https://raw.githubusercontent.com/ajmaradiaga/feeds/main/scmt/topics/SAP-Cloud-Identity-Access-Governance-qa.xmlSAP Community - SAP Cloud Identity Access Governance2026-03-01T00:12:19.759492+00:00python-feedgenSAP Cloud Identity Access Governance Q&A in SAP Communityhttps://community.sap.com/t5/technology-q-a/how-to-provision-assignments-with-validity-date-from-sap-ips-to-as-abap/qaq-p/14140569how to provision assignments with validity date from SAP IPS to AS ABAP system2025-06-30T16:22:41.595000+02:00devaprakash_bhttps://community.sap.com/t5/user/viewprofilepage/user-id/204226<P>Hello Experts,<BR /><BR />Has anyone been able to provision users to AS ABAP SAP System from IPS where the AS ABAP system is configured as an target or else as proxy system. what should be maintained in the transformation so that the connector can provision? <BR /><BR />I am guessing this is the Function Module which we will be using ips connector uses to provision user assignments <SPAN class="">BAPI_USER_ACTGROUPS_ASSIGN.<BR /><BR />I see this function module accepts validity dates for role assignments? but how to pass this in the write transformation logic?<BR /><BR />currently in write transformation of proxy system below is the logic. As per my understanding for each role the user would be assigned? then how can be pass the validity dates for each role assignment? does the IPS support that?<BR /><BR /></SPAN></P><PRE>{
<SPAN class="">"sourcePath"</SPAN>: <SPAN class="">"$.members[*].value"</SPAN>,
<SPAN class="">"preserveArrayWithSingleElement"</SPAN>: <SPAN class="">true</SPAN>,
<SPAN class="">"targetPath"</SPAN>: <SPAN class="">"$.USERLIST[?(@.USERNAME)]"</SPAN>,
<SPAN class="">"optional"</SPAN>: <SPAN class="">true</SPAN>,
<SPAN class="">"functions"</SPAN>: [
{
<SPAN class="">"type"</SPAN>: <SPAN class="">"decode"</SPAN>,
<SPAN class="">"algorithm"</SPAN>: <SPAN class="">"base32"</SPAN>,
<SPAN class="">"skipPadding"</SPAN>: <SPAN class="">true</SPAN>
},
{
<SPAN class="">"type"</SPAN>: <SPAN class="">"toString"</SPAN>,
<SPAN class="">"applyOnElements"</SPAN>: <SPAN class="">true</SPAN>
}
]
}</PRE><P><SPAN class=""> </SPAN></P><P><BR /><BR />/Deva</P>2025-06-30T16:22:41.595000+02:00https://community.sap.com/t5/enterprise-resource-planning-q-a/overwrite-role-in-enable-now-ips/qaq-p/14140730Overwrite Role in Enable Now (IPS)2025-06-30T19:08:37.399000+02:00tskwinhttps://community.sap.com/t5/user/viewprofilepage/user-id/823618<P>Hello Experts,</P><P>Users and groups from IAS are provisioned to Enable Now using IPS.</P><P>Groups (IAS) are converted to roles in Enable Now.</P><P>If roles with the same name already exist in Enable Now (created manually), can IPS overwrite these roles?</P><P>Many Thanks</P><P>Best Regards</P><P> </P>2025-06-30T19:08:37.399000+02:00https://community.sap.com/t5/human-capital-management-q-a/delete-provisoned-rolles/qaq-p/14141580Delete provisoned Rolles2025-07-01T12:59:20.260000+02:00tskwinhttps://community.sap.com/t5/user/viewprofilepage/user-id/823618<P>Hello Experts,</P><P>we are using SAP IPS to provision groups from IAS to Enable Now. In Enable Now, the provisioned IAS groups are automatically converted into roles.</P><OL><LI>How can I delete these provisioned roles in Enable Now?<BR />They were automatically created through provisioning from IAS and we want to remove some of them.</LI><LI><P>Is it possible to overwrite manually created roles with provisioned ones?<BR />For example, we have a group called "Admins" in IAS and a manually created role with the same name "Admins" already exists in Enable Now.<BR />Can the provisioning be configured in such a way that it does not create a new role in Enable Now but instead updates or takes the existing one?</P></LI></OL><P>Thank you in advance</P><P>Best regards</P>2025-07-01T12:59:20.260000+02:00https://community.sap.com/t5/technology-q-a/provisioning-users-to-sac-directly-from-entra-id/qaq-p/14149496provisioning users to SAC directly from Entra ID2025-07-10T14:33:23.170000+02:00i055464https://community.sap.com/t5/user/viewprofilepage/user-id/27557<P>Dear community,</P><P>It´s possible enable access to SAP Analytics Cloud (SAC) stories using user group defined in Entra ID?