Configure the SAP GRC Server

Perform the following on the SAP GRC Server using the administrator privileges:

  1. Execute SPRO transaction code and select SAP Reference IMG.

  2. Go to Governance, Risk and Compliance > Access Control > User Provisioning.

  3. Select the image to execute Maintain Provisioning Settings transaction.

  4. In Dialog Structure, select Maintain Global Provisioning.

  5. In the Provisioning options section, select one of the following in Auto Provisioning based on the Integration Mode:

    • For Risk Analysis: No Provisioning

    • For Access Management: Auto provisioning at end of request

Alternatively you can maintain these settings on individual systems as follows:

  1. Execute SPRO transaction code and select SAP Reference IMG.

  2. Go to Governance, Risk and Compliance > Access Control > User Provisioning.

  3. Select the image to execute Maintain Provisioning Settings transaction.

  4. In Dialog Structure, double-click Maintain System Provisioning and select the required connector that is configured as defined in Creating an RFC Connection on SAP GRC System.

  5. In the Provisioning options section, select the following based on the No Provisioning from the dropdown against label Auto Provisioning. The default value for this label is Auto provisioning at end of request.

  • A SAP ABAP type of connection must be defined in SM59 transaction, which is used to indicate the IdentityIQ connection virtually at SAP GRC server. This connection is treated as a Request Initiation System in the SAP GRC application configuration. For more information, refer to Creating an RFC Connection on SAP GRC System.

  • Status of requested Roles must be set to production on the SAP GRC Server.