CUA Role deletion

Hi All,
I'm supposed to  delete a role from the Child systems.When I'm trying to  delete role from  Central sys(CUA),role is not reflecting for the user,but user has the role in Child system.
Thanks  in Advance!
Regards,
Naveen

Hi Mili,
Can you just check what naveen has just said? He mentioned that he do not want to delete the composite role rather he just need to remove it from the user's access. Also he is not able to see the composite role assigned to the user in CUA, so he cannot delete it from there.
Naveen,
You can re-assign the composite role and check if the Idocs are moving to your child system. If it did, then this time re-login to CUA again and now remove this composite role. It should remove it from your child system as well.

Similar Messages

  • Administrator Role Deleted in Portal???

    Hi all,
    Accidentally administrator role deleted in UME.When i login j2ee_admin i deleted administrator role in UME what i do Now  plz tell me. How i found administrator role ???.Because sap predefined administrator role to j2ee_admin So i am not able to working in portal in UME all button is disabled.
    Help me Plz
    Thanks & Regards
    Kumar
    Message was edited by:
            Kumar

    Hello,
    May be you cud try out this:
    First of all give the user (J2ee_Admin) SAP_J2EE_Admin group.
    Now login to the usera administration of J2EE using the User with SAP_J2EE_Admin group.
    Next go to useradministration and then give the user (Self) different admin roles
    such as super admin, system admin, content admin etc.
    Hope this helps you.
    Regards,

  • Administrator Role deleted ???

    Hi all,
    Accidentally administrator role deleted in UME.When i login j2ee_admin i deleted administrator role in ume what i do Now i am login via j2ee_admin it gives error what i do plz tell me. How i found administrator role ???
    Help me Plz
    Thanks
    Kumar

    Hi Kumar:
    For all the non UME Roles content in Portal has some action. So I guess for Administrator Role should have an action pertaining to its admin responsibilities. Try to Create Role under Identity Management and assign the action equivalent to it.
    Goto:
    User Admin >  Identity Mgmt > Role > Create User > Give Name > Assign Action.
    Note: I'm currently not at EP server for few days, plz check the option said above and I hope they might work for you.
    If my guess is correct, you can get the Action for already existing Administrator Role from other EP Server in your organization.
    Tnx,
    Munna SAP

  • Mass Role Deletion Transport to ECC6

    Hi,
    Prior to transporting a mass role deletion through to the PRD ECC6 system, is it recommended to end date the majority of position to role relationships? End dating may maintain some visability of previous role assignments... Or is it safe to send it through and be confident that all the relationships will be removed as well as UMR based assignments?
    Any recommendations on this topics?
    Kind Regards
    Nathan

    Hi,
    Delete the roles through transports. but if you are concerning about the UMR history and end date for the roles. If so.. make sure there are no active assignments to the users.then there is no requirement for end date. in my idea generally UMR history will be there for deleted users and their assignments...as text.
    ~Praveen.

  • Role Deletion

    Hi
    I would like to delete a role from the DEV system and then have the deletion moved to Q and then P system.
    I have gone through  http://help.sap.com/saphelp_nw04/helpdata/en/e4/15e48efd6c11d296430000e82de14a/frameset.htm
    This reads "If you want the deletion to be transported, place the role objects in a transport request before deleting. To delete the role in a system linked by RFC (like a component system in Workplace), choose Role ® Distribute deletion."
    I am not sure as to how this needs to be done. How does one place the role objects in a transport request?
    If you have had a role deleted and then transported it, let me know how you have done it.
    - ravi

    Auke's answer is the correct one. Assign the role to a transport request BEFORE deleting it; this is easily done from the main screen of PFCG (just click the transport button!). If you delete the role first, BEFORE assigning it to a transport, you won't be able to assign it to any transport...
    When the role is deleted from dev and the transport is subsequently released, the role will be deleted from the downstreams systems.
    You can, of course, also create mass transports with several roles for deletion, Only remember the basic step: put the roles in the transport first, then delete, then release.

