https://raw.githubusercontent.com/ajmaradiaga/feeds/main/scmt/topics/SAP-Identity-Management-blog-posts.xml SAP Community - SAP Identity Management 2026-02-21T12:12:46.284509+00:00 python-feedgen SAP Identity Management blog posts in SAP Community https://community.sap.com/t5/technology-blog-posts-by-sap/sap-cloud-identity-services-new-features-updates-for-11th-march-2025/ba-p/14045597 SAP Cloud Identity Services - New Features updates for 11th March 2025 2025-03-15T14:44:13.283000+01:00 Yogananda https://community.sap.com/t5/user/viewprofilepage/user-id/75 <DIV><STRONG><SPAN><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-02-20_21-36-188.png" style="width: 795px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237953i4A7B65871DD6B03C/image-size/large?v=v2&amp;px=999" role="button" title="2025-02-20_21-36-188.png" alt="2025-02-20_21-36-188.png" /></span></SPAN></STRONG></DIV><DIV>&nbsp;</DIV><DIV><DIV><STRONG><SPAN>Cloud Identity Services</SPAN>&nbsp;-&nbsp;<SPAN>Authorizations Based on Policies</SPAN></STRONG></DIV><DIV>You can now restrict the access to the administration console only to one user type via the new attribute that is supported for authorizations based on policies -&nbsp;user.type.</DIV></DIV><DIV><STRONG><SPAN><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-03-15_14-24-45.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237949i82E933ECE0866A1E/image-size/large?v=v2&amp;px=999" role="button" title="2025-03-15_14-24-45.png" alt="2025-03-15_14-24-45.png" /></span></SPAN></STRONG></DIV><DIV><SPAN>Reference Documentation ;&nbsp;</SPAN><STRONG><SPAN><A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/manage-users-rights" target="_self" rel="noopener noreferrer">Configure User Authorizations</A><BR /></SPAN></STRONG></DIV><DIV>&nbsp;</DIV><DIV><STRONG><SPAN>Cloud Identity Services</SPAN>&nbsp;-&nbsp;<SPAN>Identity Federation for Applications</SPAN></STRONG></DIV><DIV>You can enable identity federation for an application to override the identity federation settings on the configured corporate identity provider for the application.&nbsp;</DIV><P><SPAN>Choose if user attributes will be taken from the corporate IdP assertion or from Identity Authentication user store. Restrict access based on user profile.</SPAN><SPAN><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-03-15_14-03-03.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237948i73C0AEC4AA8D812A/image-size/large?v=v2&amp;px=999" role="button" title="2025-03-15_14-03-03.png" alt="2025-03-15_14-03-03.png" /></span></SPAN></P><P><STRONG><SPAN>Cloud Identity Services</SPAN>&nbsp;-&nbsp;<SPAN>SAML 2.0 Configuration</SPAN></STRONG></P><P><SPAN>The SAML 2.0 configuration page on application level has been refactored from March 11th 2025 release. Now you can separately configure the metadata and certificates setting</SPAN><SPAN><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-03-15_13-53-46.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237947i775EFC20D985C177/image-size/large?v=v2&amp;px=999" role="button" title="2025-03-15_13-53-46.png" alt="2025-03-15_13-53-46.png" /></span></SPAN></P><DIV>&nbsp;</DIV><DIV><STRONG><SPAN>Cloud Identity Services</SPAN>&nbsp;-&nbsp;<SPAN>Attributes Based on Flexible Expressions</SPAN></STRONG></DIV><DIV>The display name of&nbsp;Groups&nbsp;attribute based on flexible expressions for the application is renamed to&nbsp;All Groups.</DIV><DIV><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-03-15_14-35-26.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237952iDEEC8A77851683EC/image-size/large?v=v2&amp;px=999" role="button" title="2025-03-15_14-35-26.png" alt="2025-03-15_14-35-26.png" /></span></DIV><DIV>Reference Documentation : <A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/configure-default-attributes-sent-to-application" target="_self" rel="noopener noreferrer">Configure Attributes Based on Flexible Expressions</A></DIV><DIV>&nbsp;</DIV> 2025-03-15T14:44:13.283000+01:00 https://community.sap.com/t5/technology-blog-posts-by-members/sso-implementation-in-grow-with-sap-using-microsoft-entra-id/ba-p/14045555 SSO implementation in GROW with SAP using Microsoft Entra ID 2025-03-18T16:56:18.305000+01:00 Shailendra08m https://community.sap.com/t5/user/viewprofilepage/user-id/893797 <P>The SAP Single Sign-On application&nbsp;enables users to log in once to gain secure access to all the software they require throughout the day with no need to log in again ,with SAP Single Sign-On</P><P>There are several process to set up setup SSO in On premise system as well as on cloud, here we will discuss SSO setup between Azure and SAP on Public Cloud using IdP</P><P>There are two primary options in which SAP Identity Authentication Services and Microsoft Entra ID can be integrated:<BR /><BR /></P><UL><LI>Microsoft Entra ID as the Identity Provider (IdP): This scenario makes Microsoft Entra ID the central authentication hub, with users logging into SAP applications using their Microsoft Entra ID credentials.</LI></UL><P>&nbsp;</P><UL><LI>SAP IAS as the IdP: In this case, SAP IAS becomes the primary authentication source, with users logging into Microsoft Entra ID applications using their SAP credentials.</LI></UL><P>Recently I got opportunity to setup SSO between Microsoft Entra ID&nbsp;(formerly known as&nbsp;Microsoft Azure Active Directory&nbsp;or&nbsp;Azure AD)&nbsp;, SAP IAS and SuccessFactors on SAP on Public Cloud (Grow with SAP) using SAP IAS as the IdP.</P><P>&nbsp;</P><P>Below are step to configure SSO between Azure ,IAS and Success Factor.<BR /><BR /><STRONG><U>1- Configure SAP IAS</U></STRONG><BR /><BR />Login on IAS system go to Applications and Resources -&gt; Tenant Settings -&gt;Single Sign On-&gt; SAML 2.0 Configuration the&nbsp; download metadata file on you system share this file to Azure team and ask for <STRONG>Federation Metadata XML</STRONG>&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_0-1742035914505.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237921i7A8D102F27B7416D/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_0-1742035914505.png" alt="Shailendra_Srivastava_SAP_0-1742035914505.png" /></span></P><P>&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_1-1742035914513.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237920iB8D717300810FA25/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_1-1742035914513.png" alt="Shailendra_Srivastava_SAP_1-1742035914513.png" /></span></P><P>&nbsp;</P><P>&nbsp;</P><P><BR /><STRONG><U>2- Configure Microsoft Entra ID</U></STRONG><BR /><BR />This setp should be perform by azure admin system by following step</P><P>Create an Application in Microsoft Entra ID: This application represents your SAP IAS instance.&nbsp;Login to&nbsp;<A href="https://portal.azure.com/" target="_blank" rel="nofollow noopener noreferrer">https://portal.azure.com</A>&nbsp;and setup the Microsoft Entra ID.<BR /><BR /></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_2-1742035914524.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237922iE735B5151FBA14BD/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_2-1742035914524.png" alt="Shailendra_Srivastava_SAP_2-1742035914524.png" /></span></P><P>&nbsp;</P><P><BR /><BR />Click Add -&gt; Enterprise Applications&nbsp;<BR /><BR /></P><P><BR /><BR /></P><UL><LI><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_3-1742035914534.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237923iB3896354718C7120/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_3-1742035914534.png" alt="Shailendra_Srivastava_SAP_3-1742035914534.png" /></span><P>&nbsp;</P></LI></UL><P>&nbsp;</P><P><BR />By default, Microsoft Azure supports variety of applications. Search with SAP Cloud Identity Services.&nbsp;Select the SAP Cloud Identity Services and click on create.<BR /><BR /></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_4-1742035914547.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237925iF137BDDEF870695B/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_4-1742035914547.png" alt="Shailendra_Srivastava_SAP_4-1742035914547.png" /></span></P><P>&nbsp;</P><P><BR />We will be using the SAML Metadata file to setup&nbsp;the trust between Microsoft Entra ID and SAP Identity Authentication service (IAS).&nbsp;Click on Setup Single Sign-On.<BR /><BR /></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_5-1742035914553.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237924iC49CDD8C999137E1/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_5-1742035914553.png" alt="Shailendra_Srivastava_SAP_5-1742035914553.png" /></span></P><P>&nbsp;</P><P><BR />&nbsp;<BR /><BR />Choose SAML as the SSO method and upload the SAP IAS metadata file.<BR /><BR /></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_6-1742035914559.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237928iBB865FCC6AA4601F/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_6-1742035914559.png" alt="Shailendra_Srivastava_SAP_6-1742035914559.png" /></span></P><P>&nbsp;</P><P><BR /><BR /></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_7-1742035914563.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237927i152984E1AC6121C1/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_7-1742035914563.png" alt="Shailendra_Srivastava_SAP_7-1742035914563.png" /></span></P><P>&nbsp;</P><P><BR />After saving the application you can download the<STRONG>&nbsp;</STRONG><STRONG>Federation Metadata XML</STRONG>&nbsp;file which we will add to the SAP Cloud Identity Services (IAS).<BR /><BR /></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_8-1742035914566.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237926i5DA25F2E1BCB783E/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_8-1742035914566.png" alt="Shailendra_Srivastava_SAP_8-1742035914566.png" /></span></P><P>&nbsp;</P><P><STRONG><U>3- Configure Federation metadata on &nbsp;IAS </U></STRONG></P><P>Login on IAS system and click identity Provider&nbsp; and select Corporate identity Provider</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_9-1742035914573.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237929iE8092BD1688570E2/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_9-1742035914573.png" alt="Shailendra_Srivastava_SAP_9-1742035914573.png" /></span></P><P>&nbsp;</P><P>Click on create</P><P>&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_10-1742035914580.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237930i3C2E750239B8DAF8/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_10-1742035914580.png" alt="Shailendra_Srivastava_SAP_10-1742035914580.png" /></span></P><P>&nbsp;</P><P>Fill are require data</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_11-1742035914583.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237931iB2FB34FEF33D99DC/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_11-1742035914583.png" alt="Shailendra_Srivastava_SAP_11-1742035914583.png" /></span></P><P>&nbsp;</P><P>&nbsp;</P><P>Click on create it will create entry in Identity provider</P><P>&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_12-1742035914591.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237933iA5B0E40913568637/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_12-1742035914591.png" alt="Shailendra_Srivastava_SAP_12-1742035914591.png" /></span></P><P>&nbsp;</P><P>&nbsp;Now click on SAML2.0 Configuration</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_13-1742035914596.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237932iD41BCC6C10279A43/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_13-1742035914596.png" alt="Shailendra_Srivastava_SAP_13-1742035914596.png" /></span></P><P>&nbsp;</P><P>And upload azure xml file</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_14-1742035914612.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237934i107F33ECEFCCACCF/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_14-1742035914612.png" alt="Shailendra_Srivastava_SAP_14-1742035914612.png" /></span></P><P>&nbsp;</P><P>&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_15-1742035914627.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237935i9F77CB93300589BB/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_15-1742035914627.png" alt="Shailendra_Srivastava_SAP_15-1742035914627.png" /></span></P><P>&nbsp;</P><P>&nbsp;</P><P>All setting between Azure and IAS system has been done.You can check&nbsp; SSO connection via login on IAS system ,it will pick Azure authentication and will login without asking password on IAS system</P><P>Now going to setup SSO connection between IAS and managed application system here I will setup connection between IAS to success factor, you can choose other system depend on requirement</P><P>Login on IAS system and click on Application &amp; Resources and select SuccessFactors system</P><P>&nbsp;</P><P>Now &nbsp;select single Sign-on&nbsp; and check Subject Name Identifier it should be as below</P><P>&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_16-1742035914635.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237936iC018916252403722/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_16-1742035914635.png" alt="Shailendra_Srivastava_SAP_16-1742035914635.png" /></span></P><P>&nbsp;</P><P>&nbsp;</P><P>&nbsp;</P><P>select single Sign-on&nbsp; and check Default Name ID Format</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_17-1742035914649.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237937i2F52D9E239525163/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_17-1742035914649.png" alt="Shailendra_Srivastava_SAP_17-1742035914649.png" /></span></P><P>&nbsp;</P><P>&nbsp;</P><P>Check attribute it should be as below</P><P>&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_18-1742035914654.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237939i5D1DE1DEDA734BE5/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_18-1742035914654.png" alt="Shailendra_Srivastava_SAP_18-1742035914654.png" /></span></P><P>&nbsp;</P><P>Now maintain domain in Conditional Authentication as per below</P><P>&nbsp;</P><P>&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_19-1742035914661.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237940iDE2F42A241CB66CE/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_19-1742035914661.png" alt="Shailendra_Srivastava_SAP_19-1742035914661.png" /></span></P><P>&nbsp;</P><P>All setting has been completed for SF system</P><P>&nbsp;</P><P>&nbsp;</P><P>&nbsp;</P><P>&nbsp;</P><P>Now login to sf provision url and enable SSO</P><P>&nbsp;</P><P>&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Shailendra_Srivastava_SAP_20-1742035914664.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/237938i746FA94DA26FD0C8/image-size/medium?v=v2&amp;px=400" role="button" title="Shailendra_Srivastava_SAP_20-1742035914664.png" alt="Shailendra_Srivastava_SAP_20-1742035914664.png" /></span></P><P>&nbsp;</P><P>&nbsp;</P><P>Now test sso from SF system it will automatically login on system without login page</P><P>&nbsp;</P><P>Reference</P><UL><LI><A href="https://community.sap.com/t5/technology-blogs-by-members/simplify-sso-with-microsoft-entra-id-azure-ad-sap-identity-authentication/ba-p/13580145" target="_blank">Simplify SSO with Microsoft Entra ID (Azure AD) &amp; ... - SAP Community</A></LI><LI><A href="https://learn.microsoft.com/en-us/entra/identity/saas-apps/sap-hana-cloud-platform-identity-authentication-tutorial" target="_blank" rel="nofollow noopener noreferrer">https://learn.microsoft.com/en-us/entra/identity/saas-apps/sap-hana-cloud-platform-identity-authentication-tutorial</A></LI></UL> 2025-03-18T16:56:18.305000+01:00 https://community.sap.com/t5/technology-blog-posts-by-members/sap-iag-intergration-with-sap-analytical-cloud-sac/ba-p/14048896 SAP IAG intergration with SAP Analytical cloud (SAC) 2025-03-20T18:29:42.868000+01:00 JAPNEET_SINGH_JP https://community.sap.com/t5/user/viewprofilepage/user-id/1582501 <P><STRONG>SAP Cloud Identity Access Governance (IAG)</STRONG> serves as a pivotal cloud-based solution, orchestrating identity and access management across intricate hybrid environments. By centralizing access request processes through a user-friendly, self-service portal, IAG streamlines provisioning for both on-premises and cloud applications, <STRONG>including seamless integration with SAP Analytics Cloud</STRONG>.</P><P>The first step is configuring SAP Cloud Identity Access Governance (IAG) within SAP Business Technology Platform (BTP) environment involves establishing a proxy destination. Specifically, the creation of the IPS_PROXY destination within your subscriber subaccount is paramount for seamless communication and functionality.</P><P>&nbsp;</P><P><STRONG>Step 1. Create Proxy Destination in BTP is not created.</STRONG></P><OL><LI>Navigate to the subscriber subaccount for SAP Cloud Identity Access governance in SAP BTP and create a destination with the name&nbsp;<SPAN><STRONG>IPS_PROXY</STRONG></SPAN>&nbsp;as shown in the table below.</LI><LI>Enter the&nbsp;<SPAN><STRONG>Properties</STRONG></SPAN>&nbsp;listed in the table below for the destination. All properties must be entered. Some properties must be added as&nbsp;<SPAN><STRONG>Additional Properties</STRONG></SPAN>. Copy the names of all properties as displayed. Property names and values are case sensitive.<BR /><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JAPNEET_SINGH_JP_0-1742337205989.png" style="width: 553px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/239189iA0A88588372ED2A9/image-dimensions/553x296?v=v2" width="553" height="296" role="button" title="JAPNEET_SINGH_JP_0-1742337205989.png" alt="JAPNEET_SINGH_JP_0-1742337205989.png" /></span><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JAPNEET_SINGH_JP_1-1742337299997.png" style="width: 553px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/239190i651EE32D853DD7B7/image-dimensions/553x314?v=v2" width="553" height="314" role="button" title="JAPNEET_SINGH_JP_1-1742337299997.png" alt="JAPNEET_SINGH_JP_1-1742337299997.png" /></span><P>The url in the above can be fetched from CIS cockpit.&nbsp;</P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JAPNEET_SINGH_JP_2-1742337519416.png" style="width: 549px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/239191i7B8B34F62D1E7E23/image-dimensions/549x273?v=v2" width="549" height="273" role="button" title="JAPNEET_SINGH_JP_2-1742337519416.png" alt="JAPNEET_SINGH_JP_2-1742337519416.png" /></span><P>For user and password</P><OL><LI>Go to the Identity Authentication,&nbsp;<SPAN><STRONG>Users Authorizations</STRONG></SPAN><SPAN>-&gt; Administrator</SPAN>&nbsp;and enable the option&nbsp;<SPAN><STRONG>Manage Identity Provisioning</STRONG></SPAN>&nbsp;for your user.</LI><LI>Open your Identity Provisioning and navigate to&nbsp;<SPAN><STRONG>Security</STRONG> Authorizations</SPAN><SPAN>&nbsp;&nbsp;<STRONG>&nbsp;Manage User Authorizations</STRONG> -</SPAN><SPAN><STRONG>&gt; A</STRONG></SPAN><SPAN>dministrators</SPAN>.</LI><LI>In the section&nbsp;<SPAN><STRONG>Users &amp; Authorizations</STRONG></SPAN><SPAN> Administrators</SPAN>,&nbsp;<SPAN><STRONG>Add System</STRONG></SPAN>&nbsp;for Identity Provisioning and&nbsp;<SPAN><STRONG>Configure Authorizations</STRONG></SPAN>&nbsp;for the&nbsp;<SPAN><STRONG>Access Proxy System API</STRONG></SPAN>. Note down the&nbsp;<SPAN><STRONG>Client ID</STRONG></SPAN>&nbsp;and&nbsp;<SPAN><STRONG>Secret</STRONG></SPAN>&nbsp;(once the secret is generated, you cannot retrieve or change it.).<BR /><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JAPNEET_SINGH_JP_3-1742337671103.png" style="width: 550px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/239192i60C4154A8C0BD6ED/image-dimensions/550x275?v=v2" width="550" height="275" role="button" title="JAPNEET_SINGH_JP_3-1742337671103.png" alt="JAPNEET_SINGH_JP_3-1742337671103.png" /></span><P>&nbsp;</P><P><STRONG>Step 2:Create Proxy system for SAC in CIS.</STRONG></P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JAPNEET_SINGH_JP_4-1742337846387.png" style="width: 548px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/239193i002EF180DBFD3D40/image-dimensions/548x177?v=v2" width="548" height="177" role="button" title="JAPNEET_SINGH_JP_4-1742337846387.png" alt="JAPNEET_SINGH_JP_4-1742337846387.png" /></span><P>Maintain the properties exactly as shown:</P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JAPNEET_SINGH_JP_5-1742337938685.png" style="width: 550px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/239194i3AC7A97FCA00A21A/image-dimensions/550x272?v=v2" width="550" height="272" role="button" title="JAPNEET_SINGH_JP_5-1742337938685.png" alt="JAPNEET_SINGH_JP_5-1742337938685.png" /></span><P>The OAuthtoken, user, URL and password is to be fetched from SAC.</P><P>In SAC: Goto system-&gt; Administrator</P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JAPNEET_SINGH_JP_6-1742338055151.png" style="width: 532px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/239195i959928062F960105/image-dimensions/532x258?v=v2" width="532" height="258" role="button" title="JAPNEET_SINGH_JP_6-1742338055151.png" alt="JAPNEET_SINGH_JP_6-1742338055151.png" /></span><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JAPNEET_SINGH_JP_7-1742338142794.png" style="width: 495px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/239196iDF336C209CD16273/image-dimensions/495x507?v=v2" width="495" height="507" role="button" title="JAPNEET_SINGH_JP_7-1742338142794.png" alt="JAPNEET_SINGH_JP_7-1742338142794.png" /></span><P><STRONG>Step 3: Create application in IAG.</STRONG></P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JAPNEET_SINGH_JP_8-1742338228672.png" style="width: 556px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/239197i05759FBFD2B4BB62/image-dimensions/556x175?v=v2" width="556" height="175" role="button" title="JAPNEET_SINGH_JP_8-1742338228672.png" alt="JAPNEET_SINGH_JP_8-1742338228672.png" /></span><P>Run Repository sync.&nbsp;</P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JAPNEET_SINGH_JP_9-1742338311896.png" style="width: 564px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/239198iBFFAE10AE36CD8CA/image-dimensions/564x203?v=v2" width="564" height="203" role="button" title="JAPNEET_SINGH_JP_9-1742338311896.png" alt="JAPNEET_SINGH_JP_9-1742338311896.png" /></span><P>&nbsp;</P>This completes the SAP Cloud Identity Access Governance (IAG) integration with SAP Analytics Cloud, enabling centralized, secure access management</LI></OL></LI></OL><P>Regards<BR />JP</P> 2025-03-20T18:29:42.868000+01:00 https://community.sap.com/t5/technology-blog-posts-by-sap/integrating-sap-cloud-identity-services-identity-authentication-ias-with/ba-p/14040078 Integrating SAP Cloud Identity Services (Identity Authentication - IAS) with SAP Audit Log Viewer 2025-03-23T20:29:50.328000+01:00 Yogananda https://community.sap.com/t5/user/viewprofilepage/user-id/75 <DIV class=""><P>Previous Blog : <A href="https://community.sap.com/t5/technology-blogs-by-sap/how-to-enable-sap-audit-log-viewer-service-to-collect-all-audit-logs-from/ba-p/14037435" target="_blank">https://community.sap.com/t5/technology-blogs-by-sap/how-to-enable-sap-audit-log-viewer-service-to-collect-all-audit-logs-from/ba-p/14037435</A>&nbsp;</P><H2 id="toc-hId-1705420456">Accessing Audit Logs for Identity Authentication Tenants</H2><P>To access the audit logs for changes in personal data, successful, and failed authentications for Identity Authentication tenants on both SAP, AWS, and Azure infrastructures, you can use the Audit Log Service in SAP BTP, Cloud Foundry. <FONT color="#FF0000"><EM>This process is essential for organizations that require detailed auditing to ensure that changes are tracked accurately.</EM></FONT></P><H3 id="toc-hId-1637989670">Why is this Important?</H3><P>Auditing is crucial for maintaining the integrity and security of your organization's data. By tracking who made changes, you can ensure accountability and transparency within your system.</P><H3 id="toc-hId-1441476165">Steps to Access Audit Logs</H3><OL><LI><STRONG>Navigate to the Audit Log Service</STRONG>: Access the Audit Log Service in SAP BTP, Cloud Foundry.</LI><LI><STRONG>Filter Logs</STRONG>: Use filters to view logs related to changes in personal data, successful authentications, and failed authentications.</LI><LI><STRONG>Review and Analyze</STRONG>: Carefully review the logs to identify any unauthorized changes or any suspicious activities.</LI></OL><H3 id="toc-hId-1244962660">Benefits</H3><UL><LI>Enhanced Security: By monitoring audit logs, you can detect and respond to security breaches promptly.</LI><LI>Compliance: Ensure your organization meets regulatory requirements for data protection and privacy.</LI><LI>Accountability: Track changes to identify responsible parties and maintain accountability</LI></UL></DIV><DIV class=""><DIV class=""><DIV class=""><P class=""><STRONG>Prerequisites for enabling Auditlogs Viewer for SAP Identity Authentication - Audit logs</STRONG></P><P class="">Pick your subaccount details and you must have <FONT color="#3366FF"><STRONG>SAP Cloud Identity Services and Auditlog Viewer Services</STRONG></FONT> enabled already.<span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-03-23_19-47-52.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/241566i277AC8994E09C89F/image-size/large?v=v2&amp;px=999" role="button" title="2025-03-23_19-47-52.png" alt="2025-03-23_19-47-52.png" /></span></P><P class=""><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-03-23_19-46-25.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/241567i4045A2E03FF1C733/image-size/large?v=v2&amp;px=999" role="button" title="2025-03-23_19-46-25.png" alt="2025-03-23_19-46-25.png" /></span></P><P class="">Once above details are available, you can now follow the below steps to tie the application between SAP Cloud Identity Services and Auditlog Viewer Services</P><P class=""><STRONG>Step 1</STRONG> : Login to your SAP Cloud Identity Services - Admin and go to Monitoring &amp; Reporting Tile<span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-03-23_19-50-18.png" style="width: 885px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/241570i5A62F1A669A885D3/image-size/large?v=v2&amp;px=999" role="button" title="2025-03-23_19-50-18.png" alt="2025-03-23_19-50-18.png" /></span></P><P class=""><STRONG>Step 2</STRONG> : Click Add to update configuration of your SAP BTP Tenant details (from above prerequisites steps)<span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-03-23_19-50-37.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/241569i639A4A959364FBE1/image-size/large?v=v2&amp;px=999" role="button" title="2025-03-23_19-50-37.png" alt="2025-03-23_19-50-37.png" /></span></P><P class=""><STRONG>Step 3 :&nbsp;</STRONG>Update your BTP Tenant Id and Subdomain which should match to the region shown in dropdown. List of available regions are in below link.<span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-03-23_19-51-56.png" style="width: 795px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/241565i215E78FD598C5544/image-size/large?v=v2&amp;px=999" role="button" title="2025-03-23_19-51-56.png" alt="2025-03-23_19-51-56.png" /></span><A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/access-audit-logs-aws-azure-infrastructure" target="_self" rel="noopener noreferrer">List of Available Regions for&nbsp;<SPAN class="">Identity Authentication</SPAN><SPAN>&nbsp;-&nbsp;</SPAN><SPAN class="">Cloud Foundry</SPAN><SPAN>&nbsp;Regions Mapping</SPAN></A></P><P class=""><SPAN><STRONG>Step 4:</STRONG> Once configured,you will be able to see the Subaccount Information and Auditlog viewer Link and you will have to wait for 15-20mins once configured to see the logs in Auditlog Viewer Portal.<span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-03-23_19-53-53.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/241564iBA1E756C9416D870/image-size/large?v=v2&amp;px=999" role="button" title="2025-03-23_19-53-53.png" alt="2025-03-23_19-53-53.png" /></span></SPAN></P></DIV></DIV></DIV><P class=""><STRONG>Step 5 :</STRONG> Upon accessing the Audit Log Viewer, you have the option to filter the logs based on date and keyword filters.</P><DIV class="">The audit logs provide information about the event category and timestamp, the event and object type, who performed the action and others.<span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-03-23_20-00-50.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/241563i76596B1D8A46320F/image-size/large?v=v2&amp;px=999" role="button" title="2025-03-23_20-00-50.png" alt="2025-03-23_20-00-50.png" /></span></DIV><P>&nbsp;</P><DIV class="">&nbsp;</DIV> 2025-03-23T20:29:50.328000+01:00 https://community.sap.com/t5/technology-blog-posts-by-sap/new-business-technology-platform-capabilities-customer-identity-and-consent/ba-p/14090631 New Business Technology Platform Capabilities: Customer Identity and Consent Management 2025-05-06T13:00:00.026000+02:00 ratulshah https://community.sap.com/t5/user/viewprofilepage/user-id/604338 <P><SPAN>Today, </SPAN>SAP Business Technology Platform now include<SPAN>s</SPAN> our industry leading Customer Identity and Access Management (CIAM) solution <SPAN>through</SPAN> <SPAN>the </SPAN><SPAN>BTP Enterprise Agreement. This highly scalable solution </SPAN>supports<SPAN> over</SPAN> 2.9 billion identities and 17.7 billion consent records.</P><P>&nbsp;</P><P><STRONG>Why SAP CIAM?</STRONG></P><P>With SAP CIAM, you can deliver seamless customer experiences while upholding stringent security standards and accelerating growth. By harnessing <SPAN>your </SPAN>customer<SPAN>’s</SPAN> data effectively and responsibly, this solution empowers businesses of all sizes to bridge the numerous data strategy gaps that emerge in today's digital-first landscape — where there are more touchpoints to manage, engagement channels to orchestrate, and data points to collect than ever before.<SPAN> The power to personali</SPAN><SPAN>ze is easier than ever with consent based first-party data.</SPAN></P><P><SPAN>Explore </SPAN><SPAN><A href="https://www.sap.com/products/technology-platform/customer-identity.html?pdf-asset=44f1b9fd-f27e-0010-bca6-c68f7e60039b&amp;page=1" target="_blank" rel="noopener noreferrer">this KuppingerCole report</A></SPAN><SPAN> to </SPAN><SPAN>learn how our CIAM solution stands out.</SPAN></P><P>&nbsp;</P><P>&nbsp;</P><P><STRONG>What is SAP CIAM?</STRONG></P><P>SAP CIAM is a comprehensive identity solution which transforms customer data into actionable insights. <SPAN>Designed to function as a brand’s digital front door, this multitenant, cloud-native software plays a critical role in data strategy; it enables organizations to effectively capture and manage both customer and partner data while enhancing security and privacy and delivering personalized experiences.</SPAN></P><P>By providing access to intelligent insights across the business landscape, SAP CIAM equips businesses to:&nbsp;</P><UL><LI>Secure users and safeguard data&nbsp;</LI></UL><UL><LI>Prioritize business protection with AI&nbsp;</LI></UL><UL><LI>Reduce privacy compliance risk&nbsp;</LI></UL><UL><LI>Overcome data silos&nbsp;</LI></UL><UL><LI>Increase efficiency at scale&nbsp;</LI></UL><P>&nbsp;</P><P><SPAN><A href="https://www.sap.com/products/technology-platform/customer-identity.html" target="_blank" rel="noopener noreferrer">Discover</A></SPAN> how SAP CIAM can elevate your business<SPAN> today.</SPAN></P><P><SPAN>&nbsp;</SPAN></P><P>&nbsp;</P><P><STRONG>How does SAP CIAM work?</STRONG></P><P>SAP CIAM streamlines identity creation and authentication across digital platforms, allowing easy registration management for various devices. It securely stores and enriches customer<SPAN> data</SPAN> <SPAN>with each digital transaction</SPAN>, offering options like social login and biometrics for secure access. By assembling robust customer profiles, SAP CIAM helps businesses personalize experiences, boost engagement, optimize customer journeys, and make informed decisions while integrating seamlessly with existing systems.</P><P>&nbsp;</P><P>Dive into more solution details with this <A href="https://www.sap.com/assetdetail/2023/10/ca2ab5ed-937e-0010-bca6-c68f7e60039b.html" target="_blank" rel="noopener noreferrer">short video</A>.</P><P>&nbsp;</P><P><STRONG>Who needs SAP CIAM?</STRONG></P><P>Any business that manages digital transactions can benefit from SAP CIAM. Today, it’s now more crucial than ever that organizations find a way to capture –– and manage –– customer and partner data because every online interaction is an opportunity to acquire user information, develop brand loyalty, and deepen <SPAN>t</SPAN>rust.</P><P>SAP CIAM is available with both a B2C implementation and a B2B implementation.</P><P>&nbsp;</P><P><STRONG>Getting started with SAP CIAM</STRONG></P><P>SAP CIAM is now available as part of the Business Technology Platform Enterprise Agreement (BTPEA). Existing consumption credits can be used on this solution, empowering your business to conveniently handle identity, consent, and authentication without entering into any new contracts. Learn more <SPAN><A href="https://discovery-center.cloud.sap/viewServices?category=all" target="_blank" rel="nofollow noopener noreferrer">here</A></SPAN>.</P> 2025-05-06T13:00:00.026000+02:00 https://community.sap.com/t5/technology-blog-posts-by-sap/introducing-the-new-terraform-provider-for-sap-cloud-identity-services-now/ba-p/14103416 Introducing the new Terraform Provider for SAP Cloud Identity Services – Now in Beta! 2025-05-16T19:05:47.308000+02:00 vipin_vijaykumar https://community.sap.com/t5/user/viewprofilepage/user-id/220096 <P><SPAN class="">We’re </SPAN><SPAN class="">excited </SPAN><SPAN class="">to </SPAN><SPAN class="">announce </SPAN><SPAN class="">the </SPAN><STRONG><SPAN class="">beta </SPAN><SPAN class="">release </SPAN><SPAN class="">of </SPAN><SPAN class="">the </SPAN><SPAN class="">Terraform </SPAN><SPAN class="">provider </SPAN><SPAN class="">for </SPAN><A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services" target="_self" rel="noopener noreferrer"><SPAN class="">SAP </SPAN><SPAN class="">Cloud </SPAN><SPAN class="">Identity </SPAN><SPAN class="">Services.</SPAN></A></STRONG><SPAN class="">&nbsp;Built based</SPAN><SPAN class="">&nbsp;on customer&nbsp;</SPAN><SPAN class="">feedback </SPAN><SPAN class="">and </SPAN><SPAN class="">feature </SPAN><SPAN class="">requests, this provider is a much-awaited step forward in simplifying identity management.</SPAN></P><HR /><H2 id="toc-hId-1730448552"><SPAN class="">Why </SPAN><SPAN class="">Automate </SPAN><SPAN class="">SAP </SPAN><SPAN class="">Cloud </SPAN><SPAN class="">Identity </SPAN><SPAN class="">Services?</SPAN></H2><P><SPAN class="">&nbsp;</SPAN><SPAN class="">It </SPAN><SPAN class="">provides </SPAN><SPAN class="">a </SPAN><STRONG><SPAN class="">secure, </SPAN><SPAN class="">centralised </SPAN><SPAN class="">approach</SPAN></STRONG> <SPAN class="">to </SPAN><SPAN class="">identity </SPAN><SPAN class="">and </SPAN><SPAN class="">access </SPAN><SPAN class="">management </SPAN><SPAN class="">across </SPAN><SPAN class="">systems, </SPAN><SPAN class="">making </SPAN><SPAN class="">it </SPAN><SPAN class="">an important part</SPAN><SPAN class="">&nbsp;</SPAN><SPAN class="">of </SPAN><SPAN class="">any </SPAN><SPAN class="">modern </SPAN><SPAN class="">SAP </SPAN><SPAN class="">landscape.</SPAN></P><P><SPAN class="">As </SPAN><SPAN class="">your </SPAN><SPAN class="">organisation </SPAN><SPAN class="">grows, scaling identity &amp; access management starts to become a challenge, and&nbsp;</SPAN><STRONG><SPAN class="">automation </SPAN><SPAN class="">becomes </SPAN><SPAN class="">essential.</SPAN></STRONG></P><P><SPAN class="">With </SPAN><SPAN class="">this </SPAN><SPAN class="">new </SPAN><SPAN class="">Terraform </SPAN><SPAN class="">provider, </SPAN><SPAN class="">you </SPAN><SPAN class="">can </SPAN><SPAN class="">bring </SPAN><STRONG><SPAN class="">infrastructure-</SPAN><SPAN class="">as-</SPAN><SPAN class="">code (</SPAN><SPAN class="">IaC)</SPAN></STRONG> <SPAN class="">practices </SPAN><SPAN class="">to </SPAN><SPAN class="">your </SPAN><SPAN class="">identity </SPAN><SPAN class="">environment, </SPAN><SPAN class="">delivering:</SPAN></P><UL><LI><P><SPAN class="">Repeatability</SPAN></P></LI><LI><P><SPAN class="">Auditability</SPAN></P></LI><LI><P><SPAN class="">Governance</SPAN></P></LI><LI><P><SPAN class="">Faster </SPAN><SPAN class="">deployments</SPAN></P></LI></UL><HR /><H2 id="toc-hId-1533935047"><SPAN class="">What’s </SPAN><SPAN class="">in </SPAN><SPAN class="">the </SPAN><SPAN class="">Box? <span class="lia-unicode-emoji" title=":rocket:">🚀</span></SPAN></H2><P><SPAN class="">The </SPAN><SPAN class="">provider </SPAN><SPAN class="">will </SPAN><SPAN class="">be </SPAN><SPAN class="">developed </SPAN><SPAN class="">in </SPAN><SPAN class="">a </SPAN><STRONG><SPAN class="">phased </SPAN><SPAN class="">and </SPAN><SPAN class="">scoped </SPAN><SPAN class="">manner. </SPAN></STRONG><SPAN class="">It will</SPAN><SPAN class="">&nbsp;</SPAN><SPAN class="">evolve&nbsp;</SPAN><SPAN class="">based </SPAN><SPAN class="">on</SPAN><SPAN class="">&nbsp;</SPAN><STRONG><SPAN class="">feedback</SPAN></STRONG><SPAN class="">, </SPAN><STRONG><SPAN class="">requirements</SPAN></STRONG><SPAN class="">, </SPAN><SPAN class="">and <STRONG>user</STRONG></SPAN><STRONG><SPAN class="">&nbsp;</SPAN><SPAN class="">scenarios</SPAN></STRONG><SPAN class="">.