</P><P><SPAN>the data master for IAS is Entra ID since not all users managed by IAS are in SFSF, because there are applications in IAS that do not depend on SFSF.</SPAN></P><P><SPAN>Thanks </SPAN></P><P> </P>2025-07-10T14:33:23.170000+02:00https://community.sap.com/t5/technology-q-a/license-model-of-iag/qaq-p/14168934License model of IAG2025-08-01T07:22:59.747000+02:00PLABAN_SAHOO8https://community.sap.com/t5/user/viewprofilepage/user-id/2186975<P><SPAN>can you please confirm if provisioning BTP/IAS/IPS via IAG access requests will incur Integration license of IAG or the Standard one.</SPAN></P>2025-08-01T07:22:59.747000+02:00https://community.sap.com/t5/technology-q-a/iag-how-to-select-users-to-be-sync/qaq-p/14218330IAG: how to select users to be sync2025-09-16T09:25:34.518000+02:00KDVF747https://community.sap.com/t5/user/viewprofilepage/user-id/830016<P>Hi all</P><P>Is there a way to control the number of users to be synced into IAG, from SAP S/4HANA Cloud, Public edition?</P><P>Currently the job does sync all users deployed in the application.</P><P>Thank you</P>2025-09-16T09:25:34.518000+02:00https://community.sap.com/t5/technology-q-a/grc-prod-system-provisioning-to-prod-and-non-prod-systems/qaq-p/14226028GRC prod system provisioning to Prod and non prod systems2025-09-23T19:48:55.048000+02:00barry_caghttps://community.sap.com/t5/user/viewprofilepage/user-id/814830<P>Hi Gurus,</P><P>Has anyone considered and managed / failed to setup GRC Prod environment to provision to all connected Prod and non prod systems through IAG/IAS prod tenants</P><P>Short story - GRC ARM request loaded with business role and IAG/IAS element would provision to both prod and non prod cloud apps.</P><P> </P>2025-09-23T19:48:55.048000+02:00https://community.sap.com/t5/technology-q-a/generative-ai-powered-iam-business-role-augmentation-gaira/qaq-p/14247388Generative AI Powered IAM Business Role Augmentation (GAIRA)2025-10-17T16:43:15.834000+02:00CompliflowAIhttps://community.sap.com/t5/user/viewprofilepage/user-id/2241056<P><SPAN>Generative AI Powered IAM Business Role Augmentation (GAIRA) is a transformative concept for modern enterprises, shifting Identity and Access Management (IAM) from manual, reactive processes to a proactive, intelligent, and efficient system.</SPAN><SPAN><BR /></SPAN><SPAN><BR /></SPAN><SPAN>Limitations of traditional IAM include:</SPAN><SPAN><BR /></SPAN><SPAN><BR /></SPAN><SPAN>- Manual Provisioning: Managing user accounts and privileges can be time-consuming and error-prone, particularly in large organizations.</SPAN><SPAN><BR /></SPAN><SPAN>- Inflexible Security: Rule-based systems often lack the context needed to detect subtle, behavioral-based anomalies indicative of modern threats, such as insider risks.</SPAN><SPAN><BR /></SPAN><SPAN>- Compliance Burden: The manual nature of access reviews and audit trail generation drains resources and struggles to keep pace with regulatory changes.</SPAN><SPAN><BR /></SPAN><SPAN>- Subpar User Experience: Slow access request workflows can frustrate users and hinder productivity.</SPAN><SPAN><BR /></SPAN><SPAN><BR /></SPAN><SPAN>GAIRA addresses these challenges by integrating generative AI into the four pillars of IAM:</SPAN><SPAN><BR /></SPAN><SPAN><BR /></SPAN><SPAN>1. Adaptive Authentication</SPAN><SPAN><BR /></SPAN><SPAN>- Risk-Based Access: GAIRA enables continuous, risk-based authentication by analyzing user behavior, location, and device in real-time. For instance, a login attempt from an unusual location could trigger additional verification steps.</SPAN><SPAN><BR /></SPAN><SPAN>- Frictionless Security: This dynamic security approach balances convenience and trust, enhancing security without burdening trusted users.