Blog
SAP GRC Critical Update for Integration with GRC12 SP19 and Above
Author
vivek_shrivastava
SailPoint
Dear Valued Customer,
We want to inform you about an important update regarding our SAP GRC integration, specifically with GRC version 12 SP19 and above.
SAP has introduced significant modifications in its SAP GRC version AC 12.0 SP19 and above in inactive users and sync job processes, which has affected our SAP GRC connector functionality adversely.
We have addressed the impacts of these changes and rolling out fixes in following IIQ versions: 8.3p4, 8.4p1, 8.5
Also, assisting customers on older IIQ versions with on-demand efix requests, which can be raised via your CSM representative for IIQ 8.4, 8.2p4, 8.3p2 and later patches only when using ABAP Function Module (as RFC_READ_TABLE is deprecated more than a year ago)
Details about the issues and fixes
Diable Operation
- Issue: With the upgrade of GRC from AC12 SP19 & above, you may seeSystem attribute on account schema as INACTIVE_USERfor the aggregated accounts which are disabled only on highest priority system on SAP GRC
- Resolution: This issue is observed due to the Repository sync job changes introduced by SAP for updating their table values. For resolution, kindly ensure the changes on GRC and source configuration as below:
- Ensure that the Repository sync job is scheduled on your SAP GRC instance.
- The option for ‘Disable only Master’ system will be removed from the source config. UI without impacting existing customers’ configuration. We highly recommend you to revisit your source configuration for ‘Disable’ operations.
- If you are on or upgrading to new IIQ version 8.3p4, 8.4p1, 8.5 you will not see the ‘Disable only Master’ anymore, and ‘Disable All’ is selected by default.
- If you are on the old IIQ version, and opting for the efix, the option for ‘Disable All’ needs to be selected manually
- Provide additional permissions required on the SAP Tables for GRC 12 SP19 and above for Aggregation and Disable operations.
- The instructions will be updated in our connector guides, and shall also be provided with our efix.
Modify Operations
- Issue: SAP has introduced a new process where any modifications/changes in the user profile reflect in GRC tables only after completing the Repository sync job. This has adversely affected our connector operations
- Resolution: The following steps must be performed sequentially for a successful modify operation:
- Update the identity attributes manually or using the attribute synchronisation, refer to Attribute Synchronisation section
- Run the Repository Object Sync job on your GRC system
- Run “Perform Identity request maintenance” task. Refer to our doc guide Tasks section
Link to our previous blog post which includes moe details and SAP KB Articles as attachments
Kindly reach out to your CSM or our support team for any queries or issues
Sincerely,
SAP Integrations Team