Blog
SAP GRC Critical Update: Integration Broken with GRC12 SP19 and Above
Author
vivek_shrivastava
SailPoint
For latest updates, kindly refer to our new post on this topic
Dear Valued Customer,
We want to inform you about an important update regarding our SAP GRC integration, specifically with GRC version 12 SP19 and above.
SAP has introduced significant modifications in its SAP GRC version AC 12.0 SP19 and above in inactive users and sync job processes, which has affected our SAP GRC connector functionality adversely. During our internal process of certification, we have found breaking changes in 'Disable' and ‘Modify’ use cases and incorrect data during user aggregation.
Unfortunately, the changes done by SAP in version SP19 are not compatible with our current integration design which is based on workflows supported up to SAP GRC12 SP18, and leading to these issues. We at SailPoint are committed to provide you with seamless SAP integrations and are aggressively working to address these impacts asap.
Details of the impact:
Disable Operation
The disable operation from the connector is impacted in both the configuration settings that are provided in the connector config. i.e. Disable only Master System, and Disable All Connected Systems.
- Aggregation process may result in failures if the connector configuration is set for ‘Disable only Master System’.
- Aggregated data may not be correct with ‘Disable All Connected Systems' configuration (due to the changes introduced on sync job)
Errors Observed:
- Disabling user only on the master system
Error: System attribute for the user under the application account details shows <#INACTIVE USER#>
2. Disabling users on one or more child systems but keeping it enabled on Master system
Result: No errors are observed in this scenario as the user is enabled on Master
3. Disabling the user on one or more child systems AND on the Master system
Error: System attribute for the user under the application account details shows <#INACTIVE USER#>
Modify Operation
SAP has introduced a new process where any modifications/changes in the user profile reflect in GRC tables only after completing a sync job. This has adversely affected our connector operations as:
- Changes to user attributes or status after modification do not immediately reflect in the 'GRACUSER' table.
- Running a Sync job for a specific child system results in the changes reflecting for that particular system only.
- A Full Sync job for all connected systems showcases changes for all child systems in the priority order.
Errors Observed:
- Modify Users operation fails as the connector cannot identify changes in SAP tables unless the sync job is run.
- Get Account operation shows incorrect results as requested updates are not found on the GRC side and the the entire access request is marked as ‘Failed’ on IIQ/IDN
Triggering the SAP sync job and awaiting its completion is necessary for the changes to reflect in GRC tables, and for the connector to confirm successful operations.
Mitigation Plans:
We request our SAP GRC integration customers not to upgrade to GRC 12 SP19 or above in Q1’24 as there are significant enhancements required in the SAP GRC connector to address the impacts caused by SAP changes.
At SailPoint, we are dedicated to keeping our customers informed about the latest releases and are actively working to update our GRC integration. We anticipate releasing a connector update in Q1 2024 to resolve the impacts of GRC 12 SP19 and subsequent releases.
We apologise for any inconvenience this may cause and kindly ask for your patience and cooperation as we strive to provide a solution. Updates on our progress will be announced soon.
Sincerely,
SAP Integrations Team