</SPAN></P><P><SPAN class="">In </SPAN><SPAN class="">this</SPAN><STRONG><SPAN class="">&nbsp;</SPAN><SPAN class="">beta </SPAN><SPAN class="">release</SPAN></STRONG><SPAN class="">, </SPAN><SPAN class="">our&nbsp;</SPAN><SPAN class="">focus </SPAN><SPAN class="">is </SPAN><SPAN class="">on </SPAN><SPAN class="">foundational </SPAN><SPAN class="">resources </SPAN><SPAN class="">that </SPAN><SPAN class="">are </SPAN><SPAN class="">central </SPAN><SPAN class="">to </SPAN><SPAN class="">identity &amp;</SPAN><SPAN class="">&nbsp;authentication</SPAN><SPAN class="">:</SPAN></P><H3 id="toc-hId-1466504261"><A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/applications?q=application" target="_self" rel="noopener noreferrer"><SPAN class="">Application</SPAN></A></H3><P><SPAN class="">Applications </SPAN><SPAN class="">represent </SPAN><SPAN class="">consumers </SPAN><SPAN class="">of </SPAN><SPAN class="">Identity </SPAN><SPAN class="">Authentication such as&nbsp;</SPAN><SPAN class="">SAP </SPAN><SPAN class="">cloud </SPAN><SPAN class="">solutions, </SPAN><SPAN class="">third-</SPAN><SPAN class="">party </SPAN><SPAN class="">apps, </SPAN><SPAN class="">SAP </SPAN><SPAN class="">BTP </SPAN><SPAN class="">subaccount, etc</SPAN><SPAN class="">.</SPAN></P><UL><LI><P><STRONG><SPAN class="">Terraform </SPAN><SPAN class="">Resource</SPAN></STRONG><SPAN class="">: </SPAN><SPAN class="">Configure </SPAN><SPAN class="">identity </SPAN><SPAN class="">settings </SPAN><SPAN class="">for </SPAN><SPAN class="">applications.</SPAN></P></LI><LI><P><STRONG><SPAN class="">Data </SPAN><SPAN class="">Sources</SPAN></STRONG><SPAN class="">: </SPAN><SPAN class="">Retrieve </SPAN><SPAN class="">details </SPAN><SPAN class="">of </SPAN><SPAN class="">specific </SPAN><SPAN class="">applications </SPAN><SPAN class="">or </SPAN><SPAN class="">list </SPAN><SPAN class="">all </SPAN><SPAN class="">applications </SPAN><SPAN class="">within </SPAN><SPAN class="">a </SPAN><SPAN class="">tenant.</SPAN><BR /><A href="https://registry.terraform.io/providers/SAP/sap-cloud-identity-services/latest/docs/resources/application" target="_self" rel="nofollow noopener noreferrer"><SPAN class=""><span class="lia-unicode-emoji" title=":blue_book:">📘</span></SPAN><SPAN class="">View </SPAN><SPAN class="">Docs</SPAN></A></P></LI></UL><HR /><H3 id="toc-hId-1269990756"><A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/groups?q=groups" target="_self" rel="noopener noreferrer"><SPAN class="">Group</SPAN></A></H3><P><SPAN class="">Groups </SPAN><SPAN class="">help </SPAN><SPAN class="">organise </SPAN><SPAN class="">users </SPAN><SPAN class="">based </SPAN><SPAN class="">on </SPAN><SPAN class="">roles, </SPAN><SPAN class="">permissions, </SPAN><SPAN class="">or </SPAN><SPAN class="">other </SPAN><SPAN class="">criteria.</SPAN></P><UL><LI><P><STRONG><SPAN class="">Terraform </SPAN><SPAN class="">Resource</SPAN></STRONG><SPAN class="">: </SPAN><SPAN class="">Create </SPAN><SPAN class="">and </SPAN><SPAN class="">manage </SPAN><SPAN class="">user </SPAN><SPAN class="">groups.</SPAN></P></LI><LI><P><STRONG><SPAN class="">Data </SPAN><SPAN class="">Sources</SPAN></STRONG><SPAN class="">: </SPAN><SPAN class="">Fetch </SPAN><SPAN class="">details </SPAN><SPAN class="">of </SPAN><SPAN class="">individual </SPAN><SPAN class="">groups </SPAN><SPAN class="">or </SPAN><SPAN class="">get </SPAN><SPAN class="">a </SPAN><SPAN class="">complete </SPAN><SPAN class="">list.</SPAN><BR /><A class="" href="https://registry.terraform.io/providers/SAP/sap-cloud-identity-services/latest/docs/resources/group" target="_new" rel="noopener nofollow noreferrer"><SPAN class=""><span class="lia-unicode-emoji" title=":blue_book:">📘</span></SPAN><SPAN class="">View </SPAN><SPAN class="">Docs</SPAN></A></P></LI></UL><HR /><H3 id="toc-hId-1073477251"><A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/user-types?q=users" target="_self" rel="noopener noreferrer"><SPAN class="">User</SPAN></A></H3><P><SPAN class="">Programmatically </SPAN><SPAN class="">manage </SPAN><STRONG><SPAN class="">end </SPAN><SPAN class="">users</SPAN></STRONG> <SPAN class="">with </SPAN><SPAN class="">the </SPAN><SPAN class="">ability </SPAN><SPAN class="">to </SPAN><SPAN class="">automate </SPAN><SPAN class="">user </SPAN><SPAN class="">lifecycle </SPAN><SPAN class="">operations.</SPAN></P><UL><LI><P><STRONG><SPAN class="">Terraform </SPAN><SPAN class="">Resource</SPAN></STRONG><SPAN class="">: </SPAN><SPAN class="">Define </SPAN><SPAN class="">and </SPAN><SPAN class="">manage </SPAN><SPAN class="">end </SPAN><SPAN class="">users.</SPAN></P></LI><LI><P><STRONG><SPAN class="">Data </SPAN><SPAN class="">Sources</SPAN></STRONG><SPAN class="">: </SPAN><SPAN class="">Query </SPAN><SPAN class="">individual </SPAN><SPAN class="">users </SPAN><SPAN class="">or </SPAN><SPAN class="">list </SPAN><SPAN class="">all </SPAN><SPAN class="">users </SPAN><SPAN class="">in </SPAN><SPAN class="">a </SPAN><SPAN class="">tenant.</SPAN><BR /><A class="" href="https://registry.terraform.io/providers/SAP/sap-cloud-identity-services/latest/docs/resources/user" target="_new" rel="noopener nofollow noreferrer"><SPAN class=""><span class="lia-unicode-emoji" title=":blue_book:">📘</span></SPAN><SPAN class="">View </SPAN><SPAN class="">Docs</SPAN></A></P></LI></UL><HR /><H3 id="toc-hId-876963746"><A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/manage-custom-schemas-via-administration-console?q=schema" target="_self" rel="noopener noreferrer"><SPAN class="">Schema</SPAN></A></H3><P><SPAN class="">Need </SPAN><SPAN class="">custom </SPAN><SPAN class="">attributes </SPAN><SPAN class="">for </SPAN><SPAN class="">your </SPAN><SPAN class="">users? </SPAN><SPAN class="">Define </SPAN><SPAN class="">and </SPAN><SPAN class="">manage </SPAN><SPAN class="">user </SPAN><SPAN class="">schemas </SPAN><SPAN class="">to </SPAN><SPAN class="">match </SPAN><SPAN class="">your </SPAN><SPAN class="">organisational </SPAN><SPAN class="">needs.</SPAN></P><UL><LI><P><STRONG><SPAN class="">Terraform </SPAN><SPAN class="">Resource</SPAN></STRONG><SPAN class="">: </SPAN><SPAN class="">Configure </SPAN><SPAN class="">custom </SPAN><SPAN class="">user </SPAN><SPAN class="">schemas.</SPAN></P></LI><LI><P><STRONG><SPAN class="">Data </SPAN><SPAN class="">Sources</SPAN></STRONG><SPAN class="">: </SPAN><SPAN class="">Retrieve </SPAN><SPAN class="">details </SPAN><SPAN class="">or </SPAN><SPAN class="">lists </SPAN><SPAN class="">of </SPAN><SPAN class="">schemas.</SPAN><BR /><A class="" href="https://registry.terraform.io/providers/SAP/sap-cloud-identity-services/latest/docs/resources/schema" target="_new" rel="noopener nofollow noreferrer"><SPAN class=""><span class="lia-unicode-emoji" title=":blue_book:">📘</span></SPAN><SPAN class="">View </SPAN><SPAN class="">Docs</SPAN></A></P></LI></UL><HR /><P><SPAN class="">The </SPAN><SPAN class="">provider </SPAN><SPAN class="">is </SPAN><STRONG><SPAN class="">open-</SPAN><SPAN class="">source</SPAN></STRONG> <SPAN class="">under </SPAN><SPAN class="">the </SPAN><STRONG><SPAN class="">Apache </SPAN><SPAN class="">2.0 </SPAN><SPAN class="">license</SPAN></STRONG><SPAN class="">, </SPAN><SPAN class="">and </SPAN><SPAN class="">powered </SPAN><SPAN class="">by </SPAN><SPAN class="">the </SPAN><STRONG><SPAN class="">public </SPAN><SPAN class="">APIs </SPAN><SPAN class="">published </SPAN><SPAN class="">on </SPAN><SPAN class="">the </SPAN><A href="https://api.sap.com/package/SCPIdentityServices/rest" target="_self" rel="noopener noreferrer"><SPAN class="">SAP </SPAN><SPAN class="">Business </SPAN><SPAN class="">Accelerator </SPAN><SPAN class="">Hub</SPAN></A></STRONG><SPAN class="">.</SPAN></P><HR /><H2 id="toc-hId-551367522"><SPAN class="">A </SPAN><SPAN class="">Quick </SPAN><SPAN class="">Word </SPAN><SPAN class="">on </SPAN><SPAN class="">Beta&nbsp;</SPAN></H2><P><SPAN class="">This </SPAN><SPAN class="">is </SPAN><SPAN class="">a </SPAN><STRONG><SPAN class="">beta </SPAN><SPAN class="">release,</SPAN></STRONG><SPAN class="">&nbsp;</SPAN><SPAN class="">which </SPAN><SPAN class="">means </SPAN><SPAN class="">it’s </SPAN><SPAN class="">an </SPAN><SPAN class="">early </SPAN><SPAN class="">version, </SPAN><STRONG><SPAN class="">intended </SPAN><SPAN class="">for </SPAN><SPAN class="">exploration, </SPAN><SPAN class="">experimentation, </SPAN><SPAN class="">and </SPAN><SPAN class="">feedback</SPAN></STRONG><SPAN class="">.</SPAN></P><P><STRONG><SPAN class="">Important </SPAN><SPAN class="">Notes:</SPAN></STRONG></P><UL><LI><P><STRONG><SPAN class="">Do </SPAN><SPAN class="">not </SPAN><SPAN class="">use </SPAN><SPAN class="">it </SPAN><SPAN class="">in </SPAN><SPAN class="">production </SPAN><SPAN class="">just </SPAN><SPAN class="">yet.</SPAN></STRONG></P></LI><LI><P><SPAN class="">This </SPAN><SPAN class="">release </SPAN><SPAN class="">is </SPAN><SPAN class="">for </SPAN><STRONG><SPAN class="">trial </SPAN><SPAN class="">and </SPAN><SPAN class="">evaluation</SPAN></STRONG> <SPAN class="">only.</SPAN></P></LI><LI><P><SPAN class="">Definitions, </SPAN><SPAN class="">behaviour, </SPAN><SPAN class="">and </SPAN><SPAN class="">features </SPAN><STRONG><SPAN class="">may </SPAN><SPAN class="">change</SPAN></STRONG> <SPAN class="">in </SPAN><SPAN class="">future </SPAN><SPAN class="">releases </SPAN><SPAN class="">based </SPAN><SPAN class="">on:</SPAN></P><UL><LI><P><SPAN class="">Community </SPAN><SPAN class="">feedback</SPAN></P></LI><LI><P><SPAN class="">API </SPAN><SPAN class="">limitations </SPAN><SPAN class="">or </SPAN><SPAN class="">updates</SPAN></P></LI><LI><P><SPAN class="">Real-</SPAN><SPAN class="">world </SPAN><SPAN class="">use </SPAN><SPAN class="">cases</SPAN></P></LI><LI><P><SPAN class="">Bugs </SPAN><SPAN class="">or </SPAN><SPAN class="">usability </SPAN><SPAN class="">issues</SPAN></P></LI></UL></LI></UL><HR /><H2 id="toc-hId-354854017"><SPAN class="">We </SPAN><SPAN class="">Want </SPAN><SPAN class="">Your </SPAN><SPAN class="">Feedback! </SPAN></H2><P><SPAN class="">As </SPAN><SPAN class="">you </SPAN><SPAN class="">test </SPAN><SPAN class="">it </SPAN><SPAN class="">out, </SPAN><SPAN class="">let </SPAN><SPAN class="">us </SPAN><SPAN class="">know:</SPAN></P><UL><LI><P><SPAN class=""><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span></SPAN><SPAN class="">&nbsp;What </SPAN><SPAN class="">works </SPAN><SPAN class="">well?</SPAN></P></LI><LI><P><SPAN class=""><span class="lia-unicode-emoji" title=":lady_beetle:">🐞</span></SPAN><SPAN class="">&nbsp;What’s </SPAN><SPAN class="">broken?</SPAN></P></LI><LI><P><SPAN class=""><span class="lia-unicode-emoji" title=":light_bulb:">💡</span></SPAN><SPAN class="">&nbsp;What </SPAN><SPAN class="">features </SPAN><SPAN class="">or </SPAN><SPAN class="">resources </SPAN><SPAN class="">would </SPAN><SPAN class="">you </SPAN><SPAN class="">like </SPAN><SPAN class="">to </SPAN><SPAN class="">see </SPAN><SPAN class="">next?</SPAN></P></LI><LI><P><SPAN class=""><span class="lia-unicode-emoji" title=":repeat_button:">🔁</span></SPAN><SPAN class="">&nbsp;What </SPAN><SPAN class="">automation </SPAN><SPAN class="">scenarios </SPAN><SPAN class="">are </SPAN><SPAN class="">you </SPAN><SPAN class="">trying </SPAN><SPAN class="">to </SPAN><SPAN class="">solve?</SPAN></P></LI></UL><P><SPAN class="">You </SPAN><SPAN class="">can </SPAN><SPAN class="">file </SPAN><A href="https://github.com/SAP/terraform-provider-sap-cloud-identity-services/issues/new?template=bug_report.yml" target="_self" rel="nofollow noopener noreferrer"><STRONG><SPAN class="">issues</SPAN></STRONG></A><SPAN class="">, </SPAN><SPAN class="">open </SPAN><STRONG><SPAN class="">f<A href="https://github.com/SAP/terraform-provider-sap-cloud-identity-services/issues/new?template=feature_request.yml" target="_self" rel="nofollow noopener noreferrer">eature </A></SPAN><A href="https://github.com/SAP/terraform-provider-sap-cloud-identity-services/issues/new?template=feature_request.yml" target="_self" rel="nofollow noopener noreferrer"><SPAN class="">requests</SPAN></A></STRONG><SPAN class="">, </SPAN><SPAN class="">or </SPAN><SPAN class="">share </SPAN><A href="https://github.com/SAP/terraform-provider-sap-cloud-identity-services/discussions" target="_self" rel="nofollow noopener noreferrer"><STRONG><SPAN class="">scenarios</SPAN>&nbsp;and feedback</STRONG></A>&nbsp;<SPAN class="">directly </SPAN><SPAN class="">on </SPAN><SPAN class="">the </SPAN><SPAN class="">provider’s </SPAN><A href="https://github.com/SAP/terraform-provider-sap-cloud-identity-services" target="_self" rel="nofollow noopener noreferrer"><SPAN class="">GitHub </SPAN></A><SPAN class="">repository. </SPAN><SPAN class="">We’ll </SPAN><SPAN class="">do </SPAN><SPAN class="">our </SPAN><SPAN class="">best </SPAN><SPAN class="">to </SPAN><SPAN class="">address </SPAN><SPAN class="">them</SPAN><SPAN class="">.</SPAN></P><HR /><H2 id="toc-hId-158340512"><SPAN class="">Where </SPAN><SPAN class="">to </SPAN><SPAN class="">Get </SPAN><SPAN class="">It?</SPAN></H2><P><SPAN class="">The </SPAN><SPAN class="">provider </SPAN><SPAN class="">is </SPAN><SPAN class="">now </SPAN><SPAN class="">available </SPAN><SPAN class="">on the <A href="https://registry.terraform.io/providers/SAP/sap-cloud-identity-services/latest" target="_self" rel="nofollow noopener noreferrer">Terraform</A> &amp; <A href="https://search.opentofu.org/provider/sap/sap-cloud-identity-services/latest" target="_self" rel="nofollow noopener noreferrer">OpenTofu</A> registries:</SPAN></P><HR /><P><SPAN class="">We’re </SPAN><SPAN class="">thrilled </SPAN><SPAN class="">to </SPAN><SPAN class="">take </SPAN><SPAN class="">this </SPAN><SPAN class="">step </SPAN><SPAN class="">forward </SPAN><SPAN class="">in </SPAN><SPAN class="">supporting </SPAN><STRONG><SPAN class="">SAP </SPAN><SPAN class="">Cloud </SPAN><SPAN class="">Identity </SPAN><SPAN class="">Services </SPAN><SPAN class="">automation</SPAN></STRONG> <SPAN class="">and </SPAN><SPAN class="">can’t </SPAN><SPAN class="">wait </SPAN><SPAN class="">to </SPAN><SPAN class="">see </SPAN><SPAN class="">what </SPAN><SPAN class="">the </SPAN><SPAN class="">community </SPAN><SPAN class="">builds </SPAN><SPAN class="">with </SPAN><SPAN class="">it.</SPAN></P><P><SPAN class="">🧪 </SPAN><SPAN class="">Try </SPAN><SPAN class="">it </SPAN><SPAN class="">out.</SPAN><BR /><SPAN class=""><span class="lia-unicode-emoji" title=":hammer_and_wrench:">🛠</span></SPAN><SPAN class="">&nbsp;Break </SPAN><SPAN class="">things.</SPAN><BR /><SPAN class=""><span class="lia-unicode-emoji" title=":speech_balloon:">💬</span></SPAN><SPAN class="">&nbsp;Tell </SPAN><SPAN class="">us </SPAN><SPAN class="">what </SPAN><SPAN class="">you </SPAN><SPAN class="">need.</SPAN></P><P><SPAN class="">Let’s </SPAN><SPAN class="">build </SPAN><SPAN class="">something </SPAN><SPAN class="">awesome together!</SPAN></P><P><SPAN class="">&nbsp;</SPAN></P> 2025-05-16T19:05:47.308000+02:00 https://community.sap.com/t5/technology-blog-posts-by-sap/shift-identity-management-from-sap-idm-to-sap-iag-with-cis-and-grc-ac/ba-p/14117334 Shift identity management from SAP IDM to SAP IAG with CIS and GRC AC. 2025-06-03T10:21:50.898000+02:00 Saurabh_Sharma https://community.sap.com/t5/user/viewprofilepage/user-id/1541688 <P>Disclaimer-It is recommended to conduct an SAP IDM assessment to evaluate the feasibility of migrating existing functionalities to SAP IAG, CIS, or GRC Access Control. <SPAN>The approach in this blog&nbsp;</SPAN>is particularly suitable for customers who primarily use SAP IDM for managing access in SAP systems, whether on-premise or in the cloud.In a more complex and heterogeneous enterprise-wide environment, customers are most likely to rely on a third-party identity management solution. Refer&nbsp;this <A href="https://community.sap.com/t5/technology-blog-posts-by-sap/update-on-the-sap-identity-management-migration-to-microsoft-entra/ba-p/13742820" target="_blank">blog</A> that highlights our partnership with Microsoft to position MS Entra as a successor for SAP IDM.</P><P>SAP provides a comprehensive suite of identity and access management (IAM) solutions to help customers manage user identities across their SAP applications, both on-premise and in the cloud. These solutions include SAP Identity Management (SAP IDM), SAP GRC Access Control (SAP GRC AC), SAP Cloud Identity Services (comprising Identity Authentication and Identity Provisioning), and the SAP Identity Access Governance (SAP IAG) service.</P><P>SAP IDM, the long-standing on-premise IAM solution that has supported customers for over two decades, is approaching the end of its maintenance lifecycle (refer to SAP Note 3268799). Organizations currently using SAP IDM and planning a migration strategy can consider leveraging SAP IAG, SAP Cloud Identity Services (CIS), and their existing SAP GRC Access Control systems to cover identity lifecycle management needs. In many cases, the combination of SAP IAG with CIS—or SAP IAG with CIS and a bridge to SAP GRC Access Control—can replicate most of the functionalities previously handled by SAP IDM.</P><P>SAP IAG and SAP CIS are designed to complement each other and are often deployed together in enterprise environments to deliver end-to-end identity and access management. Additionally, SAP IAG can be integrated in a bridge scenario with SAP GRC Access Control to reuse existing configurations and ensure a smooth transition.</P><P>&nbsp;</P><TABLE><TBODY><TR><TD><P><STRONG>Feature / Solution</STRONG></P></TD><TD><P><STRONG>SAP IAG</STRONG></P></TD><TD><P><STRONG>SAP Cloud Identity Services</STRONG></P></TD><TD><P><STRONG>SAP GRC Access Control</STRONG></P></TD></TR><TR><TD><P><STRONG>Deployment</STRONG></P></TD><TD><P>Cloud</P></TD><TD><P>Cloud</P></TD><TD><P>On-premise / Hybrid</P></TD></TR><TR><TD><P><STRONG>Primary Focus</STRONG></P></TD><TD><P>Access governance &amp; compliance</P></TD><TD><P>Authentication &amp; identity provisioning</P></TD><TD><P>Risk management &amp; compliance</P></TD></TR><TR><TD><P><STRONG>Authentication (SSO, MFA)</STRONG></P></TD><TD><P>No</P></TD><TD><P>Yes</P></TD><TD><P>No</P></TD></TR><TR><TD><P><STRONG>Access Risk Analysis</STRONG></P></TD><TD><P>Yes</P></TD><TD><P>No</P></TD><TD><P>Yes</P></TD></TR><TR><TD><P><STRONG>Access Request Management</STRONG></P></TD><TD><P>Yes</P></TD><TD><P>No</P></TD><TD><P>Yes</P></TD></TR><TR><TD><P><STRONG>Role Management</STRONG></P></TD><TD><P>Yes</P></TD><TD><P>No</P></TD><TD><P>Yes</P></TD></TR><TR><TD><P><STRONG>Privileged Access Management</STRONG></P></TD><TD><P>Yes</P></TD><TD><P>No</P></TD><TD><P>Yes (via EAM)</P></TD></TR><TR><TD><P><STRONG>Best Fit For</STRONG></P></TD><TD><P>Cloud-first organizations</P></TD><TD><P>Identity and access security</P></TD><TD><P>Regulated industries with complex needs</P></TD></TR></TBODY></TABLE><P>&nbsp;</P><P><STRONG>IDM Functionalities</STRONG></P><P>This section outlines the SAP IDM functionalities along with their corresponding equivalents in SAP IAG, CIS, and GRC Access Control. The relevance of each activity may vary depending on the specific SAP IDM implementation within an organization.</P><P>&nbsp;</P><TABLE><TBODY><TR><TD><P><STRONG>IDM Functionality</STRONG></P></TD><TD><P><STRONG>As-Is Configuration (SAP IDM)</STRONG></P></TD><TD><P><STRONG>Corresponding Functionality in IAG / CIS / GRC AC</STRONG></P></TD></TR><TR><TD><P><STRONG>System Connectivity – SAP &amp; Non-SAP Systems</STRONG></P></TD><TD><P>List of systems supported via SAP IDM packages: ABAP Business Suite, ABAP (Load Balanced), AD, AS Java, BW, Dual Stack, HANA DB, S/4HANA, SCI (IAS/IPS), SCIM (IPS Proxy), SuccessFactors (SFSF), Sun (AD), GRC</P></TD><TD><P>CIS: <A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/supported-systems" target="_blank" rel="noopener noreferrer">Supported Systems</A></P><P>IAG: <A href="https://help.sap.com/docs/SAP_CLOUD_IDENTITY_ACCESS_GOVERNANCE/e12d8683adfa4471ac4edd40809b9038/3b2cc169e51e409483a10c2fcd35b850.html?version=CLOUDFOUNDRY" target="_blank" rel="noopener noreferrer">Integration Scenarios</A></P></TD></TR><TR><TD><P><STRONG>Data Source</STRONG></P></TD><TD><P>SuccessFactors, HR Mini Master, AD (On-Prem/Cloud), third-party DBs</P></TD><TD><P>IAG: Integration Scenarios</P><P>GRC AC: LDAP, HR triggers for position based assignment, HR Triggers from SuccessFactors, ABAP, or custom)</P></TD></TR><TR><TD><P><STRONG>Role Type</STRONG></P></TD><TD><P>Technical Roles, Business Roles</P></TD><TD><P>IAG: Role Design Service</P><P>GRC AC: BRM Module</P></TD></TR><TR><TD><P><STRONG>GRC Integration – Risk Analysis</STRONG></P></TD><TD><P>Risk Analysis/Risk Analysis only</P></TD><TD><P>IAG: Standalone Version</P><P>IAG Bridge with GRC Access Control</P></TD></TR><TR><TD><P><STRONG>Approval Workflows</STRONG></P></TD><TD><P>Maintained Users/ Pending Value Objects</P></TD><TD><P>IAG: SAP Workflow Management Service</P><P>GRC AC: MSMP Workflows (Bridge Scenario)</P></TD></TR><TR><TD><P><STRONG>Entry Owners</STRONG></P></TD><TD><P>Maintained / Not Maintained</P></TD><TD><P>IAG / IAG Bridge: IAS User Groups</P><P>GRC AC: Bridge Scenario (Parameter 1090: No)</P></TD></TR><TR><TD><P><STRONG>Self-Services</STRONG></P></TD><TD><P>Password Self-Service, Role Requests</P></TD><TD><P>GRC AC: Password Self-Service</P></TD></TR><TR><TD><P><STRONG>Attestation (User Access Review)</STRONG></P></TD><TD><P>User Access Review</P></TD><TD><P>IAG: Access Certification</P><P>GRC AC: User Access Review (UAR)</P></TD></TR><TR><TD><P><STRONG>Mass Upload Utility</STRONG></P></TD><TD><P>Upload Users, Roles, Privileges, Mappings via Excel</P></TD><TD><P>IAG: Access Mass Update, Business Role Mass Update</P><P>GRC AC: Excel Uploads (Bridge Scenario)</P></TD></TR><TR><TD><P><STRONG>Custom Notifications</STRONG></P></TD><TD><P>Custom Notification Messages</P></TD><TD><P>GRC AC: Custom Notifications</P></TD></TR><TR><TD><P><STRONG>IDM Reports</STRONG></P></TD><TD><P>Reports from IDM DB</P></TD><TD><P>IAG: Reports</P><P>GRC AC: Reports</P></TD></TR><TR><TD><P><STRONG>Custom Configurations</STRONG></P></TD><TD><P>Custom or Enhanced Functionalities (e.g., HTML5 Forms)</P></TD><TD><P>Handled on a Need Basis</P></TD></TR><TR><TD><P><STRONG>Audit Logs</STRONG></P></TD><TD><P>Activity-Based Logging</P></TD><TD><P>IAG: BTP Audit Log Service</P><P>GRC AC: Audit Logs (Bridge Scenario)</P></TD></TR></TBODY></TABLE><P><SPAN>Discover SAP's approach to identity and access management (IAM) within the framework of the identity lifecycle through the following links-&nbsp;<A href="https://discovery-center.cloud.sap/refArchCatalog/?category=security" target="_blank" rel="noopener nofollow noreferrer">IAM reference architecture</A>&nbsp;and&nbsp;&nbsp;<A href="https://www.sap.com/documents/2018/05/38ce7d25-067d-0010-87a3-c30de2ffd8ff.html" target="_blank" rel="noopener noreferrer">CIO Guide.</A></SPAN></P> 2025-06-03T10:21:50.898000+02:00 https://community.sap.com/t5/human-capital-management-blog-posts-by-members/how-ias-and-ips-help-secure-sap-successfactors/ba-p/14126692 How IAS and IPS Help Secure SAP SuccessFactors 2025-06-13T10:25:23.988000+02:00 Chetannagpal https://community.sap.com/t5/user/viewprofilepage/user-id/383862 <P>Hey SAP Community! If you're like me, you're always trying to make business apps easier and safer to use. Today, I want to chat about two tools that help with that: Identity Authentication Service (IAS) and Identity Provisioning Service (IPS). They’re big players in SAP, especially for managing users in SAP SuccessFactors. But what do they actually do, and why should you care? Let’s break it down!</P><P><STRONG>What is IAS?</STRONG></P><P>Think of IAS like the front door to your apps. It makes sure only the right people get in. IAS helps you by letting users log in once and access everything they need without logging in again (that's called single sign-on or SSO). Plus, you get to pick how users log in, whether it’s with a password, a social media account, or even using two steps for extra security.</P><P><STRONG>Cool Things IAS Can Do:</STRONG></P><UL><LI>Easy Login (SSO): Users love not having to log in over and over on different apps. It's super convenient.</LI><LI>Extra Security: You can require more login checks based on who the user is or where they are logging in from. This keeps your apps safe.</LI><LI>Works with Other Services: Got Microsoft Azure Active Directory? No worries. IAS can talk to these outside services so everything works together smoothly.</LI><LI>Manage Setup with API: Using the tech behind IAS, you spend less time tweaking settings and more time using your apps.</LI></UL><P>IAS is like the guard at the entrance, keeping everything secure without making it complicated.</P><P><STRONG>Getting to Know IPS</STRONG></P><P>Now onto IPS! It’s not just a fancy name. If IAS is the front door, IPS is the key that makes sure everyone has the right access. It makes managing user identities simple across both cloud systems and systems running internally on your company's hardware.</P><P><STRONG>Cool Things IPS Can Do:</STRONG></P><UL><LI>User Management: IPS jumps in after you're set up with IAS to ensure everyone gets the right access on all platforms. Think of it like your personal assistant for user access.</LI><LI>Data Control: You don’t need all data everywhere. With IPS, you can control what goes where and tailor it to your needs.</LI><LI>Transparency and Notifications: IPS keeps you informed with logs and notifications about what's happening with user provisioning. You always know what's going on.</LI></UL><P>&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Chetann_Nagpal_0-1749755393880.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/273786i80A4ADE6784CB505/image-size/medium?v=v2&amp;px=400" role="button" title="Chetann_Nagpal_0-1749755393880.png" alt="Chetann_Nagpal_0-1749755393880.png" /></span></P><P>&nbsp;</P><P>&nbsp;</P><P>IPS works quietly behind the scenes, giving users access smoothly without manual hassle.</P><P><STRONG>Why IAS and IPS Matter</STRONG></P><P>You might be thinking, "Do I really need these services?" Absolutely, yes! SAP wants to make sure identity authentication is simple and pre-configured in their systems. This means less worry about user access.</P><P>IAS can also manage other identity providers, integrating them easily into your workflows. You get strong security and ease in one package.</P><P><STRONG>Setting Up IAS/IPS</STRONG></P><P>Wondering how to set this up? You’re not alone. IAS/IPS comes with many SAP cloud services, but you can also set them up through SAP Business Technology Platform. The best place to start is SAP's Tenant Discovery link to see if you have them ready.</P><P><STRONG>Customizing and Using IAS/IPS</STRONG></P><P>After setup, you can customize login pages, email templates, and usage terms. Check out SAP’s help documents for detailed guides on making the most of IAS/IPS:</P><UL><LI><A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/landing-page" target="_self" rel="noopener noreferrer">Identity Authentication Help Documents</A></LI><LI><A href="https://help.sap.com/docs/identity-provisioning/identity-provisioning/what-is-identity-provisioning" target="_self" rel="noopener noreferrer">Identity Provisioning Help Documents</A></LI></UL><P>&nbsp;</P><P><STRONG>Wrapping Up</STRONG></P><P>So there you have it, a simple look at why IAS and IPS are key for SAP SuccessFactors and other SAP cloud systems. They make life easier for you and your users, ensuring smooth and secure access. I hope this helps you understand these great tools better. Until next time, keep your identities safe and your systems secure!</P> 2025-06-13T10:25:23.988000+02:00 https://community.sap.com/t5/technology-blog-posts-by-sap/identifying-sap-certificates-in-personal-security-environment-a/ba-p/14131296 Identifying SAP Certificates in Personal Security Environment: A Comprehensive Guide 2025-06-18T19:35:52.547000+02:00 mcharrison https://community.sap.com/t5/user/viewprofilepage/user-id/149617 <H1 id="toc-hId-1604075140">Understanding Personal Security Environment (PSE) Fundamentals</H1><P>At its core, a Personal Security Environent (PSE) in SAP is a digital container designed to securely store cryptographic information, primarily digital certificates and their corresponding private keys. Think of it as a digital wallet for your SAP system's security credentials. PSEs are essential for enabling secure communication channels, such as those used in SSL/TLS, SNC (Secure Network Communications), and digital signatures.</P><P>There are several types of PSEs, each serving a specific purpose within the SAP ecosystem:</P><UL><LI>System PSE (SSFS): Often used for internal system-to-system communication and secure storage of sensitive data like database credentials.</LI><LI>Application PSE: Employed by specific SAP applications for their secure communication needs.</LI><LI>Client PSE: Used by SAP clients (e.g., SAP GUI, external applications) to authenticate themselves to SAP servers.</LI></UL><P>PSEs can also exist in different formats, primarily:</P><UL><LI>Legacy format (v2): An older format that might still be found in some older SAP installations.</LI><LI>Current format (v4): The modern and more secure format, offering enhanced cryptographic capabilities.</LI></UL><H1 id="toc-hId-1407561635">The Structure and Components of a PSE</H1><P>To effectively identify certificates within a PSE, it's crucial to understand its internal structure and the components it typically contains:</P><UL><LI>Owner Certificate (with Private Key): This is the primary certificate associated with the PSE, along with its unique private key. This pair is used by the SAP system or application to identify itself and encrypt/decrypt data.</LI><LI>Certificate Chain: A sequence of certificates that links the owner certificate back to a trusted root Certificate Authority (CA). This chain establishes the trustworthiness of the owner certificate.</LI><LI>Trust Anchors (Trusted Certificates): These are certificates of trusted Certificate Authorities (CAs) or self-signed certificates from other systems that the SAP system explicitly trusts. They are used to validate the authenticity of incoming certificates.</LI><LI>Address Book (Optional): In some cases, a PSE might also contain an address book of trusted communication partners.</LI></UL><P>PSE files are typically stored in the file system, often with a .pse extension. Common storage locations include the sec directory under the SAP instance directory (e.g., /usr/sap/&lt;SID&gt;/&lt;Instance&gt;/sec/). For certificates managed within the SAP HANA database, they might reside in database tables such as SYS.CERTIFICATES and SYS.PSE_CERTIFICATES.</P><P>To protect the sensitive private keys and certificates, PSEs employ several protection mechanisms:</P><UL><LI>PIN Protection: A password or PIN is often used to encrypt the private key within the PSE, preventing unauthorized access.</LI><LI>File Permissions: Operating system file permissions are critical to restrict access to the PSE files themselves, ensuring only authorized users or processes can read or modify them.</LI><LI>Database Privileges: For in-database certificates, appropriate database privileges are essential to control who can view, modify, or delete certificate entries.</LI></UL><H1 id="toc-hId-1211048130">Dissecting Certificate Structure for Identification:</H1><P>Before diving into identification methods, let's briefly review the key elements of a digital certificate that aid in its identification:</P><P>Distinguished Name (DN) Components: The DN is a unique identifier for the certificate's subject. Key components include:</P><UL><LI>Common Name (CN): Typically the hostname or application name.</LI><LI>Organization (O): The name of the organization.</LI><LI>Organizational Unit (OU): A specific department or unit within the organization.</LI><LI>Country (C): The two-letter country code.</LI></UL><P>Key Certificate Attributes: Beyond the DN, other attributes provide crucial identification details:</P><UL><LI>Serial Number: A unique identifier assigned by the Certificate Authority.</LI><LI>Validity Period: The start and end dates during which the certificate is considered valid.</LI><LI>Issuer Information: Details about the Certificate Authority that issued the certificate.</LI><LI>Key Usage: Defines the cryptographic purposes for which the public key contained in the certificate can be used (e.g., digital signature, key encipherment).</LI><LI>Signature Algorithm: The algorithm used to sign the certificate.</LI></UL><H1 id="toc-hId-1014534625">Methods for Certificate Identification</H1><P>Identifying certificates in SAP PSEs can be approached through various methods, each with its own strengths and use cases.</P><H2 id="toc-hId-947103839">1. Identification by Location</H2><P>The simplest form of identification is by knowing where PSE files are typically stored. Standard file paths and instance-specific locations are common starting points. For SAP HANA, certificates might also be found within database collections.</P><H2 id="toc-hId-750590334">2. Identification by Attributes</H2><P>Once a certificate is accessed, its attributes can be used for precise identification:</P><UL><LI>Distinguished Name (DN) Matching: Comparing the DN components against expected values.</LI><LI>Serial Number Lookup: Searching for a specific certificate by its unique serial number.</LI><LI>Fingerprint Comparison: Using cryptographic hash functions (e.g., SHA-256) to generate a unique fingerprint of the certificate for comparison.</LI></UL><H2 id="toc-hId-554076829">3. Identification by Purpose</H2><P>Certificates are often used for specific functions, which can also aid in their identification:</P><UL><LI>SSL Server Certificates: Used by SAP servers to secure incoming connections.</LI><LI>SSL Client Certificates: Used by SAP clients to authenticate to servers.</LI><LI>SAML Certificates: Used for Security Assertion Markup Language (SAML) based single sign-on.</LI><LI>Signing Certificates: Used for digital signatures.</LI></UL><H1 id="toc-hId-228480605">Tools for Certificate Identification</H1><P>SAP provides several tools, both command-line and GUI-based, to help with certificate identification and management.</P><H2 id="toc-hId-161049819">Using the sapgenpse Tool</H2><P>sapgenpse is a powerful command-line utility provided by SAP for managing PSEs and certificates. It's particularly useful for scripting and automated tasks.</P><P>Key commands for identification include:</P><UL><LI>sapgenpse get_my_cert -p &lt;PSE_path&gt; -v: Extracts and displays the owner certificate from a specified PSE file.</LI><LI>sapgenpse maintain_pk -p &lt;PSE_path&gt; -l: Lists all certificates contained within a PSE file.</LI><LI>sapgenpse maintain_pk: <SPAN>maintain the server's certificate list within a PSE</SPAN>.</LI></UL><P>The output of these commands provides detailed certificate information, including validity status and trust chain information.</P><H1 id="toc-hId--164546405">Using the STRUST Transaction</H1><P>For those who prefer a graphical interface, the STRUST transaction in SAP GUI is the primary tool for managing PSEs and certificates. It offers a user-friendly way to visualize and interact with certificate data.</P><P>Navigate to STRUST via the transaction code. Here, you can select and manage various PSE types. STRUST provides a visual certificate browser, allowing you to view detailed information about each certificate, including its chain, validity, and key attributes. It also supports import and export functionalities.</P><H1 id="toc-hId-408680173">Python-Based Identification</H1><P>For advanced automation and integration with other systems, Python scripting offers a flexible and powerful approach to certificate identification. Libraries like cryptography or OpenSSL can be used to parse certificate files, while custom scripts can be developed to interact with SAP systems or database views.</P><P>Python-based solutions offer significant automation benefits, including bulk certificate discovery, automated metadata extraction, and proactive expiration monitoring.</P><H1 id="toc-hId-212166668">Best Practices for SAP Certificate Management</H1><P>Effective certificate identification is just one piece of the puzzle. Implementing best practices ensures a secure and manageable SAP certificate landscape.</P><UL><LI>Naming Conventions: Adopt consistent Distinguished Name (DN) formats and use purpose-indicating Common Names (CNs). Include version tracking in comments or metadata.