Will PFCG at child systems be disabled once CUA is activated?

I have set up CUA many times but I do NOT remember whether the PFCG of the child systems will be NOT working once CUA is set up. 
I currently have no CUA to verify this.
Would you please help  tell if the PFCG at child systems will be disabled once CUA is activated?
Thanks!

Hi,
If you check CUA installation guide, there below extract is mentioned:
In the central system, you use transaction SU01 to execute the Text Comparison from
Child System function and specify the changed child system as the target system.
u2022 You send the changed role data from the child system in which you have made the role
maintenance (transaction PFCG) changes, to the central system. To do this, choose
Environment u2192 Text Comparison for CUA Central System in transaction PFCG of the
child system.
u2022 You execute the report SUSR_ZBV_GET_RECEIVER_PROFILES in the central
system using transaction SA38, or schedule it regularly as a background job to collect
the changed roles and profiles from the child system. You can specify the receiving
system using the input help. If you have only made changes in one child system, you
only need to specify this system.
u2022 You execute the report SUSR_ZBV_GET_RECEIVER_PROFILES in the child system
using transaction SA38, or schedule it regularly as a background job to send the
changed roles and profiles to the central system. You can leave the input fields empty,
as the data of the child system is always sent to the central system, regardless of the
entries.
Thanks
Sunny

Similar Messages

  • CUA- Login to Child System

    Hi,
    I have configured CUA in System ABC as Central System
    System XYZ is the child system
    The  user TEST exist in both Child and Central System. Hence i have done a transfer of User TEST from child to Central System
    Please let me know the following
    1. After the transfer, the user is also present in Child System , Please let me know whether this is usual
    2. As per my understanding, i should use the same Password in CUA System to login to all child systems. Please confirm

    Hi,
    CUA is only for user administration of all the systems from one system. Yes once you change the password of the child system from a central system it is automatically distributed to the child system.
    Please check with the link below for better understanding:
    http://help.sap.com/saphelp_nw04s/helpdata/en/fa/0ec43b5d091b3de10000000a114084/frameset.htm
    Regards,
    Pavan

  • CUA user master table updates from child system

    Hi Experts,
    In my system although there are roles assigned to users in child system they are not showing up in CUA for few user.
    Is there any program in CUA which i can use to  update the user master tables for only a limited set of users from child systems.
    Regards,
    Sandeep

    Hi Sandeep,
    Just want to check below queries....if this solves your problem..
    Is these are the new systems assigned to CUA or moved from other CUA as you said that role assignment is available in child system but not in CUA ? Another  thing that  I want you to check the User Group  assigned to user in child system and in CUA.If user gorups assigned to users are different in CUA and child system or particular group is missing in any one of the system then idoc will not move. Also check the Output device type along with address data...Any mismatch of these will stop the idoc.
    After that run the SCUG for all users, in CUA as suggested by akshay, this you can run for all 10 child system from CUA, no need to go in every child system.....

  • CUA - how can I disable child system user record RENAME?

    I have setup CUA.  How can I disable SU01/RENAME from the child system?  If a user is Renamed directly in the child system, the new record is unlocked and can be edited in the child system.  These new records are now out of sync with CUA master data.
    I dont see an option for 'rename' in SCUM.
    Is this how CUA is supposed to work, or can the rename function be disabled?
    Thanks.

    Ben,
    We have installed CUA on solution manager 4.0, the back end (child) system is R3 4.7.
    My CUA SCUM shows seperate tabs for Address and Logon data.
    On the Address tab Ive set everything to global, its a long list.
    On the Logon tab all fields, except for inital password, are set to 'global', inital password is set to 'everywhere', to allow changes directly in the child system.
    Just about everything seems to be working, except this RENAME problem.  The users are greyed out in the child system, the create button doesnt even exist anymore in SU01 in the child system.  Syncing between the CUA and Child systems is working as I expect.
    Any suggestions?
    Thanks for the quick response.

