2020. 1. 23. 20:56ㆍ카테고리 없음
'Hello, I made the type of the users in the CUA from Communication to System users but these changes did not transfer to the child system. The distribution parameters are set to Global. The RFC worked fine.and the users of the RFC connection for the CUA have the right authorization and are communication users. Apr 13, 2012 Backend Role Sync with SAP GRC 10.0 AC. After creating the roles in the backend, I ran SE38 and GRACROLEREPUSERSYNC in the GRC system. However, the roles were not imported in the GRC system and as a result could not perform the risk analysis through the nwbc. Option 2 Another way I tried was also to import these roles directly in. Authorization: Synchronizing roles in other system to CUA If you're using Central User Administration (CUA), there will be time where you might need to synchronize the roles from other systems (DEV / QAS / PRD) into CUA for user assignment.
This section applies to the SAP ERP connector only. It is relevant for CA Identity Manager and CA Secure Cloud. It is not relevant for CA Identity Governance.The SAP ERP connector lets you manage SAP Central User Administration (CUA) environments. SAP CUA maintains user records in a central master system, and automatically distributes these records to its child systems.You can acquire the child systems as endpoints as well as managing the master system as a CUA master. How the SAP ERP Connector Works with SAP CUAAfter the SAP ERP connector has connected to an SAP CUA master system, you can use your CA product to manage identities on the SAP CUA master system.
The master then propagates your changes to the child systems. Note: Passwords are.Example: Add a role to the SAP CUA master using CA Identity ManagerIn this example, you use the User Console to create an account on the SAP CUA master. Note: With SAP Kernel 6.40, an attempt to change the password of an account that does not reside on the Master system will return PASSWORD NOT ALLOWED.When connecting to a CUA master system using a pre-expired password, the following occurs:. On Account Creation for both CUA Master and CUA ChildThe password is pre-expired. You must change the password upon first logon.
Sap Cua Authomatically Synchronize Roles In The Workplace
On Account ModifyCUA Master - The password is pre-expired. You must change the password upon first logon after the change.CUA Child - The password change is not distributed to child systems. Password management must be done locally.Distribution Settings in SAP CUASome distribution settings in your CUA environment can cause unexpected results.If you use the SAP connector to change an attribute in a way that conflicts with the CUA distribution model, the modification attempted by the connector may be ignored. In some cases, SAP returns an error.