user id and process it if not processed already.
    4. process the IDocs manually in BD87 if not processed in the central and / or Child system(s).
    Let us know how it goes.
    regards,
    Dipanjan

  • CUA: Model view not created automatically in Child System

    Hi, I try to create a CUA with just a child system thru txn SCUA. The result of generation is good and all green. The part that is not right is I do not see the model view created in txn BD64 of child system, I can see it created in master system. Both RFC of master and child system are working fine. I do not see errors at WE20 & WE21 as well. Under this situation, I can see CUA active in master system but not child system. Hence, CUA is not working as it says in master system.
    I have setup CUA couple of times before but this is the first time that I encounter such a weird situation. Does anyone has any clue where could have gone wrong?
    Edited by: Annie Chan on Jul 25, 2008 5:23 PM

    Hi Everyone,
    It is indeed a RFC issue but it was a silly mistake with the incorrect hostname that I am suppose to connect to. Hence, the Distribution Model doesn't exist in the child system. Nervertheless, your advise does point to the right direction.
    Thanks so much for your input. Points are granted as accordingly.
    Regards,
    Annie

  • CUA: Distribute users from central to specified child systems

    Hello!
    I've a question concerning CUA: I've added two new systems to our CUA. Now I want to destribute the users of the central-system to the new child-systems accompanied by assigning a specifed role for the child-systems. Unfortunately, the user maintanance - mass changes (SU10) does not support assigning the child-systems to users.
    Is there any other possibility (perhaps a report) to automatically distribute the users or is it necessary to access each user manually and assign the child-systems and roles.
    Any hint would be appreciated!
    Thanks in advance!
    Greetings
    Wolfgang

    Sorry, I was convinced that mass changes don't work for systems - but they do! Next time I'm going to check possibilities in more detail!
    Greetings
    Wolfgang

  • New role in CUA user record not getting pushed to child system

    I added a new child system to our CUA setup.  I've confirmed that the RFC connections from both sides are working properly (test connection succeeds) and I've successfully completed the user transfer function in SCUG.  All exisitng roles assigned to the users in the child system are now appearing in the CUA central system as expected.  I added a new role to a user via SU01 in the central system to this child system, but when I go to the child system, it does not appear in the user's SU01 record.  Any ideas why this would not be syncing properly?
    Thanks,
    Michael

    Hi,
    Whenever you create a new role in child system, it has to be sync up with the central system.
    To sync up with the central system, login to central system goto su01>enter any user name>go to roles tab- click on Text comparision from chiled system. Its navigate to another screen, there you have to mention the child system and click on execute. it syncs up with child sytem. Hope it will help you out to resolve the issue.
    If still you are getting the same issue login to the central system.. goto SE38-- enter the program name as "RSCCUSND" and click on execute there mention the user name and the logical system id of the Child system name, select the parameters which you wanted to distribute to child system and execute it.
    Best Regards
    Mani

  • How to delete users in the child systems with CUA?

    Hi All,
    We have:
    1.  My SAP ERP 2005  (ECC 6.0)+ Windows 64bit + Oracle 10
    2. EP 7.0 + Windows 64bit + Oracle 10
    3. BI 7.0 + Windows 64bit + Oracle 10
    4. Solution Manager 4.0 (CUA)
    We managed all our QA and DEV users in ECC, EP using CUA from the Solution Manager server (Productive servers  and all the BI  7.0 System Landscape aren't in the CUA).
    My problem is when i want to delete a user. Sometimes if you delete a user in the solution manager (where the CUA is defined) the user still  exists in the Child Systems. In fact you can  see it with the SU01 only in the child system. I guess the idea is that if you delete the user in the CUA them  the user is delete in the child system.
    I found this information in the SAP Help:
    As well as the authorizations already mentioned, you also need another authorization in the central system for object S_USER_SYS. You can only assign new systems to a new user with this authorization. ( No Problem with this )
    When a user is deleted in the central system, the system entry for the user is retained until the deletion is confirmed. If an error occurs, you can repeat the deletion by canceling the system (in the child system).
    What does mean: deletion is confirmed? 
    Best Regards,
    Erick Ilarraza

    Hi, thanks a lot for your reply.
    We used the SAP Transaction SCUG to solve CUA Problem.
    It is something about the refresh of the user in the Parent / Child systems, you need to Re-Refresh users and delete it again.
    Best Regrads,
    Erick Ilarraza

  • SAP CUA connector changes password in master system AND child systems?

