cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

SAP Enterprise portal & GRC integration for portal role assignment

JCardoza
Explorer
0 Kudos
1,367

Hi All,

We have implemented GRC 10 AC & creating users in R/3 system through it.

I have a requirement -

     When we create user in R/3 system with GRC, the same user should be created in SAP Portal 7.0 as well.

     Also portal role assignment to the same user should be done through GRC only. Is it possible?

     I have came to know about Access Request Management (ARM) capability of SAP Access Control 10.0 to provision users and assign roles to the

     SAP  NetWeaver Portal.

     How to acheive above described requirement through ARM for portal 7.0 & 7.3?

Regards,

Joy

View Entire Topic
Colleen
Product and Topic Expert
Product and Topic Expert
0 Kudos

Hi Joy

Have you considered making the Portal UME based on ECC?  In doing this the ECC SAP Role becomes a portal group that you can then assign portal role to.

It means they user always receives their associated portal roles based on their ECC access. In addition, they user loses their Portal access when they lose their ECC. I find this helpful as Portal roles do not have expiration dates.

Alternatively, in GRC you could map related roles in the BRM definition so the user chooses their ECC and gets the mapped portal?

Regards

Colleen

Former Member
0 Kudos

Thanks Colleen for this . Do we need to make ECC System as Data Source if we make Portal UME based on ECC ???

Colleen
Product and Topic Expert
Product and Topic Expert
0 Kudos

Hi Anil

If ECC is the Portal UME then you technically do not provision direct to Portal. You assign the roles to ECC and they automatically appear as assigned as a portal group. You then need to map your portal groups (ECC roles) to the portal roles

Every ECC user is a Portal User. However, their access to Portal depends on the ECC to Portal role mappings as part of portal role build.

Regards

Colleen

Former Member
0 Kudos

Thanks Colleen.