</LI><LI>Organization: Centralize PSE management where possible. Maintain comprehensive documentation of certificate purposes and regularly update your certificate inventory.</LI><LI>Monitoring: Implement automated expiration checks to prevent outages. Regularly validate trust chains and audit certificate usage to detect anomalies.</LI></UL><H1 id="toc-hId-15653163">Common Challenges and Solutions</H1><P>Managing SAP certificates comes with its share of challenges. Here are some common ones and their practical solutions:</P><P><STRONG>Challenge: Identifying certificates across distributed systems.</STRONG></P><UL><LI><STRONG>Solution</STRONG>: Implement a centralized certificate inventory system with location mapping to track all PSEs and certificates across your SAP landscape.</LI></UL><P><STRONG>Challenge: Determining certificate purpose.</STRONG></P><UL><LI><STRONG>Solution</STRONG>: Enforce standardized naming conventions and metadata tagging during certificate creation to clearly indicate their intended use.&nbsp;</LI></UL><P><STRONG>Challenge: Legacy format detection.</STRONG></P><UL><LI><STRONG>Solution</STRONG>: Utilize version-aware tools (like sapgenpse with appropriate flags) and plan for systematic conversion of legacy PSEs to current formats.</LI></UL><P><STRONG>Challenge: PIN-protected PSEs.</STRONG></P><UL><LI><STRONG>Solution</STRONG>: Implement secure PIN management strategies, potentially leveraging secure credential stores or automation tools that can securely provide PINs when needed.</LI></UL><H1 id="toc-hId--180860342">Conclusion</H1><P>Identifying SAP certificates within the Personal Security Environment is a critical aspect of maintaining a secure and reliable SAP landscape. It requires a systematic approach, leveraging a combination of SAP-provided tools like sapgenpse and STRUST, alongside powerful scripting capabilities offered by Python.</P><P>By understanding the fundamentals of PSE, its structure, and the various identification methods, you can gain better control over your SAP security infrastructure. Adhering to best practices in naming, organization, and monitoring, coupled with proactive solutions to common challenges, will significantly enhance your ability to manage certificates effectively and prevent security vulnerabilities or system outages.</P><P>Ultimately, a comprehensive and up-to-date inventory of your SAP certificates forms the foundation for robust security and efficient operations. Embrace these strategies to ensure your SAP systems remain secure and trustworthy.</P> 2025-06-18T19:35:52.547000+02:00 https://community.sap.com/t5/technology-blog-posts-by-members/enhancing-security-in-identity-authentication-service-ias-with-certificate/ba-p/14182289 Enhancing Security in Identity Authentication Service (IAS) with Certificate-Based Authentication 2025-08-17T20:35:45.189000+02:00 sushilgupta857 https://community.sap.com/t5/user/viewprofilepage/user-id/720925 <H1 id="toc-hId-1608722508"><span class="lia-unicode-emoji" title=":locked_with_key:">🔐</span>Enhancing Security in Identity Authentication Service (IAS) with Certificate-Based Authentication</H1><P><span class="lia-unicode-emoji" title=":sparkles:">✨</span><EM>“Moving beyond Client ID &amp; Secret — strengthening IAS with certificate-based authentication for enterprise-grade security.”</EM></P><HR /><H2 id="toc-hId-1541291722">About Me</H2><P>Hare Krishna <span class="lia-unicode-emoji" title=":folded_hands:">🙏</span> I am an <STRONG>SAP BTP Cloud Architect</STRONG>, sharing practical insights, solutions, and real-world experiences from the SAP ecosystem.</P><HR /><H2 id="toc-hId-1344778217"><span class="lia-unicode-emoji" title=":blue_book:">📘</span>Introduction</H2><P>In modern enterprise landscapes, <STRONG>Identity Authentication Service (IAS)</STRONG> plays a key role in securing access to applications and systems. Traditionally, system user authentication in IAS relied on <STRONG>Client ID and Secret</STRONG> (essentially a username and password mechanism). While simple to implement, it comes with inherent risks—<span class="lia-unicode-emoji" title=":key:">🔑</span> password leakage and <span class="lia-unicode-emoji" title=":file_cabinet:">🗄</span>️ storage vulnerabilities.</P><P>To address these challenges, IAS provides the option to use <STRONG>certificate-based authentication</STRONG>, offering a stronger and more secure alternative.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="IAS_Authentication_Comparison.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/301717iF1B2C62C9E40AC51/image-size/medium?v=v2&amp;px=400" role="button" title="IAS_Authentication_Comparison.png" alt="IAS_Authentication_Comparison.png" /></span></P><P>&nbsp;</P><P>&nbsp;</P><P>&nbsp;</P><P>&nbsp;</P><P>&nbsp;</P><P>&nbsp;</P><H2 id="toc-hId-1148264712"><span class="lia-unicode-emoji" title=":warning:">⚠️</span>Limitations of Client ID &amp; Secret Authentication</H2><P>Although widely used, Client ID and Secret authentication has drawbacks:</P><UL><LI><P><span class="lia-unicode-emoji" title=":key:">🔑</span><STRONG>Password-like storage</STRONG>: Secrets need to be securely stored, often in encrypted vaults.</P></LI><LI><P><span class="lia-unicode-emoji" title=":police_car_light:">🚨</span><STRONG>Leakage risk</STRONG>: Exposure in logs, code repositories, or integrations can compromise the system.</P></LI></UL><HR /><H2 id="toc-hId-951751207"><span class="lia-unicode-emoji" title=":shield:">🛡</span>️ Why Certificate-Based Authentication?</H2><P>Certificate-based authentication strengthens IAS security by replacing secrets with a <STRONG>cryptographic key pair</STRONG>.</P><UL><LI><P><span class="lia-unicode-emoji" title=":locked:">🔒</span><STRONG>Stronger Security</STRONG>: Asymmetric encryption makes brute-force attacks impractical.</P></LI><LI><P><span class="lia-unicode-emoji" title=":old_key:">🗝</span>️ <STRONG>No password dependency</STRONG>: Eliminates risks tied to weak or reused passwords.</P></LI><LI><P><span class="lia-unicode-emoji" title=":stop_sign:">🛑</span><STRONG>Leakage-resistant</STRONG>: Public certificate exposure is harmless without the private key.</P></LI></UL><HR /><H2 id="toc-hId-755237702"><span class="lia-unicode-emoji" title=":gear:">⚙️</span>How It Works in IAS</H2><OL><LI><P><span class="lia-unicode-emoji" title=":bust_in_silhouette:">👤</span><STRONG>System User Creation</STRONG>: Generate a certificate instead of a Client ID and Secret.</P></LI><LI><P><span class="lia-unicode-emoji" title=":key:">🔑</span><STRONG>Public-Private Key Pair</STRONG>:</P><UL><LI><P>The public certificate is uploaded to IAS.</P></LI><LI><P>The private key remains with the consuming application.</P></LI></UL></LI><LI><P><span class="lia-unicode-emoji" title=":magnifying_glass_tilted_left:">🔍</span><STRONG>Authentication</STRONG>: IAS validates the presented certificate.</P></LI><LI><P><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span><STRONG>Access Granted</STRONG>: Secure communication is established.</P></LI></OL><HR /><H2 id="toc-hId-558724197"><span class="lia-unicode-emoji" title=":link:">🔗</span>Real-World Use Cases for Certificate-Based Authentication</H2><P>So when should you consider using <STRONG>certificate-based authentication</STRONG> in IAS?</P><P>This approach is particularly beneficial when:</P><UL><LI><P><span class="lia-unicode-emoji" title=":globe_with_meridians:">🌐</span>You need to establish <STRONG>API-based connectivity</STRONG> with IAS from <STRONG>external tools or applications</STRONG>.</P></LI><LI><P><span class="lia-unicode-emoji" title=":wrench:">🔧</span>A <STRONG>system user</STRONG> is required for integrations, automations, or monitoring purposes.</P></LI><LI><P><span class="lia-unicode-emoji" title=":shield:">🛡</span>️ You want to secure machine-to-machine (M2M) communication <STRONG>more efficiently than with Client ID &amp; Secret</STRONG>.</P></LI></UL><P>In such scenarios, certificates ensure <STRONG>stronger trust</STRONG> and <STRONG>reduce credential management risks</STRONG>, making them ideal for enterprise-grade integrations.</P><HR /><H2 id="toc-hId-362210692"><span class="lia-unicode-emoji" title=":framed_picture:">🖼</span>️ Real-Life Example: Configuring Certificate-Based Authentication in IAS</H2><H3 id="toc-hId-294779906"><span class="lia-unicode-emoji" title=":open_file_folder:">📂</span>Understanding Certificate Formats Before You Begin</H3><P>Before we jump into the actual configuration, it’s important to understand the different certificate file formats you may encounter during the process. This helps avoid confusion when handling files like .p12, .crt, and .pem.</P><P><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span><STRONG>Key Differences at a Glance</STRONG></P><DIV class=""><DIV class="">Format Contains Private Key? Contains Cert(s)? Encoding Typical Use <TABLE><TBODY><TR><TD><STRONG>.crt</STRONG></TD><TD><span class="lia-unicode-emoji" title=":cross_mark:">❌</span>No</TD><TD><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span>Yes</TD><TD>Base64 (PEM) or Binary (DER)</TD><TD>Server certificate file</TD></TR><TR><TD><STRONG>.pem</STRONG></TD><TD><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span>Optional</TD><TD><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span>Yes</TD><TD>Base64 (PEM)</TD><TD>Flexible container for certs/keys</TD></TR><TR><TD><STRONG>.p12 / .pfx</STRONG></TD><TD><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span>Yes</TD><TD><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span>Yes (can include full chain)</TD><TD>Binary (PKCS#12)</TD><TD>Import/export in apps, keystores</TD></TR></TBODY></TABLE></DIV></DIV><P><span class="lia-unicode-emoji" title=":key:">🔑</span><STRONG>Practical Flow in IAS Scenario</STRONG></P><UL><LI><P>You <STRONG>generate a .p12 (PKCS#12)</STRONG> file → this includes both your private key and certificate chain.</P></LI><LI><P>From this .p12, you typically <STRONG>extract</STRONG>:</P><UL><LI><P><STRONG>Private Key</STRONG> → required for secure client authentication.</P></LI><LI><P><STRONG>Full Certificate Chain (.crt/.pem)</STRONG> → ensures trust and proper verification.</P></LI></UL></LI></UL><P><span class="lia-unicode-emoji" title=":backhand_index_pointing_right:">👉</span>By understanding this, you’ll know <STRONG>what each file is for</STRONG> and why it’s being used in SAP IAS certificate-based authentication.</P><H3 id="toc-hId-98266401">Step by Step instructions to perform the activity</H3><P>Generate .p12 → extract private key (.pem) → extract full certificate chain (.crt/.pem) → upload public cert/chain to IAS (system user) → store private key securely in your app → enable client-certificate auth → test the API connectivity.</P><P>Login to IAS, Click on Administrators and create System User with required privileges</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-17 at 11.24.05 PM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/301771i4548893C636C364A/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-17 at 11.24.05 PM.png" alt="Screenshot 2025-08-17 at 11.24.05 PM.png" /></span></P><P>Click on Certificate</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-17 at 11.24.28 PM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/301769iBE58DC971F353CC2/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-17 at 11.24.28 PM.png" alt="Screenshot 2025-08-17 at 11.24.28 PM.png" /></span></P><P>Provide CN name and password for certificate and click on generate - it will create a .p12 file</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-17 at 11.24.55 PM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/301770iF11805615CDBB18A/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-17 at 11.24.55 PM.png" alt="Screenshot 2025-08-17 at 11.24.55 PM.png" /></span></P><P>Save it.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-17 at 11.25.30 PM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/301772i92D0D1701659A6AA/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-17 at 11.25.30 PM.png" alt="Screenshot 2025-08-17 at 11.25.30 PM.png" /></span></P><P>Open Terminal and enter command (here API_Cert.p12 is the certificate name downloaded from IAS). Post this enter the required fields like passphrase etc.</P><pre class="lia-code-sample language-abap"><code>openssl pkcs12 -in API_Cert.p12 -info</code></pre><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-17 at 11.27.29 PM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/301773i855A12773139C4B9/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-17 at 11.27.29 PM.png" alt="Screenshot 2025-08-17 at 11.27.29 PM.png" /></span></P><P>It will have private key and Full chain certificate, Copy the Private key in a text file and save it as .pem file</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-17 at 11.28.56 PM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/301775iB4D680C27868C694/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-17 at 11.28.56 PM.png" alt="Screenshot 2025-08-17 at 11.28.56 PM.png" /></span></P><P>similarly copy the full chain certificate in a text file and save it as .pem</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-17 at 11.30.23 PM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/301776i7A0F2A5650E2602D/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-17 at 11.30.23 PM.png" alt="Screenshot 2025-08-17 at 11.30.23 PM.png" /></span></P><P>Upload the full chain certificate in IAS and save it.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-17 at 11.30.56 PM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/301774i0564CD35AEDBC838/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-17 at 11.30.56 PM.png" alt="Screenshot 2025-08-17 at 11.30.56 PM.png" /></span></P><P>Certificate is successfully uploaded in IAS</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-17 at 11.32.03 PM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/301777iA941B1F87C0ECBF6/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-17 at 11.32.03 PM.png" alt="Screenshot 2025-08-17 at 11.32.03 PM.png" /></span></P><P>Let's test it using POSTMAN. Open Postman and go to settings -&gt; Add certificate -&gt; upload the certificate as shown below and provide URL of IAS and password</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-17 at 11.32.48 PM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/301778iE5C7F991B884D66F/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-17 at 11.32.48 PM.png" alt="Screenshot 2025-08-17 at 11.32.48 PM.png" /></span></P><P>Perform a get operation to check if connectivity is working fine. You should receive 200 success message like shown below</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-17 at 11.33.31 PM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/301779i36D8E1E0C4F0D178/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-17 at 11.33.31 PM.png" alt="Screenshot 2025-08-17 at 11.33.31 PM.png" /></span></P><HR /><H2 id="toc-hId-119924534"><span class="lia-unicode-emoji" title=":memo:">📝</span>Best Practices for Certificate-Based Authentication in IAS</H2><UL><LI><P><span class="lia-unicode-emoji" title=":tear_off_calendar:">📆</span><STRONG>Track certificate validity</STRONG>: Default validity is 1 year — plan renewals in advance.</P></LI><LI><P><span class="lia-unicode-emoji" title=":file_cabinet:">🗄</span>️ <STRONG>Secure private keys</STRONG>: Store them in HSMs or trusted key vaults.</P></LI><LI><P><span class="lia-unicode-emoji" title=":counterclockwise_arrows_button:">🔄</span><STRONG>Automate renewal</STRONG>: Prevent downtime due to expired certificates.</P></LI><LI><P><span class="lia-unicode-emoji" title=":bar_chart:">📊</span><STRONG>Monitor usage</STRONG>: Continuously audit authentication logs in IAS.</P></LI></UL><HR /><H2 id="toc-hId--76588971"><span class="lia-unicode-emoji" title=":direct_hit:">🎯</span>Conclusion</H2><P>Switching from Client ID &amp; Secret to <STRONG>certificate-based authentication</STRONG> in IAS is a <STRONG>major security enhancement</STRONG>. It reduces password-related risks, strengthens trust between systems, and ensures compliance.</P><P>By adopting certificates, enterprises can align IAS with <STRONG>modern security standards</STRONG>, making their environment more secure, resilient, and future-ready <span class="lia-unicode-emoji" title=":rocket:">🚀</span>.</P> 2025-08-17T20:35:45.189000+02:00 https://community.sap.com/t5/technology-blog-posts-by-members/evolving-security-in-sap-btp-goodbye-apiaccess-plan-hello-btp-cli/ba-p/14182956 🔒 Evolving Security in SAP BTP – Goodbye APIAccess Plan, Hello BTP CLI 2025-08-18T22:10:52.716000+02:00 sushilgupta857 https://community.sap.com/t5/user/viewprofilepage/user-id/720925 <H1 id="toc-hId-1608729139"><span class="lia-unicode-emoji" title=":locked_with_key:">🔐</span>SAP BTP Security Shift: From APIAccess Plan to BTP CLI Credentials</H1><H2 id="toc-hId-1541298353">🙋‍ About Me</H2><P>Hare Krishna <span class="lia-unicode-emoji" title=":folded_hands:">🙏</span> I am an SAP BTP Cloud Architect sharing practical insights, solutions, and real-world experiences from the SAP ecosystem.</P><HR /><H2 id="toc-hId-1344784848"><span class="lia-unicode-emoji" title=":glowing_star:">🌟</span>Introduction</H2><P>SAP is continuously evolving its security and authorization capabilities on the Business Technology Platform (BTP). One major shift is the move away from the <STRONG>APIAccess plan for Authorization and Trust Management Service</STRONG> towards <STRONG>BTP CLI Security API Credentials</STRONG>.</P><P>This transition brings more centralized control, enhanced governance, and future-ready security management.</P><HR /><H2 id="toc-hId-1148271343"><span class="lia-unicode-emoji" title=":question_mark:">❓</span>Why the Shift?</H2><UL><LI><P>The <STRONG>APIAccess plan</STRONG> was primarily used for developers to generate OAuth credentials via the cockpit.</P></LI><LI><P>SAP has marked it <STRONG>obsolete</STRONG>, pushing customers to adopt the more powerful <STRONG>BTP CLI Security API credential management</STRONG>.</P></LI><LI><P>This aligns with SAP’s strategy of delivering <STRONG>CLI-first, automation-ready</STRONG> tooling.</P></LI></UL><HR /><H2 id="toc-hId-951757838"><span class="lia-unicode-emoji" title=":light_bulb:">💡</span>Benefits of Using BTP CLI</H2><P><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span>Centralized credential management at the subaccount level<BR /><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span>Fine-grained, role-based access (requires <STRONG>Security Administrator role</STRONG>)<BR /><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span>Automation-friendly (ideal for CI/CD pipelines)<BR /><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span>Better lifecycle management (create, rotate, revoke credentials via CLI)<BR /><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span>Future-proof – new features/enhancements will come only in BTP CLI</P><HR /><H2 id="toc-hId-755244333"><span class="lia-unicode-emoji" title=":balance_scale:">⚖️</span>Key Differences: APIAccess vs BTP CLI Security API Credentials</H2><DIV class=""><DIV class="">Aspect&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;APIAccess Plan&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; BTP CLI Security API Credentials <TABLE><TBODY><TR><TD><STRONG>Scope</STRONG></TD><TD>Bound to a specific service instance</TD><TD>Managed at subaccount level</TD></TR><TR><TD><STRONG>Access Role</STRONG></TD><TD>Typically developer role (CF)</TD><TD>Requires <STRONG>Security Administrator</STRONG> role</TD></TR><TR><TD><STRONG>Management</STRONG></TD><TD>Created via cockpit UI</TD><TD>Managed via <STRONG>BTP CLI commands</STRONG></TD></TR><TR><TD><STRONG>Automation</STRONG></TD><TD>Limited</TD><TD>Fully automation-ready (CI/CD, scripts)</TD></TR><TR><TD><STRONG>Future Support</STRONG></TD><TD>Deprecated / Obsolete</TD><TD>Actively supported &amp; enhanced</TD></TR><TR><TD><STRONG>Governance</STRONG></TD><TD>Minimal</TD><TD>Strong audit &amp; lifecycle management</TD></TR></TBODY></TABLE></DIV></DIV><HR /><H2 id="toc-hId-558730828"><span class="lia-unicode-emoji" title=":hammer_and_wrench:">🛠</span>Steps to Manage Security API Credentials via BTP CLI</H2><H3 id="toc-hId-491300042"><span class="lia-unicode-emoji" title=":keycap_1:">1️⃣</span>Login to BTP CLI</H3><pre class="lia-code-sample language-abap"><code>btp login --url https://cpcli.cf.eu10.hana.ondemand.com --subdomain &lt;your-subdomain&gt;</code></pre><H3 id="toc-hId-294786537"><span class="lia-unicode-emoji" title=":keycap_2:">2️⃣</span>Create Security API Credential</H3><pre class="lia-code-sample language-abap"><code>btp create security/api-credential --subaccount &lt;subaccount-guid&gt; --name &lt;credential-name&gt;</code></pre><H3 id="toc-hId-98273032"><span class="lia-unicode-emoji" title=":keycap_3:">3️⃣</span>List Security API Credentials</H3><pre class="lia-code-sample language-abap"><code>btp list security/api-credential --subaccount &lt;subaccount-guid&gt;</code></pre><H3 id="toc-hId--173471842"><span class="lia-unicode-emoji" title=":keycap_4:">4️⃣</span>Get Details of a Credential</H3><pre class="lia-code-sample language-abap"><code>btp get security/api-credential --subaccount &lt;subaccount-guid&gt; --name &lt;credential-name&gt;</code></pre><H3 id="toc-hId--369985347"><span class="lia-unicode-emoji" title=":keycap_5:">5️⃣</span>Delete Security API Credential</H3><pre class="lia-code-sample language-abap"><code>btp delete security/api-credential --subaccount &lt;subaccount-guid&gt; --name &lt;credential-name&gt;</code></pre><HR /><H2 id="toc-hId--273095845"><span class="lia-unicode-emoji" title=":camera_with_flash:">📸</span>Real-Life Example (POC)</H2><P>Login to BTP CLI</P><pre class="lia-code-sample language-abap"><code>btp login --sso</code></pre><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-19 at 12.56.09 AM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/302078iB9AB4BDD794E2F9A/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-19 at 12.56.09 AM.png" alt="Screenshot 2025-08-19 at 12.56.09 AM.png" /></span></P><P>It will open browser to enter userid and password. Once authenticated successfully in browser user will be logged in the BTPCLI</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-19 at 12.56.54 AM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/302079i8EAD377073C13072/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-19 at 12.56.54 AM.png" alt="Screenshot 2025-08-19 at 12.56.54 AM.png" /></span></P><P>User should have security admin privileges to perform this task using BTPCLI as highlighted below:</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-19 at 12.57.11 AM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/302080i0C73C9ED4F0CAE39/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-19 at 12.57.11 AM.png" alt="Screenshot 2025-08-19 at 12.57.11 AM.png" /></span></P><P>Command to create BTP Security api credentials</P><pre class="lia-code-sample language-abap"><code>btp create security/api-credential --name APIConnectivitySecurityCred</code></pre><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-19 at 1.18.25 AM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/302081iA779AC2F2A62D9C5/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-19 at 1.18.25 AM.png" alt="Screenshot 2025-08-19 at 1.18.25 AM.png" /></span></P><P>Command to list the security api credentials</P><pre class="lia-code-sample language-abap"><code>btp list security/api-credential</code></pre><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-19 at 1.19.46 AM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/302082i13728050DE9097B0/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-19 at 1.19.46 AM.png" alt="Screenshot 2025-08-19 at 1.19.46 AM.png" /></span></P><P>Command to get the security api credentials:</P><pre class="lia-code-sample language-abap"><code> btp get security/api-credential APIConnectivitySecurityCred </code></pre><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-19 at 1.22.26 AM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/302083iE376E9D469BFA8AF/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-19 at 1.22.26 AM.png" alt="Screenshot 2025-08-19 at 1.22.26 AM.png" /></span></P><P>Command to delete the security api credentials:</P><pre class="lia-code-sample language-abap"><code>btp delete security/api-credential APIConnectivitySecurityCred</code></pre><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-19 at 1.22.44 AM.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/302084i484C8926240A2268/image-size/large?v=v2&amp;px=999" role="button" title="Screenshot 2025-08-19 at 1.22.44 AM.png" alt="Screenshot 2025-08-19 at 1.22.44 AM.png" /></span></P><HR /><H2 id="toc-hId--469609350"><span class="lia-unicode-emoji" title=":counterclockwise_arrows_button:">🔄</span>Migration Guidance: Moving from APIAccess Plan to BTP CLI Security API Credentials</H2><P><span class="lia-unicode-emoji" title=":backhand_index_pointing_right:">👉</span><STRONG>Why migrate?</STRONG></P><UL><LI><P><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span>APIAccess plan is deprecated/obsolete.</P></LI><LI><P><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span>BTP CLI provides a centralized, secure, and role-based way to manage credentials.</P></LI><LI><P><span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span>Future enhancements will be delivered only for the BTP CLI approach.</P></LI></UL><P><span class="lia-unicode-emoji" title=":backhand_index_pointing_right:">👉</span><STRONG>Suggested migration approach:</STRONG></P><OL><LI><P>Identify all applications, integrations, or scripts currently using credentials generated via APIAccess plan.</P></LI><LI><P>Recreate credentials using BTP CLI with the required <STRONG>Security Administrator role</STRONG> at the subaccount level.</P></LI><LI><P>Update configurations (destination services, API clients, pipelines, etc.) to consume the new credentials.</P></LI><LI><P>Decommission old credentials to avoid accidental usage.</P></LI></OL><P><span class="lia-unicode-emoji" title=":pushpin:">📌</span><STRONG>Tip:</STRONG> Run this migration in a <STRONG>test subaccount</STRONG> first to validate all dependencies before rolling out in production.</P><HR /><H2 id="toc-hId--666122855">🙋‍<span class="lia-unicode-emoji" title=":male_sign:">♂️</span> FAQs</H2><P><STRONG>Q1: Do I still need the Space Developer role for managing credentials?</STRONG><BR /><span class="lia-unicode-emoji" title=":backhand_index_pointing_right:">👉</span>No. Managing Security API Credentials requires the <STRONG>Security Administrator role at subaccount level</STRONG>, not CF space roles.</P><P><STRONG>Q2: What happens if I continue using APIAccess plan?</STRONG><BR /><span class="lia-unicode-emoji" title=":backhand_index_pointing_right:">👉</span>APIAccess is <STRONG>obsolete</STRONG>. Existing instances may continue temporarily, but no future support or enhancements will be provided.</P><P><STRONG>Q3: Can I automate credential rotation with BTP CLI?</STRONG><BR /><span class="lia-unicode-emoji" title=":backhand_index_pointing_right:">👉</span>Yes <span class="lia-unicode-emoji" title=":white_heavy_check_mark:">✅</span>. You can script credential creation/deletion via BTP CLI and integrate into CI/CD pipelines for automated rotations.</P><HR /><H2 id="toc-hId--862636360"><span class="lia-unicode-emoji" title=":books:">📚</span>References</H2><UL><LI><P><A class="" href="https://help.sap.com/whats-new/cf0cb2cb149647329b5d02aa96303f56?Component=Authorization+and+Trust+Management+Service&amp;Valid_as_Of=2024-05-15:2024-05-17&amp;locale=en-US" target="_new" rel="noopener noreferrer">SAP Help: What’s New – Authorization and Trust Management Service</A></P></LI><LI><P><A class="" href="https://help.sap.com/docs/btp/sap-business-technology-platform/managing-api-credentials-for-calling-rest-apis-of-sap-authorization-and-trust-management-service?locale=en-US" target="_new" rel="noopener noreferrer">SAP Help: Managing API Credentials for Authorization and Trust Management Service</A></P></LI></UL> 2025-08-18T22:10:52.716000+02:00 https://community.sap.com/t5/crm-and-cx-blog-posts-by-sap/introducing-scim-api-for-sap-sales-amp-service-cloud-v2-seamless-user-sync/ba-p/14200658 🚀 Introducing SCIM API for SAP Sales & Service Cloud v2: Seamless User Sync between Source & Target 2025-08-30T10:53:18.129000+02:00 Yogananda https://community.sap.com/t5/user/viewprofilepage/user-id/75 <P>&nbsp;</P><TABLE border="1" width="100%"><TBODY><TR><TD width="100%"><FONT color="#FF0000">Note</FONT> :&nbsp;<STRONG>Please note that the SCIM feature is in General Availability.</STRONG><SPAN>&nbsp;<BR /><A href="https://api.sap.com/package/SAPSalesServiceCloudV2/rest" target="_blank" rel="noopener noreferrer">https://api.sap.com/package/SAPSalesServiceCloudV2/rest</A>&nbsp;<BR /><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-09-29_10-46-03.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/321042iDC4C2E49F38904F1/image-size/large?v=v2&amp;px=999" role="button" title="2025-09-29_10-46-03.png" alt="2025-09-29_10-46-03.png" /></span><BR /></SPAN></TD></TR></TBODY></TABLE><P><STRONG>SAP Sales &amp; Service Cloud v2</STRONG> now supports&nbsp;SCIM (System for Cross-domain Identity Management)&nbsp;APIs, enabling seamless and secure user provisioning from&nbsp;<STRONG>SAP Identity Authentication Service (IAS)</STRONG>&nbsp;or&nbsp;<FONT color="#0000FF">Customer Identity Directory</FONT>&nbsp;via&nbsp;<STRONG>SAP Identity Provisioning Service (IPS).</STRONG></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Yogananda_0-1756638756679.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/307008iFC5ACCB41E22419F/image-size/large?v=v2&amp;px=999" role="button" title="Yogananda_0-1756638756679.png" alt="Yogananda_0-1756638756679.png" /></span></P><P><STRONG>This integration simplifies identity lifecycle management, ensures compliance, and eliminates manual user creation in the target system (SAP Sales &amp; Service Cloud v2).</STRONG></P><BLOCKQUOTE><P><FONT color="#993366">SCIM API in SAP Sales &amp; Service Cloud v2 is available&nbsp; by default.</FONT></P></BLOCKQUOTE><H2 id="toc-hId-1758990378"><FONT color="#0000FF"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image_2025-07-21_105541907.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/306875i3AFF9A45D26B58A2/image-size/large?v=v2&amp;px=999" role="button" title="image_2025-07-21_105541907.png" alt="image_2025-07-21_105541907.png" /></span></FONT></H2><H2 id="toc-hId-1562476873"><FONT color="#0000FF">SSC v2 SCIM API (Official API Documentation)</FONT></H2><pre class="lia-code-sample language-json"><code>### Tenant Details but you need to pass the tenant id in the URL GET {{SSCv2url}}/scim/v2/Users Content-Type: application/scim+json Authorization: Bearer {{accessToken}} PUT {{SSCv2url}}/scim/v2/Users/&lt;id&gt; Content-Type: application/scim+json Authorization: Bearer {{accessToken}} &lt;payload of the user&gt; PATCH {{SSCv2url}}/scim/v2/Users/&lt;id&gt; Content-Type: application/scim+json Authorization: Bearer {{accessToken}} &lt;payload of the user&gt;</code></pre><H2 id="toc-hId-1365963368"><span class="lia-unicode-emoji" title=":prohibited:">🚫</span><FONT color="#FF0000">Important Notes to keep in mind before enabling: </FONT></H2><H2 id="toc-hId-1169449863"><FONT color="#FF0000">No Manual User Creation Allowed</FONT></H2><P><FONT color="#000000">This ensures that all user data is centrally managed and synchronized, maintaining consistency and reducing the risk of identity mismatches or unauthorized access.</FONT></P><P>Once SCIM-based provisioning is enabled in SAP Sales &amp; Service Cloud V2:</P><BLOCKQUOTE><P><FONT color="#993366">Manual user creation in SAP Sales &amp; Service Cloud v2 is disabled.</FONT></P></BLOCKQUOTE><P><SPAN>When using IPS (SCIM 2.0 based API), only users of type Employee are provisioned. This version introduces an enhanced SCIM API that no longer requires SAP Cloud Integration. It supports patch operations and provisioning of application-specific groups(Business Roles). In addition to pagination using&nbsp;</SPAN>startIndex<SPAN>&nbsp;and&nbsp;</SPAN>count<SPAN>, cursor-based pagination is also supported.</SPAN></P><H2 id="toc-hId-972936358">Why SCIM API Matters</H2><P>SCIM is an open standard designed to automate the exchange of user identity information between identity providers and service providers. With SCIM support in SAP Sales &amp; Service Cloud v2, organizations can:</P><UL><LI>Automatically provision and de-provision users</LI><LI>Sync user attributes and roles</LI><LI>Ensure consistent identity governance</LI><LI>Reduce administrative overhead</LI></UL><H2 id="toc-hId-776422853">Benefits of SCIM Integration</H2><UL><LI>Automated User Lifecycle Management</LI><LI>Improved Security &amp; Compliance</LI><LI>Centralized Identity Governance</LI><LI>Reduced Manual Effort</LI><LI>Scalable for Large Enterprises</LI></UL><H2 id="toc-hId-579909348">Integration Flow:&nbsp; SAP IAS or Microsoft Active Directory to SAP Sales &amp; Service Cloud v2</H2><P>Below is the flow diagram illustrating how users are synced from&nbsp;<STRONG>Microsoft Active Directory or/both SAP Identity Authentication IAS</STRONG> to&nbsp;SAP Sales &amp; Service Cloud v2&nbsp;using&nbsp;IAS&nbsp;and&nbsp;IPS:<span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Yogananda_0-1756542686365.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/306873iCA6B0F59ECB2F27D/image-size/large/is-moderation-mode/true?v=v2&amp;px=999" role="button" title="Yogananda_0-1756542686365.png" alt="Yogananda_0-1756542686365.png" /></span></P><H3 id="toc-hId-512478562">Flow Breakdown:</H3><OL><LI>Microsoft Active Directory (AD): Acts as the source of truth for user identities.</LI><LI>SAP Identity Authentication Service (IAS): Connects to AD via LDAP or Azure AD and serves as the identity provider.</LI><LI>SAP Identity Provisioning Service (IPS): Pulls user data from IAS and pushes it to SAP Sales &amp; Service Cloud v2 using SCIM APIs.</LI><LI>SAP Sales &amp; Service Cloud v2: Receives user data via SCIM and provisions users automatically.</LI></OL><H2 id="toc-hId-186882338"><FONT color="#3366FF"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-09-03_20-07-51.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/308759i2A5759B11D276141/image-size/large?v=v2&amp;px=999" role="button" title="2025-09-03_20-07-51.png" alt="2025-09-03_20-07-51.png" /></span></FONT></H2><H2 id="toc-hId--9631167"><FONT color="#3366FF">Identity Provisioning (IPS) Documentation - Target System&nbsp;</FONT></H2><P><A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/target-sap-sales-cloud-and-sap-service-cloud" target="_blank" rel="noopener noreferrer">https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/target-sap-sales-cloud-and-sap-service-cloud</A>&nbsp;</P><H2 id="toc-hId-141109685">Final Thoughts</H2><P>The introduction of SCIM API support in SAP Sales &amp; Service Cloud v2 marks a significant step toward modern identity management. By leveraging IAS and IPS, organizations can streamline user provisioning, enhance security, and ensure a consistent user experience across systems.</P><P>&nbsp;</P> 2025-08-30T10:53:18.129000+02:00 https://community.sap.com/t5/technology-blog-posts-by-members/create-and-assign-authorization-policies-in-ias/ba-p/14218457 CREATE AND ASSIGN AUTHORIZATION POLICIES IN IAS 2025-09-17T12:37:51.141000+02:00 ajitchirania88 https://community.sap.com/t5/user/viewprofilepage/user-id/11152 <H3 id="toc-hId-1889233023">Introduction</H3><P>SAP Identity Authentication Services (IAS) provides secure access management for SAP cloud applications. One of the core features in IAS is <STRONG>Authorization Policies</STRONG>, which allow administrators to control access to applications and resources based on defined rules.</P><P>In this blog, we’ll go through the steps to <STRONG>create</STRONG> and <STRONG>assign</STRONG> authorization policies in IAS, ensuring only the right users have the right level of access.</P><HR /><H3 id="toc-hId-1692719518">Why Authorization Policies Matter</H3><UL><LI><P>Control user access based on attributes like group, role, or user ID</P></LI><LI><P>Enforce compliance and security requirements</P></LI><LI><P>Provide flexibility for hybrid or multi-application scenarios</P></LI><LI><P>Simplify administration by centralizing access control in IAS</P></LI></UL><P>Please follow the step by step process to create authorization policies in IAS :</P><P><STRONG>HOW THE IAS SUPER ADMIN CAN CREATE AND ASSIGN AUTHORIZATION POLICIES IN IAS </STRONG></P><OL><LI><STRONG>CREATION OF AUTHORIZATION POLICIES</STRONG></LI></OL><P><SPAN>This document tells you how you can assign the authorization policies or give admin access to Granular level to HR managing their own HR Organization and division. This will help to give granular access to HR admin in IAS by creating the authorization policies in IAS so that they can see only the employees belonging to their organization unit and reset the password for them. </SPAN></P><P><SPAN>We are creating the custom Policies for customers as we have different divisions and organization, and we would like to give access to the HR managers to their respective divisions accordingly.