EP Connector in Access Enforcer

Dear friends,
Iam trying to create a Connector for EP.
There was a Parameter value? can any one tell me what is the actual parameter value to be defined and were to find it.
Access Enforcer version 5.3
Parameter Names                                            Parameter Values
ASSIGN_GROUPS:OC                                       sapgroup
ASSIGN_ROLES:OC                                          saprole
CHANGE_USER:OC                                          sapuser
CREATE_USER:OC                                           sapuser
CREATE_USER:password                                  password
DELETE_USER:OC                                         sapuser
LOCK_USER:OC                                           sapuser
LOCK_USER:islocked                                      true
RESET_PASSWORD:OC                                sapuser
RESET_PASSWORD:password                      password
ROLESEARCH_URI                                     See your system administrator for the value.
ROLESEARCH_URI_USERNAME                     See your system administrator for the value.
ROLESEARCH_URI_PASSWORD                  See your system administrator for the value.
ROLE_DATA_SOURCE                              See your system administrator for the value.
SCHEMA_ID                                           SAPprincipals
UNLOCK_USER:OC                                 Sapuser
UNLOCK_USER:islocked                              false
USER_DATA_SOURCE                               See your system administrator for the value.
Please help.
thank

Hi Selva,
   I am not able to get what exactly you are looking for. You want to know which values you need to enter for parameter values then it is explained in the name itself.
To understand what to enter in parameter values either you need to know EP or need to work with EP administrator. It won't be easy to explain you each and every parameter. If you don't know where to find a particular parameter then I should be able to help you.
Regards,
Alpesh

Similar Messages

  • Connector problem with access enforcer

    Hi Guys,
    I am facing a really strange problem with my connectors.
    We have a test installation of GRC which was down for about 3 months.
    During this time we migrated our central SLD to another system so I needed to change the connection after getting the system up again.
    Anyhow I still can't modify, test or even create a new connector for access enforcer.
    The only error I get is "Action failed".
    I tried to analyze the logs but found no help there too.
    2007-06-18 20:41:56,833 [SAPEngine_Application_Thread[impl:3]_4] ERROR java.lang.NullPointerException
    java.lang.NullPointerException
         at com.virsa.ae.dao.sqlj.SAPConnectorDAO.iterToDTO(SAPConnectorDAO.sqlj:75)
         at com.virsa.ae.dao.sqlj.SAPConnectorDAO.findByConnectorName(SAPConnectorDAO.sqlj:15)
         at com.virsa.ae.configuration.bo.ConnectorsBO.findSAPConnectorDetails(ConnectorsBO.java:76)
         at com.virsa.ae.configuration.actions.ManageConnectorsAction.testConnection(ManageConnectorsAction.java:163)
         at com.virsa.ae.configuration.actions.ManageConnectorsAction.execute(ManageConnectorsAction.java:66)
         at com.virsa.ae.commons.utils.framework.NavigationEngine.execute(NavigationEngine.java:229)
         at com.virsa.ae.commons.utils.framework.servlet.AEFrameworkServlet.service(AEFrameworkServlet.java:412)
         at javax.servlet.http.HttpServlet.service(HttpServlet.java(Compiled Code))
         at com.sap.engine.services.servlets_jsp.server.HttpHandlerImpl.runServlet(HttpHandlerImpl.java:390)
         at com.sap.engine.services.servlets_jsp.server.HttpHandlerImpl.handleRequest(HttpHandlerImpl.java:264)
         at com.sap.engine.services.httpserver.server.RequestAnalizer.startServlet(RequestAnalizer.java:347)
         at com.sap.engine.services.httpserver.server.RequestAnalizer.startServlet(RequestAnalizer.java:325)
         at com.sap.engine.services.httpserver.server.RequestAnalizer.invokeWebContainer(RequestAnalizer.java:887)
         at com.sap.engine.services.httpserver.server.RequestAnalizer.handle(RequestAnalizer.java:241)
         at com.sap.engine.services.httpserver.server.Client.handle(Client.java:92)
         at com.sap.engine.services.httpserver.server.Processor.request(Processor.java:148)
         at com.sap.engine.core.service630.context.cluster.session.ApplicationSessionMessageListener.process(ApplicationSessionMessageListener.java(Compiled Code))
         at com.sap.engine.core.cluster.impl6.session.MessageRunner.run(MessageRunner.java(Compiled Code))
         at com.sap.engine.core.thread.impl3.ActionObject.run(ActionObject.java(Compiled Code))
         at java.security.AccessController.doPrivileged1(Native Method)
         at java.security.AccessController.doPrivileged(AccessController.java(Compiled Code))
         at com.sap.engine.core.thread.impl3.SingleThread.execute(SingleThread.java(Compiled Code))
         at com.sap.engine.core.thread.impl3.SingleThread.run(SingleThread.java(Compiled Code))
    Did anybody here face a problem like that?
    Kind regards,
    Bastian
    Message was edited by:
            Bastian Schneider
    Message was edited by:
            Bastian Schneider

