<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GRC Access Request Valid Dates restriction in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/grc-access-request-valid-dates-restriction/m-p/11627718#M1942167</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sara,&lt;/P&gt;&lt;P&gt;I did not see&amp;nbsp; a way to accomplish this through security or through EUP settings. I ran a trace just to see what authorization objects showed up. GRAC_REQ does not offer granular enough options to restrict change to just the role validity dates; if you took away change access from your requestors, it appears that they would lose a lot more. Did you try taking away change access on that object?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course they say that with enough time and money for customization, anything is doable, but heavy customization is probably not the path you want to take. What is the rationale for this requirement?&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gretchen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Apr 2016 20:21:20 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2016-04-21T20:21:20Z</dc:date>
    <item>
      <title>GRC Access Request Valid Dates restriction</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/grc-access-request-valid-dates-restriction/m-p/11627717#M1942166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have defined some users which are requestors. So these users will create access requests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Now, I would like to restrict the capability that the requestor modifies the Valid From / Valid To dates into the access request. The ones marked in red.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;IMG class="migrated-image" src="https://community.sap.com/legacyfs/online/storage/attachments/storage/7/jiveimages/935747" /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Is there any way to do it? I have checked this at EUP level, Authorization level and at MSMP level but I was not able able to find out.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards and thank you,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Sara.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Apr 2016 16:16:34 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/grc-access-request-valid-dates-restriction/m-p/11627717#M1942166</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2016-04-21T16:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: GRC Access Request Valid Dates restriction</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/grc-access-request-valid-dates-restriction/m-p/11627718#M1942167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sara,&lt;/P&gt;&lt;P&gt;I did not see&amp;nbsp; a way to accomplish this through security or through EUP settings. I ran a trace just to see what authorization objects showed up. GRAC_REQ does not offer granular enough options to restrict change to just the role validity dates; if you took away change access from your requestors, it appears that they would lose a lot more. Did you try taking away change access on that object?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course they say that with enough time and money for customization, anything is doable, but heavy customization is probably not the path you want to take. What is the rationale for this requirement?&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gretchen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Apr 2016 20:21:20 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/grc-access-request-valid-dates-restriction/m-p/11627718#M1942167</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2016-04-21T20:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: GRC Access Request Valid Dates restriction</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/grc-access-request-valid-dates-restriction/m-p/11627719#M1942168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: calibri, verdana, arial, sans-serif; background: transparent;"&gt;Hello Sara,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: calibri, verdana, arial, sans-serif; background: transparent;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit; background: transparent;"&gt;Check if this is happening only to business roles or all other roles?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: calibri, verdana, arial, sans-serif; background: transparent;"&gt;Also, Go through these SAP Notes which might help you.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;SPAN class="title" style="font-weight: inherit; font-style: inherit; font-family: calibri, verdana, arial, sans-serif; background: transparent;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit; background: transparent;"&gt;2119407 - UAM: Incorrect validity dates when business role is added in the simplified access request&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit; background: transparent;"&gt;&lt;SPAN class="title" style="font-weight: inherit; font-style: inherit; font-family: calibri, verdana, arial, sans-serif; background: transparent;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit; background: transparent;"&gt;&lt;SPAN class="title" style="font-weight: inherit; font-style: inherit; font-family: calibri, verdana, arial, sans-serif; background: transparent;"&gt;2042631 - Validity Dates for Business Roles&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit; background: transparent;"&gt;&lt;SPAN class="title" style="font-weight: inherit; font-style: inherit; font-family: calibri, verdana, arial, sans-serif; background: transparent;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;SPAN class="title" style="font-weight: inherit; font-style: inherit; font-family: calibri, verdana, arial, sans-serif; background: transparent;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit; background: transparent;"&gt;1979538 - Simplified Access Request Role Validity Dates Validation Error messages&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: calibri, verdana, arial, sans-serif; background: transparent;"&gt;Check if this thread gives you some lead to solve your issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: calibri, verdana, arial, sans-serif; background: transparent;"&gt;&lt;A class="jive-link-external-small" href="https://scn.sap.com/thread/3659245" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #3778c7; background: transparent;"&gt;https://scn.sap.com/thread/3659245&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: calibri, verdana, arial, sans-serif; background: transparent;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; color: #333333; background: #ffffff;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: calibri, verdana, arial, sans-serif; background: transparent;"&gt;Deepak M&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Apr 2016 01:38:25 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/grc-access-request-valid-dates-restriction/m-p/11627719#M1942168</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2016-04-22T01:38:25Z</dc:date>
    </item>
  </channel>
</rss>

