cancel
Showing results for 
Search instead for 
Did you mean: 

GRC 10.1 ARA Function Permission

Former Member
0 Kudos

Hi,

My risk function actions and permissions tabs are maintained via rule upload. The permission rule upload template is maintained with the condition OR for all the defined permissions at object and field levels.

After rule upload, I've proceeded to check the functions in ARA and noticed that some of the permission records are maintained with condition 'AND' instead of 'OR'. So, I have attempted to manually update the condition from 'AND' to 'OR' at the permission tab of a function.

However, when I click on 'Save' it switches back to AND.

Has anyone encountered this situation before? And, please share how to resolve this?

Regards,

Debbie

Accepted Solutions (1)

Accepted Solutions (1)

Former Member
0 Kudos

Hi Debbie,

The condition is getting updated as per the design. Kindly refer the below Notes for more details

1514544 - Explanation of logic between and within permissions


1330165 - Instructions on how to use Operators AND OR NOT


1905343 - Condition type AND is mandatory for single value fields




Regards,

Manju

Former Member
0 Kudos

Hi Manju,

Many thanks for sharing those notes. They have been helpful

However, now I'm encountering another problem. Whenever I run role/profile/user level risk analysis, I'm getting the message 'No rules selected' under column Action in the report.

I have configured ARA following the 'AC 10.0 - Pre-Implementation from Post-Installation to First Risk Analysis' deck, generated SOD rules, run the auth and repository sync jobs and checked that the functions are mapped to the correct connector group configured in SPRO.

I tried running risk analysis SAP_ALL profile, but I am also getting this message instead of risk violations. Any idea what steps are missing?


Regards,

Debbie

Former Member
0 Kudos

Hi Debbie,

Can you please check the following

1. Relevant BC Sets are activated using SCPR20 transaction which will be deliver the Ruleset data in GRC system. You need to activate the common Ruleset first and then activate other Ruleset(s).

2. The connectors are assigned to the correct logical group.

3. Re-run the synchronization Jobs.

3. Re-generate the SOD rules.

Also refer the below thread where similar issue was discussed

No Rules were selected | SCN

Hope this helps

Regards,

Manju


P.S : If the issue still persists kindly provide the SP level with the relevant screenshots.

former_member185447
Active Contributor
0 Kudos

Hello Debbie,


  • Recheck if the Connector group is properly maintained or not?


  • Download the ruleset from the SAP Default logical groups and upload them manually into custom connector groups.

Please check the following note to confirm if you are uploading the rule files properly or not


2029475 - How to upload Rule files in Access Control 10.0 and 10.1

Regards,

Rakesh Ram M

Answers (1)

Answers (1)

Former Member
0 Kudos

Hi All,

Many thanks for your inputs.

This issue is resolved after creating another connector group with the targeted system as connector and system is replaced with the new connector group in all the ARA functions.

Regards,

Debbie

jtippini
Explorer
0 Kudos

Hello Debbie,

Could you please elaborate on "system is replaced with new connector group in all functions"? is there a way of mass maintenance? Thank you

JD Sudhakar