on 2016 Jul 15 12:25 PM
Hi All,
I am running a Role Level Risk Analysis for a risk contained sample role in SAP GRC 10.1 SP5 system. Report results successfully for "Action Level" but it is showing "No Violation" at "Permission Level" though it had to show me permission level risks. I have checked the rule-set. And also have checked the Risk-rule-set which is generated, and it seems perfect.
Please help me to resolve this issue. Thanks in Advance!
Regards
Manisha
Help others by sharing your knowledge.
AnswerRequest clarification before answering.
Hello Manisha,
In addition to the above solutions, please find the following:
https://scn.sap.com/thread/3599079
Regards,
Rakesh Ram M
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hello Manisha,
Please check SAP Note # 1262329
The reason why you can see risks at Action level but not at Permission level is because the user does not have the required permissions (authorization objects) to fulfill the conditions determined by the Risk.
What you can do to troubleshoot it is:
1. Looking at said Risk through NWBC and selecting the "Permissions" tab. Take note of all authorizations required
2. Cross-check it with the user or role being checked in the Risk Analysis. If the user does not have the minimum authorization values as defined in the Risk definition, it means your Risk Analysis is working perfectly.
Risks may show up in Action level and not in Permission level -- but never the other way around.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi,
Could you please help me on the issue which I am facing.
Regards
Manisha
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi,
Could you please help me on the issue which I am facing.
Regards
Manisha
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hello Manisha,
Are you running the risk analysis from "Report and Analytics" tab? If so, this is based on the batch risk analysis data.
In that case, can you ensure that the batch risk analysis was executed for permission level also? If it was run only for action level then the case you mention might happen.
Thanks!
Sammukh
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Manisha,
Can you check the Value from and Value to fields for ACTVT in the function permission Tab.
If the value are like 1 and 2 you need to change these to 01 and 02 , the same as your backend system.
Regards,
Manju
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Manisha,
Do you see any error logs in SLG1 or ST22 dumps?
Can you try re-generating the SOD rules and check if the action and permission rules are successfully generated for all the risks.
Then , try running the risk analysis and check if you are able to see the violations at permission level.
Regards,
Manju
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.