    Please confirm if OIM can change the password in both SAP CUA master and child systems through SAP CUA connector. The connector guide mentions the following parameter can be defined in SAP CUA IT Resource.
    Parameter: SAPChangePasswordSystem Flag that accepts the value X or ' '
    If the value is X, then the password is changed
    only in the master system. If the value is ' ', then
    the password is changed in both master and child
    systems.
    This parameter is used by the Reset
    Password function.
    Thanks!

    Hi,
    1) You can use report RSCCUSND to distribute users from CUA to child client. Check section "Sending User Master Data to a Child System" in [CUA cookbook|http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/fe4f76cc-0601-0010-55a3-c4a1ab8397b1?quicklink=index&overridelayout=true].
    2) if the user account has not been synced to CUA then you should be able to delete it in child system. The button should be displayed for unsynced users. You can use transaction SCUG to sync users between new child system and CUA. Check section "Transfering Users from New System" in [CUA cookbook|http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/fe4f76cc-0601-0010-55a3-c4a1ab8397b1?quicklink=index&overridelayout=true].
    Cheers

  • How can i delete emails from my iphone or ipad one time and have it be deleted on all my devices?

    I have an iphone and ipad and want to be able to delete an email on one time and have it delete it all all my devices, including my MacBook Pro. I have Cloud set up.

    I think this might work. Im not sure though, but give it a try.
    Settings > iCloud
    Make sure Mail is turned on
    Delete the accounts you want to delete
    It should be gone from all devices

  • Integrate GRC 10.1 with CUA and how to import roles from CUA & Child systems into GRC for provisioning

    Hello,
    I am trying to integrate CUA into our GRC 10.1 system through the below steps and so far I have completed the below steps following SAP Notes 1680108 and 1616121:
    1. Connected CUABOX to GRCBOX like a plug-in system.
    2. Updated CUA Global System and CUA Model Distribution in Maintain CUA settings under User Provisioning.
    3. Next I am trying to import the roles from CUA(CUABOX) into GRC(GRCBOX) to be able to provision roles in CUA Child Systems(ECCBOX).
    After reading few discussions in SCN, I have figured that we have to download a template in Role Import and populate it accordingly to upload the CUA child system roles into GRC system for provisioning in CUA Child Systems.
    Unfortunately, this template has multiple fields and I am unable to determine the fields that should be populated as CUA Global System and CUA Child System to import into GRC. Also, when we upload CUA Child System Roles template what selections should be made in Role Import window.
    Any help in this regard is very helpful.
    Thank you,
    Pawan

    Hi Alessandro,
    I have "Create user if does not exist" setting checked for both change action and assign role action and also have CUA enabled. Here is the list of steps that I am performing:
    1. Create an access request for new account, T-CUA_CHILD and select a role from a child system ECC Z_ECC_ROLE_IN_CHILD_SYSTEM.
    2. Approvals provided to assign the ECC role.
    3. I see the following in GRFNMW_DBGMONITOR_WD.
               Auto provisioning activity at end of request at Path GRAC_DEFAULT_PATH and Stage              GRAC_SECURITY
                   New User:T-CUA_CHILD created in System(s): ECC (created without role assignments)
                   T-CUA_CHILD User does not exist in target system CUA
    GRC created an account without role assignment in ECC but also throwed me an error that the user does not exist in CUA.
    However, if I select roles from both CUA and ECC it creates the account in both systems with the selected role assignments.
    So I am wondering if there is way to provide CUA access to users by default for new account requests types. I have tried setting up default roles for CUA but it does not assign the roles by default until I select the CUA system.
    Thank you for your help!
    Pawan

  • HT4859 If I select 'delete' backup.  Can I ever access it again, and does delete on all my deviices?

    IF I select delet back in iCloud management and on a particular item that I may want to look at again in the distant future, can I ever access it again.?  And does it delete on all devises it was showing up on?  Thanks so much for any help

    If you delete an iCloud backup it is permanently deleted from your iCloud account.  After that it will no longer appear on any of your devices and you wouldn't be able to access it again.

