https://raw.githubusercontent.com/ajmaradiaga/feeds/main/scmt/topics/SAP-Identity-Management-qa.xml SAP Community - SAP Identity Management 2024-05-20T11:12:58.399423+00:00 python-feedgen SAP Identity Management Q&A in SAP Community https://community.sap.com/t5/technology-q-a/undefined-error-in-job-variables/qaq-p/12732214 Undefined Error in Job Variables 2023-11-07T14:54:22+01:00 former_member727417 https://community.sap.com/t5/user/viewprofilepage/user-id/727417 <P>I am facing an issue in a job, which was running fine till now but all of sudden the job is not able to send the csv file in a mail although the job execution is happening. The Job Constant like Email and Userid are in undefined error.</P> <P>This is happening with specific job other job are able to send csv file. </P> 2023-11-07T14:54:22+01:00 https://community.sap.com/t5/technology-q-a/question-about-abap-businessuite-workflow/qaq-p/12758058 Question about abap businessuite workflow 2023-12-06T19:04:48+01:00 ccshunji https://community.sap.com/t5/user/viewprofilepage/user-id/872310 <P>Hello SAP IDM Community,</P> <P>I hope this message finds you well. I am currently working on a task related to the 'connector.abap.businessuite' workflow, specifically within the 'AssignUserMembership' operation. I've observed that there is a 'SetModifyContext' under the 'destination' tab, where the attribute 'CHANGE_MODE' is set to 'U' by default. I am curious to understand the significance of this setting. Could anyone kindly shed some light on its meaning and implications?</P> <P><A href="https://answers.sap.com/storage/temp/2233463-change-mode.jpg" data-attachment="2233463" rel="noopener noreferrer">change-mode.jpg</A></P> <P>Additionally, in my comparison between 'abap businessuite' and 'connector.abap', I noticed that under the same 'AssignUserMembership' operation, 'connector.abap' lacks the 'SetModifyContext'. I'm interested to know if anyone has insights into why these two connectors have different workflows for the same operation.</P> <P><A href="https://answers.sap.com/storage/temp/2233462-connector.jpg" data-attachment="2233462" rel="noopener noreferrer">connector.jpg</A></P> <P>Your expertise and guidance on this matter would be greatly appreciated.</P> <P>Thank you in advance for your assistance.</P>Regards,Shunji 2023-12-06T19:04:48+01:00 https://community.sap.com/t5/technology-q-a/how-to-lock-and-unlock-users-in-sap-btp/qaq-p/12791830 How to lock and unlock users in SAP BTP? 2023-12-18T09:19:36+01:00 VijayRao https://community.sap.com/t5/user/viewprofilepage/user-id/823 <P>Hi,</P> <P>Is it possible to lock and unlock users in SAP BTP more specifically in IAS tenant? We are already using SAP BTP and phase1 of the project is already live. We are now going live with phase 2 and We would like to lock users in BTP during the cutover activity.</P> <P>I've looked at the SAP business accelerator hub and did not find any APIs which could be used for the above requirement. Is there any other options I may have missed? </P> <P>Regards, Vijay</P> 2023-12-18T09:19:36+01:00 https://community.sap.com/t5/technology-q-a/connection-sap-idm-to-ips-btp/qaq-p/12818701 Connection SAP IDM to IPS (BTP) 2024-01-11T09:27:31+01:00 michael_riant https://community.sap.com/t5/user/viewprofilepage/user-id/625874 <P>Hello everyone,</P> <P>We want to connect SAP IDM to SAC cloud systems in this case .</P> <P>For this we think to go through a construction with IPS.</P> <P>Someone will tell me that it is the best method to connect IDM to BTP and IPS and give me the procedure, please?</P> <P>Sincerely,</P> <P>Michael</P> 2024-01-11T09:27:31+01:00 https://community.sap.com/t5/technology-q-a/sap-idm-custom-job-trigger-schedule-question/qaq-p/13590023 SAP IDM custom Job trigger / Schedule question 2024-01-31T23:26:07.262000+01:00 shunji https://community.sap.com/t5/user/viewprofilepage/user-id/872215 <P>Hi All experts!</P><P>Can we set up a job to trigger when an attribute is modified in IDM? While I know we can create a custom job with a scheduled frequency, such as every hour, I'm specifically interested in having the script run automatically just once when an IDM attribute is modified. I've experimented with 'On demand', but it seems the job requires manual triggering.