cancel
Showing results for 
Search instead for 
Did you mean: 

Composite role upload in GRC

surya_appala
Active Participant
0 Kudos

Hello Experts,

I have uploaded a composite role in GRC. It has got 2 single roles (A and B). After uploading, Security team has added one more single role (C) and deleted one existing single role (B) in back end system. So now composite role literally has A and C but not B where as in GRC I see the single roles as A and B only.

Like this there are many composite roles in GRC which are not in sync with roles of back end system. Do I need to upload the modified composite role again in GRC to get this corrected and also let me know if it will have any impact if the composite role is assigned to user without modifying it in GRC.

Thanks.

Regards,

Surya

Accepted Solutions (0)

Answers (2)

Answers (2)

former_member185447
Active Contributor
0 Kudos

Hello Surya,

Did you happen to check this SAP Notes?

2102784 - GRACROLERELAT - Incorrect entries


Please Check this solution


In order to Import the Composite Roles in BRM, you need to ensure that its Child Roles (Single Roles) exists in the system. Please import all the Child roles first and then try Re-Importing the Composite Role in the system. This will upload the Composite role successfully.

Regards,

Rakesh Ram M

former_member197694
Active Contributor
0 Kudos

Hello Surya,

While dealing with composite role modifications,best practice is

First single roles need to be removed from the composite role in BRM, then composite role need to be renegerated at step "Generate Roles" and PFCG will be updated accordingly.

Hope it helps you

Regards

Baithi

surya_appala
Active Participant
0 Kudos

Hello Srinivas,

We are not using BRM for role maintenance. We are just uploading them in GRC for ARM purpose only.

My question if there is any change of role in ECC system do I need to re upload them to correct the same in GRC as well. Also, without re uploading them in GRC if the composite role got assigned to any user will it have any impact ?

P.S: All single roles are already uploaded in GRC.

Thanks

Regards,

Surya

Former Member
0 Kudos

Hi Surya,

When you add or remove single roles within a composite role in the plug-in system the changes will not be adjusted in BRM when you run the repository object sync.

You will have to re-import the composite roles to BRM.

In case of single roles the authorization changes get adjusted in BRM when you run the repository object sync.

Regards,

Manju

former_member197694
Active Contributor
0 Kudos

Hello Surya,

Yes,you need to re import again and run repository sync job.

The results will be stored in GRACROLERELAT table.

User assignment will consider the role results from GRACROLERELAT table.

Regards

Baithi

surya_appala
Active Participant
0 Kudos

Hello Manjunath,

I just added SU01 in single role and ran Repository object sync. But still the authorization changes did not appear in NWBC.

Regards,

Surya

Former Member
0 Kudos

Hi Surya,

Run the repository object sync in full mode and check.

Regards,

Manju