</SPAN></P><P><SPAN>The screen shots below are for your reference from the test system, and you can use the same step for production as well. </SPAN></P><P><SPAN>Prerequisite: You have SUPER ADMIN access to IAS tenants in which you are going to create the authorization policy. </SPAN></P><P><SPAN>IAS Tenants: </SPAN></P><P><SPAN>For Test: <A href="https://XXXXXXX.accounts.ondemand.com/admin/" target="_blank" rel="noopener nofollow noreferrer">https://XXXXXXX.accounts.ondemand.com/admin/</A></SPAN></P><OL><LI><SPAN>Login to the test IAS System:</SPAN></LI></OL><P><SPAN>Give the URL <A href="https://XXXXXXX.accounts.ondemand.com/admin/" target="_blank" rel="noopener nofollow noreferrer">https://XXXXXXX.accounts.ondemand.com/admin/</A> in the browser and the below&nbsp;&nbsp; window will open. </SPAN></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_0-1758011179856.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315030i305B53BA54349583/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_0-1758011179856.png" alt="ajitchirania88_0-1758011179856.png" /></span></P><OL><LI><SPAN>Give your Email or Username and password to login to IAS an ADMIN and click on continue. </SPAN></LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_1-1758011179858.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315031i7EC62659F9DA5971/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_1-1758011179858.png" alt="ajitchirania88_1-1758011179858.png" /></span></P><OL><LI><SPAN>You will see the login screen of IAS as shown below:</SPAN></LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_2-1758011179860.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315028iF252F00186EF08C9/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_2-1758011179860.png" alt="ajitchirania88_2-1758011179860.png" /></span><SPAN>&nbsp;</SPAN></P><OL><LI><SPAN>Not go to the “Application Resources” and click on the tenant settings :</SPAN></LI></OL><P><SPAN>Here , you can go the policy-based authorization and enabled the option in the right context window.</SPAN></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_3-1758011179864.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315033iC51E25FECA31FF2A/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_3-1758011179864.png" alt="ajitchirania88_3-1758011179864.png" /></span></P><OL><LI><SPAN>Now go to the “Application Resources” section and click on the SuccessFactors application.</SPAN>&nbsp;&nbsp;</LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_4-1758011179866.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315032i7552290344C60A5C/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_4-1758011179866.png" alt="ajitchirania88_4-1758011179866.png" /></span></P><OL><LI><SPAN>Click on the applications and it will show you the screen below.&nbsp;&nbsp;&nbsp;&nbsp;</SPAN><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_5-1758011179872.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315034iB6D080D72B78B358/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_5-1758011179872.png" alt="ajitchirania88_5-1758011179872.png" /></span></LI><LI><SPAN>Go the Administration console as shown below under the System Application. You can see below highlighted one:</SPAN></LI></OL><P><SPAN>&nbsp;</SPAN><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_6-1758011179875.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315035iA3F09EBA277CBEBC/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_6-1758011179875.png" alt="ajitchirania88_6-1758011179875.png" /></span></P><OL><LI><SPAN>Now you can see to the right-side pane of the screen with Authorization policies.&nbsp; Click on that and you will see the screen below. </SPAN></LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_7-1758011179879.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315036i11DDEF71964438FD/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_7-1758011179879.png" alt="ajitchirania88_7-1758011179879.png" /></span></P><OL><LI><SPAN>Click on the create button and give a name for which you want to create a new policy. It will ask for the Policy name and the Base Policies. We have given a name as IMAS_AUT_USER as an example to show and giving access to Read the users and update the users’ details in IAS (Identity Authentication services).</SPAN></LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_8-1758011179884.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315037i38FBB6C6437C09F6/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_8-1758011179884.png" alt="ajitchirania88_8-1758011179884.png" /></span></P><OL><LI><SPAN>Now click on the create button and it will take you to the screen below:</SPAN></LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_10-1758011179889.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315039i1A769A340E3EA9AD/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_10-1758011179889.png" alt="ajitchirania88_10-1758011179889.png" /></span></P><OL><LI><SPAN>Here click on the + sign and it will take you to the screen below where you can choose the user. Division and assign the division according to the employee export file.</SPAN>&nbsp;</LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_11-1758011179894.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315040i955C2F8EDF475376/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_11-1758011179894.png" alt="ajitchirania88_11-1758011179894.png" /></span></P><OL><LI><SPAN>Choose for both the restrictions + Sign and choose user. division for both the places because we would like to give admin access to HR to see and update only the users belonging to those division.</SPAN></LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_31-1758011838217.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315065i456CAF541C7DC072/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_31-1758011838217.png" alt="ajitchirania88_31-1758011838217.png" /></span></P><P><SPAN>13. Now we need to find the value from the SF export file as attached here to see what the value is coming from the SuccessFactors for the organization/division and use the exact same field value here. </SPAN></P><P><SPAN>PFA.</SPAN></P><P><SPAN>&nbsp;</SPAN><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_13-1758011179897.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315041i57673EF92758038E/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_13-1758011179897.png" alt="ajitchirania88_13-1758011179897.png" /></span></P><OL><LI><SPAN>Check the column AS and field name custom06 value and use the same value in the above user.division field. In our case we have set up rules for AUT, so we need to filter column06 from the exported file from SF and search for AUT. We go custom06 value as AUT(AUT). This value needs to be updated in the user. Division value . ( Please note you need to fill this custom06 values from Successfactors to each user in IAS by using the source and target transformation) .</SPAN></LI></OL><P><STRONG><SPAN>Source transformation code :</SPAN></STRONG></P><P><SPAN>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; {</SPAN></P><P><SPAN>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "sourcePath": "$['urn:ietf:params:scim:schemas:extension:successfactors:2.0:User']['customFields'][?(@.customFieldName == 'custom06')]['value']",</SPAN></P><P><SPAN>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "targetPath": "$.custom06",</SPAN></P><P><SPAN>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "optional": true</SPAN></P><P><SPAN>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }</SPAN></P><P><STRONG><SPAN>Target transformation code :</SPAN></STRONG></P><P><SPAN>{</SPAN></P><P><SPAN>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "sourcePath": "$.custom06",</SPAN></P><P><SPAN>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "optional": true,</SPAN></P><P><SPAN>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "targetPath": "$['urn:ietf:params:scim:schemas:extension:enterprise:2.0:User']['division']"</SPAN></P><P><SPAN>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }</SPAN></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_14-1758011179902.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315043iDC29A21793393423/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_14-1758011179902.png" alt="ajitchirania88_14-1758011179902.png" /></span></P><OL><LI><SPAN>The same value we need to update in the user. Division field as shown below.</SPAN><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_15-1758011179906.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315046i038877F82F9F88F6/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_15-1758011179906.png" alt="ajitchirania88_15-1758011179906.png" /></span></LI><LI>At the end you can add the below authorization as well USE schemas.READ_SCIM_SCHEMAS click on ADD USE and select from the dropdown the authorization as USE schemas.READ_SCIM_SCHEMAS. This is also required READ_SCIM_SCHEMAS&nbsp;authorization policies. Otherwise, you won't be able to see and access the&nbsp;<STRONG>Export Users’</STRONG>&nbsp;title.</LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_16-1758011179911.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315045iC365F9F8F81165AA/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_16-1758011179911.png" alt="ajitchirania88_16-1758011179911.png" /></span></P><OL><LI><SPAN>Click on confirmation and it will be added.</SPAN></LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_17-1758011179914.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315044iF008FC62FC83E92D/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_17-1758011179914.png" alt="ajitchirania88_17-1758011179914.png" /></span></P><OL><LI><SPAN>First click on SAVE and then click on the Assignments tab and add the user you would like to give this &nbsp;&nbsp;authorization.</SPAN></LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_18-1758011179918.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315048iE6FE2B1DE678B571/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_18-1758011179918.png" alt="ajitchirania88_18-1758011179918.png" /></span></P><OL><LI><SPAN>Assign/click on ADD to add the users whom you want to give granular authorization. Please note that the user should exist in the IAS User directory. Now I am giving access to one user for example Mohana@gmail.com </SPAN></LI></OL><P><SPAN>&nbsp;</SPAN><SPAN>I can click on add and search the user using the email address and add the user. After that the user is assigned to the new authorization policy and the user can access the employees belongs to AUT organization.</SPAN></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_19-1758011179924.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315049i3AB77F188B638056/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_19-1758011179924.png" alt="ajitchirania88_19-1758011179924.png" /></span></P><P>&nbsp;</P><OL><LI><SPAN>Search for the user whom you want to give access to.</SPAN></LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_20-1758011179926.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315047i04C731C218AF1CCA/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_20-1758011179926.png" alt="ajitchirania88_20-1758011179926.png" /></span></P><OL><LI><SPAN>Click on the ADD.&nbsp; The user is added successfully. </SPAN></LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_21-1758011179928.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315050i8151CACF654DFF05/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_21-1758011179928.png" alt="ajitchirania88_21-1758011179928.png" /></span></P><P><SPAN>The above steps complete the creation of the new Authorization policies and assignment of users. </SPAN></P><P><STRONG><U>HOW TO ASSING AUTHORIZATION TO HR ADMIN/ ANY USERS USING THE EXISTING AUTHORIZATION POLICIES &nbsp;</U></STRONG></P><OL><LI><SPAN>Follow the steps from 1 to 7 and complete the steps as mentioned above. ( The above example shows the process , now you want to assign other users in the same authorization policies)</SPAN></LI><LI><SPAN>Now you are in the authorization policies tab, and you need to click on the filter to easily access the custom packages created and choose the one required for you to be updated. Please note that IMSA_AUT_USER is the test Authorization policy. I have created many authorizations policy for each division, that is why you can see many customer packages but here I am assigning the user to only IMSA_AUT_USER authorization policy. </SPAN></LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_22-1758011179934.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315051iDFF4254ABFB38A73/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_22-1758011179934.png" alt="ajitchirania88_22-1758011179934.png" /></span></P><OL><LI><SPAN>Click on the filter and choose customer packages.</SPAN></LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_23-1758011179940.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315052iC6F02E75A32507E5/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_23-1758011179940.png" alt="ajitchirania88_23-1758011179940.png" /></span></P><OL><LI><SPAN>Click ok to see all the customer packages filtered and you can choose the one required for you. I am choosing the IMSA_AUT_USER and would like to assign one existing user.</SPAN></LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_24-1758011179945.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315054i058874EA9ACC3E45/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_24-1758011179945.png" alt="ajitchirania88_24-1758011179945.png" /></span></P><OL><LI><SPAN>Now open the customer authorization policies named IMSA_AUT_USER. You can choose the package as per your requirements. I would like to give access to the below user for the authorization policies IMSA_AUT_USER. </SPAN></LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_25-1758011179947.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315053i15E1F1AD09AE5E25/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_25-1758011179947.png" alt="ajitchirania88_25-1758011179947.png" /></span></P><OL><LI><SPAN>You must click on the IMSA_AUT_USER authorization policy as shown in the above step. It will show you the screen below. Go to the assignments tab and assign/add the above user.</SPAN></LI></OL><P><SPAN>Click on the ADD and search for the user with username as </SPAN>BHR.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_26-1758011179951.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315055i73F7F1150880FF73/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_26-1758011179951.png" alt="ajitchirania88_26-1758011179951.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajitchirania88_27-1758011179952.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/315056i73E268F0336750C9/image-size/medium?v=v2&amp;px=400" role="button" title="ajitchirania88_27-1758011179952.png" alt="ajitchirania88_27-1758011179952.png" /></span></P><P><SPAN>Now the user has assigned the authorization policies created by you. You can reset the password for this user in IAS and try to login and you will see that this user will be able to see only a few users who are belonging to the division AUT(AUT).&nbsp; </SPAN></P><P><STRONG><SPAN>Please note :</SPAN></STRONG><SPAN> You must remove the user from Administrator group if it is assigned as an administrator otherwise the Administrator group in IAS under user &amp; Authorizations-&gt;administrator will give more permissions to the administrator. </SPAN></P> 2025-09-17T12:37:51.141000+02:00 https://community.sap.com/t5/financial-management-blog-posts-by-sap/sap-grc-for-sap-hana-early-adopter-care-program-is-open/ba-p/14233031 SAP GRC for SAP HANA - Early Adopter Care Program is Open! 2025-10-02T00:21:59.824000+02:00 ElyasAhmed https://community.sap.com/t5/user/viewprofilepage/user-id/1886529 <P><FONT size="4" color="#000000"><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ElyasAhmed_0-1759352102523.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/322135iD1B8CB16C87AB043/image-size/large?v=v2&amp;px=999" role="button" title="ElyasAhmed_0-1759352102523.png" alt="ElyasAhmed_0-1759352102523.png" /></span></FONT></P><P>&nbsp;</P><P><FONT size="6"><STRONG>Ready to Shape the Future of SAP GRC for SAP HANA?</STRONG></FONT></P><P><FONT size="4">The <STRONG>Early Adopter Care (EAC) Program for SAP GRC for SAP HANA</STRONG> (<A href="https://community.sap.com/t5/financial-management-blog-posts-by-sap/understanding-sap-s-product-strategy-for-governance-risk-and-compliance-grc/ba-p/14053197" target="_self">GRC 2026</A>) is now open!</FONT></P><P><FONT size="4">This is an opportunity to gain early access to SAP’s latest innovations in governance, risk, and compliance (GRC), which include:</FONT></P><UL><LI><FONT size="4">SAP Access Control</FONT></LI><LI><FONT size="4">SAP Process Control</FONT></LI><LI><FONT size="4">SAP Risk Management</FONT></LI><LI><FONT size="4">SAP Audit Management</FONT></LI><LI><FONT size="4">SAP Business Integrity Screening</FONT></LI><LI><FONT size="4">SAP Tax Compliance</FONT></LI><LI><FONT size="4">SAP UI Data Protection Masking</FONT></LI><LI><FONT size="4">SAP UI Data Protection Logging</FONT></LI></UL><P><FONT size="4">As a participant, you’ll be among the first to implement and provide feedback on SAP GRC for SAP HANA before general availability.</FONT></P><P><FONT size="4">This program is run in close collaboration with SAP experts, giving you direct access to development teams and dedicated support as you modernize compliance processes on SAP S/4HANA.</FONT></P><P><STRONG>&nbsp;</STRONG></P><P><FONT size="6"><STRONG>What’s in it for you?</STRONG></FONT></P><UL><LI><FONT size="4">Early access to <STRONG>SAP GRC for SAP HANA innovations</STRONG></FONT></LI><LI><FONT size="4"><STRONG>Close collaboration with SAP Development</STRONG> to minimize risks and safeguard projects</FONT></LI><LI><FONT size="4"><STRONG>Dedicated feedback channel</STRONG> with product experts and project coaches</FONT></LI><LI><FONT size="4">Visibility into who is adopting the newest GRC capabilities</FONT></LI><LI><FONT size="4">Opportunity to <STRONG>influence the direction of future releases</STRONG> with your feedback</FONT></LI></UL><P><STRONG>&nbsp;</STRONG></P><P><FONT size="6"><STRONG>When is it happening and how to register?</STRONG></FONT></P><UL><LI><FONT size="4"><STRONG>Registration:</STRONG> October 1 - November 15, 2025</FONT></LI><LI><FONT size="4"><STRONG>Program Start:</STRONG> March 9, 2026</FONT></LI></UL><P><FONT size="4">Customers can apply directly on the <A href="https://influence.sap.com/sap/ino/#campaign/4014" target="_blank" rel="noopener noreferrer">Influence Platform</A> and become part of a select group helping shape the future of SAP GRC capabilities.</FONT></P><P><STRONG>&nbsp;</STRONG></P><P><FONT size="6"><STRONG>Who should join?</STRONG></FONT></P><P><FONT size="4">This program is ideal for organizations:</FONT></P><UL><LI><FONT size="4">Already running SAP GRC solutions and planning to transition to SAP GRC for SAP HANA</FONT></LI><LI><FONT size="4">Looking to <STRONG>modernize governance, risk, and compliance</STRONG> processes on SAP S/4HANA</FONT></LI></UL><P><STRONG>&nbsp;</STRONG></P><P><FONT size="6"><STRONG>Why it matters</STRONG></FONT></P><P><FONT size="4">The Early Adopter Care Program is more than an early access, it’s a partnership. By joining, you’ll:</FONT></P><UL><LI><FONT size="4">Shape SAP GRC for SAP HANA with your <STRONG>real-world use cases</STRONG></FONT></LI><LI><FONT size="4">Gain <STRONG>first-hand support</STRONG> from SAP’s development organization</FONT></LI><LI><FONT size="4">Establish your organization as a <STRONG>thought leader</STRONG> in modern GRC adoption</FONT></LI></UL><P><STRONG>&nbsp;</STRONG></P><P><FONT size="6"><STRONG>Take the next step</STRONG></FONT></P><P><FONT size="4">Don’t miss the chance to be part of the future of SAP GRC. Join the Early Adopter Care Program today and secure your seat at the forefront of innovation.</FONT></P><P><FONT size="4">Apply now via the <A href="https://influence.sap.com/sap/ino/#campaign/4014" target="_blank" rel="noopener noreferrer">Influence Platform</A>.</FONT></P> 2025-10-02T00:21:59.824000+02:00 https://community.sap.com/t5/technology-blog-posts-by-sap/secure-your-digital-journey-with-sap-ciam/ba-p/14232983 Secure Your Digital Journey with SAP CIAM 2025-10-02T14:00:00.040000+02:00 ratulshah https://community.sap.com/t5/user/viewprofilepage/user-id/604338 <P><STRONG><SPAN>Secure Your Digital Journey with SAP CIAM</SPAN></STRONG><SPAN>&nbsp;</SPAN></P><P><SPAN>Over the years, working in customer experience and digital technologies, I have witnessed the rapid evolution of both customers and the infrastructure needed to serve them.&nbsp; When you consider the “customer,” the need to understand who they are has become a central focus of the user experience. The world of digital identity has continuously adapted. Social logins once felt like the future—now, passwordless or passkey authentication is a requirement. Data privacy has shifted from an afterthought to a boardroom priority, largely driven by regulations like </SPAN><A href="https://www.sap.com/resources/ciam-consent-privacy-compliance" target="_blank" rel="noopener noreferrer"><SPAN>GDPR, CCPA, and others</SPAN></A><SPAN>. What used to be considered "good enough" security no longer suffices, as becoming the subject of a data breach headline is a risk no company can afford..</SPAN><SPAN>&nbsp;</SPAN></P><P><SPAN>Even my daughter now warns me not to share her identity online, as I don’t have her consent—proof that awareness of digital risks is becoming second nature to the next generation. In this new era, trust isn't a nice-to-have; it’s the foundation of every customer interaction.</SPAN><SPAN>&nbsp;</SPAN></P><P><SPAN>That’s why </SPAN><A href="https://www.sap.com/products/technology-platform/customer-identity.html" target="_blank" rel="noopener noreferrer"><SPAN>Customer Identity and Access Management</SPAN></A><SPAN> (CIAM) is a critical part of any modern digital strategy and future-forward IT landscape. When organizations get digital identity right, they unlock more than just security—they create better, more trusted customer experiences at every touchpoint.</SPAN><SPAN>&nbsp;</SPAN></P><P><SPAN>&nbsp;</SPAN></P><P><STRONG><SPAN>Bridge the Gap Between Experience and Trust</SPAN></STRONG><SPAN>&nbsp;</SPAN></P><P><SPAN>In today's digital-first landscape, businesses must navigate the challenge of delivering seamless customer experiences while ensuring robust data protection—a balance that is crucial for building trust with increasingly privacy-conscious consumers. However, many organizations are stuck navigating data silos, which fragment customer insights and prevent a unified understanding of their audience.&nbsp;</SPAN><SPAN>&nbsp;</SPAN></P><P><SPAN>SAP CIAM offers a comprehensive solution to these challenges by unifying data management, enhancing security frameworks, and simplifying privacy compliance. It empowers businesses to protect against threats, manage identities efficiently, and offer personalized user experiences that foster customer loyalty.</SPAN><SPAN>&nbsp;</SPAN></P><P><SPAN>SAP CIAM overcomes the limitations of outdated systems and enables organizations to confidently:</SPAN><SPAN>&nbsp;</SPAN></P><OL><LI><SPAN>Secure users</SPAN><SPAN>&nbsp;</SPAN></LI></OL><OL><LI><SPAN>Reduce privacy concerns</SPAN><SPAN>&nbsp;</SPAN></LI></OL><OL><LI><SPAN>Scale efficiently</SPAN><SPAN>&nbsp;</SPAN></LI></OL><P><SPAN>&nbsp;</SPAN></P><OL><LI><STRONG><SPAN>Secure Users and Safeguard Data&nbsp;</SPAN></STRONG><SPAN>&nbsp;</SPAN></LI></OL><P><SPAN>Concerned about data breaches? SAP CIAM is engineered to protect your customer data and minimize security risks, building trust between you and your customers. By prioritizing robust threat detection and protection, this solution ensures your business remains secure, fostering loyalty and reinforcing customer confidence in sharing their data.&nbsp;&nbsp;</SPAN><SPAN>&nbsp;</SPAN></P><UL><LI><SPAN>Access real-time password suggestions</SPAN><SPAN>&nbsp;</SPAN></LI></UL><UL><LI><SPAN>Utilize built-in screen sets for password updates</SPAN><SPAN>&nbsp;</SPAN></LI></UL><UL><LI><SPAN>Generate one-time passwords</SPAN><SPAN>&nbsp;</SPAN></LI></UL><UL><LI><SPAN>Integrate with external identity services</SPAN><SPAN>&nbsp;</SPAN></LI></UL><UL><LI><SPAN>Enable biometric sign-in for secure login</SPAN><SPAN>&nbsp;</SPAN></LI></UL><UL><LI><SPAN>Harness AI risk-based authentication</SPAN><SPAN>&nbsp;</SPAN></LI></UL><P><SPAN>&nbsp;</SPAN></P><P><SPAN>For a deeper look at how SAP CIAM addresses today’s evolving security landscape, join us at SAP TechEd on November 6 for a dedicated CIAM security session. Register </SPAN><A href="https://www.sap.com/events/teched/berlin/flow/sap/te25/catalog-inperson/page/catalog/session/1753256002221001ZHyX" target="_blank" rel="noopener noreferrer"><SPAN>here</SPAN></A><SPAN> to secure your spot and learn more.</SPAN><SPAN>&nbsp;</SPAN></P><P><SPAN>&nbsp;</SPAN></P><OL><LI><STRONG><SPAN>Reduce Privacy Compliance Risk</SPAN></STRONG><SPAN>&nbsp;</SPAN></LI></OL><P><SPAN>Keeping up with evolving privacy regulations can be daunting. SAP CIAM simplifies these challenges through efficient consent management capabilities, enabling businesses to adhere to global standards like ISO, BSI, and SOC 2. With user-friendly self-service portals, SAP CIAM respects customer privacy while maintaining compliance—ultimately strengthening trusting relationships.</SPAN><SPAN>&nbsp;</SPAN></P><UL><LI><SPAN>Capture consent across all channels</SPAN><SPAN>&nbsp;</SPAN></LI></UL><UL><LI><SPAN>Customize for privacy policies and brand</SPAN><SPAN>&nbsp;</SPAN></LI></UL><UL><LI><SPAN>Configure single sign-on (SSO)</SPAN><SPAN>&nbsp;</SPAN></LI></UL><UL><LI><SPAN>Enable global access</SPAN><SPAN>&nbsp;</SPAN></LI></UL><P><SPAN>&nbsp;</SPAN></P><OL><LI><STRONG><SPAN>Increase Efficiency at Scale</SPAN></STRONG><SPAN>&nbsp;</SPAN></LI></OL><P><SPAN>Worried about system overload during peak times? SAP CIAM effortlessly manages traffic spikes, supporting billions of unique identities and transactions monthly. This capability allows businesses to capitalize on each opportunity without technical setbacks or undue stress on IT teams. With 347 million active users across 85 thousand sites, SAP CIAM is a proven solution for large-scale digital operations.</SPAN><SPAN>&nbsp;</SPAN></P><UL><LI><SPAN>Design and execute identity flows</SPAN><SPAN>&nbsp;</SPAN></LI></UL><UL><LI><SPAN>Duplicate site configurations and settings</SPAN><SPAN>&nbsp;</SPAN></LI></UL><UL><LI><SPAN>Offer OOTB, OIDC-compliant login experiences</SPAN><SPAN>&nbsp;</SPAN></LI></UL><UL><LI><SPAN>Create identity screens with drag-and-drop</SPAN><SPAN>&nbsp;</SPAN></LI></UL><P><SPAN>&nbsp;</SPAN></P><P><STRONG><SPAN>Elevate Your Identity Strategy with SAP CIAM</SPAN></STRONG><SPAN>&nbsp;</SPAN></P><P><SPAN>SAP CIAM empowers businesses to bolster their security measures, ensure data privacy compliance, and efficiently scale their digital operations. Additionally, it offers pre-configured connectivity with over 60 SAP products, including SAP Business Technology Platform, SAP S/4HANA, SAP Customer Experience solutions, and SAP cloud ERP solutions, enhancing integration across your enterprise.</SPAN><SPAN>&nbsp;</SPAN></P><P><SPAN>Incorporating SAP CIAM into your digital strategy could be the next step toward elevating your business with enhanced security, data protection, and scalability.</SPAN><SPAN>&nbsp;</SPAN></P><P><SPAN>&nbsp;</SPAN></P><P><SPAN>Learn more </SPAN><A href="https://www.sap.com/documents/2025/05/6868feea-077f-0010-bca6-c68f7e60039b.html" target="_blank" rel="noopener noreferrer"><SPAN>here</SPAN></A><SPAN>.</SPAN><SPAN>&nbsp;</SPAN></P> 2025-10-02T14:00:00.040000+02:00 https://community.sap.com/t5/sap-learning-blog-posts/from-penalty-to-power-play-why-identity-management-is-key-to-better/ba-p/14232025 From Penalty to Power Play: Why Identity Management Is Key to Better Customer Experiences 2025-10-03T20:53:03.532000+02:00 Dione_Sheehan https://community.sap.com/t5/user/viewprofilepage/user-id/1924893 <P>A few weeks ago, a friend bought tickets to a hockey game and wanted to transfer them to me. Like many people, we went with the quickest workaround—she shared her login credentials so I could access the tickets. But what should have been a simple process turned into several days of password resets, missed messages, and back-and-forth. By the time I finally got into her account, the tickets were gone. She had attempted to transfer them during the delay, but amid the confusion and technical issues, I never actually received them. If I had been able to log in right away, I could have just downloaded them directly. But the access issues created confusion, and without any clear support from the platform, we ended up losing the tickets—and missing the game.</P><P>It was a simple plan that fell apart because of something as basic as account access.</P><P>This experience is a small example of a much larger issue in digital commerce: the friction that arises when identity management isn’t built with the customer in mind. It’s easy to overlook, but poor identity experiences lead directly to lost opportunities—not just for consumers, but for the businesses trying to reach them.</P><P>&nbsp;</P><P><STRONG>Identity Friction = Lost Revenue</STRONG></P><P>In today’s commerce landscape, customer expectations are sky-high. If a login process is confusing, if an account is hard to access, or if personalization feels off—people walk away. And often, they don’t come back.</P><P>Poor identity experiences hurt businesses in more ways than one:</P><UL><LI><STRONG>They interrupt the buying journey.</STRONG>&nbsp;Whether it’s a login loop, a forgotten password, or a complicated checkout flow, friction at these key points drives abandonment.</LI><LI><STRONG>They block personalization.</STRONG>&nbsp;When customer data is fragmented across systems, it’s hard to deliver the tailored experiences that today’s buyers expect.</LI><LI><STRONG>They erode trust.</STRONG>&nbsp;Without clear consent management and transparency, customers hesitate to share information—or stop engaging entirely.</LI><LI><STRONG>They slow down growth.</STRONG>&nbsp;Outdated systems and homegrown solutions often can’t keep up with omnichannel strategies or evolving compliance needs.</LI></UL><P>For a deeper dive into how <A href="https://www.sap.com/products/technology-platform/customer-identity.html" target="_self" rel="noopener noreferrer">SAP CIAM</A> can help reduce identity friction, join us at SAP TechEd on November 6 for a dedicated CIAM security session. Register <A href="https://www.sap.com/events/teched/berlin/flow/sap/te25/catalog-inperson/page/catalog/session/1753256002221001ZHyX" target="_blank" rel="noopener noreferrer">here</A> to secure your spot and learn more.</P><P>&nbsp;</P><P><STRONG>Where SAP CIAM + Commerce Cloud Make the Difference</STRONG></P><P>Customer Identity and Access Management (CIAM) helps solve these challenges by making identity work for the customer—not against them. When integrated into your commerce ecosystem, CIAM doesn't just handle sign-ins—it actively supports better customer relationships and business outcomes.</P><P>Here’s how:</P><UL><LI><STRONG>It reduces friction</STRONG>&nbsp;at every stage—from anonymous browsing to account creation to repeat purchases. The experience becomes smoother, simpler, and more secure.</LI><LI><STRONG>It improves conversion</STRONG>&nbsp;by enabling personalized, real-time engagement without relying on clunky data handoffs or third-party cookies.</LI><LI><STRONG>It builds trust</STRONG>&nbsp;by giving customers control over their data, preferences, and permissions—while helping businesses stay compliant across regions.</LI><LI><STRONG>It supports scale</STRONG>&nbsp;by integrating identity across every digital touchpoint, enabling consistent experiences on web, mobile, in-store, and beyond.</LI></UL><P>In short, CIAM allows businesses to move away from fragmented, frustrating interactions and toward a unified customer experience that feels intuitive, safe, and relevant—every time. To hear firsthand how SAP customers are achieving this with SAP CIAM and Commerce Cloud, join us at SAP Connect in Las Vegas on October 8. Register <A href="https://www.sap.com/events/connect/vegas/flow/sap/sc25/catalog-inperson/page/catalog/session/1750082827980001gQD5" target="_blank" rel="noopener noreferrer">here</A> to attend.</P><P>&nbsp;</P><P><STRONG>The Takeaway</STRONG></P><P>In commerce, moments of friction are more than just annoyances—they’re missed opportunities. Whether it’s lost hockey tickets or lost revenue, the cause is often the same: a broken identity experience.</P><P>Modern CIAM, especially when combined with a powerful commerce platform, turns identity into an asset. It streamlines the journey, protects the user, and empowers businesses to engage with clarity and confidence.</P><P>And the best part? It just works—so your customers don’t have to.&nbsp;</P><P>Learn more <A href="https://www.sap.com/documents/2025/05/6868feea-077f-0010-bca6-c68f7e60039b.html" target="_blank" rel="noopener noreferrer"><SPAN>here</SPAN></A><SPAN>.</SPAN></P> 2025-10-03T20:53:03.532000+02:00 https://community.sap.com/t5/enterprise-resource-planning-blog-posts-by-sap/posting-system-wide-messages-using-quot-manage-news-quot-app/ba-p/14246416 Posting System-wide Messages Using "Manage News" App 2025-10-17T16:05:13.051000+02:00 George_Yu1 https://community.sap.com/t5/user/viewprofilepage/user-id/131765 <H1 id="toc-hId-1633778441">Introduction</H1><P>For long time SAP users, they enjoy the benefit of posting and reading a system related message in SAP ECC or SAP S/4HANA systems using transaction code /sm02. From 2508 Release, SAP Cloud ERP (formerly called SAP S/4HANA Cloud Public Edition) can do the same on My Home page.&nbsp; This blog discusses the details on how to create the messages called News Articles, especially how to make them visible to your intended audience.</P><P>&nbsp;</P><H1 id="toc-hId-1437264936">Background</H1><P>Until Release 2508, our customers can see a beautiful My Home page with display of software related news (see box in the below figure).&nbsp; The news is limited to SAP provided features in your subscribed function areas, such as Supply Chain, Human Resources, etc.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Software related News" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328668i1C3B512649C87C60/image-size/large/is-moderation-mode/true?v=v2&amp;px=999" role="button" title="Software related News.jpg" alt="Software related News" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">Software related News</span></span></P><P>Many users were asking if they can post their own news in the News section.&nbsp; This feature becomes available in Release 2508 so that an administrator (yes, only the user with <EM>SAP_BR_ADMINISTRATOR</EM> business role) can post relevant news to the users on a needed basis. Here is an example of news postings – Hot Fix Collection 6 is going to be applied this weekend.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="News Article Postings" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328669i4A3F366431496253/image-size/large/is-moderation-mode/true?v=v2&amp;px=999" role="button" title="News Article Postings.jpg" alt="News Article Postings" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">News Article Postings</span></span></P><P>Recently I heard some users were attempting to post their own news without much success. I tried and figured out what is the mechanism behind and would explain them in detail in this blog.</P><P>&nbsp;</P><H1 id="toc-hId-1240751431">News Article Creation</H1><P>To create a News Article, we use the <STRONG>Manage News </STRONG>app.&nbsp; To launch this app, the user needs to have the business user role <EM>SAP_BR_ADMINISTRATOR</EM>, which contains the Business Catalog <EM>SAP_CORE_BC_CUX_NWS_MNG_PC</EM>.&nbsp;</P><P>When you launch the <STRONG>Manage News </STRONG>app for the first time, it should be empty, News Articles are 0, News Groups are 0 and News Images are 0.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Empty Entries in the Manage News app" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328670iA5D4696E62B88641/image-size/large/is-moderation-mode/true?v=v2&amp;px=999" role="button" title="Empty Entries in the Manage News app.jpg" alt="Empty Entries in the Manage News app" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">Empty Entries in the Manage News app</span></span></P><P>Before discussing news article creation, let me explain some relevant components first.