Home / SAP Access Control

SAP Access Control

4 Data Protection Tips for Growing Businesses

Security – particularly of the cyber variety – is of paramount importance in today’s business world. If you don’t have a plan for proactively warding off attacks and safeguarding data, you’re going to have some pretty major problems. The threats are all around you – are you prepared to help …

Read More »

SAP Access Control (GRC) Firefighter ID Review

In my earlier blog about Firefighter lifecycles (https://blogs.sap.com/2014/03/03/firefighter-id-lifecycle/), I mentioned the requirement to review Firefighter IDs on a regular basis. Over the last couple of years, this requirement has become an audit finding in most organizations. Firefighter ID management is still a challenge for most organizations as adequate tools are …

Read More »

Logical Deletion of GRC Workflow Instance

What is Logical Deletion?   Logical Deletion of a workflow instance (hence called “workflow”) means canceling the workflow. When logically deleted, the workitems are removed from the approvers’ work inbox. Please note, a logically deleted workflow cannot be reversed or restarted. However, all the information of the logically deleted workflow will …

Read More »

SAP GRC Tag Collection

Dear all, with this blog I’d like to invite all members of the GRC space to participate in the new community and to use the new features. To get that kicked-off easily please find the tags and the direct links as follows: SAP Access Control SAP Access Control SAP GRC …

Read More »

Escalation only on workdays in the MSMP workflow

I really like the concept of enhancements, as it gives the flexibility to change the behavior of the application from the standard to a custom requirement. There is a step by step WIKI about creating simple enhancements, which is helpful to get started: Enhancement Framework – Class Enhancements – Pre-exit, …

Read More »

Watch out… for these common scenarios!

SAP GRC Access Control is the top application on the market in its category, it has great features. But like any other application, it brings its share of issues with every new support package upgrade or new release. When looking for upgrading or applying a corrective note, it is always …

Read More »

Enhance GRAC_UIBB_USER_REGISTER

SAP EHP2 FOR SAP NETWEAVER 7.0 Release 702 SP-Level 0017   A requirement to extend existing standard functionality for PSS when users register questions and answers. User input validation is necessary when saving – it is not to be allowed for users to duplicate answers for different questions.   In …

Read More »

SNC Name in Access Request

In SAP GRC Access Control it is common practice to provision SNC Name via Access Request. As the SNC name will be different for each user, the core question is, how to populate the correct SNC name in the Access Request form to provision in the plug-in SAP systems. The …

Read More »

Repository sync is not updating GRACUSERCONN

Some customers are experiencing the following issue after upgrade to GRC 10.1 SP 10 and SP11:   Despite repository sync job is completed without any dumps the table GRACUSERCONN is not updated,   To solve this issue implement SAP Notes below   2221261 – Code changes in repository sync for …

Read More »

My First Firefighter

The main goal of this Screen Personas flavor My First Firefighter, is to provide the GRC Access Control administrator with diagnostic of firefighter configuration. The flavor collects firefighter configuration data and compares to expected value for a correct behavior. This comparison result into a detailed log to assist GRC administrators …

Read More »

PFCG Synchronization Dump

Hello GRC Community,       Some customers are facing a dump when trying to synchronize the authorizations between BRM and PFCG,     And if you check the st22 there is a dump like the one below:     —————————————————————————————————- Category                             ABAP Programming Error Runtime Errors                   SAPSQL_ARRAY_INSERT_DUPREC Except.                               CX_SY_OPEN_SQL_DB …

Read More »

Deactivation of the NWBC Splash Screen

Dear all,   this document outlines how the NWBC splash screen can be deactivated. When launching the NetWeaver Business Client (Transaction NWBC) the splash screen starts first. The splash screen shows all the role assignments the user has and is helpful in test systems for testing the roles. However, in …

Read More »

EAM Utilisation and Log Review Process

Dear all,   the motivation to write this document comes with the GRC Document Collaboration Topics project. Leo has requested more information about EAM audit trails and utilisation from a business point of view.   SAP Access Control with its module Emergency Access Management (EAM) enables users to perform activities …

Read More »

Direct vs. Indirect Role Assignment

This document elaborates the differences of the direct vs. indirect role assignments in SAP Access Control. Each scenario has its pros and cons and can be used dedicated or also in combination. Direct Role Assignment Authorization roles (and profiles) are directly assigned to the User Master Records via SU01/PFCG, Access …

Read More »

BRM Role Methodology via Condition Groups

3/Nov/2016 – Blog updated for re-tagging. Content migrated from SCN This document has been written to explain how you can customise the ROLE METHODOLOGY steps depending on role criteria. The configuration requires the use of a BRF+ rule that using CND_GRP (condition group) as the rule result.   Please note, …

Read More »

It’s Just a Few GRC Ideas….Place

3/Nov/2016 – blog updated for re-tagging due to SCN migration Hi GRC Community   Do you get frustrated by functionality that it lacking? Do you see something in the solution and consider it an incident but are then told it’s by design? Are you creative and love to continually improve …

Read More »

GRC Product Support Monthly Newsletter

Hello GRC Community-   Every month, GRC Product Support together with our Development team will share with you information proactively to help keep you up to speed on important news. The Newsletter will be uploaded to KBA 2123844 . This is our first edition and would like to hear from …

Read More »