</P><P>Can we establish a schedule that, once selected, will execute once an then cease? If yes, how to setup the MC_SCHE_RULE table and MC_SCHED_ITEM?</P><P>Any insights or suggestions on this matter would be appreciated.</P><P>Thank you.</P> 2024-01-31T23:26:07.262000+01:00 https://community.sap.com/t5/technology-q-a/how-to-read-security-audit-logs-sm19-sm20-using-fm-rsau-read-log/qaq-p/13590977 How to read Security audit Logs (SM19/SM20) using FM RSAU_READ_LOG? 2024-02-01T13:27:19.641000+01:00 devaprakash_b https://community.sap.com/t5/user/viewprofilepage/user-id/204226 <P>Hello Everyone,<BR /><BR />I would like to read the security audit logs generated for the user during a specified time using the Function Module RASU_READ_LOG, but facing challenges in providing the required input.<BR /><BR />Not understanding what input to be passed and which are required, tried a lot but the results returning are empty. I was able to fetch records using another FM&nbsp;RSAU_API_GET_LOG_DATA, but cannot use this as the FM is not remote/RFC enabled.&nbsp;<BR /><BR />Can someone kindly let me know or share some documentation related to this FM&nbsp;RASU_READ_LOG about expected inputs.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="devaprakash_b_1-1706790157593.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/58334i1F5C0EC15D675DBE/image-size/medium?v=v2&amp;px=400" role="button" title="devaprakash_b_1-1706790157593.png" alt="devaprakash_b_1-1706790157593.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="devaprakash_b_2-1706790160464.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/58335i2C815F285F955EE0/image-size/medium?v=v2&amp;px=400" role="button" title="devaprakash_b_2-1706790160464.png" alt="devaprakash_b_2-1706790160464.png" /></span></P><P>&nbsp;</P><P>&nbsp;</P> 2024-02-01T13:27:19.641000+01:00 https://community.sap.com/t5/technology-q-a/ias-custom-password-policy/qaq-p/13593890 IAS Custom password policy 2024-02-04T14:14:51.522000+01:00 madhusudhanan https://community.sap.com/t5/user/viewprofilepage/user-id/11814 <P>When I try to create a custom policy to change the password length, maximum is not changeable. Does any one know if it's a bug or not possible?</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="madhusudhanan_0-1707052320133.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/59953i38D7A75A1A025DDB/image-size/medium?v=v2&amp;px=400" role="button" title="madhusudhanan_0-1707052320133.png" alt="madhusudhanan_0-1707052320133.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="madhusudhanan_1-1707052428226.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/59954iF77052E004C07F14/image-size/medium?v=v2&amp;px=400" role="button" title="madhusudhanan_1-1707052428226.png" alt="madhusudhanan_1-1707052428226.png" /></span></P><P>Thanks,</P><P>Madhu</P><P>&nbsp;</P><P>&nbsp;</P> 2024-02-04T14:14:51.522000+01:00 https://community.sap.com/t5/technology-q-a/role-request-getting-auto-reconcile/qaq-p/13599481 Role Request getting auto reconcile 2024-02-08T15:04:44.621000+01:00 laxmi275 https://community.sap.com/t5/user/viewprofilepage/user-id/876381 <P>Hi IDM Gurus,<BR /><BR />There is an issue, a user had requested a role last year it got approved but Status was failed, Operation Text was "Not Assigned".<BR />The role request got auto reconciled again same approval flow happened but still not assigned.<BR />Even after approving, the role is not getting assigned and getting reconciled again and again.<BR /><BR />Could you please provide assistance to find out the cause of this issue.<BR /><SPAN>Your prompt guidance is highly appreciated.<BR /><BR /></SPAN>Thanks &amp; Regards,<BR />Laxmi<BR /><BR /></P> 2024-02-08T15:04:44.621000+01:00 https://community.sap.com/t5/technology-q-a/some-employees-are-not-being-synced-to-ias-ips-from-successfactors-not/qaq-p/13607253 Some employees are not being synced to IAS/IPS from SuccessFactors, not included on skip/error log 2024-02-15T23:56:39.051000+01:00 sydniefitts https://community.sap.com/t5/user/viewprofilepage/user-id/160055 <P>Hello,</P><P>Some employees are not being synced to IAS/IPS and do not appear on the error or skip logs. There are no filters set to exclude these users, their data in SuccessFactors is unique, and we do not have IAS for ONB enabled. Has anyone encountered this issue? If so, what was the fix? Any insight on what may be the cause is greatly appreciated!