</P><H2 id="toc-hId-1173320645">&nbsp;</H2><H2 id="toc-hId-976807140">News Images</H2><P>Besides default images, customers can upload their own images to be used together with news articles.&nbsp; For example, I downloaded one system maintenance related image from SAP’s brand image library as below.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="My Image for System Maintenance News Articles" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328673i9D026C9ED9385493/image-size/large/is-moderation-mode/true?v=v2&amp;px=999" role="button" title="My Image for System Maintenance News Articles.jpg" alt="My Image for System Maintenance News Articles" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">My Image for System Maintenance News Articles</span></span></P><P>By clicking on the <STRONG>News Images</STRONG> tab, and <STRONG>Create</STRONG> button, we can create a news image called “System Maintenance”.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="News Image – System Maintenance" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328676i40AF6AB886594484/image-size/large?v=v2&amp;px=999" role="button" title="News Image – System Maintenance.jpg" alt="News Image – System Maintenance" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">News Image – System Maintenance</span></span></P><P>I also downloaded another blue Joule image to be used for Artificial Intelligence related news.&nbsp; In the News Images tab, you can see these two Image entries are created.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Two Image Entries in News Images Tab" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328677i937170EF881A2753/image-size/large?v=v2&amp;px=999" role="button" title="Two Image Entries in News Images Tab.jpg" alt="Two Image Entries in News Images Tab" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">Two Image Entries in News Images Tab</span></span></P><P>&nbsp;</P><H2 id="toc-hId-780293635">News Groups</H2><P>News Groups are used to group relevant news articles together and display under one umbrella. For example, I have two system related News Articles</P><UL><LI>System Upgrade 1 for Release 2602 Upgrade</LI><LI>System Upgrade 2 for HFC 1 Upgrade</LI></UL><P>Since they are all System Maintenance related news, I put them under the same System Maintenance Group. When you check the News, you can see System Maintenance related news are all grouped together.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="System Maintenance Group News" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328678i6652E4B3B902D622/image-size/large/is-moderation-mode/true?v=v2&amp;px=999" role="button" title="System Maintenance Group News.jpg" alt="System Maintenance Group News" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">System Maintenance Group News</span></span></P><P>When you click on the News screen “System Maintenance”, a second window pops-up.&nbsp; It lists three news</P><OL><LI>Critical: System Upgrade 2</LI><LI>Critical: System Upgrade 1</LI><LI>Normal: Caution: Business Catalogs</LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Three News Articles within the System Maintenance News Group" style="width: 836px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328679i6B189B654A046A3C/image-size/large/is-moderation-mode/true?v=v2&amp;px=999" role="button" title="Three News Articles within the System Maintenance News Group .jpg" alt="Three News Articles within the System Maintenance News Group" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">Three News Articles within the System Maintenance News Group</span></span></P><P>The sequence of this group of news is most probably based on creation time.&nbsp; The newly created news is on top.</P><P>In addition, one news article can belong to more than one news groups. That is the case of News Article <STRONG>Caution: Business Catalogs</STRONG>.&nbsp; It belongs to two News Groups: “AI Joule Group” and “System Maintenance”.&nbsp; I will discuss that further later.</P><P>The creation of a News Group is quite straightforward as shown below. You can also assign an image to a News Group.&nbsp; This image will supersede any images assigned to a news article.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="System Maintenance News Group" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328680iC78427B773611ACB/image-size/large?v=v2&amp;px=999" role="button" title="System Maintenance News Group.jpg" alt="System Maintenance News Group" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">System Maintenance News Group</span></span></P><P>When you leave the&nbsp;<STRONG>Description&nbsp;</STRONG>section blank, the system will display a default message for you as shown below: <U>Discover new features and changes of this release</U>.&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Default News Group Description" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329131iCB3F54932742406A/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="Default News Group Description.jpg" alt="Default News Group Description" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">Default News Group Description</span></span></P><P>&nbsp;</P><H2 id="toc-hId-583780130">News Article</H2><P>Now let’s create our first News Article: <STRONG>System Upgrade 1</STRONG> as shown below.&nbsp; It is a created News Article with a background image (Blue Joule). You can further <STRONG>Edit</STRONG> it or <STRONG>Delete</STRONG> it.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="System Upgrade News Article" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328681i54BB5DBA940E94FE/image-size/large?v=v2&amp;px=999" role="button" title="System Upgrade News Article.jpg" alt="System Upgrade News Article" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">System Upgrade News Article</span></span></P><P>Overall, the creation is quite straightforward.&nbsp; I only explain a few entries:</P><UL><LI><STRONG>Title</STRONG> and <STRONG>Subtitle</STRONG> is a combination.&nbsp; You need to make it eye catching for users.</LI><LI><STRONG>Footer Text</STRONG> could indicate its author; at least that’s how I use it.</LI><LI><STRONG>Background Image</STRONG> is optional, but a good picture saves thousands of words.&nbsp; However, if this news article is under a News Group umbrella, the image won’t show when you display the news.</LI><LI><STRONG>Publish Start</STRONG> is tricky. If you want to see the News Article right away to verify your news, you could put a yesterday’s date here.&nbsp; Otherwise, you can put your intended publish time.</LI><LI><STRONG>Status</STRONG>: as soon you click the <STRONG>Create</STRONG> button, it changes from <STRONG><EM>Draft</EM></STRONG> to <STRONG><EM>Published</EM></STRONG>.</LI><LI><STRONG>News App Assignment</STRONG> is for limiting the news exposure by applications.&nbsp; For example, if the news is only intended for users of certain applications, such as&nbsp;<STRONG>Manage Workforce</STRONG>, you create a&nbsp;<STRONG>Manage Workforce&nbsp;</STRONG>app entry.&nbsp; With that, the news is only displayed to those users with access to the&nbsp;<STRONG>Manage Workforce&nbsp;</STRONG>app.</LI><LI><STRONG>News Group Assignment</STRONG><SPAN> allows you to assign more than one group.&nbsp; With that your news article will appear in each News Group when you click on the News section.&nbsp;&nbsp;</SPAN>For example, this <STRONG>System Upgrade 1 </STRONG>news article will appear not only in <STRONG>System Maintenance </STRONG>Group, but also in <STRONG>AI Joule Group</STRONG> as shown below.</LI></UL><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="The System Upgrade 1 News Article Displayed under AI Joule Group" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328682iB07444059AAC12F2/image-size/large/is-moderation-mode/true?v=v2&amp;px=999" role="button" title="The System Upgrade 1 News Article Displayed under AI Joule Group.jpg" alt="The System Upgrade 1 News Article Displayed under AI Joule Group" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">The System Upgrade 1 News Article Displayed under AI Joule Group</span></span></P><P>When you create a news article without assigning a News Group, this news article will appear as an independent (vs. belonging to a news group) entry in News section. For example, I have one news article called “System Announcement” which does not belong to any news groups. It will show by itself.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="A News Article without a News Group" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328692iADB7826D15DDBADF/image-size/large/is-moderation-mode/true?v=v2&amp;px=999" role="button" title="A News Article without a News Group .jpg" alt="A News Article without a News Group" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">A News Article without a News Group</span></span><SPAN>Here you probably noticed the background image is a glass dome.&nbsp; That is the default image by the system because I didn't assign a background image to this news article.</SPAN></P><H1 id="toc-hId-258183906">News Display</H1><P>When I first worked on <STRONG>Manage News</STRONG> app, I could not see my news articles in News Section. I found out the business catalog <EM>SAP_CORE_BC_CUX_NWS_DSP_PC</EM> must be assigned to the users for them to see the News.&nbsp; This is not documented anywhere!</P><P>Let’s check this business catalog out in the <STRONG>Business Catalogs </STRONG>app.&nbsp; It only serves one Fiori application, the <STRONG>Display News</STRONG> app.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Business Catalog of SAP_CORE_BC_CUX_NWS_DSP_PC" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328683i9C99222CB9945E72/image-size/large?v=v2&amp;px=999" role="button" title="Business Catalog of SAP_CORE_BC_CUX_NWS_DSP_PC.jpg" alt="Business Catalog of SAP_CORE_BC_CUX_NWS_DSP_PC" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">Business Catalog of SAP_CORE_BC_CUX_NWS_DSP_PC</span></span></P><P>By expanding above screen to include <STRONG>Used in Business Role Templates</STRONG> tab, I found it is used in <EM>SAP_BR_EMPLOYEE</EM> business role template. Our developer probably thinks all users should have the role of <EM>SAP_BR_EMPLOYEE</EM>.&nbsp; Therefore, displaying news is not a problem.&nbsp; This might not be the case. Because this business role introduces a lot of Employee Self-Service apps, not necessarily adopted by all our customers.</P><P>My advice is to create a user defined business role like <EM>Z_Display_News_All_Employee</EM> which contains one business catalog <EM>SAP_CORE_BC_CUX_NWS_DSP_PC</EM>; then you assign all users to this role.&nbsp; There is no need to assign a space or a page to the role.&nbsp; You can transport this user defined role to your Test and Production tenants (Note: I created this blog related objects in a production tenant to limit the impact to others; you usually do this in your Dev tenant).</P><P>With the proper business catalog <EM>SAP_CORE_BC_CUX_NWS_DSP_PC</EM> assigned, I can see the News in my Fiori Launchpad – My Home – News.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Four News Groups Are on Display" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328684i12C8490B5766DA46/image-size/large/is-moderation-mode/true?v=v2&amp;px=999" role="button" title="Four News Groups Are on Display.jpg" alt="Four News Groups Are on Display" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">Four News Groups Are on Display</span></span></P><P>&nbsp;</P><H1 id="toc-hId-61670401">Updates</H1><P>1/16/2026: With 2602 Release, there is a "Required Reading" button. With that option on, the user has to read and acknowledge the news.&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Required Reading.jpg" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/362005i46823BAB5628C502/image-size/large/is-moderation-mode/true?v=v2&amp;px=999" role="button" title="Required Reading.jpg" alt="Required Reading.jpg" /></span></P><P>This mandatory news is displayed when a user logs on to the system as shown below.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Mandatory News.jpg" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/362013i1366CEF463D6C4D9/image-size/large/is-moderation-mode/true?v=v2&amp;px=999" role="button" title="Mandatory News.jpg" alt="Mandatory News.jpg" /></span></P><P>&nbsp;</P><H1 id="toc-hId--134843104">Conclusion</H1><P>With the above explanations, you should be able to create a news article or a group of news articles as an administrator and view them as a business user.&nbsp; The <STRONG>Manage News</STRONG> app is a powerful tool to keep your users informed on your SAP Cloud ERP system.</P><P>&nbsp;</P><H1 id="toc-hId-438383474">Reference</H1><UL><LI>SAP Help: <A href="https://help.sap.com/docs/SAP_S4HANA_CLOUD/4fc8d03390c342da8a60f8ee387bca1a/c5a2d4b695814722a5becf9a4d6586b3.html?version=2508.VAL" target="_blank" rel="noopener noreferrer">Manage News</A></LI><LI>Blog: <A href="https://community.sap.com/t5/enterprise-resource-planning-blogs-by-sap/user-management-in-a-nutshell-for-the-sap-s-4hana-cloud-public-edition/ba-p/13556782" target="_blank">User Management in a Nutshell for the SAP S/4HANA Cloud, public edition</A></LI></UL><P>&nbsp;</P><P>Update History:</P><P>1/16/2026: Added Updates section before Conclusion.</P> 2025-10-17T16:05:13.051000+02:00 https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-iii-successfactors/ba-p/14233747 Identity and Access Management with Microsoft Entra, Part III: SuccessFactors and Role Provisioning 2025-10-20T10:05:47.788000+02:00 MartinRaepple https://community.sap.com/t5/user/viewprofilepage/user-id/171519 <P><A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_blank">Part II</A> of this blog series took a technical deep-dive into a hybrid scenario for managing identities and their access across SAP Business Technology Platform (BTP) and S/4HANA on-premise. Part III enhances the scenario by introducing SAP SuccessFactors (SF) as the source for employee and user data, and leverages the&nbsp;new capabilities in Entra for SCIM-based provisioning to SAP Cloud Identity Service (CIS) supporting <EM>groups</EM> to streamline end-to-end role assignments in the connected SAP ABAP backend.</P><H2 id="toc-hId-1761851243">Scenario Overview</H2><P>Part III introduces substantial changes and enhancements to the scenario in <A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_self">part II</A>:</P><UL><LI>Microsoft Entra and Active Directory (AD) were the primary and authoritative systems (aka "source of authority", SOA) for identity data in <A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_self">part II</A>. For many organizations, however, the trusted SOA for identities is a <A href="https://www.sap.com/products/hcm/employee-central-hris/what-is-hris.html" target="_blank" rel="noopener noreferrer">Human Resource Information System (HRIS)</A> such as SAP SuccessFactors (SF), which will be added to the scenario in this part, and where new employees are now onboarded<SPAN>.</SPAN></LI><LI>Identity creation, updates, and deprovisioning are now driven by HR events (e.g., hiring, role changes, terminations) from SF. AD and Entra become downstream provisioning targets in this scenario. Because users require access to SAP from SAP GUI on their corporate AD domain-joined workstation using Kerberos/<A href="https://help.sap.com/doc/saphelp_nw75/7.5.5/en-US/e6/56f466e99a11d1a5b00000e835363f/frameset.htm" target="_blank" rel="noopener noreferrer">SNC</A>-based single sign-on (SSO, see <A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_self">part II</A>), the solution architecture in this scenario integrates SF with the <A href="https://learn.microsoft.com/en-us/entra/identity/saas-apps/sap-successfactors-inbound-provisioning-tutorial" target="_blank" rel="noopener nofollow noreferrer">SAP SuccessFactors to Active Directory user provisioning connector</A>&nbsp;from the <A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-integrated-apps" target="_blank" rel="noopener nofollow noreferrer">Microsoft Entra App Gallery.</A>&nbsp;This p<SPAN>re-built, cloud-based solution&nbsp;</SPAN>supports&nbsp;<EM>inbound-</EM> or&nbsp;<EM><A href="https://learn.microsoft.com/en-us/entra/identity/app-provisioning/what-is-hr-driven-provisioning" target="_blank" rel="noopener nofollow noreferrer">HR-driven</A></EM>&nbsp;provisioning of new employees from SF to AD <SPAN>through Entra.</SPAN>&nbsp;New users provisioned to AD by this connector will be synchronized to Entra with the existing setup&nbsp;of t<SPAN>he&nbsp;</SPAN><A href="https://learn.microsoft.com/en-us/entra/identity/hybrid/cloud-sync/concept-how-it-works" target="_blank" rel="noopener nofollow noreferrer">Microsoft Entra Cloud Sync Provisioning Agent</A><SPAN>&nbsp;from <A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_self">part II</A> of this blog series that runs on the Domain Controller (DC) in our&nbsp;fictitious company BestRun's corporate network</SPAN>.</LI><LI><A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_self">Part II</A> focused on the automation of provisioning the user's identity data. The user's authorization in the SAP backend (we used&nbsp;role<SPAN>&nbsp;</SPAN><A href="https://help.sap.com/docs/ABAP_PLATFORM_NEW/c238d694b825421f940829321ffa326a/4ec2c02e6e391014adc9fffe4e204223.html?q=SAP_BC_ABAP_DEVELOPER_5&amp;locale=en-US" target="_blank" rel="noopener noreferrer">SAP_BC_ABAP_DEVELOPER_5</A>&nbsp;<SPAN>as an example)&nbsp;</SPAN>was still managed manually by assigning the user to the equally named group "SAP_BC_ABAP_DEVELOPER_5" in the CIS tenant (see step 10.20 in&nbsp;<A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_self">part II</A>). Also the group in CIS had to be created manually in the previous part of the scenario (see steps 9.17-9.19). This approach may work for a few backend authorizations, but won't scale for a larger number of connected systems and applications with complex authorization models. A key objective in this scenario is to fully automate end-to-end provisioning and deprovisioning of the user's authorizations, which includes the synchronization of backend roles and their corresponding groups in CIS and Entra, as well as the memberships of users to these groups, that ultimately assigns them to the backend roles. The updated version of the <A href="https://learn.microsoft.com/en-us/entra/identity/saas-apps/sap-cloud-platform-identity-authentication-provisioning-tutorial" target="_blank" rel="noopener nofollow noreferrer">SAP CIS connector</A>&nbsp;from the <A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-integrated-apps" target="_blank" rel="noopener nofollow noreferrer">Microsoft Entra App Galley</A> now enables automated provisioning of&nbsp;<EM>groups</EM> and their&nbsp;<EM>entitlements</EM> as&nbsp;<EM>memberships</EM>&nbsp;from Entra to CIS. This new feature in the SCIM (System for Cross-domain Identity Management, IETF RFCs&nbsp;<A href="https://tools.ietf.org/html/rfc7642" target="_blank" rel="nofollow noopener noreferrer">7642</A>,&nbsp;<A href="https://tools.ietf.org/html/rfc7643" target="_blank" rel="nofollow noopener noreferrer">7643</A>&nbsp;and&nbsp;<A href="https://tools.ietf.org/html/rfc7644" target="_blank" rel="nofollow noopener noreferrer">7644</A>)-compliant outbound provisioning connector in Entra streamlines the end-to-end lifecycle management for authorizations in the scenario. By assigning the new user to a group representing the&nbsp;<A href="https://learning.sap.com/learning-journeys/exploring-the-authorization-concept-for-sap-s-4hana-and-sap-business-suite/creating-standard-roles" target="_blank" rel="noopener noreferrer">PFCG role</A>&nbsp;in the SAP ABAP system, this group and the user's membership are now also automatically provisioned to CIS, and from there to the backend system. Similar to <A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_self">part II</A>, the group in Entra and CIS is mapped to the PFCG role by using the same name.</LI></UL><P>Figure 1 illustrates the SOA for the IAM entities in the scenario:</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Figure 1" style="width: 282px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329689i917D242B40ECE381/image-size/large/is-moderation-mode/true?v=v2&amp;px=999" role="button" title="figure1.png" alt="Figure 1" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">Figure 1</span></span></P><P>&nbsp;</P><P>Although SOA for identity data moves to SF, the connected SAP system remains the authority for the <EM>definition</EM> of the roles that can be assigned in the scenario. Managing the actual&nbsp;<EM>assignment</EM> of users to these roles through access packages and approval workflows remains the responsibility of Entra ID Governance. With no single SOA for users, groups and roles centralized at one place in the system landscape, figure 2 shows the updated and newly introduced system components based on the existing setup from <A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_self">part II</A>, and illustrates the steps of the provisioning flow for a new onboarded employee requesting access to a role in the corporate SAP system:</P><P>&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Figure 2" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329690iC40448471EB1C535/image-size/large/is-moderation-mode/true?v=v2&amp;px=999" role="button" title="figure2.png" alt="Figure 2" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">Figure 2</span></span></P><P>&nbsp;</P><P>&nbsp;</P><P>&nbsp;</P><OL><LI>CIS is responsible to integrate the connected SAP systems following this <A href="https://architecture.learning.sap.com/docs/ref-arch/20c6b29b1e/2" target="_blank" rel="noopener noreferrer">reference architecture</A>. It synchronizes the role from the backend (SAP_BC_EPM_DEMO in this scenario) with the&nbsp;<A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/sap-application-server-abap" target="_blank" rel="noopener noreferrer">SAP Application Server ABAP connector configured as a Source System</A> in BestRun's CIS tenant Identity Provisioning Service (IPS) which results in creating a group with the same name in the tenant's local directory. Connectivity from CIS to the SAP system on-premises remains unchanged from <A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_self">part II</A>&nbsp;and is established via the <A href="https://discovery-center.cloud.sap/serviceCatalog/connectivity-service?region=all" target="_blank" rel="noopener nofollow noreferrer">connectivity service in BTP</A> and the <A href="https://help.sap.com/docs/connectivity/sap-btp-connectivity-cf/cloud-connector" target="_blank" rel="noopener noreferrer">SAP Cloud Connector</A> deployed in the corporate network.</LI><LI>CIS also takes care for creating the group in Entra by provisioning it with the <A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/target-microsoft-entra-id" target="_blank" rel="noopener noreferrer">Entra ID connector configured as a target system</A> in the CIS tenant. This connector uses the <A href="https://learn.microsoft.com/en-us/graph/api/resources/groups-overview?view=graph-rest-1.0&amp;tabs=http" target="_blank" rel="noopener nofollow noreferrer">Microsoft Graph API</A> to manage groups in Entra.</LI><LI>The HR admin adds a new employee record in SF for the user in the sceanrio, Linda Larson.&nbsp;</LI><LI>The <A href="https://learn.microsoft.com/en-us/entra/identity/saas-apps/sap-successfactors-inbound-provisioning-tutorial" target="_blank" rel="noopener nofollow noreferrer">SAP SuccessFactors to Active Directory user provisioning connector</A>&nbsp;picks up the new employee record&nbsp;<SPAN>by calling the&nbsp;<A href="https://learn.microsoft.com/en-us/entra/identity/app-provisioning/sap-successfactors-integration-reference" target="_blank" rel="noopener nofollow noreferrer">SF Employee Central OData API endpoints</A>&nbsp;</SPAN>to query for new or updated data.</LI><LI>The connector then provisions a user account for the new employee Linda in BestRun's corporate AD via&nbsp;<A href="https://learn.microsoft.com/en-us/entra/identity/hybrid/cloud-sync/concept-how-it-works" target="_blank" rel="noopener nofollow noreferrer">Entra Cloud Sync and the Entra Provisioning Agent</A>&nbsp;on the DC.</LI><LI>With Entra Cloud Sync configured in <A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_self">part II</A> to <A href="https://learn.microsoft.com/en-us/entra/identity/hybrid/cloud-sync/how-to-configure" target="_blank" rel="noopener nofollow noreferrer">synchronize AD with the Entra</A> tenant, the new account in the corporate AD is also provisioned to BestRun's Entra ID tenant.</LI><LI>Linda starts a request for the <EM>SAP EPM</EM> access package with the <A href="https://docs.azure.cn/en-us/entra/id-governance/my-access-portal-overview" target="_blank" rel="noopener nofollow noreferrer">MyAccess portal</A>. For this initial login to Entra, Linda can use the <SPAN>self-service password reset (SSPR) feature in Entra to set her new Entra user account's password.&nbsp;With <A href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sspr-writeback" target="_blank" rel="noopener nofollow noreferrer">password writeback enabled in Entra Cloud Sync</A> and SSPR to use password writeback, Linda's initial password reset or any future changes of her password are synchronized back to BestRun's on-premises AD as well.&nbsp;</SPAN><SPAN>By completing the request, Linda is assigned to the access package resources, and becomes a member in the SAP_BC_EPM_DEMO group in Entra. To keep things simple, the access package policy requires no approval steps in this scenario.</SPAN></LI><LI>The <A href="https://learn.microsoft.com/en-us/entra/identity/saas-apps/sap-cloud-platform-identity-authentication-provisioning-tutorial" target="_blank" rel="noopener nofollow noreferrer">SAP CIS connector enterprise app</A>&nbsp;is configured to perform all operations (create/update/delete) on new or existing user objects, but to skip creation on groups. Otherwise, Entra would try to create the same group again in CIS that has already been created in step 1, which would result in a naming conflict. Instead, it creates a new user account for Linda in CIS, but only updates her&nbsp;membership to the <SPAN>SAP_BC_EPM_DEMO group in&nbsp;</SPAN>BestRun's CIS tenant.<BR />In addition to the new support for groups in the new version of the SAP CIS connector, authentication to CIS no longer uses basic authentication that sends static credentials with every request. Instead, short‑lived tokens with scoped, limited privileges using the <A href="https://datatracker.ietf.org/doc/html/rfc6749#section-4.4" target="_blank" rel="noopener nofollow noreferrer">OAuth 2.0 client credentials grant flow</A>&nbsp;enhance security over basic authentication.</LI><LI>Provisioning to the SAP backend with the already existing&nbsp;<A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/target-sap-application-server-abap" target="_blank" rel="noopener noreferrer">SAP Application Server ABAP connector configured as a Target System</A>&nbsp;in IPS starts by reading the new user and her group membership from the CIS tenant's local directory, and creating the new user in SAP as well as assigning this user to the corresponding&nbsp;<SPAN>SAP_BC_EPM_DEMO role.</SPAN></LI><LI>Finally, Linda can login to BestRun's corporate AD from her workstation, obtains a Kerberos token from the DC, and uses it to securely single sign-on to the backend from&nbsp;SAP GUI and the SAP Secure Login Client. This requires mapping of her user principal name (UPN) in AD to her SAP user, which has already been configured in the mappings of the SAP CIS connector in Entra (see step 6.18 in <A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_self">part II</A>) and the transformation of the SAP Application Server ABAP target system in IPS (see step 9.12 in <A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_self">part II</A>).</LI></OL><P>If you want to see the scenario in action, tune into <A href="https://eu01web.zoom.us/rec/share/GhPI3WX8f78T47EuMtsFrT3P5ADDEyyUuqj_vEGlMN3Dtvu6e_wpPrqYKnX7TPVt.T_4kNxoeY4L8rkut" target="_blank" rel="noopener nofollow noreferrer">the recording</A> from our latest online session (in german language) with the <A href="https://dsagnet.de/gremium/sap-iam-strategie-mit-microsoft" target="_blank" rel="noopener nofollow noreferrer">DSAG TG "SAP IAM Strategie mit Microsoft"&nbsp;</A> from October 7th, or check out <A href="https://www.youtube.com/watch?v=MKZb0b2tXIU&amp;feature=youtu.be" target="_blank" rel="noopener nofollow noreferrer">episode 263</A> from&nbsp;<a href="https://community.sap.com/t5/user/viewprofilepage/user-id/3494">@Holger-Bruchelt</a>&nbsp;<A href="https://www.saponazurepodcast.de/" target="_blank" rel="noopener nofollow noreferrer">SAP on Azure video podcast</A>.</P><P><div class="video-embed-center video-embed"><iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FMKZb0b2tXIU%3Ffeature%3Doembed&amp;display_name=YouTube&amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DMKZb0b2tXIU&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FMKZb0b2tXIU%2Fhqdefault.jpg&amp;type=text%2Fhtml&amp;schema=youtube" width="200" height="112" scrolling="no" title="#263 - ToW SuccessFactors integration &amp; Role provisioning (Martin Raepple) | SAP on Azure Video" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"></iframe></div></P><H2 id="toc-hId-883691727" id="toc-hId-1565337738"><SPAN>Prerequisites and lab setup</SPAN></H2><P><SPAN>You can continue to use all subscriptions, systems and tenants from your lab in&nbsp;<A href="https://community.sap.com/t5/technology-blogs-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_blank">part II</A>, because all prerequisites&nbsp;also apply for this scenario. In addition, make sure that you meet the following prerequisites to successfully implement the enhanced scope of this scenario:</SPAN></P><UL><LI><SPAN>Administrative access to an <STRONG>SF instance</STRONG> with permissions to setup provisioning credentials and onboard new employees.</SPAN></LI><LI><SPAN>An SCI tenant in a <A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/connect-to-on-premise-systems-in-sap-cloud-identity-infrastructure" target="_blank" rel="noopener noreferrer">matching region</A> of your BTP subaccount for on-premise connectivity that has <A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/target-microsoft-entra-id" target="_blank" rel="noopener noreferrer"><STRONG>Microsoft Entra ID</STRONG> as a target system</A> enabled.</SPAN></LI><LI><SPAN>An <A href="https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-enable-sspr" target="_blank" rel="noopener nofollow noreferrer">Entra ID tenant with self-service password reset (SSPR) enabled</A> and <A href="https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-enable-cloud-sync-sspr-writeback" target="_blank" rel="noopener nofollow noreferrer">Entra Connect cloud sync configured for SSPR writeback</A> to the AD in the scenario.</SPAN></LI><LI><SPAN>Re-run steps 9.1 to 9.10 of&nbsp;<A href="https://community.sap.com/t5/technology-blogs-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_blank">part II</A></SPAN><SPAN>&nbsp;in your CIS tenatn with the updated file <A href="https://github.com/raepple/iam-with-entra/blob/0a73239a81c596811d0e704eb715045c2fdddde0/part3/LocalDirectory.json" target="_blank" rel="noopener nofollow noreferrer">LocalDirectory.json</A> for the LocalDirectory source system, and the updated file <A href="https://github.com/raepple/iam-with-entra/blob/0a73239a81c596811d0e704eb715045c2fdddde0/part3/SAPA4H_IPS.json" target="_blank" rel="noopener nofollow noreferrer">SAPA4H_IPS.json</A> for the SAPA4H target system. The updated files apply minor changes to the transformations of both systems based on <A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/bc-p/14021715/highlight/true#M171937" target="_blank">valuable feedback in the comments to part II</A>. The customAttributes are no longer used to carry over the values for the SAP user name and SNC mapping from Entra to CIS. Instead, the extension attribute sapUserName is used, and construction of the SNC mapping has moved from Entra to the transformation of the SAPA4H target systems (lines 13 to 28).</SPAN></LI></UL><TABLE border="1" width="100%"><TBODY><TR><TD width="100%"><SPAN><STRONG>Note&nbsp;</STRONG><span class="lia-unicode-emoji" title=":loudspeaker:">📢</span><span class="lia-unicode-emoji" title=":loudspeaker:">📢</span><span class="lia-unicode-emoji" title=":loudspeaker:">📢</span></SPAN></TD></TR><TR><TD width="100%"><P><SPAN>This tutorial extends and updates the scenario&nbsp;</SPAN><SPAN>from <A href="https://community.sap.com/t5/technology-blogs-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_blank">part II</A>. Any components and their configurations that are not added or changed in this scenario, such as the SAP Cloud Connector or Active Directory, are not covered in this tutorial. If you arrived here and have not completed <A href="https://community.sap.com/t5/technology-blogs-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_blank">part II</A>, please do so first, and then come back again.</SPAN></P></TD></TR></TBODY></TABLE><P><SPAN>As before, supporting files for this tutorial can be found in the blog series&nbsp;<A href="https://github.com/raepple/iam-with-entra" target="_blank" rel="noopener nofollow noreferrer">GitHub repository</A>. Now l</SPAN>et's get started with setting up the provisioning of new employees from SAP SuccessFactors to Entra.</P><H2 id="toc-hId-1368824233">Create API User in SuccessFactors for provisioning to Entra</H2><P>Calling the SF OData APIs from both SF connector apps (Entra &amp; AD) requires an API User in your SF instance who has the appropriate permissions to <A href="https://learn.microsoft.com/en-us/entra/identity/app-provisioning/sap-successfactors-attribute-reference" target="_blank" rel="noopener nofollow noreferrer">retrieve the required entities and their attributes</A>.</P><TABLE border="1"><TBODY><TR><TD width="46.2879px" height="30px"><STRONG>Step</STRONG></TD><TD width="350px" height="30px"><STRONG>Description</STRONG></TD><TD width="350px" height="30px"><STRONG>Screenshot</STRONG></TD></TR><TR><TD width="46.2879px" height="375px">1.1</TD><TD width="350px" height="375px"><STRONG>Login</STRONG> to your SF instance as a system administrator who has access to the <EM>Admin Center</EM>.</TD><TD width="350px" height="375px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-1.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323059i1B59BBDBCDDD4A33/image-size/medium?v=v2&amp;px=400" role="button" title="1-1.jpg" alt="1-1.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="110px">1.2</TD><TD width="350px" height="110px">Enter <EM>Import Employee Data</EM> in the <STRONG>search bar</STRONG> and select the action from the search results.</TD><TD width="350px" height="110px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-2.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323060i7964CEF9C7817A56/image-size/medium?v=v2&amp;px=400" role="button" title="1-2.jpg" alt="1-2.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="199px">1.3</TD><TD width="350px" height="199px"><P>Select <EM>Basic Import</EM> from the <STRONG>entity</STRONG> drop-down list.</P><P>Click <STRONG>Browse...</STRONG></P></TD><TD width="350px" height="199px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-3.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323061iB05B9AC607ED2276/image-size/medium?v=v2&amp;px=400" role="button" title="1-3.jpg" alt="1-3.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="140px">1.4</TD><TD width="350px" height="140px">Open the <A href="https://github.com/raepple/iam-with-entra/blob/39542db929093ab4a974db4b3bb37b763532762b/part3/entra_api_user_import.csv" target="_blank" rel="noopener nofollow noreferrer">CSV file</A> to import the API user from the <A href="https://github.com/raepple/iam-with-entra/tree/main/part3" target="_blank" rel="noopener nofollow noreferrer">GitHub repo</A>.</TD><TD width="350px" height="140px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-4.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323058i6D52F83BE01AD00E/image-size/medium?v=v2&amp;px=400" role="button" title="1-4.jpg" alt="1-4.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="162px">1.5</TD><TD width="350px" height="162px">Click <STRONG>Validate Import File Data</STRONG>.</TD><TD width="350px" height="162px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-5.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323062i5B8E010A05CC894E/image-size/medium?v=v2&amp;px=400" role="button" title="1-5.jpg" alt="1-5.