https://raw.githubusercontent.com/ajmaradiaga/feeds/main/scmt/topics/SAP-Cloud-Identity-Services-qa.xml SAP Community - SAP Cloud Identity Services 2024-05-20T11:12:28.289666+00:00 python-feedgen SAP Cloud Identity Services Q&A in SAP Community https://community.sap.com/t5/technology-q-a/how-can-assign-in-identity-authentication-service-ias-bulk-users-to-a-group/qaq-p/13667423 How can assign in Identity Authentication Service IAS bulk users to a group? 2024-04-11T21:02:02.902000+02:00 ThomasHiesener https://community.sap.com/t5/user/viewprofilepage/user-id/43307 <P>Hello,</P><P>we created groups in&nbsp;Identity Authentication Service IAS.<BR />Now we need to add hundreds of users to these groups.<BR />We found only the option to add users one by one to a group, which is not helpful.</P><P>We could import groups via CSV file upload.</P><P>But users to a group?</P><P>&nbsp;</P><P>Many Thanks!</P><P>Thomas</P><P><a href="https://community.sap.com/t5/c-khhcw49343/SAP+Cloud+Identity+Services/pd-p/67837800100800007337" class="lia-product-mention" data-product="155-1">SAP Cloud Identity Services</a>&nbsp;</P><P>&nbsp;</P> 2024-04-11T21:02:02.902000+02:00 https://community.sap.com/t5/human-capital-management-q-a/ias-ips-conditional-provisioning-business-vs-personal-email-of-user/qaq-p/13673837 IAS/IPS: conditional provisioning business vs. personal email of user 2024-04-17T22:31:29.472000+02:00 andreas_linhart https://community.sap.com/t5/user/viewprofilepage/user-id/140942 <P>Hi all,</P><P>I am seeking help for adapting the transformation template script in IPS for the SuccessFactors source system for mapping the IAS user email <U>either</U> from EC user field "email" (Business Email) in case of white-collar <U>or</U> from "custom02" (Personal Email) in case of blue-collar workers (Email types B &amp; P from contact information section are already mapped accordingly for HRIS sync).</P><P>I am not good at coding but in pseudo code I was thinking about something like this:</P><P><EM>IF user.custom02 (personal email) = NULL</EM><BR /><EM>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; THEN email = user.email (business email)</EM><BR /><EM>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;(here condition for unique IAS user email generation)</EM><BR /><EM>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;IF user.email = NULL || dummy-value</EM><BR /><EM>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; THEN email = ECUserID@dummy.sap</EM><BR /><EM>ELSE email = user.custom02</EM></P><P>I am not sure if it would work like this... Did anyone face this requirement before or could help with putting this into proper code for the IPS Transformation Template?</P><P>I am using IAS SCIM API v2 btw.</P><P>Regards,</P><P>Andreas</P> 2024-04-17T22:31:29.472000+02:00 https://community.sap.com/t5/technology-q-a/shadow-user-in-btp/qaq-p/13674383 Shadow user in BTP 2024-04-18T11:36:17.711000+02:00 tskwin https://community.sap.com/t5/user/viewprofilepage/user-id/823618 <P>Hello,</P><P>What are the possible methods for automatic user provisioning from SAP IAS to SAP BTP while "Create Shadow Users During Logon" option in SAP BTP is deactivated ?</P><P><SPAN>Or do users need to be created manually in SAP BTP in that case?</SPAN></P><P><SPAN>Many thanks for every tip ?<BR /></SPAN></P><P>&nbsp;</P><P><SPAN>Best Regards</SPAN></P><P>&nbsp;</P> 2024-04-18T11:36:17.711000+02:00 https://community.sap.com/t5/technology-q-a/can-we-configure-a-custom-branding-of-the-ias-after-login/qaq-p/13674812 Can we configure a custom branding of the IAS after login ? 2024-04-18T15:22:47.211000+02:00 Mohamed69290 https://community.sap.com/t5/user/viewprofilepage/user-id/165054 <P>I understand that we can customize the login page through a CSS file. However, I would also like to customize the appearance after login.