  • CUA Roles residing in Child system are not showing in Central System

    I just hooked up CUA today and have linked 8 child systems to the central system.  The 8 child system users and roles have already been established in the child systems.  Do I need to run program susr_zbv_get_receiver_profiles in each of the child systems to get the roles in the child systems to show up in the Central System for each user?  I tried this in one child system and it worked.
    Or is there something else I need to do without going into each child system?
    I tried this program susr_zbv_get_receiver_profiles in the Central system but it did not work.

    are you looking for roles or profiles? profiles will not show up in the central system. If you run SCUL do you see anything? when you first added the child system did you use an SAP user that had the proper permissions? In both the child and the parent? There are two roles that the user must belong to to add the child to the parent they are SAP_BC_USR_CUA_SETUP_CENTRAL and SAP_BC_USR_CUA_CENTRAL.
    If you have any question about the permissions of these user at the time you added the child to the parent I'd delete the child and re-add with either the above roles or a user with SAP_ALL in BOTH the child and the parent systems

  • CUA - role

    Assume I have 4 systems connected CUA (T1P)
    C9P
    E1P
    D3P
    J2P
    There are many roles existing in T1P that have same name with roles in J2P.
    I understand that the roles will not be maintained via CUA. So
    I have deleted the roles in T1P that have same name with J2P.
    The result is that, my ID go through J2P system and also deleted the role which has the same name as the role that I delete in TIP (CUA system). FYI. I don't have the ID and access in J2P system at all.
    So this is caused a big problem in J2P system as it's production. Is there any reason, why it happen, anything wrong? Pls  help.

    Hi Dino,
    It depends on how you setup field distribution parameters in SCUM.
    -Pinkle

  • CUA roles sometimes do not match the target system

    Hi,
    We are using CUA on Solution manager to assign roles to our different systems.  Every now and then what is in CUA does not match the target System.
    I know that you can look at the idocs using WE05 and see what the root cause was, fix it and then re-assign the role.
    The problem is that when you assign the role using CUA, it doesn't warn you that the transmission failed on the target system.
    We just went live last week, so I am added and removing roles from many different users using SU01 and SU10 and I do not think it is a valuable use of time to sift through the idoc logs every time I make a change.  Especially, since most of the time it works.
    Is there a better way to monitor the Idoc logs?  Can you have it send a notification (email for example) when there is an error?  Is there a better process then WE05?
    Thank you in advance for the help!
    Neil

    Neil. It was a long time I played around with CUA. But I am remembering some transaction where you had the logs. Think it is SCUL.
    I searched saphelp and got the following hits for you:
    http://help.sap.com/saphelp_nw70/helpdata/EN/c1/db4063fd3111d5997a00508b6b8b11/frameset.htm
    http://help.sap.com/saphelp_nw70/helpdata/EN/cc/50b43be7492354e10000000a114084/frameset.htm
    Best of luck to you!
    Regards Fredrik

  • Partner role delete

    Hi guy,
    I have the need that a partner role is not allowed in a special sales order.
    My first idea was to solve it with a partner schema.
    But that is not possible, 'cause of the following problem;
    If the sales order type XX, was created without a reference, the partner role is allowed.
    If the sales order type XX, was created with a reference to a sales order type XY it is also allowed.
    But it is not allowed, if the sales order type XX was created with a reference to a sales order type YY oder with a reference to sales order type XY, which was created with reference to type YY.
    =>As the role is allowed generally, but not if there is any reference to a special type, the schema don't work.
    So I would like to delete the partnerrole in a USEREXIT and send a mail or message to the user.
    Does someone know a suitable exit or badi ?
    Greatings Manuel

    Hi Rasheed,
    I tried USEREXIT_SAVE_DOCUMENT_PREPARE in MV45AFZZ (because the MOVE_FIELD_TO_VBAK AND MOVE_FIELD_TO_VBAP isn't processed after a change of partners).
    My coding:
    ...(check if partnerrole is forbidden)
    delete xvbpa with where parvw = 'ZZ'.
    When I debug the behaviour it is deleting the entry in xvbpa, but after saving the partnerrole does still exist.
    Where is my failure ??
    Greatings
    Manuel

  • Mass role deletion in CUP 5.3

    Hi all,
    in our CUP 5.3 system someone has unintendedly imported all roles and profiles from the backend system (about 4000 roles).
    How can we delete those roles from CUP without having to delete it from the frontend, which will take ages.
    Is there any way or database script to safely remove the roles?
    They can be determined by either role approver or last reaffirm date.
    Thanks
    Daniela

    That's why I tell my customers
    "Whatever you want to do in Role Import - ALWAYS klick on "from file" first. No Exceptions. Never!"
    You're out of luck, there is no delete script. You can ask support for the DB ER document, but you'll have to do DB manipulations on your own risk, I'm afraid...
    Frank.

  • Essbase server access role - delete DB allowed?

