User update in Child system through CUA

Hi,
I created a role in child system and assigned it to the users in the parent system
However, users are not getting updated in the child system
Plz suggest

Did you run text comparison after creating the role ?
If not do that .
[SU01 --> enter user --> Roles --> Text comparison from child system OR run report SUSR_ZBV_GET_RECEIVER_PROFILES ]
Thanks
Prince Jose
Message was edited by:
        Prince Jose

Similar Messages

  • How to delete users in the child systems with CUA?

    Hi All,
    We have:
    1.  My SAP ERP 2005  (ECC 6.0)+ Windows 64bit + Oracle 10
    2. EP 7.0 + Windows 64bit + Oracle 10
    3. BI 7.0 + Windows 64bit + Oracle 10
    4. Solution Manager 4.0 (CUA)
    We managed all our QA and DEV users in ECC, EP using CUA from the Solution Manager server (Productive servers  and all the BI  7.0 System Landscape aren't in the CUA).
    My problem is when i want to delete a user. Sometimes if you delete a user in the solution manager (where the CUA is defined) the user still  exists in the Child Systems. In fact you can  see it with the SU01 only in the child system. I guess the idea is that if you delete the user in the CUA them  the user is delete in the child system.
    I found this information in the SAP Help:
    As well as the authorizations already mentioned, you also need another authorization in the central system for object S_USER_SYS. You can only assign new systems to a new user with this authorization. ( No Problem with this )
    When a user is deleted in the central system, the system entry for the user is retained until the deletion is confirmed. If an error occurs, you can repeat the deletion by canceling the system (in the child system).
    What does mean: deletion is confirmed? 
    Best Regards,
    Erick Ilarraza

    Hi, thanks a lot for your reply.
    We used the SAP Transaction SCUG to solve CUA Problem.
    It is something about the refresh of the user in the Parent / Child systems, you need to Re-Refresh users and delete it again.
    Best Regrads,
    Erick Ilarraza

  • CUA user master table updates from child system

    Hi Experts,
    In my system although there are roles assigned to users in child system they are not showing up in CUA for few user.
    Is there any program in CUA which i can use to  update the user master tables for only a limited set of users from child systems.
    Regards,
    Sandeep

    Hi Sandeep,
    Just want to check below queries....if this solves your problem..
    Is these are the new systems assigned to CUA or moved from other CUA as you said that role assignment is available in child system but not in CUA ? Another  thing that  I want you to check the User Group  assigned to user in child system and in CUA.If user gorups assigned to users are different in CUA and child system or particular group is missing in any one of the system then idoc will not move. Also check the Output device type along with address data...Any mismatch of these will stop the idoc.
    After that run the SCUG for all users, in CUA as suggested by akshay, this you can run for all 10 child system from CUA, no need to go in every child system.....

  • RFC for User Lock and Unlock for child systems in CUA

    Dear All,
    Can anyone tell me, how to lock or unlock a user in child systems from CUA using a BAPI or RFC.
    As per the requirement I can not use TCode SU01 for this purpose. I can only use RFC/BAPI for the same.
    Thanks
    Om
    Edited by: Om Somesh on Apr 13, 2009 3:57 PM

    Hi OM,
    One way could be to use RFC_READ_TABLE in order to look at USR02.
    The second method is by using SCUM transaction code
    Regards
    Krishna

  • HT1222 My Ipod needs an update but I don't have internet service on my computer so is it possible to send the update to the email  to update the ipod system through the Ipod with wi-fi?

    my ipod needs an update but i don't have internet service on my computer i was wondering is it posible to send the update to the email to update the ipod system through Wi-Fi?

    If your iPod touch is already running iOS 5 then you should be able to upgrade to iOS 5.0.1 on the device with a Wi-Fi connection.
    tt2

  • CUA- Deleting user IDs from Child systems

    Is there a possibility of configuring CUA in such a way that user IDs can be created and access can be updated from CUA but deleting user IDs should be taking place only in the child system (Not in all the child systems)?