</P> 2024-04-18T15:22:47.211000+02:00 https://community.sap.com/t5/technology-q-a/activation-of-ias/qaq-p/13675766 Activation of IAS 2024-04-19T11:29:19.152000+02:00 vidyaraghavan https://community.sap.com/t5/user/viewprofilepage/user-id/31176 <P>Hi Team,</P><P>We have Azure setup as the Corporate IDP where users will be logging through Azure via SSO and then redirected to SF via IAS as proxy. There are few consultants who will be logging via Password.</P><P>The default Identity Provider is set as Microsoft Azure(<SPAN>Allow users stored in Identity Authentication service to log on was enabled)</SPAN>&nbsp;. When we started to test activation via password user, it directed me to the Azure screen. Deleted cookies but still same behavior. I had to switch the default identity provider to "Identity Authentication" then it worked( We have conditional authentication rule setup- 1 as PWD and other as SSO). Later to test activation for SSO users, had to set the identity provider back to Azure. Just want to check is this expected behavior.&nbsp;</P><P>Please share if anyone has experienced this issue and is normal behavior.</P><P>Thanks</P><P>Regards</P><P>Vidya</P> 2024-04-19T11:29:19.152000+02:00 https://community.sap.com/t5/technology-q-a/sap-ias-password-synchronisation-with-active-directory/qaq-p/13678586 SAP IAS - Password Synchronisation with Active Directory 2024-04-22T20:37:47.984000+02:00 RP_25 https://community.sap.com/t5/user/viewprofilepage/user-id/33824 <P>Hello all,<BR />Is it possible to sync passwords between IAS and Active Directory?&nbsp;<BR />I have a scenario under which users can authenticate using the SPNEGO mechanism: however, in case the kerberos token is not available, they should be able to log-in via Username and Password, using the same password that they use to authenticate via AD.</P><P>I was not able to find anything in the documentation that reflects a similar scenario.</P><P>Any hint?<BR />Best,<BR />Roberto.</P> 2024-04-22T20:37:47.984000+02:00 https://community.sap.com/t5/technology-q-a/putnextentry-failed-storing-spml-sapuser/qaq-p/13678887 putNextEntry failed storing SPML.SAPUSER 2024-04-23T07:08:19.985000+02:00 laxmi275 https://community.sap.com/t5/user/viewprofilepage/user-id/876381 <P>Hi All,<BR /><BR />I'm getting "<FONT color="#FF0000">putNextEntry failed storing SPML.SAPUSER</FONT>" Error while&nbsp; reprocessing the user failed privilege.<BR />User account attribute is correctly set in IDM and as mentioned in&nbsp;<BR /><A href="https://community.sap.com/t5/technology-q-a/unable-to-reprocess-the-failed-role/qaq-p/11322380#feedback-error" target="_blank">https://community.sap.com/t5/technology-q-a/unable-to-reprocess-the-failed-role/qaq-p/11322380#feedback-error</A>&nbsp;<BR /><BR />the privilege is not orphan, could you please help where I'm missing to check.<BR /><BR />Thanks &amp; Regards,<BR />Laxmi</P> 2024-04-23T07:08:19.985000+02:00 https://community.sap.com/t5/technology-q-a/sap-application-user-provision-based-on-application-role-via-entra-id/qaq-p/13679713 SAP Application User provision based on Application Role via Entra ID 2024-04-23T17:22:07.846000+02:00 Parin https://community.sap.com/t5/user/viewprofilepage/user-id/1442199 <P>Hi Team,</P><P>As SAP IDM is expected to retire soon in the coming years, wanted to know possibility of it being replaced by Entra ID ( azure AD).</P><P>SAP IDM and SAP applications including security components - SAP GRC and IAG are very well integrated with each other as they are a part of same family.</P><P>Wanted to know if Entra ID can replace SAP IDM , with respect to tasks like :</P><P>1. Informing SAP IPS system to provision users to target application based on approval/deny event from SAP GRC or SAP IAG.</P><P>Is this possible with Entra Id ? How does the SAP Application role information flow from SAP GRC / IAG to Entra ID is it even possible ?