</SPAN><SPAN><BR /></SPAN><SPAN><BR /></SPAN><SPAN>2. Intelligent Authorization</SPAN><SPAN><BR /></SPAN><SPAN>- Automated Role Management: Generative AI analyzes historical access data and user roles to recommend optimal role assignments, significantly reducing manual effort and errors.</SPAN><SPAN><BR /></SPAN><SPAN>- Contextual Access Recommendations: For access requests needing approval, GAIRA provides context-rich insights based on peer-group comparisons and historical outcomes, facilitating faster, informed decisions.</SPAN><SPAN><BR /></SPAN><SPAN><BR /></SPAN><SPAN>3. Streamlined Administration</SPAN><SPAN><BR /></SPAN><SPAN>- Lifecycle Automation: GAIRA automates the entire user lifecycle, from onboarding to offboarding, dynamically assigning and removing access rights based on predefined policies and roles.</SPAN><SPAN><BR /></SPAN><SPAN>- Enhanced User Experience: Users can interact with the IAM system using natural language via conversational AI interfaces, improving productivity and reducing the burden on IT help desks.</SPAN></P>2025-10-17T16:43:15.834000+02:00https://community.sap.com/t5/technology-q-a/iag-access-request-creating-a-new-user-in-ecc-backend-for-an-existing-ias/qaq-p/14251600IAG Access Request: creating a new user in ECC backend for an existing IAS user2025-10-23T12:49:37.780000+02:00fmartinezhttps://community.sap.com/t5/user/viewprofilepage/user-id/9856<P>Dear all,</P><P>As an IAG user I create a new request in AR, choosing as Access Type "Application" and then I choose the ECC onprem application we have integrated with IAG. My user doesn't exist in ECC yet. Then after the request has been approved, the Provisioning job fails because it tries to create the ECC user as "<First Name in IAS><space><Last Name in IAS> which of course fails. Is there any way to tell IAG to create the backend user with other name, for example the Display Name in IAG, or other value?</P>2025-10-23T12:49:37.780000+02:00https://community.sap.com/t5/technology-q-a/ias-tenant/qaq-p/14260502IAS Tenant2025-11-04T16:31:28.468000+01:00tskwinhttps://community.sap.com/t5/user/viewprofilepage/user-id/823618<P>Hello Experts,</P><P>As far as I know, it was previously recommended to use the Test IAS tenant only for testing purposes (i.e. Sandbox), and to use the Productive IAS tenant for productive cloud applications as well as for development and test environments.</P><P>Previous recommendation:</P><UL><LI>IAS Test<STRONG> →</STRONG> Sandbox environments</LI><LI>IAS Prod<STRONG> →</STRONG> PROD, DEV, and QAS</LI></UL><P>My question to the community:</P><P>What is the current recommended approach?</P><P>Should this setup still be followed:</P><UL><LI><UL><LI><STRONG>IAS Test →</STRONG> Sandbox environments (only testing)</LI><LI><STRONG>IAS Prod →</STRONG> PROD, DEV, and QAS ( SAC PROD + SAC QAS)</LI></UL></LI></UL><P><U>Or does SAP now recommend a different model, for example:</U></P><UL><LI><STRONG>IAS Test →</STRONG> for development and test environments</LI><LI><STRONG>IAS Prod →</STRONG> only for PROD</LI></UL><P>I would like to make this decision for our landscape (e.g. SAC QAS & PROD) and would appreciate an up-to-date assessment of which option is currently considered Best Practice.</P><P>Thank you in advance</P><P>Best Regards</P>2025-11-04T16:31:28.468000+01:00https://community.sap.com/t5/technology-q-a/sap-cloud-identity-access-governance-license-counting-logic/qaq-p/14274125SAP Cloud Identity Access Governance License Counting Logic2025-11-20T18:11:03.269000+01:00JuliaLuhttps://community.sap.com/t5/user/viewprofilepage/user-id/131826<P>For <STRONG>Expired Users</STRONG> in SAP ERP and SAP S/4HANA, they will not be counted for SAP Cloud Identity Access Governance License, right?</P><P>When a SAP S/4HANA User is deemed to be expired, will IAG automatically stop monitoring that user and will the license consumption be reduced by 1? Thanks.