</P><P>Thank you,</P><P>Sydnie</P> 2024-02-15T23:56:39.051000+01:00 https://community.sap.com/t5/human-capital-management-q-a/loginmethod-pwd-and-sso-in-scim-api-version-2/qaq-p/13618782 loginmethod PWD and SSO in SCIM API version 2 2024-02-26T08:52:27.681000+01:00 meenakshi_si https://community.sap.com/t5/user/viewprofilepage/user-id/30351 <P>Hi Eperts,</P><P>We had below code for loginmethod in SCIM APi version 1:</P><P>"targetPath": "$.userType",<BR />"condition": "$.loginMethod == 'PWD'",<BR />"constant": "partner"<BR />},<BR />{<BR />"targetPath": "$.userType",<BR />"condition": "$.loginMethod == 'SSO'",<BR />"constant": "employee"<BR />},<BR />{<BR />"targetPath": "$.userType",<BR />"condition": "$.loginMethod == ''",<BR />"constant": "employee"</P><P>How to add the loginmethod like this in SCIM API version 2? Please advise.</P><P>Thanks,</P> 2024-02-26T08:52:27.681000+01:00 https://community.sap.com/t5/technology-q-a/ias-as-proxy/qaq-p/13626289 IAS as proxy 2024-03-03T17:43:16.434000+01:00 tskwin https://community.sap.com/t5/user/viewprofilepage/user-id/823618 <P>Hello experts,</P><P>I have configured SAP IAS as a proxy to Azure AD.</P><P>The groups from Azure AD (Groups Claim) are mapped to SAP BTP under "Role Collections" -&gt; "User Groups"-&gt;Object ID from Azure Group.</P><P>However, how can I map or synchronize the groups that I have created in IAS to SAP BTP?</P><P>Is it to recommended to map&nbsp; the groups from Azure to IAS ?</P><P>Thank you very much.</P> 2024-03-03T17:43:16.434000+01:00 https://community.sap.com/t5/technology-q-a/user-creation-failed-due-to-validation-error/qaq-p/13635322 User creation failed due to validation error 2024-03-12T12:15:32.524000+01:00 laxmi275 https://community.sap.com/t5/user/viewprofilepage/user-id/876381 <P>Hello All,<BR /><BR />While creating user from IDM to Domino for 3-4 users we are getting "Failed due to validation error".<BR />Domino Team said its issue from IDM end.<BR /><BR />Please guide me what can be the possible reason for getting this error and how can I resolve it.<BR /><BR />Thanks &amp; Regards,<BR />Laxmi</P> 2024-03-12T12:15:32.524000+01:00 https://community.sap.com/t5/technology-q-a/sap-idm-sac-support-for-sac-roles-and-team-liaison-in-idm/qaq-p/13638533 SAP IDM/SAC Support for SAC roles and TEAM liaison in IDM 2024-03-14T16:19:50.917000+01:00 michael_riant https://community.sap.com/t5/user/viewprofilepage/user-id/625874 <P>Hello,</P><P>We just connected IDM to SAC via IPS.</P><P>We are able to create users in ISC from IDM and assign them TEAMS.</P><P>However, when assigning a user to a TEAM, this removes the connection between the TEAM and its SAC roles.</P><P>I read that it was necessary in the api to return the roles of the Team but we did not find a solution to recover this and how to send it back to SAC.</P><P><A href="https://www.ibsolution.com/academy/blog_en/sap-cyber-security/seven-challenges-in-connecting-sac-to-sap-ips" target="_blank" rel="nofollow noopener noreferrer">https://www.ibsolution.com/academy/blog_en/sap-cyber-security/seven-challenges-in-connecting-sac-to-sap-ips</A></P><P>Has anyone ever encountered this problem?&nbsp;</P><P>if yes what was your solution?</P><P>Regards</P><P>Michael</P> 2024-03-14T16:19:50.917000+01:00 https://community.sap.com/t5/technology-q-a/authentication-error-while-connecting-to-domino-from-idm/qaq-p/13642715 Authentication error while connecting to Domino from IDM 2024-03-19T12:09:33.292000+01:00 laxmi275 https://community.sap.com/t5/user/viewprofilepage/user-id/876381 <P>Hi All,<BR /><BR />Needed your guidance for below two case.</P><P>--&gt;&nbsp; I'm getting below error while connecting to Domino from IDM Test env.