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="199px">1.6</TD><TD width="350px" height="199px"><P>Check for the <STRONG>Validation Successful</STRONG> message.</P><P>Click <STRONG>Import</STRONG>.</P></TD><TD width="350px" height="199px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-6.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323064i1B97BE0FBD73B4E5/image-size/medium?v=v2&amp;px=400" role="button" title="1-6.jpg" alt="1-6.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="79px">1.7</TD><TD width="350px" height="79px">Wait for the <STRONG>confirmation message</STRONG> that the file has been uploaded and is being processed.</TD><TD width="350px" height="79px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-7.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323063i849299EB0199276B/image-size/medium?v=v2&amp;px=400" role="button" title="1-7.jpg" alt="1-7.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="67px">1.8</TD><TD width="350px" height="67px">Enter <STRONG>Manage Permission Roles</STRONG> in the search bar and select the action from the search results.</TD><TD width="350px" height="67px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-8.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323065iC50F0C2EBE2B30B9/image-size/medium?v=v2&amp;px=400" role="button" title="1-8.jpg" alt="1-8.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="83px">1.9</TD><TD width="350px" height="83px">Click <STRONG>Create</STRONG>.</TD><TD width="350px" height="83px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-9.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323066i85790CC25D33DC75/image-size/medium?v=v2&amp;px=400" role="button" title="1-9.jpg" alt="1-9.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="234px">1.10</TD><TD width="350px" height="234px"><P>Enter <EM>Entra Provisioning Role</EM> as the <STRONG>Name</STRONG> for the new Permission Role that will be assigned to the imported API user.</P><P>Keep the default value <EM>Employee</EM> for <STRONG>User Type</STRONG>, and click <STRONG>Next</STRONG>.</P></TD><TD width="350px" height="234px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-10.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323067i2E19DC6F9C23F8AC/image-size/medium?v=v2&amp;px=400" role="button" title="1-10.jpg" alt="1-10.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="241px">1.11</TD><TD width="350px" height="241px"><P>On the Add Permissions step in the Create Role wizard, enter <EM>Manage Integration Tools</EM> in the <STRONG>search bar</STRONG>&nbsp;and click the lens icon.</P><P><STRONG>Activate</STRONG> the checkbox for <EM>Allow Admin to Access OData API throuch Basic Authentication</EM>.</P></TD><TD width="350px" height="241px"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1-11.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323069i8E60C758B303334E/image-size/medium?v=v2&amp;px=400" role="button" title="1-11.jpg" alt="1-11.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="217px">1.12</TD><TD width="350px" height="217px"><P>Enter <EM>Employee Central API</EM> in the <STRONG>search bar</STRONG> and click the lens icon.</P><P><STRONG>Activate</STRONG> the following checkboxes:</P><UL><LI>Employee Central Foundation OData API (read-only)</LI><LI>Employee Central HRIS OData API (read-only)</LI><LI>Employee Central Foundation OData API (editable)</LI><LI>Employee Central HRIS OData API (editable)</LI></UL></TD><TD width="350px" height="217px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-12.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323169i9E0F15E15CBFFC08/image-size/medium?v=v2&amp;px=400" role="button" title="1-12.jpg" alt="1-12.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="315px">1.13</TD><TD width="350px" height="315px"><P>Enter <EM>Employee Data</EM>&nbsp;in the <STRONG>search bar</STRONG> and click the lens icon.</P><P>Scroll to the <STRONG>User Information</STRONG> section and <STRONG>activate</STRONG> the <STRONG>View</STRONG> checkbox for all attributes.</P></TD><TD width="350px" height="315px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-13.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323071iDECEDA2DBAFB8480/image-size/medium?v=v2&amp;px=400" role="button" title="1-13.jpg" alt="1-13.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="402px">1.14</TD><TD width="350px" height="402px">Scroll down to the <STRONG>HR Information</STRONG> section and <STRONG>active</STRONG> the <STRONG>View</STRONG> checkbox for all attributes.</TD><TD width="350px" height="402px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-14.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323077i26DF741821B67369/image-size/medium?v=v2&amp;px=400" role="button" title="1-14.jpg" alt="1-14.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="277px">1.15</TD><TD width="350px" height="277px"><P>Scroll down to the <STRONG>Employment Details</STRONG> section and <STRONG>activate</STRONG> the <STRONG>View</STRONG> checkbox for all attributes.</P><P>Click <STRONG>Next</STRONG>.</P></TD><TD width="350px" height="277px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-15.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323078i6EEC00AD606F0ACC/image-size/medium?v=v2&amp;px=400" role="button" title="1-15.jpg" alt="1-15.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="284px">1.16</TD><TD width="350px" height="284px">Click <STRONG>Save</STRONG>.</TD><TD width="350px" height="284px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-16.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323079i195554F8B410E08C/image-size/medium?v=v2&amp;px=400" role="button" title="1-16.jpg" alt="1-16.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="188px">1.17</TD><TD width="350px" height="188px">Click <STRONG>Not Now</STRONG>.</TD><TD width="350px" height="188px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-17.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323080i06829747256F7A39/image-size/medium?v=v2&amp;px=400" role="button" title="1-17.jpg" alt="1-17.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="48px">1.18</TD><TD width="350px" height="48px">In the <STRONG>search bar</STRONG>, enter <EM>Manage Permission Groups</EM> and select the action from the search results.</TD><TD width="350px" height="48px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-18.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323081iF0404AAD332EA294/image-size/medium?v=v2&amp;px=400" role="button" title="1-18.jpg" alt="1-18.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="114px">1.19</TD><TD width="350px" height="114px">Click <STRONG>Create New</STRONG>.</TD><TD width="350px" height="114px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-19.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323082i39E502F0AC2012DF/image-size/medium?v=v2&amp;px=400" role="button" title="1-19.jpg" alt="1-19.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="30px">1.20</TD><TD width="350px" height="30px"><P>Enter <EM>Entra Provisioning Group</EM> for the <STRONG>Group Name</STRONG> of the new permission group.</P><P>Add the imported API user to the new group by selecting&nbsp;<STRONG>User Type</STRONG> <EM>Employee</EM>.</P><P>Select <STRONG>User</STRONG> from the <STRONG>People Pool</STRONG> drop down list.</P><P>Select <EM>= (equal to)</EM> as the <STRONG>search operation</STRONG>, and enter <EM>Entra</EM> as the value.&nbsp;</P><P>Select the imported API user record <EM>entra entra provisioning</EM> from the value help.</P><P>Click <STRONG>Done</STRONG>.</P></TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-20.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323083iBA322FC45977BA2B/image-size/medium?v=v2&amp;px=400" role="button" title="1-20.jpg" alt="1-20.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="30px">1.21</TD><TD width="350px" height="30px">Click <STRONG>Done</STRONG>.</TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-21.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323084iD34A7779A1D22864/image-size/medium?v=v2&amp;px=400" role="button" title="1-21.jpg" alt="1-21.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="30px">1.22</TD><TD width="350px" height="30px">In the <STRONG>search bar</STRONG>, enter <EM>Manage Permission Roles&nbsp;</EM>and select the action from the search results.</TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-22.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323085i9E4D04F57C144FC2/image-size/medium?v=v2&amp;px=400" role="button" title="1-22.jpg" alt="1-22.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="30px">1.23</TD><TD width="350px" height="30px">From the list of permission roles, click on the&nbsp;<STRONG>Add Role Assignment</STRONG>&nbsp;action for the new <STRONG>Entra Permission Role</STRONG>.</TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-23.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323087iD936181505CD5BF0/image-size/medium?v=v2&amp;px=400" role="button" title="1-23.jpg" alt="1-23.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="30px">1.24</TD><TD width="350px" height="30px"><P>Keep the default values on the <STRONG>Basic information</STRONG> tab.</P><P>Click <STRONG>Next</STRONG>.</P></TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-24.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323088iE23F2CF4D41C8D1D/image-size/medium?v=v2&amp;px=400" role="button" title="1-24.jpg" alt="1-24.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="30px">1.25</TD><TD width="350px" height="30px"><P>Select the <STRONG>From groups</STRONG> option.</P><P>Click <STRONG>Select Groups</STRONG>.</P></TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-25.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323089i30E7B9BC40B1AD62/image-size/medium?v=v2&amp;px=400" role="button" title="1-25.jpg" alt="1-25.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="30px">1.26</TD><TD width="350px" height="30px"><P><STRONG>Activate</STRONG> the checkbox for the new<STRONG> Entra Provisioning Group</STRONG>.</P><P>Click <STRONG>Select</STRONG>.</P></TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-26.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323090i4D12FD48E1882E0C/image-size/medium?v=v2&amp;px=400" role="button" title="1-26.jpg" alt="1-26.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="30px">1.27</TD><TD width="350px" height="30px">Click <STRONG>Next</STRONG>.</TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-27.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323091i82ED31522003DA7D/image-size/medium?v=v2&amp;px=400" role="button" title="1-27.jpg" alt="1-27.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="30px">1.28</TD><TD width="350px" height="30px"><P>Keep the default values on the <STRONG>Define a Target Population</STRONG> step and click <STRONG>Next</STRONG>.</P><P>Keep the default values on the <STRONG>Define Data Blocking</STRONG> step and click <STRONG>Next</STRONG>.</P><P>On the <STRONG>Preview</STRONG> step, click <STRONG>Save</STRONG>.</P></TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-28.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323092iC9BBDF41415911E5/image-size/medium?v=v2&amp;px=400" role="button" title="1-28.jpg" alt="1-28.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="30px">1.29</TD><TD width="350px" height="30px">Enter <EM>Reset User Passwords</EM> in the <STRONG>search bar</STRONG> and select the action from the results list.</TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-29.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323093iDD8EF62B93BEB298/image-size/medium?v=v2&amp;px=400" role="button" title="1-29.jpg" alt="1-29.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="30px">1.30</TD><TD width="350px" height="30px"><P>In the <STRONG>Username</STRONG> field, enter <EM>entra_provisioning_user</EM>.</P><P>Select the imported API user <STRONG>entra_provisioning_user (entra entra provisioning)</STRONG> from the value help.</P></TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-30.jpg" style="width: 332px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323094i60A7CE0AFF45FB56/image-size/medium?v=v2&amp;px=400" role="button" title="1-30.jpg" alt="1-30.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="30px">1.31</TD><TD width="350px" height="30px"><P>Select the user in the result list.</P><P>Enter the same value for the password in the <STRONG>New Password</STRONG> and <STRONG>Confirm Password</STRONG> field.</P><P>Click <STRONG>Reset User Password</STRONG>.</P></TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-31.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323095i0713465BAAE3F153/image-size/medium?v=v2&amp;px=400" role="button" title="1-31.jpg" alt="1-31.jpg" /></span></TD></TR><TR><TD width="46.2879px" height="30px">1.32</TD><TD width="350px" height="30px">The <STRONG>confirmation</STRONG> that the password has been resetted is shown.</TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="1-32.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323096i5B5B1CB0A4D66DAE/image-size/medium?v=v2&amp;px=400" role="button" title="1-32.jpg" alt="1-32.jpg" /></span></TD></TR></TBODY></TABLE><H2 id="toc-hId-1172310728">Setup provisioning from SuccessFactors to Active Directory</H2><P><SPAN>The new API user's credentials are now being used to setup the SAP SuccessFactors connector for provisioning new employees to BestRun's corporate AD.&nbsp; This&nbsp;</SPAN>ensures that every employee managed in SF also gets a user account in AD which is required for SSO via SNC and Kerberos when accessing BestRun's SAP system(s) from a corporate AD domain-joined workstation.</P><TABLE border="1" width="744px"><TBODY><TR><TD width="46px" height="30px"><STRONG>Step</STRONG></TD><TD width="417px" height="30px"><STRONG>Description</STRONG></TD><TD width="281px" height="30px"><STRONG>Screenshot</STRONG></TD></TR><TR><TD width="46px" height="124px">2.1</TD><TD width="417px" height="124px"><P><STRONG>Login</STRONG><SPAN>&nbsp;with your Microsoft Entra tenant administrator to the&nbsp;</SPAN><A href="https://entra.microsoft.com/?Microsoft_AAD_Connect_Provisioning_forceSchemaEditorEnabled=true" target="_blank" rel="noopener nofollow noreferrer">Entra admin center</A><SPAN>&nbsp;with an&nbsp;</SPAN><STRONG>additional URL query parameter</STRONG><SPAN>&nbsp;</SPAN><EM>Microsoft_AAD_Connect_Provisioning_<BR />forceSchemaEditorEnabled</EM><SPAN>&nbsp;set to&nbsp;</SPAN><EM>true</EM><SPAN>:&nbsp;</SPAN><A href="https://entra.microsoft.com/?Microsoft_AAD_Connect_Provisioning_forceSchemaEditorEnabled=true" target="_blank" rel="nofollow noopener noreferrer">https://entra.microsoft.com/?Microsoft_AAD_Connect_Provisioning_forceSchemaEditorEnabled=true</A><SPAN>.</SPAN></P><P>Select <STRONG>Enterprise apps</STRONG> from the&nbsp;Entra tenant's main navigation menu.</P><P>Click <STRONG>New application</STRONG>.</P></TD><TD width="281px" height="124px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-1.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/324672i56AFF37762D75ADB/image-size/medium?v=v2&amp;px=400" role="button" title="5-1.jpg" alt="5-1.jpg" /></span></TD></TR><TR><TD width="46px" height="226px">2.2</TD><TD width="417px" height="226px"><P>Enter SuccessFactors to in the search bar.</P><P>Click the tile with label <STRONG>SuccessFactors to Active Directory User Provisioning</STRONG>.</P></TD><TD width="281px" height="226px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-2.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/324673i59171A3BBEC8679C/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-2.jpg" alt="5-2.jpg" /></span></TD></TR><TR><TD width="46px" height="277px">2.3</TD><TD width="417px" height="277px"><P>Enter a name for the new enteprise app (for example <EM>SuccessFactors to Active Directory User Provisioning &lt;your SF instance company ID&gt;</EM>)<STRONG>.</STRONG></P><P>Click&nbsp;<STRONG>Create</STRONG>.</P></TD><TD width="281px" height="277px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-3.jpg" style="width: 394px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/324675i88765EAFE9C08493/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-3.jpg" alt="5-3.jpg" /></span></TD></TR><TR><TD width="46px" height="262px">2.4</TD><TD width="417px" height="262px">Select <STRONG>Provisioning</STRONG> from the navigation menu of the newly created enterprise app.</TD><TD width="281px" height="262px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-4.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/324676i7AE754A575B97BDD/image-size/medium?v=v2&amp;px=400" role="button" title="5-4.jpg" alt="5-4.jpg" /></span></TD></TR><TR><TD width="46px" height="446px">2.5</TD><TD width="417px" height="446px"><P>For the configuration settings in the next step, the distinguished name (DN) of the path in AD where new users should be created is required.&nbsp;</P><P>You can either create a new container in AD for the onboarded employees from SF, or use an existing one.</P><P>The screenshot shows the <STRONG>Active Directory Users and Computers</STRONG> tool with the default <STRONG>Users</STRONG> container selected and its properties dialog opened. From the tab <STRONG>Attribute Editor</STRONG>, the attribute <STRONG>distinguishedName</STRONG> is selected, and its value <EM>CN=Users,DC=corp,DC=bestrun,DC=com</EM> copied for the configuration of the following step (note that the <EM>DC</EM> (domain) components in your lab setup may be different.).</P></TD><TD width="281px" height="446px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-5.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/324677iDFB51F0AF8E0FB5A/image-size/medium?v=v2&amp;px=400" role="button" title="5-5.jpg" alt="5-5.jpg" /></span></TD></TR><TR><TD width="46px" height="476px">2.6</TD><TD width="417px" height="476px"><P>Select <STRONG>Provisioning</STRONG> from the navigation menu and expand the <STRONG>Admin Credentials</STRONG> section.</P><P>&nbsp;</P><P>Enter the following values:</P><UL><LI><STRONG>Tenant URL</STRONG>: Provide the tenant URL of your SF instance's API server which can be <A href="https://help.sap.com/docs/successfactors-platform/sap-successfactors-api-reference-guide-odata-v2/list-of-sap-successfactors-api-servers" target="_blank" rel="noopener noreferrer">looked-up here</A>. <STRONG>Note</STRONG>: Do <EM>not</EM> add the URL scheme (<EM>https://</EM>) to the value, but only the hostname.</LI><LI><STRONG>Default OU for New Users</STRONG>: Paste the value from the previous step, or enter any path in your corporate AD where you want new users to be created.</LI><LI><STRONG>Active Directory Domain</STRONG>: Select the domain from the drop-down box that your Entra Connect Sync agent is configured for.</LI><LI><STRONG>Admin Password</STRONG>: The vlaue you entered when resetting the new API user's password in step 1.31</LI><LI><STRONG>Admin Username</STRONG>: The name of the imported user in step 1.4 (<EM>entra_provisioning_user</EM>), followed by the <EM>@-</EM>sign and the&nbsp;company&nbsp;<SPAN>ID of your SF instance.</SPAN></LI></UL><P><SPAN>Click <STRONG>Test Connection</STRONG>.</SPAN></P></TD><TD width="281px" height="476px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-6.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/324688i03D4877882494EFD/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-6.jpg" alt="5-6.jpg" /></span></TD></TR><TR><TD width="46px" height="179px">2.7</TD><TD width="417px" height="179px"><P><SPAN>Wait for the&nbsp;</SPAN><STRONG>confirmation</STRONG><SPAN>&nbsp;that the values could be successfully verified. Testing the connection also checks that the permissions of the provided API user are correctly set in the SF instance.</SPAN></P><P>Click<SPAN>&nbsp;</SPAN><STRONG>Save</STRONG>.</P></TD><TD width="281px" height="179px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-7.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/324690iAB199D9C8B709667/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-7.jpg" alt="5-7.jpg" /></span></TD></TR><TR><TD width="46px" height="103px">2.8</TD><TD width="417px" height="103px"><P>Expand the<SPAN>&nbsp;</SPAN><STRONG>Mappings</STRONG><SPAN>&nbsp;</SPAN>section.</P><P>Click<SPAN>&nbsp;</SPAN><STRONG>Provision SuccessFactors Users</STRONG>.</P></TD><TD width="281px" height="103px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-8.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/324691iE85923BF359F961E/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-8.jpg" alt="5-8.jpg" /></span></TD></TR><TR><TD width="46px" height="341px">2.9</TD><TD width="417px" height="341px"><P>By default, all employee records in the connected SF instance will be synchronized to Entra once provisioning is started.</P><P>For testing purposes of this scenario you will restrict provisioning to the test user only.</P><P>Click<SPAN>&nbsp;</SPAN><STRONG>All records</STRONG>.</P></TD><TD width="281px" height="341px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-9.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/324692i73A9FF0C45F84FE7/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-9.jpg" alt="5-9.jpg" /></span></TD></TR><TR><TD width="46px" height="199px">2.10</TD><TD width="417px" height="199px">Click<SPAN>&nbsp;</SPAN><STRONG>Add new filter group</STRONG>.</TD><TD width="281px" height="199px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-10.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/324693i2BAE8DA353E0FC92/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-10.jpg" alt="5-10.jpg" /></span></TD></TR><TR><TD width="46px" height="237px">2.11</TD><TD width="417px" height="237px"><P>Enter the following value for the new filter group:</P><UL><LI><STRONG>Source attribute</STRONG>: personIdExternal</LI><LI><STRONG>Operator</STRONG>: EQUALS</LI><LI><STRONG>Clause value</STRONG>:<SPAN>&nbsp;</SPAN><EM>llarson</EM></LI></UL><P>For the new<SPAN>&nbsp;</SPAN><STRONG>Scoping Filter Title</STRONG>, enter<SPAN>&nbsp;</SPAN><EM>Filter for llarson</EM>.</P><P>Click<SPAN>&nbsp;</SPAN><STRONG>Apply</STRONG>.</P></TD><TD width="281px" height="237px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-11.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/324694i50E597A361BA319E/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-11.jpg" alt="5-11.jpg" /></span></TD></TR><TR><TD width="46px" height="286px">2.12</TD><TD width="417px" height="286px">Click<SPAN>&nbsp;</SPAN><STRONG>Apply</STRONG>.</TD><TD width="281px" height="286px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-12.jpg" style="width: 382px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/324695iBA005EED2452341F/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-12.jpg" alt="5-12.jpg" /></span></TD></TR><TR><TD width="46px" height="222px">2.13</TD><TD width="417px" height="222px">For the <STRONG>userPrincipalName</STRONG> attribute mapping, click <STRONG>Edit</STRONG>.</TD><TD width="281px" height="222px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-13.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/326811i486719FD86D2A9CC/image-size/medium?v=v2&amp;px=400" role="button" title="5-13.jpg" alt="5-13.jpg" /></span></TD></TR><TR><TD width="46px" height="251px">2.14</TD><TD width="417px" height="251px"><P>Change the <STRONG>expression</STRONG> from</P><PRE>[personIdExternal] </PRE><P>to</P><PRE>Join("@", [personIdExternal], "corp.bestrun.com")</PRE><P><STRONG>Replace</STRONG> "<EM>corp.bestrun.com</EM>" with your AD domain name.</P><P>Click <STRONG>Ok</STRONG>.</P></TD><TD width="281px" height="251px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="2-14.jpg" style="width: 376px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329624i0D3CD6B1B1A35025/image-size/medium?v=v2&amp;px=400" role="button" title="2-14.jpg" alt="2-14.jpg" /></span></TD></TR><TR><TD width="46px" height="176px">2.15</TD><TD width="417px" height="176px"><SPAN>Click&nbsp;</SPAN><STRONG>Save</STRONG><SPAN>&nbsp;and confirm with&nbsp;</SPAN><STRONG>Yes</STRONG><SPAN>.</SPAN></TD><TD width="281px" height="176px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-15.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/324746iDD3D0A40B06F915D/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-15.jpg" alt="5-15.jpg" /></span></TD></TR><TR><TD width="46px" height="56px">2.16</TD><TD width="417px" height="56px"><STRONG>Close</STRONG> the <STRONG>Attribute Mapping</STRONG> dialog box.</TD><TD width="281px" height="56px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-16.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/324747i38249571B6D687FE/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-16.jpg" alt="5-16.jpg" /></span></TD></TR></TBODY></TABLE><H2 id="toc-hId-975797223">Setup users and groups provisioning to SAP CIS in Entra</H2><P>To use the new features for <EM>groups provisioning</EM> and <EM>OAuth-based authentication</EM> in the SCIM-based SAP CIS provisioning connector, a new enterprise application will be created. You may want to remove the CIS enterprise app created in steps 6.1 to 6.23 of part II.</P><TABLE border="1"><TBODY><TR><TD width="46.3542px" height="30px"><STRONG>Step</STRONG></TD><TD width="364.875px" height="30px"><STRONG>Description</STRONG></TD><TD width="350px" height="30px"><STRONG>Screenshot</STRONG></TD></TR><TR><TD width="46.3542px" height="136px">3.1</TD><TD width="364.875px" height="136px"><P>Select <STRONG>Enterprise apps</STRONG> from the&nbsp;Entra tenant's main navigation menu.</P><P>Click <STRONG>New application</STRONG>.</P></TD><TD width="350px" height="136px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="4-1.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323133i8F1A63EF538DD48D/image-size/medium?v=v2&amp;px=400" role="button" title="4-1.jpg" alt="4-1.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="402px">3.2</TD><TD width="364.875px" height="402px"><P>Enter <EM>SAP Cloud Identity</EM> in the <STRONG>search bar</STRONG>.</P><P>Click on the tile with the label <STRONG>SAP Cloud Identity Services</STRONG>.</P></TD><TD width="350px" height="402px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="4-2.jpg" style="width: 337px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323134iE0A282BDAEC80CF2/image-size/medium?v=v2&amp;px=400" role="button" title="4-2.jpg" alt="4-2.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="402px">3.3</TD><TD width="364.875px" height="402px"><P>Provide <STRONG>name</STRONG> for the new instance, for example <EM>SAP Cloud Identity Service (&lt;your CIS tenant id&gt;)</EM>.</P><P>Click <STRONG>Create</STRONG>.</P></TD><TD width="350px" height="402px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="4-3.jpg" style="width: 297px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323135i98257ECEB527B844/image-size/medium?v=v2&amp;px=400" role="button" title="4-3.jpg" alt="4-3.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="285px">3.4</TD><TD width="364.875px" height="285px">Back on the <STRONG>Overview</STRONG> page, click the <STRONG>Provision User Accounts</STRONG> tile.</TD><TD width="350px" height="285px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="4-8.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323143i947680C34D8D9AB9/image-size/medium?v=v2&amp;px=400" role="button" title="4-8.jpg" alt="4-8.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="730px">3.5</TD><TD width="364.875px" height="730px"><P>Switch the <STRONG>Provisioning Mode</STRONG> from <STRONG>Manual</STRONG> to <STRONG>Automatic</STRONG>.</P><P><STRONG>Expand</STRONG> the <STRONG>Admin Credentials</STRONG> section and enter the following values:</P><UL><LI><STRONG>Authentication Method: </STRONG><EM>OAuth2 Client Credentials Grant</EM></LI><LI><STRONG>Tenant URL</STRONG>: Provide the SCIM endpoint URL of your CIS tenant, for example&nbsp; <EM>https://&lt;your tenant id&gt;.accounts.ondemand.com/scim</EM></LI><LI><STRONG>Token Endpoint</STRONG>: The OAuth token endpoint URL of your CIS tenant (for example&nbsp;<EM>https://&lt;your tenant id&gt;.accounts.ondemand.com/oauth2/token</EM>). You can lookup the token endpoint in your CIS tenant's admin console by navigating to <STRONG>Applications and Resource -&gt; Tenant settings -&gt; Single Sign-On -&gt; OpenID Connect Configuration</STRONG>.&nbsp;</LI><LI><STRONG>Client Credentials</STRONG>: Enter the value for Client ID captured in <A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_blank">step 4.7 of part II</A>.</LI><LI><STRONG>Client Secret</STRONG>:&nbsp;Enter the value for Client secret captured in <A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_blank">step 4.7 of part II</A>.</LI></UL><P>Click <STRONG>Test Connection</STRONG>.</P></TD><TD width="350px" height="730px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="4-9.jpg" style="width: 348px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323144i3BCBCD4B1FA953A3/image-size/medium?v=v2&amp;px=400" role="button" title="4-9.jpg" alt="4-9.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="181px">3.6</TD><TD width="364.875px" height="181px"><P>Wait for the <STRONG>confirmation</STRONG> that the configuration has been tested successfully.</P><P>Click <STRONG>Save</STRONG>.</P></TD><TD width="350px" height="181px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="4-10.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/323145i7FF8A69083A431E2/image-size/medium?v=v2&amp;px=400" role="button" title="4-10.jpg" alt="4-10.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="218px">3.7</TD><TD width="364.875px" height="218px"><P>Next, adjust the mappings to add the user's on-premise principal name as the SAP user name.</P><P><STRONG>Expand</STRONG> the <STRONG>Mappings</STRONG> section.</P><P>Click <STRONG>Provision Microsoft Entra ID Users</STRONG>.&nbsp;</P></TD><TD width="350px" height="218px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="3-7.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329694iBDC55959E9C17580/image-size/medium?v=v2&amp;px=400" role="button" title="3-7.jpg" alt="3-7.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="402px">3.8</TD><TD width="364.875px" height="402px"><P>Activate the checkbox<SPAN>&nbsp;</SPAN><STRONG>Show advanced options</STRONG>.</P><P>By accessing the Microsoft Entra Admin Center with the addition URL query parameter in step 2.1, the additional option to edit the attributes for Entra appears in the<SPAN>&nbsp;</SPAN><STRONG>Supported Attributes</STRONG><SPAN>&nbsp;</SPAN>section.</P><P>Click<SPAN>&nbsp;</SPAN><STRONG>Edit attribute list for Microsoft Entra ID</STRONG>.</P></TD><TD width="350px" height="402px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="3-8.jpg" style="width: 246px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329695i2151DBD168134851/image-size/medium?v=v2&amp;px=400" role="button" title="3-8.jpg" alt="3-8.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="403px">3.9</TD><TD width="364.875px" height="403px"><P>Scroll down to the last row in the table and enter</P><PRE>onPremisesUserPrincipalName</PRE><P>in the attribute<SPAN>&nbsp;</SPAN><STRONG>name</STRONG><SPAN>&nbsp;</SPAN>field.</P><P>Click<SPAN>&nbsp;</SPAN><STRONG>Save</STRONG>, and confirm with<SPAN>&nbsp;</SPAN><STRONG>Yes</STRONG>.</P></TD><TD width="350px" height="403px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="3-9.jpg" style="width: 306px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329697iD9D8C8031DB15C7F/image-size/medium?v=v2&amp;px=400" role="button" title="3-9.jpg" alt="3-9.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="176px">3.10</TD><TD width="364.875px" height="176px">Click <STRONG>Edit attribute list for SAP Cloud Identity Services</STRONG>.</TD><TD width="350px" height="176px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="3-10.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329698i74703557BD30CF93/image-size/medium?v=v2&amp;px=400" role="button" title="3-10.jpg" alt="3-10.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="195px">3.11</TD><TD width="364.875px" height="195px"><P>Scroll down to the last row in the table and enter</P><PRE>urn:ietf:params:scim:schemas:extension:sap:<BR />2.0:User:sapUserName</PRE><P>in the attribute<SPAN>&nbsp;</SPAN><STRONG>name</STRONG><SPAN>&nbsp;</SPAN>field.</P><P>Click<SPAN>&nbsp;</SPAN><STRONG>Save</STRONG>, and confirm with<SPAN>&nbsp;</SPAN><STRONG>Yes</STRONG>.</P></TD><TD width="350px" height="195px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="3-11.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329699iCFB95D3AB070BF76/image-size/medium?v=v2&amp;px=400" role="button" title="3-11.jpg" alt="3-11.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="283px">3.12</TD><TD width="364.875px" height="283px">Click <STRONG>Add New Mapping</STRONG>.</TD><TD width="350px" height="283px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="3-12.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329700i22F97F8770DDB648/image-size/medium?v=v2&amp;px=400" role="button" title="3-12.jpg" alt="3-12.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="358px">3.13</TD><TD width="364.875px" height="358px"><P>Select "Expression" for<SPAN>&nbsp;</SPAN><STRONG>Mapping type</STRONG>.</P><P>The Entra attribute "<SPAN>onPremisesUserPrincipalName"</SPAN><SPAN>&nbsp;</SPAN>added in step 3.9 has the format "&lt;Windows user name&gt;@&lt;Kerberos realm name&gt;". The<SPAN>&nbsp;</SPAN><EM>SAP login name</EM><SPAN>&nbsp;</SPAN>should be equal to the<SPAN>&nbsp;</SPAN><EM>Windows user name</EM>&nbsp;that can be considered unique across all users in the organization.</P><P>The following expression<SPAN>&nbsp;</SPAN><A href="https://learn.microsoft.com/en-us/entra/identity/app-provisioning/functions-for-customizing-application-data#split" target="_blank" rel="noopener nofollow noreferrer">extracts</A><SPAN>&nbsp;</SPAN>the Windows user name from the "onPremisesUserPrincipalName" and converts it<SPAN>&nbsp;</SPAN><SPAN><A href="https://learn.microsoft.com/en-us/entra/identity/app-provisioning/functions-for-customizing-application-data#toupper" target="_blank" rel="noopener nofollow noreferrer">to upper case</A>&nbsp;for the SAP login name:</SPAN></P><PRE>Item(Split([onPremisesUserPrincipalName], "@"), 1)</PRE><P><SPAN>Enter this string for the&nbsp;<STRONG>Expression</STRONG>.</SPAN></P><P><SPAN>As the&nbsp;<STRONG>Target attribute</STRONG>, select&nbsp;"<EM>urn:ietf:params:scim:schemas:extension:sap: 2.0:User:sapUserName</EM>" from the list.</SPAN></P><P><SPAN>Click&nbsp;<STRONG>Ok</STRONG>.</SPAN></P></TD><TD width="350px" height="358px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="3-13.jpg" style="width: 382px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329702i7C8E3B6ED1F877F9/image-size/medium?v=v2&amp;px=400" role="button" title="3-13.jpg" alt="3-13.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="30px">3.14</TD><TD width="364.875px" height="30px">Click <STRONG>Save</STRONG>.</TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="3-14.jpg" style="width: 296px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329703iD1118C28FD471D3D/image-size/medium?v=v2&amp;px=400" role="button" title="3-14.jpg" alt="3-14.jpg" /></span></TD></TR></TBODY></TABLE><H2 id="toc-hId-779283718">Configure permissions in Entra for provisioning of groups from CIS</H2><P>CIS provisions the groups (representing the PFCG roles in the SAP backend) with the Graph API to Entra. The required permissions to do so are configured in this step in the application registration created as part of the enterprise app for CIS.&nbsp;&nbsp;</P><TABLE border="1"><TBODY><TR><TD width="46.3542px" height="30px"><STRONG>Step</STRONG></TD><TD width="350px" height="30px"><STRONG>Description</STRONG></TD><TD width="350px" height="30px"><STRONG>Screenshot</STRONG></TD></TR><TR><TD width="46.3542px" height="282px">4.1</TD><TD width="350px" height="282px"><P>From the navigation menu, select <STRONG>App registrations</STRONG>.</P><P>On the <STRONG>All applications</STRONG> tab, search for the name of your enterprise app chosen in step 3.3, for example <EM>SAP Cloud Identity Services (&lt;tenant id&gt;).</EM></P><P><STRONG>Select</STRONG> the application registration for the CIS enterprise app from the search results.</P></TD><TD width="350px" height="282px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-1.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327207i03F6B4E3A6A72E7A/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-1.jpg" alt="5-1.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="300px">4.2</TD><TD width="350px" height="300px"><P>Select <STRONG>Certificates &amp; Secrets</STRONG> from the navigation menu.</P><P>Switch to the <STRONG>Client secrets</STRONG> tab.</P><P>Click <STRONG>New client secret</STRONG>.</P></TD><TD width="350px" height="300px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-2.