</P><P>&nbsp;</P> 2024-04-23T17:22:07.846000+02:00 https://community.sap.com/t5/technology-q-a/sap-cloud-identity-services-identity-authentication-with-sap-ecc/qaq-p/13680583 SAP Cloud Identity Services - Identity Authentication with sap ecc 2024-04-24T11:09:42.807000+02:00 Jacopo_Carrara https://community.sap.com/t5/user/viewprofilepage/user-id/1395625 <P>Hy all,</P><P>is it possibile tu use&nbsp;<SPAN>SAP Cloud Identity Services - Identity Authentication with sap ecc?Our customer has a ecc system that use as fiori gateway for a S/4 hana system.</SPAN></P><P><SPAN>It's possibile to implement 2fa with <SPAN>SAP Cloud Identity Services - Identity Authentication and&nbsp;Delegate Authentication to a&nbsp;a 3rd party or on-premise IdP(entra ID in thsi case)&nbsp;</SPAN>for fiori in this situation?</SPAN></P><P>Kind regards</P><DIV class=""><DIV class=""><DIV class=""><DIV class="">&nbsp;</DIV></DIV></DIV></DIV> 2024-04-24T11:09:42.807000+02:00 https://community.sap.com/t5/technology-q-a/oidc-configuration-in-s-4/qaq-p/13686054 OIDC configuration in S/4 2024-04-29T15:54:08.577000+02:00 Chandresh1 https://community.sap.com/t5/user/viewprofilepage/user-id/1446516 <P>We are in process of configuring SSO for SAP Fiori Apps.</P><P>We are using Ping ID as corporate identity provider and using BTP IAS as proxy host. Ping Id is OIDC compliant and we have used OIDC protocol for this configuration.&nbsp;</P><P>Configuration between BTP IAS and Ping is completed. Below are&nbsp; queries for configuration of s/4 application in BTP IAS:</P><P>1) Can we add S/4 system as SAML2.0 protocol? will that work for configuring SSO with Ping ID as we have configured PingID as OIDC protocol at BTP IAS.</P><P>2) If point 1 do not work, is there any document available of configuration of s/4 application in BTP IAS as OIDC protocol? what all configuration do I need to do in s/4 system for this?</P><P>Regards,</P><P>Chadresh.</P> 2024-04-29T15:54:08.577000+02:00 https://community.sap.com/t5/technology-q-a/providing-ias-authentication-through-cloud-identity-service-for-ui5-mta-app/qaq-p/13687726 providing IAS authentication through cloud identity service for UI5 MTA app 2024-04-30T20:10:11.395000+02:00 rakeshBaggam https://community.sap.com/t5/user/viewprofilepage/user-id/1419543 <P>Hi,<BR />I have created a sap ui5&nbsp; MTA(multi target application) with stand alone app router. its having mta-approuter(router), mta-ui(ui5 app), xs-security.json, mta.yml etc..<BR />mta-approuter is having xs-app.json file which is pointing to mta-ui as the welcome file and authentication as 'route'. mta-ui as well having another xs-app.json file which is having the default route pointing to html5-repo-rt and 'xsuaa' as authentication type.<BR />I have deployed this app to CF and on running the app from CF its working good.</P><P>Now I wanted to try out cloud identity services which provides IAS authentication. So i have created an IDP in my trial account. then inside my mta-ui's 'xs-app.json' i have changed authentication type from 'xsuaa' to 'ias' .</P><P>And in my mta.yml i have added a identity service in the required section of app router and&nbsp; defined it in resource section as well.</P><P>Now I have deployed it to CF. On try running the app I am getting the below error. even i tried enabling third party cookies.&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Error.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/104099iA4961898E2A1AE97/image-size/large?v=v2&amp;px=999" role="button" title="Error.png" alt="Error.png" /></span></P><P>my expectation is same like default IDP with cloud identity services as well SSO works smoothly.</P><P>Can you please help me what am i missing?</P><P>PFA details of app/trial account.</P><P>&nbsp;</P><P>Thank in Advance.</P> 2024-04-30T20:10:11.395000+02:00 https://community.sap.com/t5/human-capital-management-q-a/sf-employment-type-replication-to-ias-user-store/qaq-p/13687842 SF Employment Type replication to IAS user store 2024-04-30T23:27:19.016000+02:00 ahonsheng https://community.sap.com/t5/user/viewprofilepage/user-id/152920 <P>Hey all,</P><P>There's a requirement on bringing the employment type field from SF to user attribute in IAS user store? Is this possible?