<BR /><BR />(LDAP error: The supplied credential is invalid)<BR />Explanation: [LDAP: error code 49 - Failed, invalid credentials for "UserID"] - javax.naming.AuthenticationException: [LDAP: error code 49 - Failed, invalid credentials for "UserID"]<BR /><BR />The password is correct in IDM, in logs also its fetching correct, I can able to access it via Jxplorer and can able to login into Domino which is installed in IDM Test Env with same credentials but still getting error while connecting by IDM workflow.<BR /><BR />--&gt; Getting "Restricted Operation on server" error while performing delete operation from IDM to Domino. Creation, Modification is working but deletion is troughing error.<BR /><BR />As per Domino Team they have provided manager access to IDM Technical userID that has required access to perform this action. Still Can't able to find where the actual issue is.<BR /><BR />Could you please provide assistance what can be possible mistake there can be in IDM/ Domino configuration or resolution for the issue.<BR /><BR /><BR />Thanks &amp; Regards,<BR />Laxmi</P> 2024-03-19T12:09:33.292000+01:00 https://community.sap.com/t5/technology-q-a/extract-data-from-file-fetched-from-ui/qaq-p/13666087 Extract Data from File fetched from UI 2024-04-10T18:28:40.870000+02:00 laxmi275 https://community.sap.com/t5/user/viewprofilepage/user-id/876381 <P>Hi All,<BR /><BR />From UI I can able to fetch the file and store it into a folder but in next step I'm facing little issue to fetch file from folder.<BR />Using From ASCII pass I can achieve it but I need to make it dynamic so that in next action task it takes the file from same place where it had store in first action task.<BR />I tried storing the path in job variable in action task 1 but couldn't able to fetch this variable data in action task 2.<BR /><BR />Please assist.<BR /><BR />Thanks &amp; Regards,<BR />Laxmi</P> 2024-04-10T18:28:40.870000+02:00 https://community.sap.com/t5/technology-q-a/shadow-user-in-btp/qaq-p/13674383 Shadow user in BTP 2024-04-18T11:36:17.711000+02:00 tskwin https://community.sap.com/t5/user/viewprofilepage/user-id/823618 <P>Hello,</P><P>What are the possible methods for automatic user provisioning from SAP IAS to SAP BTP while "Create Shadow Users During Logon" option in SAP BTP is deactivated ?</P><P><SPAN>Or do users need to be created manually in SAP BTP in that case?</SPAN></P><P><SPAN>Many thanks for every tip ?<BR /></SPAN></P><P>&nbsp;</P><P><SPAN>Best Regards</SPAN></P><P>&nbsp;</P> 2024-04-18T11:36:17.711000+02:00 https://community.sap.com/t5/technology-q-a/what-is-the-standard-page-to-display-employee-username-in-successfactors/qaq-p/13677909 what is the standard page to display employee Username in SuccessFactors : IAS or Spotlight? 2024-04-22T11:31:01.611000+02:00 pboulicaut https://community.sap.com/t5/user/viewprofilepage/user-id/27536 <P>with the latest release of SuccessFactors H1 2024 (B2405) , we no longer able to display username in SuccessFactors new feature : Spotlight view &amp; spotlight preview.</P><P>what is the expected "latest experience" page to display Employee username ?</P><P>is it SuccessFactors Public Profile view ?&nbsp;</P><P>or</P><P>is it IAS Employee Profile view XXX.ondemand.com/ui/protected/profilemanagement ?</P><P>For your information:&nbsp;</P><P>name format is enabled</P><P>Hide Username in the UI is Disabled&nbsp;</P><P>i’ve only found a sap note that described the enabled value :&nbsp;</P><P><A href="https://userapps.support.sap.com/sap/support/knowledge/en/3016071" target="_blank" rel="noopener noreferrer"><SPAN class="">If this feature is enabled, username won’t be displayed on the Global Header and the employee quickcard. You cannot run a username search or see username in the search results in the areas that have adopted People Search, which include the Global Header, Org Chart, People Profile, Change Audit Report, and others.</SPAN> </A></P> 2024-04-22T11:31:01.611000+02:00 https://community.sap.com/t5/technology-q-a/putnextentry-failed-storing-spml-sapuser/qaq-p/13678887 putNextEntry failed storing SPML.SAPUSER 2024-04-23T07:08:19.985000+02:00 laxmi275 https://community.sap.com/t5/user/viewprofilepage/user-id/876381 <P>Hi All,<BR /><BR />I'm getting "<FONT color="#FF0000">putNextEntry failed storing SPML.SAPUSER</FONT>" Error while&nbsp; reprocessing the user failed privilege.