  • Users were re-created in Child systems not in Cnetral System (CUA)

    Hi,
    The set of users were deleted some time back and today i verified in child system (PROD) with criteria as list of users without roles/profiles then I found a set of users in child systems.
    Were as those user master records are not showing in Central System (CUA).
    I verified the change document, It is showing the deleted date and later some time again it was created with no roles and profiles. On the same date all the others users are also get created.
    Then I have checked the change document of a user and verified is there any IDOC was generated in central system on that time and date but I didnu2019t find anything...
    I was expecting that the old IDOC's which are in status "distribution unconfirmed" with of the user and later there would be happen many changes for that user and which are get reflected in child system but the IDOC which was in unconfirmed status. When any one try's to execute the process through BDM2 or BD87 for that IDOC then again there would be chance of re-build the user account..... But one thing i was confused is if the old IDOC get re-generate then it has to be shown in the CUA system also?.
    It was strange issue, so please let me know what the reason behind it.....
    Please help me out...
    SV

    >
    Nishant Sourabh wrote:
    > I assume BD87 was executed in the child system and the idocs where manually processed which created these ids back again ....not sure if that is what happened. never seen something like that.
    Hi Nishant,
    what you are writing is the most common situation of how these users got 'recreated'.
    If you have a look at the method for user change idocs, you will notice, that it is the same method for creation and changing (CLONE).
    So if you have an unprocessed change idoc in the child system and you delete the user (succesfully) and reprocess this idoc in the child system locally, the user will get 'recreated'.
    b.rgds,
    Bernhard

  • User roles un-assigned in CUA but acces in child system is ok

    hi
    i am have a really weird issue. a user who has access in roles in child clients, suddenly his roles disappeared from CUA. it did not effect access in child systems. any suggestions how to investigate this.
    thanks

    Did you click the Naughty Button in SCUL? Check OSS Note 1074552...
    Could also be a cause of failing idocs.
    Regards,
    Trond
    PS: The above note is for cases where users loose their visible role assignments in CUA, although roles remain assigned in the child system(s), not for cases where role assignments from CUA never trickles through to the child systems. The mentioned OSS note is a direct result of a case worked on by yours truly in 2007. I include below a warning I posted on sapfans about the issue:
    Word of warning: RSUSR_CUA_CLEANUP_USZBVSYS is faulty!!!
    The program RSUSR_CUA_CLEANUP_USZBVSYS is available as a standard SAP program from at least version 6.20. It can be run from SE38/SA38 or launched from a pushbutton (far right) on the "results" screen of transaction SCUL.
    The program is intended to delete "obsolete" entries from table USZBVSYS, which contains log entries for assigned child systems in a CUA environment. The program is run in the main CUA system, and supposedly deletes entries for systems where users no longer have access.
    There is a serious problem with the program, as acknowledged and confirmed by SAP in an OSS note I opened a few days ago. Under certain circumstances (more than 500 entries for any child system in the CUA landscape), the program wipes clean the whole table, instead of just the obsolete entries.
    The consequences are dire. Table USZBVSYS is used for several fundamental CUA functions, such as remote password reset from the CUA master system. After the wipe, executing SU01 and attempting to reset a users password in a child system will no longer work. The assigned child systems are no longer visible in the reset password pop-up (nor anywhere else in SU01, including the Roles tab). You'll have to edit the user via SU01, and click on the annoying pop-up showing "new system assigned to user" for each system where the user has access...
    The only way to fix the issue is to re-run SCUG for all systems in the CUA landscape. We had to do this across 6 CUA's, each containing 30+ child systems/clients and 10000+ users, which was very time-consuming and annoying. Also, there seems to be cases where roles have been wiped out from users on the CUA master systems, possibly due to consequences of the empty USZBVSYS table.
    SAP has conceeded the program is faulty, and have proposed a new version (note 1074551). Without applying this correction, the program should NOT be run.
    Note that users can still log in to and work in the child systems, it's just the "visibility" from the CUA master system which is missing. Tables USLA04/USL04 are still intact.
    Just wanted to warn the community; we've spent some considerable time discussing with SAP and rectifying the mess created by RSUSR_CUA_CLEANUP_USZBVSYS...
    Edited by: Trond Stroemme on Aug 5, 2008 3:03 PM

Maybe you are looking for