  • To get the logical system names of all the child systems in a CUA envirnmnt

    Hi Gurus ,
    Is there any table where we can find the logical system names of all the child sytems in a CUA environment .
    This is for a requirement that i need to develop an automated process where we can reset the password of all the child system in a CUA environemt when requested by the user at once .
    I found some tables such as V_TBDLS , but they do not contain the exact information what i need .
    Thanks in advance ,
    Harshit Rungta

    Hi,
    You are in the right track. BD54 will show you the logical system name for all the existed systems in CUA.
    Else you can also go to your CUA system and execute t-code SALE --> Basic Setting --->Logical Systems  ---> Assign logical system to client -
    > Display details
    here you can see logical system names for all the clients assigned to CUA.
    Thanks,
    Deb

  • Deletion doent reflect child system

    Hi All,
    We have deleted a composite role from CUA,but to our suprise single role still exist in child system. How to delete these now?
    We have tried to re-distrubute the idoc- unsuccessful
    We cant use PRGN_COMPRESS_TIMES  as CUA is conneted.
    Any help will be appreciated.
    Thank you,
    Sri

    Hi,
    What is the status of the Idocs in Central system and Child systems? Are they processed properly? If yes and still you see the Single Roles in the child system then do the following:
    1. Check the Composite role first in the child system (and in central also if it is existing there too). If the role is not ok to see then first take of it.
    2. Do a text comparison in the Central system for the Respective Child system(s) and save the user once more by getting into change mode.  Now check whether the roles are gone or not.
    3. if the single roles are still there then assign the composite role once more and save and then remove it again. Check the SCUL status for the user id and process it if not processed already.
    4. process the IDocs manually in BD87 if not processed in the central and / or Child system(s).
    Let us know how it goes.
    regards,
    Dipanjan

  • Users were re-created in Child systems not in Cnetral System (CUA)

    Hi,
    The set of users were deleted some time back and today i verified in child system (PROD) with criteria as list of users without roles/profiles then I found a set of users in child systems.
    Were as those user master records are not showing in Central System (CUA).
    I verified the change document, It is showing the deleted date and later some time again it was created with no roles and profiles. On the same date all the others users are also get created.
    Then I have checked the change document of a user and verified is there any IDOC was generated in central system on that time and date but I didnu2019t find anything...
    I was expecting that the old IDOC's which are in status "distribution unconfirmed" with of the user and later there would be happen many changes for that user and which are get reflected in child system but the IDOC which was in unconfirmed status. When any one try's to execute the process through BDM2 or BD87 for that IDOC then again there would be chance of re-build the user account..... But one thing i was confused is if the old IDOC get re-generate then it has to be shown in the CUA system also?.
    It was strange issue, so please let me know what the reason behind it.....
    Please help me out...
    SV

    >
    Nishant Sourabh wrote:
    > I assume BD87 was executed in the child system and the idocs where manually processed which created these ids back again ....not sure if that is what happened. never seen something like that.
    Hi Nishant,
    what you are writing is the most common situation of how these users got 'recreated'.
    If you have a look at the method for user change idocs, you will notice, that it is the same method for creation and changing (CLONE).
    So if you have an unprocessed change idoc in the child system and you delete the user (succesfully) and reprocess this idoc in the child system locally, the user will get 'recreated'.
    b.rgds,
    Bernhard

  • Users created in CUA does not distribute to child systems

    Hi
    I searched this forum and after pulling my hair for 2 days I am asking this question. I created a user in CUA and gave him child system access with the necessary roles.
    I was under the impression that the user will get replicated / distributed automaticlaly to the child systems which i selected at the time of user creation in CUA
    But it does not happen. I login the child system and search for the user. It says User does not exist. I saw SCUL in CUA and the log shows a grey icon next to the username and when I place my cursor on the icon, the tect comes " Distribution unconfirmed"
    What am I missing? Everything looks ok to me
    Why is the user or users not geting replicated or distributed to the child systems with the necessary roles / profiles?