</P>2025-11-20T18:11:03.269000+01:00https://community.sap.com/t5/technology-q-a/autopath-in-iag-is-not-working-for-pam-requests/qaq-p/14277448Autopath in IAG is not working for PAM requests2025-11-25T18:01:58.760000+01:00fmartinezhttps://community.sap.com/t5/user/viewprofilepage/user-id/9856<P>Dear colleagues,</P><P>We have activated the rulesets in SAP IAG so when a user creates an access requests and chooses 'AUTO_APPROVAL' as request reason, the autopath workflow (no approvers required) is used. </P><P>This works fine for normal access requests, but if we request a PAM user, this message appears:</P><P><STRONG><EM>"PAM Assignment request cannot be auto approved. Please contact your IAG Administrator to correct the access request workflow configuration"</EM></STRONG></P><P>We have also tried with other different rule, which is based on the request type. In case it is 'PAM', the autopath is used. The behaviour is just like the one we have with the first case, same message. </P><P>Is there any way in SAP IAG to activate auto-approvals for Privileged Accesses?</P><P>Thank you</P><P>Francisco</P><P> </P><P> </P><P> </P>2025-11-25T18:01:58.760000+01:00https://community.sap.com/t5/technology-q-a/error-while-connecting-from-sap-btp-integration-suite-to-sap-s4-cloud-odata/qaq-p/14280585Error: While connecting from SAP BTP Integration Suite to SAP S4 Cloud Odata2025-11-30T19:42:29.722000+01:00rajeshpshttps://community.sap.com/t5/user/viewprofilepage/user-id/157724<P>Hello Team,</P><P> </P><P>I'm getting below error while connecting from SAP BTP Integration Suite Cloud to SAP S4 Cloud Odata service.</P><P>"<SPAN>com.sap.gateway.core.ip.component.odata.exception.OsciException: HTTP Request failed with error : <HOST>: No address associated with hostname, cause: java.net.UnknownHostException: <HOST>: No address associated with hostname</SPAN>"</P><P> </P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rajeshps_1-1764527895212.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/346799iDD39DE0DFCDC769F/image-size/medium?v=v2&px=400" role="button" title="rajeshps_1-1764527895212.png" alt="rajeshps_1-1764527895212.png" /></span></P><P> </P><P> </P><P>Thanks and Regards,</P><P>Rajesh PS</P>2025-11-30T19:42:29.722000+01:00https://community.sap.com/t5/technology-q-a/ff-sap-public-cloud/qaq-p/14286193FF SAP Public cloud2025-12-08T16:48:15.179000+01:00SAPuser1996https://community.sap.com/t5/user/viewprofilepage/user-id/2095685<P>Hello, </P><P><SPAN>I would like to know if it is possible to create and use Firefighter IDs in SAP Public Cloud, similar to how we do in the on-premise version. Additionally, is SAP Identity Access Governance (IAG) required for this functionality?</SPAN><BR /><SPAN>If this is not possible, what replaces or substitutes this concept in the SAP Public Cloud environment?</SPAN></P><P>Thank you </P>2025-12-08T16:48:15.179000+01:00https://community.sap.com/t5/technology-q-a/sap-ias-admin-console/qaq-p/14287300SAP IAS Admin Console2025-12-09T20:09:22.861000+01:00tskwinhttps://community.sap.com/t5/user/viewprofilepage/user-id/823618<P>Hello everyone,</P><P>What would be the best way to secure the SAP IAS Administration Console?</P><P>Is it a good idea to restrict access to a specific IP range (e.g. only the company network)? I’m concerned about locking myself out in case the IP address changes.</P><P>Or would it be better to implement 2FA for an admin group containing all admins? In that case, there’s also the risk of locking myself out.</P><P>I would appreciate your experiences and tips!</P><P>Many Thanks </P><P>Best Regards</P>2025-12-09T20:09:22.861000+01:00https://community.sap.com/t5/financial-management-q-a/sap-iag-access-request-status-audit-logs/qaq-p/14302289SAP IAG Access Request Status audit logs2026-01-06T17:33:18.916000+01:00JuliaLuhttps://community.sap.com/t5/user/viewprofilepage/user-id/131826<P>Seeking advisory guidance on SAP Cloud Identity Access Governance (8010452)</P><P>The IAG customer would like to generate a report that shows access requests approved by an individual user or their team members.