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327208i0586C3A913EE0848/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-2.jpg" alt="5-2.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="137px">4.3</TD><TD width="350px" height="137px"><P>Enter a <STRONG>description</STRONG> for the new secret, for example <EM>Entra Provisioning </EM>and select an <STRONG>expiration</STRONG> period.</P><P>Click <STRONG>Add</STRONG>.</P></TD><TD width="350px" height="137px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-3.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327210iB93CCD71FB992396/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-3.jpg" alt="5-3.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="103px">4.4</TD><TD width="350px" height="103px"><STRONG>Copy</STRONG> the <STRONG>value</STRONG> of the new secret to the clipboard and paste it to a temporary text file. It will be used in a later step.</TD><TD width="350px" height="103px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-4.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327212iAA9CC4EEB6CC3EC6/image-size/medium?v=v2&amp;px=400" role="button" title="5-4.jpg" alt="5-4.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="248px">4.5</TD><TD width="350px" height="248px"><P>Select <STRONG>API permissions</STRONG> from the navigation menu.</P><P>Click <STRONG>Add a permission</STRONG>.</P></TD><TD width="350px" height="248px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-5.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327293iA7C5257E8572075F/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-5.jpg" alt="5-5.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="209px">4.6</TD><TD width="350px" height="209px">From the <STRONG>Microsoft APIs</STRONG>, click on the <STRONG>Microsoft Graph</STRONG> tile.</TD><TD width="350px" height="209px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-6.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327294iDAD21873B05014AA/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-6.jpg" alt="5-6.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="404px">4.7</TD><TD width="350px" height="404px"><P>CIS calls the Graph APIs on its own behalf, and not on-behalf-of a signed-in user. Therefore, select <STRONG>Application permissions</STRONG>.</P><P>In the <STRONG>search</STRONG> bar, start typing&nbsp;<EM>Group.ReadWrite.</EM></P><P>From the result list, activate the checkbox for the permission <STRONG>Group.ReadWrite.All</STRONG>.</P><P>Click <STRONG>Add permissions</STRONG>.</P><P><STRONG><span class="lia-unicode-emoji" title=":loudspeaker:">📢</span>Note</STRONG>: To follow the <A href="https://en.wikipedia.org/wiki/Principle_of_least_privilege" target="_blank" rel="noopener nofollow noreferrer"><EM>least privilege principle,</EM></A>&nbsp;only the permissions required for this scenario are added. Although CIS can also provision users to Entra, which would require an additional Graph API permission, we do not use this feature, and therefore only add the permission to manage groups.</P></TD><TD width="350px" height="404px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-7.jpg" style="width: 242px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327295iC032A3B4542BC599/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-7.jpg" alt="5-7.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="82px">4.8</TD><TD width="350px" height="82px">To&nbsp;approve the new permission, provide the required admin consent by clicking <STRONG>Grant admin consent for &lt;your tenant domain&gt;</STRONG>.</TD><TD width="350px" height="82px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-8.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327296iB2D3D091D7AC8BF2/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="5-8.jpg" alt="5-8.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="166px">4.9</TD><TD width="350px" height="166px"><P>Select <STRONG>Overview</STRONG> from the navigation menu.</P><P><STRONG>Copy</STRONG> the <STRONG>Application (client) ID</STRONG> to the clipboard, and paste it to the temporary text file where you've already kept the secret value.</P></TD><TD width="350px" height="166px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-5.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327258iA977DE771BC2986E/image-size/medium?v=v2&amp;px=400" role="button" title="5-5.jpg" alt="5-5.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="131px">4.10</TD><TD width="350px" height="131px">Click <STRONG>Endpoints</STRONG>.</TD><TD width="350px" height="131px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="5-6.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327259iA021C493FA89024E/image-size/medium?v=v2&amp;px=400" role="button" title="5-6.jpg" alt="5-6.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="226px">4.11</TD><TD width="350px" height="226px"><STRONG>Copy</STRONG> the <STRONG>OAuth 2.0 token endpoint (v1)</STRONG> to the clipboard and paste it to the temporary text file where you've already kept the other configuration values.</TD><TD width="350px" height="226px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="MartinRaepple_0-1760555633386.jpeg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328060iE6CF4E321AAF7DA9/image-size/medium?v=v2&amp;px=400" role="button" title="MartinRaepple_0-1760555633386.jpeg" alt="MartinRaepple_0-1760555633386.jpeg" /></span><P>&nbsp;</P></TD></TR></TBODY></TABLE><H2 id="toc-hId-582770213">Add SAP as source system in IPS</H2><P>Now it is time to configure the additional <EM>source system</EM> in IPS for <EM>reading</EM> roles from the backend and create the groups from them in the tenant's local directory.</P><TABLE border="1"><TBODY><TR><TD width="46.2879px" height="30px"><STRONG>Step</STRONG></TD><TD width="350px" height="30px"><STRONG>Description</STRONG></TD><TD width="350px" height="30px"><STRONG>Screenshot</STRONG></TD></TR><TR><TD>5.1</TD><TD><P><STRONG>Login</STRONG>&nbsp;as the CIS administrator to your <STRONG>CIS tenant's admin console</STRONG> at https://&lt;tenantID&gt;.accounts.ondemand.com/admin.</P><P>From the <STRONG>Identity Provisioning</STRONG> menu, select <STRONG>Source Systems</STRONG>.</P></TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="6-1.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327298i1ACEE3B172FF52EB/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="6-1.jpg" alt="6-1.jpg" /></span></TD></TR><TR><TD>5.2</TD><TD>Click <STRONG>Add</STRONG>.</TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="6-2.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327302i34B464E2D8AE2999/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="6-2.jpg" alt="6-2.jpg" /></span></TD></TR><TR><TD>5.3</TD><TD><P>You will create the new source system from a file, which can be found in the tutorial series&nbsp;<A href="https://github.com/raepple/iam-with-entra/tree/main/part3" target="_blank" rel="nofollow noopener noreferrer">GitHub repository.&nbsp;</A></P><P>Click <STRONG>Browse...</STRONG> and open the file <A href="https://github.com/raepple/iam-with-entra/blob/bcb4b9e7bf94904c5d675b28e800a679b5c86352/part3/SAP%20A4H%20Source%20System.json" target="_blank" rel="noopener nofollow noreferrer">SAP A4H Source System.json</A> from the file dialog.</P><P>Click <STRONG>Save</STRONG>.</P></TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="6-3.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327445i1165420C499BB759/image-size/medium?v=v2&amp;px=400" role="button" title="6-3.jpg" alt="6-3.jpg" /></span></TD></TR><TR><TD>5.4</TD><TD><P>Switch to the <STRONG>Transformations</STRONG> tab to review the configuration.</P><P>Only roles are read from the SAP Application Server ABAP and created as groups in CIS. Reading users from ABAP has been removed from the transformation settings, because Entra is the SOA for them in this scenario.</P></TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="6-4.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327446i03CCECBD78497658/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="6-4.jpg" alt="6-4.jpg" /></span></TD></TR><TR><TD>5.5</TD><TD>Switch to the <STRONG>Properties</STRONG> tab. For testing purposes, the <EM>abap.role.name.filter</EM> property is set on the source system to only read roles starting with the string SAP_BC_EPM.</TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="6-5.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327447i19F6190E240FF571/image-size/medium?v=v2&amp;px=400" role="button" title="6-5.jpg" alt="6-5.jpg" /></span></TD></TR></TBODY></TABLE><H2 id="toc-hId-386256708">Add Entra tenant as target system in IPS</H2><TABLE border="1"><TBODY><TR><TD width="46.2879px" height="30px"><STRONG>Step</STRONG></TD><TD width="350px" height="30px"><STRONG>Description</STRONG></TD><TD width="350px" height="30px"><STRONG>Screenshot</STRONG></TD></TR><TR><TD>6.1</TD><TD>Select <STRONG>Target Systems</STRONG> from the <STRONG>Identity Provisioning</STRONG> menu.</TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="7-1.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327454i2F9769038007B985/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="7-1.jpg" alt="7-1.jpg" /></span></TD></TR><TR><TD>6.2</TD><TD>Click <STRONG>Add</STRONG>.</TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="7-2.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327455i96684903D4D04867/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="7-2.jpg" alt="7-2.jpg" /></span></TD></TR><TR><TD>6.3</TD><TD><P>Click <STRONG>Browse...</STRONG> and select the file&nbsp;<SPAN><A href="https://github.com/raepple/iam-with-entra/blob/bcb4b9e7bf94904c5d675b28e800a679b5c86352/part3/Entra%20ID%20Target%20System.json" target="_blank" rel="noopener nofollow noreferrer">Entra ID Target System.json</A> from the <A href="https://github.com/raepple/iam-with-entra/tree/main/part3" target="_blank" rel="nofollow noopener noreferrer">GitHub repository</A>.</SPAN></P><P><SPAN>Switch to the <STRONG>Properties</STRONG> tab.</SPAN></P></TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="7-3.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327466iEC04E4830B9B0D86/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="7-3.jpg" alt="7-3.jpg" /></span></TD></TR><TR><TD>6.4</TD><TD><P>Paste the values from your temporary text file into the following properties:</P><UL><LI><STRONG>OAuth2TokenServiceURL</STRONG>: Value for the <STRONG>OAuth 2.0 token endpoint (v1)</STRONG> copied in step 4.11</LI><LI><STRONG>Password</STRONG>: Value for the <STRONG>secret</STRONG> copied in step 4.4</LI><LI><STRONG>User</STRONG>: Value for the <STRONG>Application (client) ID</STRONG> copied in step 4.9</LI></UL><P>Click <STRONG>Save</STRONG>.</P></TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="7-4.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327472iAF5AEF0A3C848041/image-size/medium?v=v2&amp;px=400" role="button" title="7-4.jpg" alt="7-4.jpg" /></span></TD></TR><TR><TD>6.5</TD><TD><P>Switch to the <STRONG>Transformations</STRONG> tab to review the imported configuration.</P><P>Similar to the new source system, the target systems also only provisions groups to Entra. Users have been removed from the default transformation.</P></TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="7-5.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327474iAA9A0B6E9D67C804/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="7-5.jpg" alt="7-5.jpg" /></span></TD></TR></TBODY></TABLE><H2 id="toc-hId-189743203">Provision the PFCG roles as groups to Entra</H2><P>To continue with the configuration in Entra ID Governance for the <EM>SAP EPM</EM> access package which includes the <EM>SAP_BC_EPM_DEMO, </EM>this group must be provisioned first from the SAP system via CIS to Entra. With the configuration of the new source and target system in CIS, you can start this initial provisioning.</P><TABLE border="1"><TBODY><TR><TD width="46.3542px" height="30px"><STRONG>Step</STRONG></TD><TD width="315.292px" height="30px"><STRONG>Description</STRONG></TD><TD width="315px" height="30px"><STRONG>Screenshot</STRONG></TD></TR><TR><TD width="46.3542px" height="200px">7.1</TD><TD width="315.292px" height="200px"><P>Select <STRONG>Source Systems</STRONG> from the <STRONG>Identity Provisioning</STRONG> menu.</P><P>From the list of <STRONG>Customer Managed</STRONG> source systems, select the <STRONG>SAP A4H</STRONG> source system.</P><P>Switch to the <STRONG>Jobs</STRONG> tab.</P></TD><TD width="315px" height="200px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="7-1.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328077iB5B0BB5584EF9636/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="7-1.jpg" alt="7-1.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="30px">7.2</TD><TD width="315.292px" height="30px">Click <STRONG>Run Now</STRONG> for the <STRONG>Read Job</STRONG> type.</TD><TD width="315px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="7-2.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328079i5C498752E1408D68/image-size/medium?v=v2&amp;px=400" role="button" title="7-2.jpg" alt="7-2.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="30px">7.3</TD><TD width="315.292px" height="30px">Select <STRONG>Provisioning Logs</STRONG> from the <STRONG>Identity Provisioning</STRONG> menu.</TD><TD width="315px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="7-3.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328080i4FE62ADE19D4102B/image-size/medium?v=v2&amp;px=400" role="button" title="7-3.jpg" alt="7-3.jpg" /></span></TD></TR><TR><TD>7.4</TD><TD><STRONG>Select</STRONG> the first job for the <STRONG>SAP A4H</STRONG> source system from the list to view the execution logs.</TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="7-4.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328081i34F02D28746F2E5D/image-size/medium?v=v2&amp;px=400" role="button" title="7-4.jpg" alt="7-4.jpg" /></span></TD></TR><TR><TD>7.5</TD><TD><P>After the job has finished, check the <STRONG>job log statistics</STRONG>.</P><P>You can see the number of <EM>roles</EM> read from the source system SAP A4H and the same number of <STRONG>groups</STRONG> written to (created in) Entra ID.</P></TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="7-5.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328082iD6C6B9AB295D76DA/image-size/medium?v=v2&amp;px=400" role="button" title="7-5.jpg" alt="7-5.jpg" /></span></TD></TR></TBODY></TABLE><H2 id="toc-hId--6770302">Create the SAP EPM Access Package</H2><P>The following steps guide you through the process of creating the SAP EPM access package that will contain the previously provisioned SAP_BC_EPM_DEMO group.</P><TABLE border="1"><TBODY><TR><TD width="46.3542px" height="30px"><STRONG>Step</STRONG></TD><TD width="350px" height="30px"><STRONG>Description</STRONG></TD><TD width="350px" height="30px"><STRONG>Screenshot</STRONG></TD></TR><TR><TD width="46.3542px" height="246px">8.1</TD><TD width="350px" height="246px"><P>Go back to the <A href="https://entra.microsoft.com/#home" target="_blank" rel="noopener nofollow noreferrer">Entra admin center</A>.</P><P>Expand the <STRONG>ID Governance</STRONG> section and select <STRONG>Entitlement management</STRONG> from the navigation menu.</P><P>Select <STRONG>Access packages</STRONG> from the submenu.</P></TD><TD width="350px" height="246px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="8-1.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328083i88EDB06BFBF8CDB3/image-size/medium?v=v2&amp;px=400" role="button" title="8-1.jpg" alt="8-1.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="30px">8.2</TD><TD width="350px" height="30px">Click <STRONG>New access package</STRONG>.</TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="8-2.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328084iD3C98BBA1EB47555/image-size/medium?v=v2&amp;px=400" role="button" title="8-2.jpg" alt="8-2.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="30px">8.3</TD><TD width="350px" height="30px"><P>Enter <EM>SAP EPM</EM> for the <STRONG>name</STRONG>, and provide a <STRONG>description</STRONG>, for example <EM>Access to SAP Enterprise Procurement Model demo app</EM>.</P><P>Click <STRONG>Next: Resource roles</STRONG>.</P></TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="8-3.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328085iB30800C1BF3ABEA9/image-size/medium?v=v2&amp;px=400" role="button" title="8-3.jpg" alt="8-3.jpg" /></span></TD></TR><TR><TD>8.4</TD><TD>Click <STRONG>Groups and Teams</STRONG>.</TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="8-4.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328086i7711BC4C90662FC6/image-size/medium?v=v2&amp;px=400" role="button" title="8-4.jpg" alt="8-4.jpg" /></span></TD></TR><TR><TD>8.5</TD><TD><P><STRONG>Activate</STRONG> the checkbox <STRONG>See all Group and Team(s) not in the 'General' catalog</STRONG>.</P><P>Enter <EM>SAP_BC_EPM</EM> in the search field and <STRONG>activate</STRONG> the checkbox for the <EM>SAP_BC_EPM_DEMO</EM> group.</P><P>Click <STRONG>Select</STRONG>.</P></TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="8-5.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328087iD7468679AF2ED012/image-size/medium?v=v2&amp;px=400" role="button" title="8-5.jpg" alt="8-5.jpg" /></span></TD></TR><TR><TD>8.6</TD><TD><P>From the <STRONG>Role</STRONG> drop-down box, select <STRONG>Member</STRONG>.</P><P>Click <STRONG>Next: Requests</STRONG></P></TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="8-6.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328088i8B895A00364C4CC7/image-size/medium?v=v2&amp;px=400" role="button" title="8-6.jpg" alt="8-6.jpg" /></span></TD></TR><TR><TD>8.7</TD><TD><P>Select <STRONG>For users in your directory</STRONG> from the <STRONG>Users who can request access</STRONG> options.</P><P>Select <STRONG>All members (excluding guests)</STRONG>.</P><P>Set <STRONG>Require approval</STRONG> to <STRONG>No</STRONG>.</P><P>Click <STRONG>Next: Requestor information</STRONG>.</P></TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="8-7.jpg" style="width: 336px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328089i7A74A7E5FF328FF0/image-size/medium?v=v2&amp;px=400" role="button" title="8-7.jpg" alt="8-7.jpg" /></span></TD></TR><TR><TD>8.8</TD><TD><P>Click <STRONG>Next: Lifecycle</STRONG>.</P><P>Choose <STRONG>Never</STRONG> from the <STRONG>Access package assignments expire</STRONG> options.</P><P>Set <STRONG>User can request specific timeline</STRONG> to <STRONG>No</STRONG>.</P><P>Click <STRONG>Next: Rules</STRONG>.</P></TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="8-8.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328090i37DC2BC1EA38C54C/image-size/medium?v=v2&amp;px=400" role="button" title="8-8.jpg" alt="8-8.jpg" /></span></TD></TR><TR><TD>8.9</TD><TD><P>Click <STRONG>Next: Review + Create</STRONG>.</P><P>Click <STRONG>Create</STRONG>.</P></TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="8-9.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328091iB7281A6583E93E06/image-size/medium?v=v2&amp;px=400" role="button" title="8-9.jpg" alt="8-9.jpg" /></span></TD></TR><TR><TD>8.10</TD><TD><STRONG>Copy</STRONG> from the newly created access package the <STRONG>link to the My Access portal</STRONG> and paste it to a temporary text file.</TD><TD><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="8-10.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328092i2F930C666A3F33AD/image-size/medium?v=v2&amp;px=400" role="button" title="8-10.jpg" alt="8-10.jpg" /></span></TD></TR></TBODY></TABLE><H2 id="toc-hId-143970550">Onboard the new employee in SuccessFactors</H2><P>As the HR admin, go back to SuccessFactors and onboard the new employee Linda Larson.&nbsp;</P><TABLE border="1"><TBODY><TR><TD width="46.3542px" height="30px"><STRONG>Step</STRONG></TD><TD width="350px" height="30px"><STRONG>Description</STRONG></TD><TD width="350px" height="30px"><STRONG>Screenshot</STRONG></TD></TR><TR><TD width="46.3542px" height="30px">9.1</TD><TD width="350px" height="30px">In the <STRONG>search bar</STRONG>, start typing <STRONG>Add new employee</STRONG> and select the action from the search results.</TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="9-1.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328097i6B5143B6DF5230A9/image-size/medium?v=v2&amp;px=400" role="button" title="9-1.jpg" alt="9-1.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="30px">9.2</TD><TD width="350px" height="30px"><P>In the <STRONG>Identity</STRONG> section, leave the default <STRONG>Hire Date (today)</STRONG>, select a <STRONG>Company</STRONG> and <STRONG>Event Reason</STRONG> (for example <STRONG>New Hire</STRONG>) from the list.</P><P>Enter the following <STRONG>Name information</STRONG>:</P><UL><LI><STRONG>First Name</STRONG>: Linda</LI><LI><STRONG>Last Name</STRONG>: Larson</LI><LI><STRONG>Display Name</STRONG>: Linda Larson</LI></UL><P>In <STRONG>Employee Information</STRONG>, enter <EM>llarson</EM> for the <STRONG>Person Id</STRONG>.</P><P>Click <STRONG>Continue</STRONG>.</P></TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MartinRaepple_0-1760568541179.jpeg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328105iDE2201F872428532/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="MartinRaepple_0-1760568541179.jpeg" alt="MartinRaepple_0-1760568541179.jpeg" /></span></TD></TR><TR><TD width="46.3542px" height="30px">9.3</TD><TD width="350px" height="30px">Keep the default settings in <STRONG>Personal information</STRONG> and click <STRONG>Continue</STRONG>.</TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="9-3.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328099i6725EC450B584143/image-size/medium?v=v2&amp;px=400" role="button" title="9-3.jpg" alt="9-3.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="30px">9.4</TD><TD width="350px" height="30px"><P>In Job information, select a <STRONG>Job Classification</STRONG> from the list.</P><P>Click <STRONG>Continue</STRONG>.</P></TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="9-4.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328100i5B93C0516C94A3F5/image-size/medium?v=v2&amp;px=400" role="button" title="9-4.jpg" alt="9-4.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="30px">9.5</TD><TD width="350px" height="30px">Click <STRONG>Submit</STRONG>.</TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="9-5.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328102i39875625BB9732FA/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="9-5.jpg" alt="9-5.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="30px">9.6</TD><TD width="350px" height="30px">Click <STRONG>View Profile of Linda Larson</STRONG>.</TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="9-6.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328103i167F14F1B1F5A95F/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="9-6.jpg" alt="9-6.jpg" /></span></TD></TR><TR><TD width="46.3542px" height="30px">9.7</TD><TD width="350px" height="30px">The profile of the new onboarded employee is shown.</TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="9-7.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/328104i78245570FFF99425/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="9-7.jpg" alt="9-7.jpg" /></span></TD></TR></TBODY></TABLE><H2 id="toc-hId--52542955">Provision the new employee to AD and Entra</H2><P>Next, you will provision the new employee to AD with the enterprise app configured for SuccessFactors in steps 1 ff. From there, an account in Entra gets created with Cloud Sync, and an alternative e-mail address is set by the administrator. This is required for the self-service password reset when the new onboarded user logs-in for the first time in the next section. We'll explore more sophisticated mechanisms for the employee onboarding process and initial login experience with <A href="https://learn.microsoft.com/en-us/entra/id-governance/what-are-lifecycle-workflows" target="_blank" rel="noopener nofollow noreferrer">Entra ID Governance lifecycle workflows</A>&nbsp;in one of the next parts of this blog series.</P><TABLE border="1"><TBODY><TR><TD width="49.1771px" height="30px"><STRONG>Step</STRONG></TD><TD width="350px" height="30px"><STRONG>Description</STRONG></TD><TD width="350px" height="30px"><STRONG>Screenshot</STRONG></TD></TR><TR><TD width="49.1771px" height="171px">10.1</TD><TD width="350px" height="171px"><P>Select <STRONG>Enterprise apps</STRONG> from the navigation menu.</P><P>In the search field, enter the name of your SuccessFactors app created in step 2.3.</P><P><STRONG>Select</STRONG> the app from the search results list.</P></TD><TD width="350px" height="171px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-1.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329325iFF03CC73D2740FE1/image-size/medium?v=v2&amp;px=400" role="button" title="10-1.jpg" alt="10-1.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="402px">10.2</TD><TD width="350px" height="402px">Select <STRONG>Provisioning</STRONG> from the app's menu.</TD><TD width="350px" height="402px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-2.jpg" style="width: 272px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329326i5842A751E6121ADC/image-size/medium?v=v2&amp;px=400" role="button" title="10-2.jpg" alt="10-2.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="284px">10.3</TD><TD width="350px" height="284px"><P>Select <STRONG>Provisioning on demand</STRONG> from the menu.</P><P>Enter the new employees <STRONG>personId</STRONG> from step 9.2 in the <STRONG>Select a user</STRONG>&nbsp;field.</P><P>Click <STRONG>Provision</STRONG>.</P></TD><TD width="350px" height="284px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-3.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329327i351448A4BDB6043E/image-size/medium?v=v2&amp;px=400" role="button" title="10-3.jpg" alt="10-3.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="140px">10.4</TD><TD width="350px" height="140px"><P>The new employee's user account gets created in AD and the results are shown.</P><P>Click <STRONG>Close</STRONG>.</P></TD><TD width="350px" height="140px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-4.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329328iAE55D35C536C6C07/image-size/medium?v=v2&amp;px=400" role="button" title="10-4.jpg" alt="10-4.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="402px">10.5</TD><TD width="350px" height="402px"><P>On your DC, open the <STRONG>Active Directory Users and Computers (ADUC)</STRONG> tool.&nbsp;</P><P>Navigate to the path where you provision new users from SF to (as configured in step 2.6).</P><P>Search for the new user and open the <STRONG>Properties</STRONG>&nbsp;for it.</P></TD><TD width="350px" height="402px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-5.jpg" style="width: 306px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329329i4B491D2A0B3690A2/image-size/medium?v=v2&amp;px=400" role="button" title="10-5.jpg" alt="10-5.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="402px">10.6</TD><TD width="350px" height="402px"><P>Switch to the <STRONG>Attribute Editor</STRONG> tab.</P><P>Search for the <STRONG>distinguishedName</STRONG> attribute.</P><P>Click <STRONG>View</STRONG>.</P></TD><TD width="350px" height="402px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-6.jpg" style="width: 325px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329330iCE96C3120BB2FFDF/image-size/medium?v=v2&amp;px=400" role="button" title="10-6.jpg" alt="10-6.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="206px">10.7</TD><TD width="350px" height="206px"><STRONG>Copy</STRONG> the value of the attribute to the clipboard.</TD><TD width="350px" height="206px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-7.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329331iF675B782CF94CF62/image-size/medium?v=v2&amp;px=400" role="button" title="10-7.jpg" alt="10-7.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="230px">10.8</TD><TD width="350px" height="230px">Go back to the Entra admin center and select <STRONG>Entra Connect</STRONG> from the top navigation menu.</TD><TD width="350px" height="230px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-8.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329332i40EA820540EDB96D/image-size/medium?v=v2&amp;px=400" role="button" title="10-8.jpg" alt="10-8.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="231px">10.9</TD><TD width="350px" height="231px">Select <STRONG>Cloud Sync</STRONG>.</TD><TD width="350px" height="231px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-9.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329333iB6A46B7A2390CB2E/image-size/medium?v=v2&amp;px=400" role="button" title="10-9.jpg" alt="10-9.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="125px">10.10</TD><TD width="350px" height="125px"><STRONG>Click</STRONG> on your&nbsp;<STRONG>AD to Microsoft Entra ID</STRONG> configuration from the list.</TD><TD width="350px" height="125px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-10.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329334i7F87EDDD836386EF/image-size/medium?v=v2&amp;px=400" role="button" title="10-10.jpg" alt="10-10.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="245px">10.11</TD><TD width="350px" height="245px"><P>Select <STRONG>Provision on demand</STRONG> from the menu.</P><P><STRONG>Paste</STRONG> the new AD user's distinguished name attribute value from the clipboard into the <STRONG>Enter a user </STRONG>field.</P><P>Click <STRONG>Provison</STRONG>.</P></TD><TD width="350px" height="245px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-11.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329335i53D1AF01F77EBB1C/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="10-11.jpg" alt="10-11.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="30px">10.12</TD><TD width="350px" height="30px"><P>Entra will search for the user in AD, create the new account, and display the results.</P><P>Click <STRONG>Close</STRONG>.</P></TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-12.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329336i1ED486213BCBE2B5/image-size/medium?v=v2&amp;px=400" role="button" title="10-12.jpg" alt="10-12.jpg" /></span></TD></TR><TR><TD width="49.1771px">10.13</TD><TD width="350px"><P>From the top navigation menu, select <STRONG>Users</STRONG>.</P><P>Search for the new user by entering its user name.</P><P><STRONG>Select</STRONG> the new user from the list.</P></TD><TD width="350px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-13.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329427i60F18FBB9A5BACEC/image-size/medium?v=v2&amp;px=400" role="button" title="10-13.jpg" alt="10-13.jpg" /></span></TD></TR><TR><TD width="49.1771px">10.14</TD><TD width="350px">Click <STRONG>Edit properties</STRONG>.</TD><TD width="350px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-14.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329429iAB76A1BE2698A02C/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="10-14.jpg" alt="10-14.jpg" /></span></TD></TR><TR><TD width="49.1771px">10.15</TD><TD width="350px"><P>Switch to the <STRONG>Contact Information</STRONG> tab.</P><P>Click <STRONG>Add or edit other emails</STRONG>.</P></TD><TD width="350px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-15.jpg" style="width: 330px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329430i261721AE76D879EE/image-size/medium?v=v2&amp;px=400" role="button" title="10-15.jpg" alt="10-15.jpg" /></span></TD></TR><TR><TD width="49.1771px">10.16</TD><TD width="350px"><P>Enter an email address in the field that you have access to for testing purposes. This <EM>must not be</EM> the new users primary email address.</P><P>Click <STRONG>Save</STRONG>.</P></TD><TD width="350px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-16.jpg" style="width: 232px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329431i155E5613F5EE6C73/image-size/medium?v=v2&amp;px=400" role="button" title="10-16.jpg" alt="10-16.jpg" /></span></TD></TR><TR><TD width="49.1771px">10.17</TD><TD width="350px">Click <STRONG>Save</STRONG>.</TD><TD width="350px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="10-17.jpg" style="width: 284px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329432i65FD0EABB5BFE861/image-size/medium?v=v2&amp;px=400" role="button" title="10-17.jpg" alt="10-17.jpg" /></span></TD></TR></TBODY></TABLE><H2 id="toc-hId--249056460">Request the SAP EPM access package</H2><P>Before making the request for the SAP EPM access package, the new employee Linda Larson has to (re)set her password in Entra using the <A href="https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-enable-sspr" target="_blank" rel="noopener nofollow noreferrer">self-service password reset in Entra ID</A>. and subsequentely also for her user account in AD with the <A href="https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-enable-cloud-sync-sspr-writeback" target="_blank" rel="noopener nofollow noreferrer">SSPR password writeback option enabled</A> as listed in the prerequisites section of this tutorial.</P><TABLE border="1" width="743px"><TBODY><TR><TD width="49.1771px" height="30px"><STRONG>Step</STRONG></TD><TD width="346.573px" height="30px"><STRONG>Description</STRONG></TD><TD width="346.583px" height="30px"><STRONG>Screenshot</STRONG></TD></TR><TR><TD width="49.1771px" height="263px">11.1</TD><TD width="346.573px" height="263px"><P>Open a new <STRONG>private browser</STRONG> window.</P><P>Open the <STRONG>URL to the My Access portal</STRONG> copied in step 8.10.</P><P>On the login page, enter your new employees login name or primary email address.</P><P>Click <STRONG>Next</STRONG>.</P><P>Select the <STRONG>Forgot my password</STRONG> link.</P></TD><TD width="346.583px" height="263px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-1.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329436i44B7C66CB22EF224/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="11-1.jpg" alt="11-1.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="244px">11.2</TD><TD width="346.573px" height="244px"><P>Enter the character and numbers as shown in <A href="https://en.wikipedia.org/wiki/CAPTCHA" target="_blank" rel="noopener nofollow noreferrer">CAPTCHA</A>.</P><P>Click <STRONG>Next</STRONG>.</P></TD><TD width="346.583px" height="244px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-2.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329437i2212FDE7A0F3A476/image-size/medium?v=v2&amp;px=400" role="button" title="11-2.jpg" alt="11-2.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="159px">11.3</TD><TD width="346.573px" height="159px"><P>Select the <STRONG>I forgot my password</STRONG> option.</P><P>Click <STRONG>Next</STRONG>.</P></TD><TD width="346.583px" height="159px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-3.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329438iC851099DDCBC8132/image-size/medium?v=v2&amp;px=400" role="button" title="11-3.jpg" alt="11-3.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="173px">11.4</TD><TD width="346.573px" height="173px">Click <STRONG>Email</STRONG> to send a verification code to your alternative email address provided in step 10.16.</TD><TD width="346.583px" height="173px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-4.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329439i1D46748491E026CC/image-size/medium?v=v2&amp;px=400" role="button" title="11-4.jpg" alt="11-4.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="147px">11.5</TD><TD width="346.573px" height="147px"><P>Open the inbox of your alternative email address. You should have received an <STRONG>email</STRONG> with the verification code.</P><P><STRONG>Copy</STRONG> the code to the clipboard.</P></TD><TD width="346.583px" height="147px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-5.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329440i16182B39C5EFA581/image-size/medium?v=v2&amp;px=400" role="button" title="11-5.jpg" alt="11-5.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="181px">11.6</TD><TD width="346.573px" height="181px"><P><STRONG>Paste</STRONG> the code in the entry field.</P><P>Click <STRONG>Next</STRONG>.</P></TD><TD width="346.583px" height="181px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-6.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329442i93367936E49B86A7/image-size/medium?v=v2&amp;px=400" role="button" title="11-6.jpg" alt="11-6.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="241px">11.7</TD><TD width="346.573px" height="241px"><P>Enter your new (initial) password.</P><P>Click <STRONG>Finish</STRONG>.</P></TD><TD width="346.583px" height="241px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-7.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329443i533A39881F46EECF/image-size/medium?v=v2&amp;px=400" role="button" title="11-7.jpg" alt="11-7.