https://raw.githubusercontent.com/ajmaradiaga/feeds/main/scmt/topics/SAP-Identity-Management-qa.xml SAP Community - SAP Identity Management 2026-02-19T00:12:45.669125+00:00 python-feedgen SAP Identity Management Q&A in SAP Community https://community.sap.com/t5/technology-q-a/error-provisioning-roles-from-idm-to-hana-repositories-the-provided-input/qaq-p/14173130 Error Provisioning roles from IdM to HANA repositories - The provided input is not valid design time 2025-08-06T11:12:18.072000+02:00 Satish1995 https://community.sap.com/t5/user/viewprofilepage/user-id/1533082 <P>Hello All,</P><P>I have been trying to assign few roles to users from IdM to HANA repositories but received error stating that&nbsp;<STRONG>The provided input is not valid design time role.&nbsp;&nbsp;</STRONG>I can assign the role manually in HANA system.</P><P>Could you please check and help me out.</P><P>&nbsp;</P><P>Thank you!!<span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/297082i9F1C209370C903EF/image-size/large?v=v2&amp;px=999" role="button" title="image.png" alt="image.png" /></span></P> 2025-08-06T11:12:18.072000+02:00 https://community.sap.com/t5/human-capital-management-q-a/ias-notification-for-migrated-users-from-external-sites-learning-only-user/qaq-p/14196931 IAS- Notification for Migrated users from External Sites - Learning only-user 2025-08-28T12:42:12.559000+02:00 luisfrancisco93 https://community.sap.com/t5/user/viewprofilepage/user-id/37774 <DIV class=""><DIV class=""><DIV class=""><DIV class="">&nbsp;</DIV></DIV></DIV></DIV><DIV class="">Hi I would like to ask: if email notifications are enabled in IAS, when the ReadJob is executed for the users migrated from Learning, will they receive a notification to activate their accounts?</DIV> 2025-08-28T12:42:12.559000+02:00 https://community.sap.com/t5/technology-q-a/create-2-source-system-in-ias-sf-for-user-provisioning-and-entra-for-group/qaq-p/14206843 create 2 source system in IAS: SF for user provisioning and ENTRA for Group Provisioning 2025-09-04T08:35:49.801000+02:00 Sahil_Sachdeva https://community.sap.com/t5/user/viewprofilepage/user-id/128140 <P><SPAN>Dear All,</SPAN><BR /><SPAN>I am seeking assistance with combining multiple sources to a single target, IAS, using automated triggers. Users will be imported from SuccessFactors, and groups will be created and provisioned from ENTRA. However, upon investigation, I have found that the assignment of these groups to users in IAS is not occurring.</SPAN><BR /><BR /><SPAN>Specifically, the groups are being created, but the users are not being assigned to them in IAS. I am curious to know if anyone has encountered this issue before and has any guidance on resolving it.</SPAN><BR /><BR /><SPAN>Best regards,</SPAN></P> 2025-09-04T08:35:49.801000+02:00 https://community.sap.com/t5/technology-q-a/sap-idm-digit-change-on-entryid-causes-selection-of-further-data/qaq-p/14232558 SAP IDM: Digit change on EntryId causes selection of further data 2025-10-01T13:24:05.257000+02:00 adamkowicz2k20 https://community.sap.com/t5/user/viewprofilepage/user-id/745473 <P>Dear Gurus,</P><P>I have a question regarding the SAP IDM Url, why is it possible to see the other entries by changing the digits on the EntryId in the browser, is there a possiblity to mask the EntryId?&nbsp;</P><P data-unlink="true">Below is the output of my browser when I am logged in as Admin User in our SAP IDM and looked for a colleague to change his values.&nbsp;</P><P data-unlink="true">http://localhost:50000/webdynpro/dispatcher/sap.com/tc~idm~wd~workflow/EditTask?TaskId=1643&amp;EntryId=43408#&nbsp;</P><P>The out put of the Values are Mr. X with the company details etc.&nbsp;</P><P>But when I change the last digits of the above url to 9 instead of 8,&nbsp; I am able to see the other entries.