    >
    Jackofalltrades wrote:
    > 2. Also the communication user from Client to CUA is getting locked very frequently. When I do a text comparison from CUA, it always pops the username and password login screen and then I have to enter it and the text comparison happens. I don't know what that happens
    >
    > Any ideas for point 1 and 2 ?
    Hi,
    that is an indication, that the RFC-connection is not defined properly. As soon it does not work, you will get the login screen (on the login screen the default client (503) is filled automatically, but that has nothing to do with the problem you have).
    First check the password of the RFC-user you use. Simply change this user to type 'dialog' and try to log on with the password you know. If that works, reenter this password in SM59. Perform the authorization test in SM59 afterwards. Mind possible upper/lowercase problems with the password depending on the releases your systems are.
    You can also try to perform a remote login through sm59 to make sure, tath you can log on with that RFC-user (as long he is of type dailog this will work). If the rfc-user gets locked frequently, then something is wrong with the rfc configuration. In most cases the entered password is simply wrong.
    Check this first!
    b.rgds, Bernhard

  • CUA Roles residing in Child system are not showing in Central System

    I just hooked up CUA today and have linked 8 child systems to the central system.  The 8 child system users and roles have already been established in the child systems.  Do I need to run program susr_zbv_get_receiver_profiles in each of the child systems to get the roles in the child systems to show up in the Central System for each user?  I tried this in one child system and it worked.
    Or is there something else I need to do without going into each child system?
    I tried this program susr_zbv_get_receiver_profiles in the Central system but it did not work.

    are you looking for roles or profiles? profiles will not show up in the central system. If you run SCUL do you see anything? when you first added the child system did you use an SAP user that had the proper permissions? In both the child and the parent? There are two roles that the user must belong to to add the child to the parent they are SAP_BC_USR_CUA_SETUP_CENTRAL and SAP_BC_USR_CUA_CENTRAL.
    If you have any question about the permissions of these user at the time you added the child to the parent I'd delete the child and re-add with either the above roles or a user with SAP_ALL in BOTH the child and the parent systems

  • For SU01 automatically addition of field extension with  "0" in child system

    Hi
    Ids and roles are created through CUA and then it is distributed in the child systems. However in one of the child system, the users are automatically assigned a value 0 in extension field of SU01. This is then not allowing the program RSEOUT01 to be executed in the CUA system.
    We checked the error message in SCUL and it says " No telephone number entered ".
    Can anybody help?
    Regards

    Hi Saurabh,
    This is due to Company address set-up.
    Here is the Solution:
    1. Login to the respective Child system and go to transaction SUCOMP.
    2. Remove the Extension number here.then save.
    Note: When there is extension system will ask for telephone number.
    Regards
    Kiran.S

  • CUA client doesn't know any profile/role anymore after adding child system

    Hi,
    I did set up a CUA client on our Solman system. The client is client 500 which has been copied over from 000 via the SAP_CUST profile.
    In this client 500 I did create some users with the SAP_ALL profile, so no problem here.
    After adding a child system to the CUA, it seems that if I want to create a new user in the CUA client 500 it doesn't know any role/profile anymore which is standard available in this client.
    In PFCG I can find a lot of standard roles, but when adding one via SU01 I do get the error that it doesn't exist. The same goes for the profile SAP_ALL.
    Just to be clear, adding profiles or roles from child systems is not a problem, just adding roles or profiles for the CUA client itself doesn't seems to work anymore.
    I had this problem on a 7.0 solman system and now also on a 7.01.
    Did anyone had the same problem?
    Thanks,
    Gregory

    Hello Georges,
    I have exactly the same issue.
    I have created a new CUA. I have copie 001 client to 333 client, using SAP_ALL profile.
    Now, from CUA client (333), I cannot add any roles or profiles to my user.
    I have created an RFC D1CCLNT333, but it does not resolved the problem.
    Did you do anything else to fix your issue ?
    Thanks
    Best regards
    CP2009

  • Does child systems with 3 clients need 3 RFCs?

    Hello
    One quick question
    Does child system that has 3 clients need 3 RFC conenctions to connect to CUA?
    We have ECC with 3 clients. When I go in one client SM59 and create RFC connection to CUA, everything is good.
    When I go in SM59 of other client and I create RFC(same as logical name of CUA) , it says it already exist since I created in my previous client
    Any thoughts? I know from CUA I would need 3 RFCs for the 3 clients but from the child do I need 3 RFCs? If yes, its not allowing.