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="130px">11.8</TD><TD width="346.573px" height="130px"><P><STRONG>Wait</STRONG> for the password reset confirmation.</P><P>Select the <STRONG>click here</STRONG> link.</P></TD><TD width="346.583px" height="130px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-8.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329444iFE5D8BD055AB3B91/image-size/medium?v=v2&amp;px=400" role="button" title="11-8.jpg" alt="11-8.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="263px">11.9</TD><TD width="346.573px" height="263px"><STRONG>Enter</STRONG> your username and click <STRONG>Next</STRONG>.</TD><TD width="346.583px" height="263px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-9.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329445iF113E306F921C07C/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="11-9.jpg" alt="11-9.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="264px">11.10</TD><TD width="346.573px" height="264px"><P><STRONG>Enter</STRONG> your new password.</P><P>Click <STRONG>Sign in</STRONG>.</P></TD><TD width="346.583px" height="264px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-10.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329446i7B2F196530836ED2/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="11-10.jpg" alt="11-10.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="293px">11.11</TD><TD width="346.573px" height="293px">Click <STRONG>Next</STRONG>.</TD><TD width="346.583px" height="293px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-11.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329447iB2C9DC2FC04182A3/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="11-11.jpg" alt="11-11.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="164px">11.12</TD><TD width="346.573px" height="164px">For testing purposes, click <STRONG>Skip setup</STRONG> for now.</TD><TD width="346.583px" height="164px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-12.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329448iCA79442028712950/image-size/medium?v=v2&amp;px=400" role="button" title="11-12.jpg" alt="11-12.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="232px">11.13</TD><TD width="346.573px" height="232px"><P>The request for the SAP EPM access package is started.</P><P>Click <STRONG>Continue</STRONG>.</P></TD><TD width="346.583px" height="232px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-13.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329449iC08E8FC116EBF9ED/image-size/medium?v=v2&amp;px=400" role="button" title="11-13.jpg" alt="11-13.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="30px">11.14</TD><TD width="346.573px" height="30px"><P>Optionally provide a business justification for the new request.</P><P>Click <STRONG>Submit request</STRONG>.</P></TD><TD width="346.583px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-14.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329450i3527B4166A8A90CF/image-size/medium?v=v2&amp;px=400" role="button" title="11-14.jpg" alt="11-14.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="30px">11.15</TD><TD width="346.573px" height="30px"><P>In the <A href="https://entra.microsoft.com/" target="_blank" rel="noopener nofollow noreferrer">Entra admin center</A>, select <STRONG>Groups</STRONG> from the top navigation menu.</P><P>On the <STRONG>Overview</STRONG> page, enter the test group's name SAP_BC_EPM_DEMO in the <STRONG>search</STRONG> field.</P><P><STRONG>Select</STRONG> the group from the search results list.</P></TD><TD width="346.583px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-15.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329451iD5974891B82B5682/image-size/medium?v=v2&amp;px=400" role="button" title="11-15.jpg" alt="11-15.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="30px">11.16</TD><TD width="346.573px" height="30px"><P>Select <STRONG>Members</STRONG> from the group navigation menu.</P><P>By requesting the access package and auto-approving it, Linda Larson became now a member of this group.</P></TD><TD width="346.583px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="11-16.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329452i374EA6E212A308ED/image-size/medium?v=v2&amp;px=400" role="button" title="11-16.jpg" alt="11-16.jpg" /></span></TD></TR></TBODY></TABLE><H2 id="toc-hId--445569965">Provision the group membership to CIS</H2><P>Let's see the updated SCIM connector with support for groups in action, and provision Linda's new user account and her membership to the&nbsp;SAP_BC_EPM_DEMO to your CIS tenant's local directory. Since the group hasn't been created in CIS when your ran the initial load of the PFCG roles to Entra in steps 7.1 ff, the group will be provisioned as well.&nbsp;</P><TABLE border="1"><TBODY><TR><TD width="49.1771px" height="30px"><STRONG>Step</STRONG></TD><TD width="350px" height="30px"><STRONG>Description</STRONG></TD><TD width="350px" height="30px"><STRONG>Screenshot</STRONG></TD></TR><TR><TD width="49.1771px" height="185px">12.1</TD><TD width="350px" height="185px"><P>Select <STRONG>Enterprise apps</STRONG> from the top navigation menu.</P><P><STRONG>Search</STRONG> for your CIS tenant's enterprise app and select if from the search results.</P></TD><TD width="350px" height="185px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="12-1.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329705i096B2BD17DA5DEA7/image-size/medium?v=v2&amp;px=400" role="button" title="12-1.jpg" alt="12-1.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="300px">12.2</TD><TD width="350px" height="300px">Select <STRONG>Provisioning</STRONG> from the app's menu.</TD><TD width="350px" height="300px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="12-2.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329706i0B5AC7D8A17A6107/image-size/medium?v=v2&amp;px=400" role="button" title="12-2.jpg" alt="12-2.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="240px">12.3</TD><TD width="350px" height="240px"><P>Before provisioning the group and its members to CIS, it must be assigned to the app.</P><P>Select <STRONG>Users and groups</STRONG>.</P></TD><TD width="350px" height="240px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="12-3.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329707iA36F2202E5DA01B1/image-size/medium?v=v2&amp;px=400" role="button" title="12-3.jpg" alt="12-3.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="258px">12.4</TD><TD width="350px" height="258px">Click <STRONG>None Selected</STRONG>.</TD><TD width="350px" height="258px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="12-4.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329708i1AAA87E3D42A370C/image-size/medium?v=v2&amp;px=400" role="button" title="12-4.jpg" alt="12-4.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="402px">12.5</TD><TD width="350px" height="402px"><P>In the <STRONG>Search</STRONG> field, enter the group's name SAP_BC_EPM_DEMO.</P><P><STRONG>Activate</STRONG> the checkbox for the group in the search results and click <STRONG>Select</STRONG>.</P></TD><TD width="350px" height="402px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="12-5.jpg" style="width: 287px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329709iDC8F9817AA7ECEC2/image-size/medium?v=v2&amp;px=400" role="button" title="12-5.jpg" alt="12-5.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="348px">12.6</TD><TD width="350px" height="348px">Click <STRONG>Assign</STRONG>.</TD><TD width="350px" height="348px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="12-6.jpg" style="width: 393px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329710iD934BD6F17D0C06E/image-size/medium?v=v2&amp;px=400" role="button" title="12-6.jpg" alt="12-6.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="184px">12.7</TD><TD width="350px" height="184px"><P>Select <STRONG>Provision on demand</STRONG> from the menu.</P><P>In the <STRONG>Selected group</STRONG> field, enter the group's name SAP_BC_EPM_DEMO.</P><P>Keep the default choice <STRONG>View members only</STRONG>, select the user from the members&nbsp;<STRONG>drop-down list</STRONG> by <STRONG>activating</STRONG> the checkbox for Linda Larson.</P><P>Click <STRONG>Provision</STRONG>.</P></TD><TD width="350px" height="184px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="12-7.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329711i5059B5F5638E35AA/image-size/medium?v=v2&amp;px=400" role="button" title="12-7.jpg" alt="12-7.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="30px">12.8</TD><TD width="350px" height="30px"><P>The results of the provisioning action are shown.</P><P>On the <STRONG>Group details</STRONG> tab, you can see that the group SAP_BC_EPM_DEMO was created in your CIS tenant.</P><P>Switch to the <STRONG>Group membership operations</STRONG> tab.</P></TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="12-8.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329712iBFB15DB750F12BBC/image-size/medium?v=v2&amp;px=400" role="button" title="12-8.jpg" alt="12-8.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="30px">12.9</TD><TD width="350px" height="30px"><P>Linda's membership was also added successfully to the new group in CIS.</P><P>Switch to the <STRONG>User operations</STRONG> tab.</P></TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="12-9.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329713i965DC0C49743CF34/image-size/medium?v=v2&amp;px=400" role="button" title="12-9.jpg" alt="12-9.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="30px">12.10</TD><TD width="350px" height="30px"><P>A new user account for Linda was also created in the CIS tenant.&nbsp;</P><P>Click <STRONG>View details</STRONG>.</P></TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="12-10.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329714iAB91CF2E9AA11F7C/image-size/medium?v=v2&amp;px=400" role="button" title="12-10.jpg" alt="12-10.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="30px">12.11</TD><TD width="350px" height="30px">Linda's new user account in CIS has been created with the attribute values according to the mapping configuration customized in steps 3.7 to 3.13. The last line shows the new <STRONG>sapUserName</STRONG> attribute set with Linda's on-premise user name in AD.&nbsp;&nbsp;</TD><TD width="350px" height="30px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="12-11.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329715i3E8001B0B038004C/image-size/medium?v=v2&amp;px=400" role="button" title="12-11.jpg" alt="12-11.jpg" /></span></TD></TR></TBODY></TABLE><H2 id="toc-hId--642083470">Provision the role assignment to SAP</H2><P>Final step: Let's provision Linda's new user and her group membership in CIS to the SAP backend system.&nbsp;</P><TABLE border="1"><TBODY><TR><TD width="49.1771px" height="30px"><STRONG>Step</STRONG></TD><TD width="350px" height="30px"><STRONG>Description</STRONG></TD><TD width="350px" height="30px"><STRONG>Screenshot</STRONG></TD></TR><TR><TD width="49.1771px" height="356px">13.1</TD><TD width="350px" height="356px"><P>Go back to your CIS tenant's administration console.</P><P>Select <STRONG>Groups</STRONG> from the <STRONG>Users &amp; Authorizations</STRONG> menu.</P><P>Select the newly created group SAP_BC_EPM_DEMO from the list and check that Linda's user has been added successfully as a member.</P><P>Next, select <STRONG>Source Systems</STRONG> from the <STRONG>Identity Provisioning</STRONG> menu.</P></TD><TD width="350px" height="356px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="13-1.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329773iB71C403C61DCA8F0/image-size/medium?v=v2&amp;px=400" role="button" title="13-1.jpg" alt="13-1.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="302px">13.2</TD><TD width="350px" height="302px"><P>Select the <STRONG>LocalDirectory</STRONG> source system from the list.</P><P>Make sure that you've recreated this source system with the <A href="https://github.com/raepple/iam-with-entra/blob/0a73239a81c596811d0e704eb715045c2fdddde0/part3/LocalDirectory.json" target="_blank" rel="noopener nofollow noreferrer">new import file</A> from this tutorials GitHub repository path as mentioned in the prerequisites section.</P><P>Switch to the <STRONG>Jobs</STRONG> tab.</P><P>Click <STRONG>Run Now</STRONG>.</P></TD><TD width="350px" height="302px"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="13-2.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329774iE770630D94B1C01E/image-size/medium?v=v2&amp;px=400" role="button" title="13-2.jpg" alt="13-2.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="179px">13.3</TD><TD width="350px" height="179px"><P>Select <STRONG>Provisioning Logs</STRONG> from the <STRONG>Identity Provisioning</STRONG> menu.</P><P>Wait for the <STRONG>Status</STRONG> to <EM>Finish Successfully</EM> and then select the top log entry for your <STRONG>LocalDirectory</STRONG> source system.</P></TD><TD width="350px" height="179px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="13-3.jpg" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329775iAD96514EEE45C105/image-size/large?v=v2&amp;px=999" role="button" title="13-3.jpg" alt="13-3.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="139px">13-4</TD><TD width="350px" height="139px">In the <STRONG>Statistics</STRONG> of the provisioning action you can see that a new user was created in the SAP system, and that the equally named role for the group has been updated with Linda's membership.</TD><TD width="350px" height="139px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="13-4.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329776i0FFB03122943C668/image-size/medium?v=v2&amp;px=400" role="button" title="13-4.jpg" alt="13-4.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="358px">13.5</TD><TD width="350px" height="358px"><P>Check the new role assignment in the SAP system and Linda's correct SNC mapping for Kerberos-based SSO by <STRONG>logging</STRONG> into the domain-joined workstation.</P><P>To login, use the <STRONG>password</STRONG> that you've (re)set in step 11.7 and that has been written back to AD.</P></TD><TD width="350px" height="358px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="13-5.jpg" style="width: 382px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329777iDDBBEFE38C7E7B6E/image-size/medium/is-moderation-mode/true?v=v2&amp;px=400" role="button" title="13-5.jpg" alt="13-5.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="227px">13.6</TD><TD width="350px" height="227px"><P>Start SAP GUI.</P><P>You may need to add the connection to the SAP backend as described in step 10.29 and 10.30 in <A href="https://community.sap.com/t5/technology-blog-posts-by-members/identity-and-access-management-with-microsoft-entra-part-ii-provisioning-to/ba-p/13990927" target="_blank">part II</A>.</P><P><STRONG>Right-click</STRONG> on the connection and select <STRONG>SNC Login with Single Sign-On</STRONG>.&nbsp;</P></TD><TD width="350px" height="227px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="13-6.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329778iF55C4EA712D44840/image-size/medium?v=v2&amp;px=400" role="button" title="13-6.jpg" alt="13-6.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="196px">13.7</TD><TD width="350px" height="196px"><P>Because this is the first login for the new user you are prompted to either reset the initial password, or deactivate it.</P><P>Click on<SPAN>&nbsp;</SPAN><STRONG>Delete</STRONG><SPAN>&nbsp;</SPAN>to use SNC and Kerberos-based SSO.&nbsp;</P></TD><TD width="350px" height="196px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="13-7.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329779iC55520BE054A544A/image-size/medium?v=v2&amp;px=400" role="button" title="13-7.jpg" alt="13-7.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="248px">13.8</TD><TD width="350px" height="248px"><SPAN>You are single signed-on to the SAP system using SNC and Kerberos SSO, and Linda's user menu shows the entries for the <STRONG>EPM Demo Applications</STRONG> as a result of the successful assignment to the SAP_BC_EPM_DEMO role.</SPAN></TD><TD width="350px" height="248px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="13-8.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329780iB0D42DB422D73CBA/image-size/medium?v=v2&amp;px=400" role="button" title="13-8.jpg" alt="13-8.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="172px">13.9</TD><TD width="350px" height="172px"><P>As an administrator in the SAP system, start transaction <STRONG>PFCG</STRONG>.</P><P>In the <STRONG>Role</STRONG> field, enter SAP_BC_EPM_DEMO.</P><P>Click <STRONG>Display</STRONG>.</P></TD><TD width="350px" height="172px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="13-9.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329781iBD7D9D704465F547/image-size/medium?v=v2&amp;px=400" role="button" title="13-9.jpg" alt="13-9.jpg" /></span></TD></TR><TR><TD width="49.1771px" height="218px">13.10</TD><TD width="350px" height="218px"><P>Swith to the <STRONG>User</STRONG> tab.</P><P>You can see Linda's SAP user account LLARSON assinged to the role.</P></TD><TD width="350px" height="218px"><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="13-10.jpg" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/329782iA2789539EF6C50FF/image-size/medium?v=v2&amp;px=400" role="button" title="13-10.jpg" alt="13-10.jpg" /></span></TD></TR></TBODY></TABLE><P><STRONG>Done</STRONG>! Once again, thank you for following this tutorial and the blog series, and looking forward to your comments &amp; feedback.</P> 2025-10-20T10:05:47.788000+02:00 https://community.sap.com/t5/technology-blog-posts-by-members/push-uuid-from-ias-to-s4hana-tasks-list-on-btp-task-center-is-empty-for/ba-p/14298510 Push UUID from IAS to S4HANA - Tasks list on BTP task Center is empty for S4HANA 2026-01-01T05:41:20.344000+01:00 navyaaa https://community.sap.com/t5/user/viewprofilepage/user-id/448321 <H2 id="toc-hId-1767539302"><STRONG>Introduction:</STRONG></H2><P>After completing all prerequisites and following the SAP documentation to configure the Task Center for an SAP S/4HANA system, it is quite common to encounter a situation where no tasks are displayed in the Task Center—even though task creation appears to be working correctly in the backend.</P><P>This blog addresses one of the most frequently overlooked root causes behind this issue: the absence of a Global User ID (UUID) in the SAP S/4HANA system. Even when the Task Center is correctly configured on SAP BTP and tasks are visible in the pull cache, missing UUID mapping can prevent the Task Center from resolving the processor correctly, resulting in an empty Task Center UI.</P><P>In this blog, I will walk you through a critical but often missed step required to ensure tasks are displayed correctly in the Task Center. The focus is on establishing a one-way synchronization from SAP Identity Authentication Service (IAS) to SAP S/4HANA to push the UUIDs for existing users, without performing a full user provisioning or re-synchronization.</P><H2 id="toc-hId-1571025797"><STRONG>Solution:</STRONG></H2><P>Even after configuring the Task Center on HANA on-premise and completing all required steps on BTP, the Task Center may appear empty, as shown in the screenshot below.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="navya_shree2_1-1767006178298.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/356437i84006257B39A5258/image-size/medium?v=v2&amp;px=400" role="button" title="navya_shree2_1-1767006178298.png" alt="navya_shree2_1-1767006178298.png" /></span></P><P>When you check the Task Center pull cache, you can see that the task exists; however, it is still not displayed in the Task Center app. As shown in the screenshot below, the task appears with the processor name set to the SAP user ID. This situation occurs when a GUID (UUID) is not available in the SAP HANA system. In such cases, the system falls back to using the SAP user ID instead of the UUID. As a result, the Task Center is unable to correctly resolve the processor, and the task is not displayed in the Task Center app.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="navya_shree2_0-1767007359114.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/356438i1CDC325FBBFB0B86/image-size/medium?v=v2&amp;px=400" role="button" title="navya_shree2_0-1767007359114.png" alt="navya_shree2_0-1767007359114.png" /></span></P><P>To resolve this issue, we need to ensure that a UUID is available in the SAP system. The steps to achieve this are explained below. Before updating the UUID in the SAP HANA system, the user profile in the SU01 screen appears as shown in the screenshot below.<BR />SU01--&gt;Goto--&gt;External User ID(UID)</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="navya_shree2_0-1767010597234.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/356452i4161A4071731B134/image-size/medium?v=v2&amp;px=400" role="button" title="navya_shree2_0-1767010597234.png" alt="navya_shree2_0-1767010597234.png" /></span></P><P>Please note that in this scenario, we are not synchronizing SAP users to IAS and then syncing the UUID back to the HANA system. Since the UUIDs and users already exist in IAS as a result of the SuccessFactors integration, we will establish a one-way synchronization from IAS to SAP S/4HANA solely to push the UUID into the system</P><P>To push the UUID (Global User ID) to SAP system please follow below steps.</P><P><BR /><STRONG>Prerequisite:</STRONG><BR />1.&nbsp; Login to your Cloud Connector: Make sure your Cloud connectors connection from BTP to HANA has access to below BAPI/FM&nbsp;</P><UL><LI>PRGN_ROLE_GETLIST</LI><LI>BAPI_USER_GETLIST</LI><LI>BAPI_USER_GET_DETAIL</LI><LI>BAPI_USER_CREATE1</LI><LI>BAPI_USER_ACTGROUPS_ASSIGN</LI><LI>IDENTITY_MODIFY</LI><LI>BAPI_USER_DELETE</LI><LI>PRGN_ACTIVITY_GROUPS_LOAD_RFC</LI></UL><P>2. Create a technical user in SAP HANA, or reuse an existing technical user that is used to pull tasks for the Task Center. Ensure that this user is assigned the required role listed below. This technical user will be used to create the RFC destination in the BTP subaccount, which will later be used to create the target system in IAS</P><UL><LI>SAP_BC_JSF_COMMUNICATION</LI></UL><P>3. Create a RFC destination on the BTP account where your IAS is hosted by referring to below SAP guide.<BR /><A href="https://help.sap.com/docs/connectivity/sap-btp-connectivity-cf/create-rfc-destinations" target="_blank" rel="noopener noreferrer">https://help.sap.com/docs/connectivity/sap-btp-connectivity-cf/create-rfc-destinations</A></P><P><STRONG>Note:</STRONG> If you prefer to create the RFC destination in a different subaccount - perhaps within the same sub account as SAP Work Zone or the Task Center- ensure that you create an Identity Access Management (IAM) service instance in that subaccount. This is required so that the RFC destination you create is visible in the IAS administration console.<BR /><BR />After completing the prerequisites, log in to IAS and create the source and destination systems to perform the push.</P><P><STRONG>Creating Source system:</STRONG> Because the users are already available in IAS, select <STRONG>Local Identity Directory</STRONG> as the source system.<BR />Creating the Source system is straightforward.&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="navya_shree2_0-1767008453477.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/356439iE721D5A04E25215A/image-size/medium?v=v2&amp;px=400" role="button" title="navya_shree2_0-1767008453477.png" alt="navya_shree2_0-1767008453477.png" /></span></P><pre class="lia-code-sample language-abap"><code>{ "user": { "mappings": [ { "sourcePath": "$.id", "targetPath": "$['urn:sap:cloud:scim:schemas:extension:custom:2.0:User']['userId']", "targetVariable": "entityIdSourceSystem" }, { "sourcePath": "$['urn:ietf:params:scim:schemas:extension:sap:2.0:User']['userUuid']", "targetPath": "$['urn:ietf:params:scim:schemas:extension:sap:2.0:User']['userUuid']" }, { "sourcePath": "$.schemas", "targetPath": "$.schemas", "preserveArrayWithSingleElement": true }, { "sourcePath": "$.userName", "targetPath": "$.userName", "optional": true, "correlationAttribute": true }, { "sourcePath": "$.displayName", "targetPath": "$.displayName", "optional": true }, { "sourcePath": "$.groups", "targetPath": "$.groups", "optional": true, "preserveArrayWithSingleElement": true }, { "sourcePath": "$['urn:sap:cloud:scim:schemas:extension:custom:2.0:User']", "targetPath": "$['urn:sap:cloud:scim:schemas:extension:custom:2.0:User']", "optional": true }, { "sourcePath": "$['urn:ietf:params:scim:schemas:extension:sap:2.0:User']['sourceSystem']", "targetPath": "$['urn:ietf:params:scim:schemas:extension:sap:2.0:User']['sourceSystem']", "optional": true }, { "sourcePath": "$['urn:ietf:params:scim:schemas:extension:sap:2.0:User']['sourceSystemId']", "targetPath": "$['urn:ietf:params:scim:schemas:extension:sap:2.0:User']['sourceSystemId']", "optional": true }, { "sourcePath": "$['urn:ietf:params:scim:schemas:extension:sap:2.0:User']['userId']", "targetPath": "$['urn:ietf:params:scim:schemas:extension:sap:2.0:User']['userId']", "optional": true }, { "sourcePath": "$['urn:ietf:params:scim:schemas:extension:enterprise:2.0:User']['employeeNumber']", "targetPath": "$['urn:ietf:params:scim:schemas:extension:enterprise:2.0:User']['employeeNumber']", "optional": true } ] }, "group": { "ignore": true, "mappings": [ { "sourcePath": "$.id", "targetVariable": "entityIdSourceSystem", "correlationAttribute": true }, { "sourcePath": "$['urn:sap:cloud:scim:schemas:extension:custom:2.0:Group']['name']", "targetPath": "$['urn:sap:cloud:scim:schemas:extension:custom:2.0:Group']['name']" }, { "sourcePath": "$.displayName", "targetPath": "$.displayName" }, { "sourcePath": "$.members", "targetPath": "$.members", "optional": true, "preserveArrayWithSingleElement": true } ] } }</code></pre><P><BR /><STRONG>Create Target system:</STRONG>&nbsp;Here our target is SAP HANA. below refer below screenshots and code snippet to create the same. here the target system type is&nbsp;SAP Application Server ABAP. and please select the destination which you created in prerequisite step 3.<BR />Make sure you skip operations for delete and create as we trying to do update only and you can also update the alias(email), groups roles to S4HANA along with UUID but here i am only focusing on UUID.<BR /><BR /></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="navya_shree2_1-1767008671705.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/356444i3F6448B3BB285AC3/image-size/medium?v=v2&amp;px=400" role="button" title="navya_shree2_1-1767008671705.png" alt="navya_shree2_1-1767008671705.png" /></span></P><pre class="lia-code-sample language-abap"><code>{ "user": { "skipOperations": [ "create", "delete" ], "mappings": [ { "sourceVariable": "entityIdTargetSystem", "targetPath": "$.USERNAME" }, { "sourcePath": "$.userName", "targetPath": "$.USERNAME" }, { "sourcePath": "$['urn:ietf:params:scim:schemas:extension:sap:2.0:User']['userUuid']", "targetPath": "$.SAPUSER_UUID.SAP_UID" }, { "constant": "updateEntity", "targetVariable": "operationTypeVariable" }, { "constant": "createEntity", "targetVariable": "operationTypeVariable", "scope": "createEntity" }, { "condition": "$.active == false &amp;&amp; '${operationTypeVariable}' == 'createEntity'", "constant": "X", "targetPath": "$.LOCK_LOCALLY" }, { "condition": "'${operationTypeVariable}' == 'updateEntity'", "constant": "U", "targetPath": "$.LOCK" }, { "condition": "$.active == false &amp;&amp; '${operationTypeVariable}' == 'updateEntity'", "constant": "L", "targetPath": "$.LOCK" } ] } }</code></pre><P>Once the source and target systems are created, open the source system and perform a test run for a single user to ensure that everything is working correctly. After successful validation, you can remove the user filter and perform a mass update for all users in the system.<BR /><BR /></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="navya_shree2_0-1767008999198.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/356445iB45F09A6EA31BA4D/image-size/medium?v=v2&amp;px=400" role="button" title="navya_shree2_0-1767008999198.png" alt="navya_shree2_0-1767008999198.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="navya_shree2_2-1767009113766.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/356447iBE0085F23015ED91/image-size/medium?v=v2&amp;px=400" role="button" title="navya_shree2_2-1767009113766.png" alt="navya_shree2_2-1767009113766.png" /></span></P><P>Once the update is completed you will be able to see UUID in SU01 user profile as below.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="navya_shree2_1-1767010698860.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/356453i8AD86CDB937DD320/image-size/medium?v=v2&amp;px=400" role="button" title="navya_shree2_1-1767010698860.png" alt="navya_shree2_1-1767010698860.png" /></span></P><P><BR />Also, The&nbsp;Task Center pull cache will have UUID for the processor field instead of the SAP user name and Tasks will be shown in the Task center as below.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="navya_shree2_3-1767009382945.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/356449iF64088A2EC869FAE/image-size/medium?v=v2&amp;px=400" role="button" title="navya_shree2_3-1767009382945.png" alt="navya_shree2_3-1767009382945.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="navya_shree2_0-1767010251154.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/356450iA08EE5FF60B1BCC7/image-size/medium?v=v2&amp;px=400" role="button" title="navya_shree2_0-1767010251154.png" alt="navya_shree2_0-1767010251154.png" /></span></P><P>&nbsp;</P><H2 id="toc-hId-1374512292"><STRONG>Conclusion:</STRONG></H2><P>An empty Task Center—despite correct backend task creation and successful pull cache entries—can be misleading and time-consuming to troubleshoot. As demonstrated in this blog, the root cause is often the absence of a UUID in the SAP S/4HANA user master, which prevents the Task Center from resolving the task processor correctly.</P><P>By ensuring that the Global User ID (UUID) is pushed from IAS to SAP S/4HANA through a one-way synchronization, this issue can be resolved effectively without impacting existing user provisioning or SuccessFactors integrations. Once the UUID is updated in the SU01 user profile, the Task Center pull cache correctly reflects the UUID, and tasks become visible in the Task Center application as expected.</P><P>I hope this blog helps you avoid common pitfalls during Task Center setup and saves valuable troubleshooting time. Feel free to share your feedback or experiences, and happy learning!</P><P>Thanks and Regards,<BR />Navyashree</P><P>&nbsp;</P><P><BR /><BR /></P><P>&nbsp;</P><P>&nbsp;</P> 2026-01-01T05:41:20.344000+01:00 https://community.sap.com/t5/enterprise-architecture-blog-posts/enhancing-security-enabling-multi-factor-authentication-enforcement-for-s/ba-p/14320971 Enhancing security: Enabling Multi-Factor Authentication enforcement for S-users 2026-02-06T13:51:09.128000+01:00 Akhat_12 https://community.sap.com/t5/user/viewprofilepage/user-id/1582 <P class="lia-align-justify" style="text-align : justify;"><STRONG>Starting from January 15, 2026, super administrators can enforce <A href="https://support.sap.com/en/my-support/mfa.html" target="_blank" rel="noopener noreferrer">Multi-Factor Authentication (MFA)</A> for their S-users.&nbsp;</STRONG>This new feature has been developed based on direct customer feedback and in response to the evolving security landscape, resulting in stronger protection for your user accounts.</P><P class="lia-align-justify" style="text-align : justify;"><STRONG>What is Multifactor Authentication?</STRONG></P><P class="lia-align-justify" style="text-align : justify;">Multi-factor authentication, commonly known as MFA, is a powerful security measure that helps safeguard your accounts by requiring more than just a password. Instead of relying solely on something you know (like a password, PIN, or signature), MFA asks for an extra layer of verification, which could be:</P><UL class="lia-align-justify" style="text-align : justify;"><LI>Something you have: A one-time code generated by an authenticator app on your smartphone</LI><LI>Something you are: Biometrics, a fingerprint or a facial scan</LI></UL><P class="lia-align-justify" style="text-align : justify;">By combining these different authentication factors, MFA makes it significantly tougher for attackers to break into your account. This is in fact one of the most effective ways to prevent unauthorized access and stop most data breaches.</P><P class="lia-align-justify" style="text-align : justify;"><STRONG>Strengthening security with enhanced MFA Options for S-Users</STRONG></P><P class="lia-align-justify" style="text-align : justify;">Protecting critical SAP assets is crucial for our customers. Therefore, our approach to multi-factor authentication is evolving to meet this challenge. Now, super administrators can take a proactive role by enforcing MFA for S-users, while individuals still have the freedom to secure their accounts independently. This dual approach – <STRONG>administrator-led enforcement alongside voluntary enablement</STRONG> – offers the flexibility and meets modern security demands.</P><P class="lia-align-justify" style="text-align : justify;">In the past, enabling MFA was left up to each S-user’s discretion. However, relying solely on voluntary enrollment is no longer sufficient to safeguard sensitive business information. By empowering both administrators and users, we’re making it easier to prevent unauthorized access and strengthen your organization’s security.</P><P class="lia-align-justify" style="text-align : justify;"><STRONG>NEW scenario:&nbsp;Selective MFA enforcement by customer’s own super administrators</STRONG></P><P class="lia-align-justify" style="text-align : justify;">Now, super administrators can take a proactive role by enforcing MFA for S-users <STRONG>of their own company</STRONG>, while individuals still have the freedom to secure their accounts independently. <STRONG>Of course, this should be in line and aligned with the companies' own security policy</STRONG>.</P><P class="lia-align-justify" style="text-align : justify;">Through the User Management Tool (UMT) in&nbsp;<A href="https://me.sap.com/" target="_blank" rel="noopener noreferrer">SAP for Me</A>, super administrators have the option to activate MFA for S-users. This new feature allows administrators to:&nbsp;</P><UL class="lia-align-justify" style="text-align : justify;"><LI><STRONG>Enforce MFA:</STRONG>&nbsp;Search for, filter, and select specific S-users or all of them to make MFA mandatory for their logins.</LI><LI><STRONG>Exclude technical users:&nbsp;</STRONG>Crucially, super administrators can exclude specific technical accounts (like those used for the BTP cloud connector) from the MFA requirement, ensuring that core business processes continue to run smoothly.</LI></UL><P class="lia-align-justify" style="text-align : justify;">After MFA is enforced, the selected S-user(s) will receive an email notification with simple instructions on next steps and be guided through a one-time setup on their next login, ensuring a seamless and secure transition.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Akhat_12_0-1770143232193.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/368666i39E68D6767FD7E6F/image-size/large?v=v2&amp;px=999" role="button" title="Akhat_12_0-1770143232193.png" alt="Akhat_12_0-1770143232193.png" /></span></P><P class="lia-align-justify" style="text-align : justify;"><STRONG>EXISTING scenario: Voluntary MFA enablement by the S-users themselves</STRONG></P><P class="lia-align-justify" style="text-align : justify;">The option for individual users to proactively secure their own accounts&nbsp;<STRONG>remains fully available</STRONG>.&nbsp;</P><P class="lia-align-justify" style="text-align : justify;">Any S-user can visit their profile page via&nbsp;<A href="https://accounts.sap.com/ui/protected/profilemanagement" target="_blank" rel="noopener noreferrer">SAP's profile management</A>&nbsp;at any time to enable MFA for themselves. This has been a great option for security-conscious users who want to protect their accounts even before an administrator-led rollout.</P><P class="lia-align-justify" style="text-align : justify;"><STRONG>Please note:</STRONG> MFA enforced by the super administrator overrides any voluntary setting previously configured by the user.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Akhat_12_1-1770143260189.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/368667iEE810BBC0EF30EC3/image-size/large?v=v2&amp;px=999" role="button" title="Akhat_12_1-1770143260189.png" alt="Akhat_12_1-1770143260189.png" /></span></P> 2026-02-06T13:51:09.128000+01:00