</P><P>&nbsp;</P><P>Currently on API v2 / SCIM API</P> 2024-04-30T23:27:19.016000+02:00 https://community.sap.com/t5/technology-q-a/automatic-assignment-to-groups-in-ias/qaq-p/13687910 Automatic assignment to groups in IAS 2024-05-01T03:24:05.411000+02:00 SAPSupport https://community.sap.com/t5/user/viewprofilepage/user-id/121003 <P>We would like to automatically assign users to groups in IAS, based on an attribute that we can provision from SF to IAS through IPS. Question is: is it possible? Should it be done through transformation rules at IPS level?&nbsp;&nbsp;</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B> 2024-05-01T03:24:05.411000+02:00 https://community.sap.com/t5/technology-q-a/is-activation-of-us-language-a-requirement-prerequisite-for-ias-ips/qaq-p/13690564 Is activation of US language a requirement/prerequisite for IAS/IPS? 2024-05-03T11:06:30.031000+02:00 WengR https://community.sap.com/t5/user/viewprofilepage/user-id/91179 <P>Today we only have English UK and French in all our instance. We are also planning to activate the English US language and the IAS/IPS. I wonder if there is connection between the two i.e. the language should be activated first before IAS/IPS?&nbsp;</P> 2024-05-03T11:06:30.031000+02:00 https://community.sap.com/t5/technology-q-a/establishing-trust-with-custom-identity-provider-for-platform-users-failed/qaq-p/13697379 Establishing Trust with Custom Identity Provider for Platform Users failed 2024-05-10T10:14:21.496000+02:00 MioYasutake https://community.sap.com/t5/user/viewprofilepage/user-id/789 <P>Hi community,</P><P>I am trying to establish trust between my BTP global account (trial) with a custom IAS tenant by following the document below:</P><P><A href="https://help.sap.com/docs/btp/sap-business-technology-platform/establish-trust-and-federation-of-custom-identity-providers-for-platform-users?locale=en-US" target="_self" rel="noopener noreferrer">https://help.sap.com/docs/btp/sap-business-technology-platform/establish-trust-and-federation-of-custom-identity-providers-for-platform-users?locale=en-US</A></P><P>I have subscribed to Cloud Identity Services and my user has been added to it as an administrator.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MioYasutake_0-1715328500004.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/108505i9BF49DB4C0B0B0C3/image-size/medium?v=v2&amp;px=400" role="button" title="MioYasutake_0-1715328500004.png" alt="MioYasutake_0-1715328500004.png" /></span></P><P>When I tried to establish trust, I got the following error:</P><P><STRONG>Please reference the correlation ID d61ffe82-fb25-459e-7c9f-bb5a116def62 in the support ticket</STRONG></P><P>&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MioYasutake_1-1715328541743.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/108506iFD5D0EB19E795866/image-size/medium?v=v2&amp;px=400" role="button" title="MioYasutake_1-1715328541743.png" alt="MioYasutake_1-1715328541743.png" /></span></P><P>I searched for the correlation ID in IAS Troubleshooting Logs, but nothing was found.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MioYasutake_2-1715328633114.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/108508i713EE6F12CDBCE24/image-size/large?v=v2&amp;px=999" role="button" title="MioYasutake_2-1715328633114.png" alt="MioYasutake_2-1715328633114.png" /></span></P><P>At subaccont level, I would be able to manually establish trust by exporing and importing metadata, but in global account, I don't see an option to download metadata. Is there any workaround or resolution for this issue?