<BR />User account attribute is correctly set in IDM and as mentioned in&nbsp;<BR /><A href="https://community.sap.com/t5/technology-q-a/unable-to-reprocess-the-failed-role/qaq-p/11322380#feedback-error" target="_blank">https://community.sap.com/t5/technology-q-a/unable-to-reprocess-the-failed-role/qaq-p/11322380#feedback-error</A>&nbsp;<BR /><BR />the privilege is not orphan, could you please help where I'm missing to check.<BR /><BR />Thanks &amp; Regards,<BR />Laxmi</P> 2024-04-23T07:08:19.985000+02:00 https://community.sap.com/t5/technology-q-a/how-to-enable-activation-email-in-ias-for-manual-import-from-s-4hana-public/qaq-p/13689924 How to enable activation email in IAS for manual import from S/4HANA Public Cloud? 2024-05-02T19:22:07.907000+02:00 shaji_narayanan https://community.sap.com/t5/user/viewprofilepage/user-id/9978 <P>Hello IAM/IAS Gurus,</P><P>How can I enable the activation email to be sent to each newly created user (via a manual import) in IAS Tenant?&nbsp;&nbsp;</P><P>I use the import job to create users in bulk in IAS.&nbsp; The import file is created from the backend S/4HANA public cloud tenant.</P><P>While the users are getting created in the IAS tenant, no activation email is sent to them.</P><P>As a workaround, I am manually initiating an activation email in IAS.&nbsp; This process is time-consuming and does not send the link for the backend S/4HANA public cloud tenant.</P><P>How can I ensure that when each time a mass user import is performed, the newly created users created will get an activation email, along with the url/link to the <U><STRONG>specific back-end S/4HANA public cloud tenant from which the import file was created</STRONG></U>?&nbsp; The underlined requirement is key, as the import file could be created from multiple S/4HANA public tenants (eg: Starter, DEV or TEST).</P><P>Thank you in advance and best regards,</P><P>Shaji</P> 2024-05-02T19:22:07.907000+02:00 https://community.sap.com/t5/technology-q-a/problem-in-sap-idm-while-running-sfsf-delta-load-using-last-modified-on/qaq-p/13694032 Problem in SAP IDM while running SFSF Delta load using last_modified_on filter 2024-05-07T16:05:58.397000+02:00 ravi_paul https://community.sap.com/t5/user/viewprofilepage/user-id/216731 <P>Hi Gurus,</P><P>We have IDM 8 SP4 version installed and want to integrate SuccessFactor(SF) Employee Central(EC) module where we are using CompoundEmployee SOAP API to retrieve user data. Good part is, while we do a full run(initial load), we are able to read users data from SF EC however we also have to setup delta read from SF EC.</P><P>While I was going thru many blogs and articles on CompoundEmployee, I found we should use last_modified_on filter/parameter from the last successful run that should give us information but unfortunately I'm unable to retrieve info. I have followed SAP Note - <A href="https://me.sap.com/notes/2784576/E" target="_blank" rel="noopener noreferrer">https://me.sap.com/notes/2784576/E</A></P><P>Here are the screenshot from IDM -</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ravi_paul_0-1715090198832.png" style="width: 556px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/106925i8CDD70637BE81A43/image-dimensions/556x286?v=v2" width="556" height="286" role="button" title="ravi_paul_0-1715090198832.png" alt="ravi_paul_0-1715090198832.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ravi_paul_1-1715090233417.png" style="width: 521px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/106926i2F4D5E2243CE6DDF/image-dimensions/521x218?v=v2" width="521" height="218" role="button" title="ravi_paul_1-1715090233417.png" alt="ravi_paul_1-1715090233417.png" /></span></P><P>Table Entry of same user when ran full sync which shows that changes was made within 3 months to user's profile -</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ravi_paul_2-1715090450731.png" style="width: 732px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/106928i639DD4D37BCF24D4/image-dimensions/732x165?v=v2" width="732" height="165" role="button" title="ravi_paul_2-1715090450731.png" alt="ravi_paul_2-1715090450731.png" /></span></P><P>Regards,</P><P>Ravi Paul</P><P>&nbsp;</P><P>&nbsp;</P> 2024-05-07T16:05:58.397000+02:00