cancel
Showing results for 
Search instead for 
Did you mean: 

User provisioning failure in GRC AC 10.1 (CUA integrated)

0 Kudos

Dear All,

Facing a strange issue with ARM module of AC 10.1

System setup :

GRC AC 10.1  SP 06

CUA System (USER SEARCH AND DETAILS SOURCE)

Target system : ECC

All user provisioning actions performed via CUA to ECC.

Issue details - 01

When i submit a user creation request for ECC , request fails and gives following errors/warnings in SLG1

  • User doesn't exist in CUA system - Fake message.
  • You are not authorized to assign the roles in CUA - Fake message
  • User can't be created in ECC system. - Fake message

When I check in target system (ECC) user got created from CUA but password details were not sent to user.

What I checked so far :

CUA Settings active.

SAP_ALL authorizations given

AC connector settings are fine, synch job runs fine.

Issue details - 02

When i submit a change user request for role removal in ECC , request fails and gives following errors/warnings in SLG1 and request ends without doing action.

  • Role not assigned to user - Fake message, role is with user, i can see it existing assignments on request creation page.

Issue 02 - raised to SAP already a month back but 0 progress with all incorrect suggestions.

Issue details : 03

When i select the user ID on request it doesn't automatically populates user name, last name and email address, though user details source configured  correctly.

Would appreciate if anyone share your ideas, troubleshooting skills to resolve above issue?

Greetings,

Jay

Accepted Solutions (0)

Answers (4)

Answers (4)

0 Kudos

Hi Jay,

has there been any progress with regarding your provisioning problems? I wonder, because we are struggeling with the exact same issues here:

  • failed provisioning when new child systems are added to a user in CUA through GRC
  • user details such as last name, e-mail, etc. are not populated automatically, though user detail source is configured
  • role removal provided through a change user request does end in slg1 message 'role not assigned to user' + no actual role removel neither in parent nor in child system
Former Member
0 Kudos

Hello

I have an identical issue . applied note SAP 1616121 . as Integrated AD with GRC 10.1 and SAP NW 7.4 portal.

However SAP recommended to remove Target CUA connectors to bring in SAP NW portals Systems.

On doing this , request gets provisioned only if the id exist in CUA .For a new account GRC cannot process this request .

Any suggestions on this

0 Kudos

Hi Parag,

Checked the note, it doesn't help to fix the issue.

We have maintained CUA as active.

Regards,

Jay

Former Member
0 Kudos

HI jay

I am having exactly same issue as you mentioned in point 2.

were you able to resolve it? if yes can you please provide the solution

Parveen

former_member193066
Active Contributor
0 Kudos

Hello,

is your issue resolved or you need help?

still trying to understand does sap message says fake or you have mentioned it as fake?

Regards,

Prasant

0 Kudos

Hi Prasant,

Thanks for reading it. I mean SLG1 log is giving incorrect message.

Regards,

Jay

Former Member
0 Kudos

Hi Jaya,

Can you please refer: http://service.sap.com/sap/support/notes/2072086

And check your CUA configurations for GRC: http://service.sap.com/sap/support/notes/1616121

How about the user sync job, did it run successfully. Try to run this job in full sync and let us know if you still have any issues.

Regards,

Ameet

0 Kudos

Hi Ameet,

Thanks for looking at the question and replying too.

SCUM settings are Global and settings active are as per 1616121.

Regards,

Jay

Former Member
0 Kudos

Hi Jay,

Could you run RFC authorization test?

Run trace for CUA-RFC user and to the calling system as well.

You are trying to submit user create/change request for one user or multiple user accounts?

Can you please paste snap shots of your SCUM configurations, i need to be sure if this is set as Global or Local and the respective configurations.

Regards,

Ameet

0 Kudos

Hi Ameet,

RFC - authorization test to CUA is fine.

SAP_ALL - Authorizations are given.

Attached SCUM settings, as i said are global.

Point here is GRC can change user in CUA i.e. creates/assign the role but request ends with errors,messages.  If it is a authorization error then GRC can't modify the user in CUA system.

Greetings,

Jay