    Yes, normally the logical system name is used and having this the same as the RFC destination helps.
    But this does name a type of "name space" implication...
    Perhaps you want to consider where you have your master system and use client side security (the authorization group concept for S_RFC_ADM, and S_ICF type DEST to call them?
    Even if you restrict RFC, it will always need to do that which is is designed to do. Client side security makes sense in cases such as CUA.
    Cheers,
    Julius

  • CUA and SU10: unexpected deletion in all child systems

    Hi,
    I am facing with a problem with SU10 and CUA.
    I have updated a lot of users with SU10 in CUA. For 20 users in a child system, I first add a new role, everything is fine. Then I perform a remove of a old role (I know that the end date will be changed), everything is fine except for one user. All roles were removed from all systems where the user is defined ! However, when I look in each child systems, it is not the case, the roles are well present except in the child sytem for which I do the remove.
    This problem occurs twice, for different users. It is a real problem because we have to adapt a lot of users.
    I have reinstalled the 'missing' roles with SCUG and with the change document for users but it can be a workaround because I have discovered this by chance. I can imagine check all users after each run of SU10.
    Hope someone can help me.
    Regards

    Hi Olivier,
    that sounds like you are facing the problem corrected with sap note #1117530......
    The removal shows up only at the next change of a user, the actual deletion of role assignements because of the copy might have happend already some time ago.....
    b.rgds, Bernhard

  • Role assignment to user in child system

    Hi,
    We have a CUA with role assignment in SCUM defined as global. There is any way of assigning roles to users in child system when CUA system is not available? There is any way to allow roles assignement  in both Parent and  child systems?
    Many thanks for your help!!
    Raquel

    One way would be to temporarily delete the CUA assignment in the child and then maintain locally, but you will need to attach it again... and decide whether you want the CUA master to know about what you have done.
    Plan B on older Support Packs is to take a look at the correction instructions of [SAP Note 1504495|https://service.sap.com/sap/support/notes/1504495] but for this you need full access () to the S_USER objects, in which case you could detatch the CUA anyway.
    However as a temporary workaround in Test systems it could have been usefull.
    Plan C: Allow reference user assignments locally and authorize the role indirectly. Via the available authorizations of and access to the reference users you can then contain the scenario. Works fine for me if the concept of reference users is understood.
    However in most cases you should do it via the CUA and will end up doing this anyway via the CUA - that is what you have a CUA for. So... logon to your CUA in the morning, give the SAPGui scheme a nice bright colour and administrate the users and role assignments there. This is a small price to pay compared to not having a CUA or IdM...
    Cheers,
    Julius

  • Delete option coming in child System

    We have recently implemented CUA in our landscape.Now that we are able to see delete option available in one of the child system which is not there in the initial stages and not in any othere child systems.Can any one help me in finding the reason for its occurance and make it consistent with other systems.

    Hi Naveen,
    Do one thing. Try to save the CUA model through SCUA once again and look out for errors. Let yus know the errors you get. Also do one thing. Try remote login from the master ssytem into child system using the RFC destination. I think the ALE user in the RFC destination is either locked or has wrong password maintained.
    regards.
    Ruchit.

Maybe you are looking for

  • Can connect w/ PPPoE... but not route

    Ok.. I've been working on this off an on for over a month and I have reached my end, I think. Problem: I have a Linksys WRT54GL v1.1. My ISP (through cable, not DSL) requires a PPPoE connection. I can get the Router to successfully connect to the ISP

  • HP recovery could not restore computer error code 0xe0ef000e

    I bought a nice Solid State drive.  Unfortunately it is not possible to upgrade my system to new hard drive.  It fails every time with HP recovery could not restore computer error code 0xe0ef000e.  This is after removing everything...  graphics card,

  • Using Airport Express as Wireless Repeater upstairs?

    Greetings, I have a recent Netgear WNDR4000 WIFI router situated in my home "network closet" downstairs. I'm noticing that sometimes I loose connection upstairs and even though it is probably not the greatest placement to keep the router in this box,

  • Taking exactly 10 min to open the task list using smartview

    Hi All, We are using hyperion smartview 11.1.2.2 when I connect to hyperion planning task list using smartview it is taking exactly 10 min to open the task but the same is taking only 3 seconds in our Production environment. Can someone help me out.

  • Submit Button in InfoPath has stopped working??

    Hi there, I wonder if you can help me. I had a infopath form that involved people submitting a form and then approval was sent to their line manager and they would then approve the entry. This was working fine and now, despite everyone being in the s