    I had a simular problem with CC and I had to contact SAP. They gave me a script to run against the database that remove the connector. The problem seemed somewhat common for CC 5.1. Not sure if this applies to AE.

  • Access enforcer and User Data Source for HR

    We are on Access Enforcer 5.2 - service pack 2:
    My problem is that when creating a new request in AE, I able to get a list of all users when I point my User Data Source to either SAP or UME. However when I attempt to create a request whilst pointing the User Data Source at the SAPHR system, I do not get any users back (and we have user set up in the SAP HR system).
    I’ve changed the connector to ‘YES’ under the HR System box, I’ve changed the Data Source Type and Details Source Type to point at the SAPHR and still it fails to fetch any users.
    I've tried looking at the log, but can't get much out of it.
    I would appreciate it, if anyone could provide any assistance.
    Thanks you in advance.
    Amarjit
    Message was edited by:
            amarjit singh

    Hi Micheal,
    Thanks for your reply.
    I'm pointing both Data Source Type and Details Source Type to the same system SAPHR and to the same system name (which is our dev system)
    Regards,
    Amarjit

  • Access Enforcer LDAP mappings

    Hello everyboby,
    I have Access Enforcer 5.1 VP1 and I would like to know how use the LDAP mappings.
    For example, I want recover the manager's name into LDAP automatically on Access Enforcer during an user request.
    Thank you very much for your assistance.
    David Heang

    Hi,
    First you need to connect the Connector for the LDAP when the Connector is working, You need to define the LDAP Mappings.
    For Recovering the Manager Name in to Access Enforcer from LDAP (Active Directory) you need to Map the  LDAP Entry classs object "<b>manager</b>" to the Access Enforcer "LDAP Mappings"
    Now the Manager for the User will be picked up if the Relationsip is defiend in the LDAP Directory.
    LDAP Objects are different for the Different LDAP Types.
    Hope it Helps,
    Vikas

  • Risk Analysis Error - Access Enforcer

    Hi Experts,
    I am getting error while running risk analysis in Access Enforcer and the error is
    <b>Risk analysis failed: Exception in getting the results from the web service : Service call exception; nested exception is: java.lang.Exception: Incorrect content-type found 'text/html'
    </b>
    We are using seperate RFC IDs for Access Enforcer connector and Comlaince Calibrator connector.
    Please help me.
    Thanks&Regards,
    Vijay

    Reddy,
    The user must indeed be created in the UME as a Compliance Calibrator user.
    I don't know exactly which role he should be assigned, usually I indicate there my CC admin user-id and password.
    When you see it is working with that user-id, you can try to re-fine the roles.
    Some more info regarding what needs to be set in the URI in case the one I inducated in my previous answer is not working:
    "There are two selectable versions of Compliance Calibrator. If you select 5.0 Web Service, three additional fields appear (URI, UserName, and Password). For the URI field, you need to navigate to the SAP NetWeaver Web Application Server Home page > Web Services Navigator > CCRiskAnalysisService > WSDLs > Standard link of Document, where you will see a list of all web services in the server. Select the desired URI address. If you select Compliance Calibrator 4.0, there is no need to connect to a URI address."
    Karim

