GRC System Configuration

  1. The RFC destination for authentications and SOD check must be present in Tcode SM59. ( Ex. IAG_SOD_AUTH, IAG_SOD)

  2. Configuration parameters for the bridge must be set up with the RFC names created in step 1 under SPRO >Governance, Risks and Compliance > Access Control > Maintain Configuration Settings.

    Parameter Group Parameter ID Parameter value

    Cloud Integration

    1090

    YES

    Cloud Integration

    1091

    RFC name created in step 4 for SOD

    Cloud Integration

    1092

    RFC name created in step 4 for SOD Auth

    Example of parameter names:

  3. Separate RFC destinations for all the cloud applications.

    Note
    The name of the RFC destination for every cloud application must be exactly the same as its corresponding application ID name in IAG. This behavior is for SAP by-design.

  4. In SAP Gateway administrator, the IAG_PROVISION_STATUS_UPDATE_SRV service must be maintained under SPRO > Governance, Risks and Compliance > SAP NetWeaver > SAP Gateway Administration > General Settings > Activate and Maintain Services.

  5. The repository sync job GRAC_REPOSITORY_OBJECT_SYNC must be ran in GRC as well for cloud applications.