Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

GRC: User not created in backend (CUA client)

nguyen_huynh
Explorer
0 Kudos

Hello expert,

We have GRC 10, SP13.

I have configured the connectors and setting for my CUA client.

I also configured my CUA client in SPRO.

I am able to select my CUA client in ARQ. When submitting, the request is approved.

Audit Log is showing:

Application log is showing:

But there is no user provisioned in my CUA client, not any IDOC or log in showing in my CUA master.

Did I missed something? Any advise is appriciated.

Regards Nguyen

7 REPLIES 7

Former Member
0 Kudos

Hi Nguyen,

This issue seems to be because of the CUA setup only.

Please confirm and check for the below configuration settings:

1) Maintain CUA Settings. Did you maintain CUA system/client as the target client.

2) Can you see all the child connectors under Maintian CUA settings. Check the tables:  GRACCUADIST and GRACCUAMSTR

3) Have you installed CUA plug-ins in CUA system.

4) Check for the FM: /GRCPI/GRIA_ASSIGN_OBJECT_NH

Let us know if this helps or for any more issues.

Regards,

Ameet

0 Kudos

Hi Ameet, thanks for your info.

1) Maintain CUA Settings. Did you maintain CUA system/client as the target client. --> Sorry, I am not sure what you mean? I have configured CUA for my backend and I can create a user via my CUA master, the CUA client is provisioned by sended IDOC from the master. Now I would like GRC provisioning the user to the CUA client instead of the CUA master.

2) Can you see all the child connectors under Maintian CUA settings. Check the tables:  GRACCUADIST and GRACCUAMSTR --> yes, my configured CUA client is listed in table GRACCUADIST, table GRACCUAMSTR is empty as I don't want my GRC to use CUA as a global tool.

3) Have you installed CUA plug-ins in CUA system. --> My CUA client and master have the GRC Plugin.

4) Check for the FM: /GRCPI/GRIA_ASSIGN_OBJECT_NH --> FM exist in CUA client/ master and GRC. What is this FM good for?

Thanks for advise, regards Nguyen

0 Kudos

Hi Nguyen,

Follow: GRC -> Access Control ->User Provisioning -> Maintain CUA Settings

http://service.sap.com/sap/support/notes/1616121

Where do you want to have user provisioning in place..in CUA master or CUA child system?

Can you please confirm for the CUA gloabl system configuration under "maintain CUA settings"

Ameet

0 Kudos


Hi Ameet,

I want to have user provisioning in CUA child system. My company is using for some systems CUA and for other systems they are not linked to CUA. I would like to have ARQ for both, meaning 1 request which provisions user to CUA child and to the non CUA system. So option "CUA Global system" is not feasible for us as if I undrestand correct, this option would only allow provisioning CUA clients.

So this is why setting CUA Global System is empty. Please correct me if I am wrong.

CUA Model Distribution is maintained by me with the CUA childs. see screen above.

Thanks for advise, regards Nguyen

0 Kudos

hi Nguyen,

Now that you have mentioned the fact that you want to use ARM via both CUA and directly, I have to bear the bad news and let you know that this is not possible. You have to provision all systems via CUA or directly from GRC. I raised a customer call to ask the same question to SAP and received this response Very response.

if you are adamant on utilising CUA then you will have to connect the other plugin systems to the CUA system also and configure the Global CUA setting also (from what I understood from the support team).

0 Kudos

Hi Harinam,

thanks for your info. This really bad news for us.

Best Nguyen

0 Kudos

I may have misunderstood your issue.


Just looking at your screenshot, I am sure you have to configure your actual master CUA in the Global setting also. Try that and see if it works. We had different issues with CUA after, as our project wished to have user creation via CUA but role assignments both via CUA and via SU01 (i.e. direct). This is not possible.