  • PD profiles in Access Enforcer

    Hello
    Regarding setting up PD Profiles in Access Enforcer,
    1. Are PD Profiles set up manually in AE
    or
    2. Is there a connector configuration that derives PD profiles from the HR system
    0r
    3. Is there a flat file upload of PD profile data in AE, like we do with roles.
    Can you also point me to any guide in SAP marketplace / Wiki How to Guides, that describes setting up PD profiles in Access Enforcer.
    Your help is appreciated.

    Hi Selva,
       I am not able to get what exactly you are looking for. You want to know which values you need to enter for parameter values then it is explained in the name itself.
    To understand what to enter in parameter values either you need to know EP or need to work with EP administrator. It won't be easy to explain you each and every parameter. If you don't know where to find a particular parameter then I should be able to help you.
    Regards,
    Alpesh

  • Access Enforcer (error in creating a request)

    Hi All,
    when i am creating a new request in Access Enforcer . After filling alll the details and clicking the submit button it is showing  a error in creating request .Path not found.

    Hello,
    You must have to select at least one condition attribute while creating your initiator. It seems initiator condition not meeting the details you are filling in your request. So it is not able to trigger the workflow initiator.
    For simple scenario, if you are filling your company details in your request then change your initiator condition attribute to "Company".(Don't include more condition attributes for now). Once it works out then change initiator details back to your requirements.
    Please let me know if this will not resolve your issue.
    Thanks
    Himadama

  • Access Enforcer(error in approving the request) and import roles

    Dear all,
    error in approving the request at security stage(last)
    manager and role owner are successfully approved.
    and also importing roles into access enforcer was not successful.
    imortstatus : 0 roles imported of 28 records found.
    please find the system log:
    2008-09-05 13:01:34,625 [SAPEngine_Application_Thread[impl:3]_8] DEBUG com.virsa.ae.service.messaging.MessageFormatter : parseDesc :   : INTO the method : desc :Please specify a file to import.paramNames :paramsMap :{FIELD_NAME=#_!FIELD_NAME#_!}
    2008-09-05 13:01:34,625 [SAPEngine_Application_Thread[impl:3]_8] DEBUG com.virsa.ae.service.cache.AECacheUtil : getResourceBundle :   : INTO the method : en
    2008-09-05 13:01:34,625 [SAPEngine_Application_Thread[impl:3]_8] DEBUG com.virsa.ae.service.cache.AECacheUtil : getResourceBundle :   : INTO the method : en
    2008-09-05 13:01:34,625 [SAPEngine_Application_Thread[impl:3]_8] DEBUG com.virsa.ae.service.cache.AECacheUtil : getResourceBundle :   : INTO the method : en
    2008-09-05 13:01:34,625 [SAPEngine_Application_Thread[impl:3]_8] DEBUG com.virsa.ae.service.cache.AECacheUtil : getResourceBundle :   : INTO the method : en
    2008-09-05 13:01:34,625 [SAPEngine_Application_Thread[impl:3]_8] DEBUG com.virsa.ae.service.cache.AECacheUtil : getResourceBundle :   : INTO the method : en
    2008-09-05 13:02:28,234 [Thread-47] DEBUG