</P><P>In addition, they would like to view audit logs within the Access Request Status app. Is it possible to enable this?</P><P>Currently, the available IAG reports are administrative reports that display all access requests and therefore cannot be shared with business users.</P>2026-01-06T17:33:18.916000+01:00https://community.sap.com/t5/technology-q-a/ias-login-name-dependencies/qaq-p/14307451IAS Login Name dependencies2026-01-14T14:56:45.075000+01:00tskwinhttps://community.sap.com/t5/user/viewprofilepage/user-id/823618<P class=""><SPAN class="">Hi everyone,</SPAN></P><P class=""><SPAN class="">Quick question about the Login Name field in IAS:</SPAN></P><P class=""><SPAN class="">Does it matter what I enter here? I often see an email address, but could I also use an employee ID or a short name?</SPAN></P><P><SPAN class="">Are there SAP applications or scenarios that require the "Login Name" to be a specific attribute (e.g. Email), or is the field completely flexible?</SPAN></P><P class=""><SPAN class="">I want to avoid SSO issues with specific apps if the value is wrong. Does anyone have experience with dependencies for this field?</SPAN></P><P class=""><SPAN class="">Many Thanks</SPAN></P><P class=""><SPAN class="">Best Regards</SPAN></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tskwin_0-1768398869181.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/361375iA35ED6C264F67341/image-size/medium?v=v2&px=400" role="button" title="tskwin_0-1768398869181.png" alt="tskwin_0-1768398869181.png" /></span></P>2026-01-14T14:56:45.075000+01:00https://community.sap.com/t5/technology-q-a/iag-assign-mitigation-control-at-user-level/qaq-p/14314787IAG: Assign Mitigation Control at User level2026-01-26T14:24:18.170000+01:00plaban_sahoo28https://community.sap.com/t5/user/viewprofilepage/user-id/795565<P>Is Mitigation control assignment possible at User level. if so through which app is the same possible</P>2026-01-26T14:24:18.170000+01:00https://community.sap.com/t5/questions-about-sap-websites/does-sap-cloud-identity-services-cis-ias-ips-support-position-based/qaq-p/14318632Does Sap Cloud Identity Services (CIS) - IAS/IPS support position based security?2026-01-30T14:48:03.146000+01:00Amit_Parmar1https://community.sap.com/t5/user/viewprofilepage/user-id/179914<P>I am interested to know if the new age SAP Cloud Identity solutions suppor the position based security for S/4HANA (HCM on S/4HANA)?<BR />I could not find any mention of this anywhere on sap help documentations.</P>2026-01-30T14:48:03.146000+01:00https://community.sap.com/t5/technology-q-a/iag-s-4hana-user-id-mapping-requirement/qaq-p/14328683IAG–S/4HANA User ID Mapping Requirement2026-02-15T09:05:25.737000+01:00Pradeepgona19https://community.sap.com/t5/user/viewprofilepage/user-id/1962607<P>Hi</P><P>I have requirement regarding an integration involving SAP Identity Access Governance (IAG), SAP Cloud Identity Services (IAS/IPS), and our on-premise SAP S/4HANA system.</P><P>We are currently provisioning users from Microsoft Entra ID into SAP Cloud Identity Services, where users will create and assigned P-User IDs. Once the User IDs created in CIS, We are maintaining “Login Name” as our required naming convention (XXYYZZNN) for S/4 HANA system.</P><P>As per SAP Recommendation we are creating user IDs as P user IDs in BTP-IAG Subaccount. However, our S/4HANA system requires user IDs to follow a specific internal naming convention (XXYYZZNN). We need guidance and confirmation on the recommended approach to ensure that:</P><P>1.SAP IAG provisions users into S/4HANA with our required naming convention (XXYYZZNN) instead of the IAS P-User ID.</P><P>2. Attribute mapping and transformation rules between IAS, IPS, IAG, and S/4HANA. We would appreciate assistance advising on the correct configuration steps for attribute mapping and user ID transformation within IAG.</P>2026-02-15T09:05:25.737000+01:00