</P> 2024-05-10T10:14:21.496000+02:00 https://community.sap.com/t5/technology-q-a/destination-service-failed-after-deployment-cloud-foundry/qaq-p/13698612 Destination Service failed after deployment - Cloud Foundry 2024-05-12T19:05:43.254000+02:00 andreeav https://community.sap.com/t5/user/viewprofilepage/user-id/172085 <P>Hello,&nbsp;</P><P>After re-deploying MTA application on BTP I encountered the following error :</P><P><STRONG>"Updating service "*-destination-service" failed: Service broker error: Service broker destination-service-broker failed with: Failed to update the destination service instance with the user provided configuration."</STRONG></P><P>What could be the cause of it?</P> 2024-05-12T19:05:43.254000+02:00 https://community.sap.com/t5/technology-q-a/risk-based-authentication-in-sap-cis/qaq-p/13700362 Risk Based Authentication in SAP CIS 2024-05-14T09:58:34.607000+02:00 Rushi_Sangamkar https://community.sap.com/t5/user/viewprofilepage/user-id/138212 <P>Hi Experts,</P><P>&nbsp; &nbsp; &nbsp; &nbsp; I am trying to configure RBA in SAP CIS for restricting the access of application limited to series of IP addresses (internal to a network).&nbsp;</P><P>While configuring the RBA, there are 2 options one is IP Range and another is Forwarded IP range.</P><P>As per the documentation, we need to provide IP range in the IP range field to d<SPAN>efine a range of IP addresses that authentication requests to&nbsp;</SPAN><SPAN class="">Identity Authentication</SPAN><SPAN>&nbsp;can be sent from.</SPAN>&nbsp;And for Forwarded IP range field, <SPAN>we need to define a range of IP addresses for the original IP addresses that authentication requests to&nbsp;</SPAN><SPAN class="">Identity Authentication</SPAN><SPAN>&nbsp;can be sent from. This range is used in conjunction with IP Range in scenarios where authentication requests to&nbsp;</SPAN><SPAN class="">Identity Authentication</SPAN><SPAN>&nbsp;are made by a proxy on-behalf of the user/client.&nbsp;And for this IP Range field needs to be defined first.&nbsp;</SPAN></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rushi_Sangamkar_0-1715672381266.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/109970i277AA5A0DAC47E89/image-size/medium?v=v2&amp;px=400" role="button" title="Rushi_Sangamkar_0-1715672381266.png" alt="Rushi_Sangamkar_0-1715672381266.png" /></span></P><P>So, the question here is, if I need to limit the access to IP address which are specific to intranet (internal network IP addresses), do I still need to define public IP address range from where application would be accessed. For example, if I am defining a rule with allow authentication action and in IP Range field in I am providing internal IP address range like&nbsp; 10.21.0.0/16 and then try to access the application. It is not allowing me to access it and gives me error message.&nbsp;</P><P>However, when I insert the public IP address of my machine with CIDR range in the IP Range field I am able to access the application. So does it mean that I need to provide public IP address range in IP Range field and Internal IP address range in Forwarded IP range field for this scenario to work.&nbsp;</P><P>Working inputs:</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rushi_Sangamkar_1-1715673183420.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/109972i87B7937B79E57B47/image-size/medium?v=v2&amp;px=400" role="button" title="Rushi_Sangamkar_1-1715673183420.png" alt="Rushi_Sangamkar_1-1715673183420.png" /></span></P><P>Not working inputs:</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rushi_Sangamkar_2-1715673241011.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/109973iBC447A8C13F4638C/image-size/medium?v=v2&amp;px=400" role="button" title="Rushi_Sangamkar_2-1715673241011.png" alt="Rushi_Sangamkar_2-1715673241011.png" /></span></P><P>Let me know how it works and any hints of how it can be configured.&nbsp;</P><P>Thanks</P><P>&nbsp;</P><P>&nbsp;</P><P>&nbsp;</P> 2024-05-14T09:58:34.607000+02:00 https://community.sap.com/t5/technology-q-a/ips-only-provision-entity-if-user-logged-into-another-system/qaq-p/13702272 IPS only provision entity, if user logged into another system 2024-05-15T14:10:11.360000+02:00 Jamma https://community.sap.com/t5/user/viewprofilepage/user-id/1398503 <P>Hi all,</P><P>I received the requirement to provision users from AzureAD to SAP Enable Now, which should be pretty straight forward as far as I know.