    In Addition to my previous response:
    I meant to include the following:
    Some of the fields that need to be properly defined with attributes are:
           System: must have the know SAP system defined here
           Role Approver (i presently are using most of the roles without having need for approval; I created a user called NOAPPRV in AE)
           Functional Area: need to have all the areas defined that roles will be assigned to
           Company: I only have one company so that's an easy one
    Some areas I presently do not use but found they must ne coded and coded properly:
           ResponsibilityID:   N/A  (coded as is)
           CommentsMandatory: NO (coded as is)
           Parent Role Owner:   NO
           Business Process: NA  (I believe I originally coded N/A and it did not like that)
           Sub Process: NA  (again N/A I believe error on me)
           Reaffirm Period: presently I am using 0 (zero)
           LastReaffirm: presently using 12/31/9999
    Hope this helps a bit
    I wanted to include an attachment with a sample of my Role Import spreadsheet but I'm not sure exactly how to do that; if I figure that out or someone can provide me the process I will include it
    Jerry Synoga
    Ryerson Inc.
    630-758-2021

  • Validity date issue: Access Enforcer

    Hi All,
    There is a request in Access Enforcer wherein there are total 4 stages of approval, the first 2 stages have been properly approved however when the same arrived to the 3rd stage of approval, the validity date for the request was over and therefore the approvers tried to extend the same, but the "more" tab is not appearing and therefore the approvers are not able to approve the request by extensing the validity date.
    Can you please help with this issue?
    Thanks
    Vani

    Vani,
      Go to the stage level settings for this particular stage via configuration -> workflow -> stage. Change the option of 'Change request content' to 'Yes' and the approver in this stage should be able to change the vailidity dates.
    Regards,
    Alpesh

  • Auto Email generation in multiple language in Access Enforcer 5.2

    Hi All,
    We have configured workflow in Access Enforcer 5.2 for autoprovisioning of users in the system. Requestor gets an email in english with the userid and password once the user is provisioned in the system. Now the requirment is to send these emails in different language, which is specific to the user. Like a spanish user should receive the email in spanish language.
    Whether this has anything to do with language setting while user creation.
    Please suggest.
    Thanks & Regards,
    Pravin

    Hi Pravin,
        It has nothing to do with the language settings for the user. This configuration has to be done in closing section of Email reminders under workflow. As per my experience with AE 5.2/CUP 5.3, I don't think this is possible as of now. This could be a good functionality, so you can open an enhancement request with SAP.
    Regards,
    Alpesh

  • Multi User request in Access Enforcer

    Is anyone aware of a user limit in an access enforcer multi user request?
    We get errors when we submit  a multi user access enforcer request with more than 25 users.
    Thanks

    Hi
    There is no standard limit even though we advice to keep the user to max of 20 .
    The limit depends upon the email content you have configured .
    In case in your email notifications you have taken the argument USERID then mulitple user creation request causes issue and the limit gets set to anything between 20-25 , again depending on content of the email .
    Thanks

  • Why Access Enforcer 5.2 considers u201CCritical Transactionu201D as a SOD Risk ?

    Hello,
    When I submit a request with Critical Transaction and no SOD conflict, Access Enforcer forwards my request to the SOD Manager.
    I have a Detour Path triggered by the condition u201CSOD Violationsu201D.
    The settings are in:
    - Access Enforcer 5.2: Configurations -> Risk Analysis -> Default Analysis Type: Object Level
    - Compliance Calibrator 5.2:
    Configuration -> Risk Analysis -> Default Values -> Default report type for risk analysis: Permission Level
    I am wondering why Access Enforcer 5.2 considers u201CCritical Transactionu201D as a SOD Risk
    Thank you.
    Abderrahim

    Hi,
    As per my knowledge even though you set the risk analysis to be done at a single level, AE will do at all the levels, i.e., at SoD, critical action, and critical permission. If you want to have only SOD risks, you need to either deactivate all critical action rules in RAR, or create a new ruleset and assign all the SOD risks to it and use it with AE.
    This will help you to address the issue.
    Best Regards,
    Raghu

  • Upload of role in Access Enforcer 5.2.

