Sunday, 7 December 2025

GRC - Shared SAP GRC Configuration

In GRC system --> we need to do this configuration.

IMG screen in GRC system.

T-code for IMG - SPRO



* General settings, shared master data  settings, reporting & Common component settings are common settings for access control, Process control and Risk Management customizing.

Then we have Access control --> Which is specific to Access control.
Process control --> Which is specific to Process Control.
Risk Management --> Which is specific to Risk Management.


Step1:





* Based on license, we have with SAP. Need to active the component.
Once after activating the components in IMG. You will see specific info in NWBC

Step2:


Let create one admin user, GRAC_ALL in both GRC and ERP system
Roles tab --> SAP_GRAC*
Add all the roles with filter SAP_GRAC* to user.
SAVE


Step3:

Login to ERP system

Create user GRAC_ALL in ERP system 
Add profiles --> SAP_ALL & SAP_NEW
SAVE

Step4:

From GRC system.

Access T-code: SPRO
Click on - SAP Reference IMG










Now Click on Clock symbol- General settings.







Click on -> New Entries                                                                                                                                 
Select the required component
 1.GRC-AC - Access control.
2.GRC-PC - Process control.
3.GRC-RM - Risk Management.

Click on Active check box to activate realted component data. SAVE & Followed by TR details need to provide.






Step 5:

Create logical system in GRC system.

T-code: BD54
<SID>CLNT<client no.>


Transport request no.2


Step 6:

Access T-code - SCC4

Logical system, which is created in step 5 need to assign that in Step 6.
To the respective client.

Step 7: In ERP( satellite) system:
Login with user: GRAC_ALL

Ensure correct logical system is updataed in ECC(satellite) system.

Step 8: RFC connection 

Communication user in ERP system:
User Name: RFC_GRCAC
Profiles: SAP_ALL and SAP_new


Communication user in GRC system:
User Name: RFC_GRCAC
Profiles: SAP_GRAC_ALL


*Role - SAP_GRAC_ALL is super user with all authorization of GRC AC component.













 

No comments:

Post a Comment