<BR />But now I got asked, if it is possible to only provision users to SAP Enable Now, if they, at least once, logged in to SAP Concur. The thought process behind all that is, that we might save some licences, if only the employees, who actually work with SAP Concur are provisioning, instead of every employee of the company.</P><P>Now I have two questions.</P><P>1. Generally speaking, is it possible, to only provision from a source system to a target system, if they logged into another system, which is neither source nor target?</P><P>2. If this is possible, how would I check for this in a condition?</P><P>I feel like this won't be possible, because inside the source system transformation, you can only access the user's attributes of AzureAD and i'm pretty sure that there's no attribute to check, if a user has logged into a specific system or not.</P><P>Any help would be greatly appreciated.</P> 2024-05-15T14:10:11.360000+02:00 https://community.sap.com/t5/technology-q-a/prevent-of-simultaneous-login-with-a-single-user-account/qaq-p/13702867 Prevent of simultaneous login with a single user account 2024-05-16T03:36:22.046000+02:00 SAPSupport https://community.sap.com/t5/user/viewprofilepage/user-id/121003 <P>Hello,&nbsp;</P><P>We have set up IAS and then configured SSO with Azure. The client requirement is to prevent multiple simultaneously logins with the same user account from different browsers. We are trying to set up this in IAS with no success.</P><P>We cannot find any setting in order to set up this.&nbsp;</P><P>Kind regards,</P><BR />------------------------------------------------------------------------------------------------------------------------------------------------<BR /><B>Learn more about the SAP Support user and program <A target="_blank" href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/maximizing-the-power-of-sap-community-at-product-support/ba-p/13501276">here</A>.</B> 2024-05-16T03:36:22.046000+02:00 https://community.sap.com/t5/technology-q-a/azure-user-group-replacement/qaq-p/13705013 Azure user group replacement 2024-05-17T16:10:09.545000+02:00 Jacob_Rajan https://community.sap.com/t5/user/viewprofilepage/user-id/1434064 <P>Hello Experts,</P><P>We are having Azure as a Source System and IAS as the target system. We are replicating the user data from Azure Environment to the IAS. We use both the User and Group mapping transformation.</P><P>The job is working fine and we are able to fetch the data and write into the target system.</P><P>The challenge what I have is, I need to transform a specfic User Group to&nbsp; a different value.</P><P>I have written the transformation code in my TARGET SYSTEM (IAS) as follows.</P><P>The two blocks are found under the User Group section.&nbsp;</P><P>I have checked with the 'Validate' function and it is just converting it into UpperCase and replacement function doesn't function at all.</P><P>Does anyone have an idea about what i am missing here</P><P>Input : Abcd</P><P>Output : ABCD</P><P><STRONG>Transformation</STRONG></P><P>{<BR />"sourcePath": "$.displayName",<BR />"targetPath": "$.displayName",<BR />"functions": [<BR />{<BR />"function": "replaceString",<BR />"target": "Abcd",<BR />"replacement": "SAP_CBC_CONSUMPTION_AUDITOR"<BR />},<BR />{<BR />"function": "toUpperCaseString",<BR />"locale": "en_EN"<BR />}<BR />]<BR />}</P><P>&nbsp;</P><P>{<BR />"sourcePath": "$.displayName",<BR />"targetPath": "$['urn:sap:cloud:scim:schemas:extension:custom:2.0:Group']['name']",<BR />"scope": "createEntity",<BR />"functions": [<BR />{<BR />"function": "replaceString",<BR />"target": "Abcd",<BR />"replacement": "SAP_CBC_CONSUMPTION_AUDITOR"<BR />},<BR />{<BR />"function": "toUpperCaseString",<BR />"locale": "en_EN"<BR />}<BR />]</P> 2024-05-17T16:10:09.545000+02:00