    Hi All,
    I need to upload roles in Access Enforcer from SAP ECC system. Actually i have uploaded the roles in Access Enforcer, but all unwanted roles have also got uploaded.
    Now i need some way, first to clean entire uploaded roles & then upload selected roles.
    Please suggest.
    Thanks & Regards,
    Pravin

    Hi Pravin,
       Here are the steps:
    1) Download all the roles into an excel spreadsheet:
    Go to configuration -> Roles- Search roles -> Click on 'Export' button. This CUP, go to 'Search Roles'. Click on 'Search' button without providing any search criteria. This will return all the roles available in CUP. Now, click on Export button. CUP will export all the roles into Excel spreadsheet in the format which CUP understands.
    2) Delete all the roles from CUP: Now, in the same screen as above, select all the roles and delete them.
    3) Delete not needed roles from spreadsheet and upload it into CUP:
    Now, delete all the unwanted roles from CUP and play with the spreadsheet to manipulate other parameters like role approvers, systems, business process etc and upload that spreadsheet into CUP.
    Regards,
    Alpesh
    SAP GRC Manager (PwC)

  • Access Enforcer Role Import - Reaffirm period

    Hello
    What does the following terms mean;
    last reaffirm
    reaffirmperiod
    We current upload roles into AE, with last reaffirm as current date, and reaffirmperiod of 60 which means 5 years.
    Can someone please explain what these terms mean, because many roles have reaffirm periods that end in 2010.
    Thanks

    Hi Prakas,
    Reaffirm period ( in months ) is the duration after which you would like the Approver of the Role ( Role Owner /Role Approver ) to get notified on which all user in SAP has access to that Role and Does he want to continue giving that role to them or wants to remove that Role from all of them or any one of them .
    He would get the details on which Role requires Reaffrim at following location :
    In AE 5.2 ;  login with Role approver id ( eg ABC )  into AE .
    In tab Access Enforcer > Reaffirm .
    A list of All the roles of which ABC is apporver and which require re-affrim would display here.
    ABC can now take approriate action by selecting the role name.
    *Last reaffrim * is the date when the Role was Reaffrim /revisited/reassgined last.
    In your scenario you have given Reaffrim period = 60 which means your Role Owner would get the Role in his Reaffrim inbox after 5 years .
    This is not best practise . For security reason , SAP advices to keep the Reaffrim period to a maximum of 2 months.
    I hope this answers your query .
    Thanks
    Jasmine

  • Access Enforcer - Downloading Requestor Lists

    We would like to see a list of all of those who have submitted Access Enforcer requests to date. There is no option on the Informer tab that gives us this information. The only way we can find is to download each page from a request search.
    Has anyone done any SQL-type queries on the database to get reports with information that is not offered by AE?
    Any help will be appreciated.

    Hi,
    What is your AE version ?
    Informer tab has analytical reports , you can use them.
    Have A nice Day.

Maybe you are looking for

  • Find an ipad and dont know what to do.

    Hi i find an ipad and want to return to his owner but it has password. I don't know what to do... Police... is not an option in Argentina. What can i do?

  • View Office Documents?​?

    I am new to the BB realm of phones. Currently enjoying my World Edition as I learn how to use it more and more every day. What software is recommended for viewing microsoft word and excel documents. How about pdf files? Verizon... Mac user  Message E

  • Reset provider-specific properties back to default

    Hello community, I could use some quick help with something.  I have changed the Description of an characteristic specific to a DSO (when in change mode in the DSO, right-click characteristic, select "Provider-specific properties", and change Descrip

  • JFileChooser bug?

    Hi, I've encountered a strange thing (is it a bug?) in JFileChooser. It goes like this: in the Open File chooser, when I click on the name of a file, it goes to edit mode of that filename. If I click outside so as to cancel the renaming, a file in th

  • Updating style.css or style itself doesn't update topics

    I am having an issue with the styles within RH. There is a defined style.css that was created, however, when the individual fonts or formats are changed within it, it doesn't change the topics. In addition, when I tried to just update a specific styl