on ‎2019 Jun 12 5:46 PM
Hello,
While raising Model based request we have identified that some of the non selectable roles are visible in availble section of refernce user , so is it possible to restrict this template to show only those roles which can be selected .
For example:
Let suppose we have below roles
Composite 1 : MAIN ROLE ASSIGNED TO USER1 IN BACK END AND SELECTABLE IN BRM
Child 1 : Child role which is part of composite1 and is not selectable in BRM
Child 2:Child role which is part of composite1 and is not selectable in BRM
So now in model user if we give USER1 as a refernce user then availble selection shows all three roles Composite1, child 1 and child 2 , however we want only Composite1 should be visible and selectable.
Request clarification before answering.
Hi Pranjal,
Indirectly assigned roles should not show up in Existing Assignments as well as in Model User requests. If they are showing up, please check if the Composite to Single role relationship is correctly maintained in GRC BRM.
This is a issue which i have chased SAP support lot of times and still they do not have proper fix for the issue as they do not have any indicator for indirectly assigned roles in GRACUSERROLE. Instead they will take the roles from GRACUSERROLE and if it is a composite role they will do a check against GRACROLERELAT table and then exclude child roles of composite role from Existing assignments or Model User screens. This logic works correctly only when you have maintained Composite to Single role relationship correctly in your BRM.However, the logic goes for toss if you have child roles of composite role directly assigned as well and based on validity dates and all.
If issue still exists, raise a message to SAP.
2772540 - Singles from the Composite role directly fetched in existing assignment
2091817 - UAM: Indirect Assignment are displayed in model user
2033916 - Indirect Assignment are shown in model user
Regards,
Madhu
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
If you have the Composite 1 as the Business Role(Item Type) then you will be able to select only Business Role but not the technical role.
Thanks
Ramesh
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 32 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.