    Generally good advice to keep the uniqueness of UIDs over time, also after Elvis has left the building
    What you could consider is a CUA RFC user which is not authorized to delete UID's and schedule a purge job for those IDOCs which deleted only them.
    However these sorts of "workaround" solutions are not the best advise, to be honest. What happens it someone temporarily assigns SAP_ALL because there is a big problem and authorizations should be excluded as the cause to get it working again?
    Also, every time a new child system is added to the CUA you will be flooded.
    My advice: Rather change your procedure (as discribed by Jurgen).
    What would be interesting to test is whether you are authorized to move a user (change the authorization relevevant group which they currently have) to a group which the CUA user is no long able to subsequently administrate? But theen you will still be hunting down IDOCs from time to time, most likely.
    If your shop is big enough to have these systems you have described, then you might want to consider an IdM system to replace your CUA at some time.
    If you wish, I will move this thread to the IdM forum.
    Cheers,
    Julius
    ps: Please do not cross-post.

  • Unable to see user created in Child system

    Hi There,
    I am facing a peculiar issue with CUA.
    1) A user created in CUA is not appearing in Child system.
    2)When I checked the IDOC status it is Green(03) in both the systems.
    3)When I remove the system in the CUA for that client , it  is fine.
    4)When i again added the system it is fine in IDOCs as well and when I reset the password the status of IDOC in child system  says user does not exist.
    Please let me know if anybody had similar issue and any solutions I could look into

    Just to make things more clear.
    1)logical systems would not be an issue because the idocs would not appear in child system had it been the case.
    2)I tried the option to remove the particular child system from the user profile under systems ,saved and then added the system.
    When I went to child system, the idoc  says user created but again when I reset the password in the CUA for  that system   and check the idoc in child systems it fails saying user does not exist.

  • CUP 5.3: Has anyone set-up user deletion process that works through CUA?

    Hello,
    I wonder if anyone has managed to set-up a user account deletion process that works through CUA?
    We can't get CUP to delete the system assignment in CUA before the back-end account is deleted.
    Any kind of advice or information regarding this problem would be appreciated.
    Br,
    Stefan Ericsson
    +358-50-4867527

    Jes,
    We have 2 approvers for each role. We defined in the Role Approver Stage that it be routed to the alternate approver should the main approver not respond in the next 3 days (via Forward to Alternate Approver). Bear in mind, once it is escalated to the alternate approver, the main approver will not be able to view/approve the request anymore. If the alternate approver does not approve/reject the request, the request will be left as is.
    In our case, we have used the functionality in CUP to pre-define the alternate approver rather than in your case, you would want to only escalate it as and when your Security Admin decides to. I believe if your Security Admin staff has admin rights in CUP, they are able to forward it to another approver via the Administrator tab. Else you can create a new stage to foward to your admin staff if it is not action upon.

  • SAP CUA connector changes password in master system AND child systems?

    Please confirm if OIM can change the password in both SAP CUA master and child systems through SAP CUA connector. The connector guide mentions the following parameter can be defined in SAP CUA IT Resource.
    Parameter: SAPChangePasswordSystem Flag that accepts the value X or ' '
    If the value is X, then the password is changed
    only in the master system. If the value is ' ', then
    the password is changed in both master and child
    systems.
    This parameter is used by the Reset
    Password function.
    Thanks!

    Hi,
    1) You can use report RSCCUSND to distribute users from CUA to child client. Check section "Sending User Master Data to a Child System" in [CUA cookbook|http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/fe4f76cc-0601-0010-55a3-c4a1ab8397b1?quicklink=index&overridelayout=true].
    2) if the user account has not been synced to CUA then you should be able to delete it in child system. The button should be displayed for unsynced users. You can use transaction SCUG to sync users between new child system and CUA. Check section "Transfering Users from New System" in [CUA cookbook|http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/fe4f76cc-0601-0010-55a3-c4a1ab8397b1?quicklink=index&overridelayout=true].
    Cheers

  • CUA-User does not exist in Child system

    Hi All,
    User has been created in  child system through central system,and respective roles also assigned through central system.Now,the issue is when user is trying to log in child system,it's showing user does not exist.
    I did Text comparison also,status is okay.
    Kindly help!
    Regards,
    Naveen

    Hi,
    Could you just login to the child system and view the userid created through su01?
    1. In case you are unable to do the same, there is certainly a problem  with idoc distribution for which you can find the reasons in SCUL.
    2. In case the userid exists in child syatem, you need to check if address data for the userid is being maintained in child system or not.
    In case you get an error message " Address data not maintained"  while viewing the userid through su01 in the child system, then you need to execute report RSADRCK2 in the child system.
    You may refer to the following link in this case:
    http://help.sap.com/saphelp_sm32/helpdata/en/85/91cd3b11571962e10000000a11402f/frameset.htm