    Good morning everyone.
    We have provisioned a group in Planning with the Essbase server access role which grants read level access to Essbase databases.
    We have checked that a user assigned to this group can actually access Essbase DBs to execute calcscripts and report scripts and that it does not have permission to open the DB outline --but it apparently still has permission to delete a database (as seen in the following image: https://c69ee7db-a-62cb3a1a-s-sites.googlegroups.com/site/ktratsites/Home/delete_Essb_DB.png )
    As you can guess, we have not tried whether this user could actually delete an Essbase database.
    Can anyone confirm whether a user given the Essbase Server Access role could really delete an Essbase DB?
    IMHO, this should not be possible.
    Thanks a lot.
    Best regards,
    G.S.Feliu

    It will show the option to delete but if you select it then it should display "Insufficient privilege for this operation"
    Cheers
    John
    http://john-goodwin.blogspot.com/

  • Bulk Role Delete

    I want to unassign a set of roles for a number of users and delete the user accounts for these users.Is it possible to do this using the Bulk Action option available in SUN IDM 8.1? If so what should be the format of the csv file I need to give as input? Currently I am giving a file with the content:
    user,command,roles,resources
    206812,delete,|Remove|A:Portal LDAP:All Users,MYNMG
    But this is only deleting the resource MYNMG. It is not unassigning the role A:Portal LDAP:All Users. Can someone tell me what the error in my input file is?
    Also which option should I choose from the Action dropdown?

    Hi,
    This is the command file I use to remove roles.
    command,user,waveset.roles
    Update,206812,|Remove|A:Portal LDAP:All Users
    Hope this helps

  • Role deletion in CUP

    Hi Experts,
    Please help us out.
    We had some test roles created in ERM, imported to CUP and tested by User Assignment. Now we want to clean the roles before role upload. We have deleted all roles in ERM but in CUP it is giving error-
    " Cannot delete since referred by request."
    We have archived all kind of requests but we are still getting the error. Please suggest.
    Thanks & Regards,
    Sabita

    Hi All,
    I found the option to enable/disable the role or to set the Role validity date . It's available as tick mark icon along with the + and - icons on the System tab when the role is selected for change. I just missed this button as i expected this property of the role either in the information section or in some of the tabs :(.Anyways, happy to find it now
    Cheers,
    Anil

  • Unlink and remove role = delete user???

    Hi All,
    We are using Sun IDM 7.1.1.21 and have run into this problem. I believe it's a product bug because it doesn't make any sense. We have users in an AD resource, and they are linked to that resource in IDM using a role. If, for some reason, the user is deleted from AD, and re-setup we have to "re-link" the user because the "accountGUID" attribute has the wrong GUID for the user and IDM doesn't like that. We are doing this using Recon. When recon runs, and catches this user, the situation comes back as "Confirmed", which is fine, we are using a per account workflow to handle the changes. We then compare the GUIDs of the objects in the workflow, if they are different, we would unlink the IDM account and relink it to the new GUID. We are setting the following options on the unlink.
    <set name='options.unlinkTargets'>
    <list>
    <s>AD</s>
    </list>
    </set>
    <set name='options.deleteAccounts'>
    <s>false</s>
    </set>
    and we remove the role, becuase if we do not, nothing happens. When the user object is checked in, it gets deleted from the resource. I'm sure this is happening becuase the accountID DOES exist (when the user is re-setup on the back-end the same DN is given to the user). Obviously this result is undesireable. So now I have 2 questions.
    1. Am I doing this wrong?
    2. Why would IDM delete an account when deleteAccounts and unlinkTargets are explicitly set on the checkin?

    OK. I figured out where the problem was. Renaming the accountGUID without removing the role only caused a "rename account to same name" error. I was not setting the correct options when removing the role. I needed to set:
    <set name='options.noDelete'>
    <s>true</s>
    </set>
    <set name='options.deleteUser'>
    <s>false</s>
    </set>
    This did the trick. The roles were removed and the user unlinked without any harm done to the resource account. I was then able to re-add the roles and relink to the existing resource account without a problem.
    Thanks.

  • Role Deleted - Profile remains on User record

    All -
    We currently have a situation where users still have a profile assigned to them even after the role was removed and later deleted.
    We had a number of custom roles deemed obsolete.  Consequently, these roles were deleted.  All users were removed from these roles before they were deleted.  In looking back at the users, the profile for the now deleted role still exists on the user record.  We run PFUD nightly but this has not resolved the issue that some users have non-generated and non-valid profiles on their user master record.  Please advise if there is a way to resolve this inconsistency.
    Thanks,
    Marnie

    I would remove them manually. How many users are there with old manual profiles?
    Removing the profiles themselves for good you can do easily, but there is no standard program for a mass deletion.
    If you are 100% certain that you can remove the profiles without any impact, then you can remove the check on the assignment.
    Deleting them in Su02 will make this check though.
    Cheers,
    Julius

Maybe you are looking for