  • New role in CUA user record not getting pushed to child system

    I added a new child system to our CUA setup.  I've confirmed that the RFC connections from both sides are working properly (test connection succeeds) and I've successfully completed the user transfer function in SCUG.  All exisitng roles assigned to the users in the child system are now appearing in the CUA central system as expected.  I added a new role to a user via SU01 in the central system to this child system, but when I go to the child system, it does not appear in the user's SU01 record.  Any ideas why this would not be syncing properly?
    Thanks,
    Michael

    Hi,
    Whenever you create a new role in child system, it has to be sync up with the central system.
    To sync up with the central system, login to central system goto su01>enter any user name>go to roles tab- click on Text comparision from chiled system. Its navigate to another screen, there you have to mention the child system and click on execute. it syncs up with child sytem. Hope it will help you out to resolve the issue.
    If still you are getting the same issue login to the central system.. goto SE38-- enter the program name as "RSCCUSND" and click on execute there mention the user name and the logical system id of the Child system name, select the parameters which you wanted to distribute to child system and execute it.
    Best Regards
    Mani

  • CUA and SU10: unexpected deletion in all child systems

    Hi,
    I am facing with a problem with SU10 and CUA.
    I have updated a lot of users with SU10 in CUA. For 20 users in a child system, I first add a new role, everything is fine. Then I perform a remove of a old role (I know that the end date will be changed), everything is fine except for one user. All roles were removed from all systems where the user is defined ! However, when I look in each child systems, it is not the case, the roles are well present except in the child sytem for which I do the remove.
    This problem occurs twice, for different users. It is a real problem because we have to adapt a lot of users.
    I have reinstalled the 'missing' roles with SCUG and with the change document for users but it can be a workaround because I have discovered this by chance. I can imagine check all users after each run of SU10.
    Hope someone can help me.
    Regards

    Hi Olivier,
    that sounds like you are facing the problem corrected with sap note #1117530......
    The removal shows up only at the next change of a user, the actual deletion of role assignements because of the copy might have happend already some time ago.....
    b.rgds, Bernhard

  • How to get the list of roles assigned to a user in all the child systems

    how to get the list of roles assigned to a user in all the child systems from CUA SYSTEM

    Try transaction SUIM in your CUA system. Go to user, cross-system information, users by roles. If you run it wide open, you'll get all users and all roles assigned for all systems managed in your CUA.
    Krysta

  • Role assignment to user in child system

    Hi,
    We have a CUA with role assignment in SCUM defined as global. There is any way of assigning roles to users in child system when CUA system is not available? There is any way to allow roles assignement  in both Parent and  child systems?
    Many thanks for your help!!
    Raquel

    One way would be to temporarily delete the CUA assignment in the child and then maintain locally, but you will need to attach it again... and decide whether you want the CUA master to know about what you have done.
    Plan B on older Support Packs is to take a look at the correction instructions of [SAP Note 1504495|https://service.sap.com/sap/support/notes/1504495] but for this you need full access () to the S_USER objects, in which case you could detatch the CUA anyway.
    However as a temporary workaround in Test systems it could have been usefull.
    Plan C: Allow reference user assignments locally and authorize the role indirectly. Via the available authorizations of and access to the reference users you can then contain the scenario. Works fine for me if the concept of reference users is understood.
    However in most cases you should do it via the CUA and will end up doing this anyway via the CUA - that is what you have a CUA for. So... logon to your CUA in the morning, give the SAPGui scheme a nice bright colour and administrate the users and role assignments there. This is a small price to pay compared to not having a CUA or IdM...
    Cheers,
    Julius

  • CUA history for child systems

    Hi all
    I have seen quite a few forum entries about change history and tables to see the mapping of roles to users, such as:
    Table AGR_USERS (actual assignments)
    Table USLA04 (actual assignments in a CUA central system)
    SUIM report RSSCD100_PFCG for viewing change documents of roles.
    - but does anyone know of any reports / tables that show the change history of a user/what roles they have had assigned, for child system in a CUA set up?
    SUIM and RSSCD100_PFCG only show the local client... we have lost our child systems user <-> roles mappings after a refresh and we want to see history of what roles where assigned to what user, but running these reports in the CUA system only shows local users, and running it in the child is no good as it's just been refreshed and is a copy of the CUA system now anyway!
    Any help much appreciated... we have users in the child system shouting as the don't have the correct authorisations...
    Thanks
    Ross

    Seems nobody knows....    Closing....

Maybe you are looking for