&nbsp;</P><P><A href="http://localhost:50000/webdynpro/dispatcher/sap.com/tc~idm~wd~workflow/EditTask?TaskId=1643&amp;EntryId=4340" target="_blank" rel="noopener nofollow noreferrer">http://localhost:50000/webdynpro/dispatcher/sap.com/tc~idm~wd~workflow/EditTask?TaskId=1643&amp;EntryId=4340</A><STRONG>9</STRONG>#&nbsp;</P><P>For a IDM Admin shouldn't be the problem but for other normal users should be limited. Is there a possiblity to limit the view or the access to avoid these kind of view?&nbsp;</P><P>Looking forward to hear from you&nbsp;</P> 2025-10-01T13:24:05.257000+02:00 https://community.sap.com/t5/technology-q-a/business-event-definition-error-for-mcp-task/qaq-p/14243048 Business event definition error for MCP task 2025-10-14T07:49:58.432000+02:00 plaban_sahoo28 https://community.sap.com/t5/user/viewprofilepage/user-id/795565 <P>Hi All,</P><P>when providing the 'agent of control performance' in the 'requested end' tab of MCP task , there is a binding error as attached. However, when the binding is changed to agent of escalation, there is no binding error.</P><P>But the reminder(requested end') should be sent to agent of control performance. please guide as how to</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MCP2.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327051iE3334A77A5AC9E2D/image-size/medium?v=v2&amp;px=400" role="button" title="MCP2.png" alt="MCP2.png" /></span></P><P> </P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MCP1.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/327052i79F5CB99424435C1/image-size/medium?v=v2&amp;px=400" role="button" title="MCP1.png" alt="MCP1.png" /></span></P><P> BR, plaban</P> 2025-10-14T07:49:58.432000+02:00 https://community.sap.com/t5/technology-q-a/we-have-now-uploaded-the-standard-ruleset-into-iag-and-able-to-run-an-sod/qaq-p/14256589 We have now uploaded the standard ruleset into IAG And able to run an SOD report against S4 Hana 2025-10-30T00:22:43.127000+01:00 SapnaKarthikeyan https://community.sap.com/t5/user/viewprofilepage/user-id/1469799 <P>We need to now set up MITIGATION CONTROLS for open SODs — meanwhile the business and audit want to see underlying actions and permissions mapped with each Risk Id . How do I provide that information ?&nbsp;</P> 2025-10-30T00:22:43.127000+01:00 https://community.sap.com/t5/technology-q-a/how-to-check-sod-for-digital-manufacturing/qaq-p/14257479 How to check SOD for Digital Manufacturing? 2025-10-30T20:51:16.899000+01:00 SapnaKarthikeyan https://community.sap.com/t5/user/viewprofilepage/user-id/1469799 <P>We do not have IAG Bridge to connect to SAP GRC. Is there any other way to Implement SOD checks for SAP Digital Manufacturing ?&nbsp;</P><P>Any recommedations and tools ?</P> 2025-10-30T20:51:16.899000+01:00 https://community.sap.com/t5/technology-q-a/how-can-i-replicate-the-passwords-defined-in-sap-ias-to-my-destination/qaq-p/14260830 How can I replicate the passwords defined in SAP IAS to my destination system 2025-11-05T00:22:07.991000+01:00 csrsilva https://community.sap.com/t5/user/viewprofilepage/user-id/278765 <P>I'm using IAS as the source and S4HANA on-premise as the target, and I've already implemented user replication.</P><P>However, I'm having a problem. I want to use the same password that each user has defined in SAP IAS so they can log into the S4HANA system, but I haven't been able to. The only thing I see in the transformations default code indicates that a random password is created with certain requirements, such as character count, uppercase and lowercase letters, etc.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="csilva1_0-1762298187782.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/336295iC566F881C97032E7/image-size/medium?v=v2&amp;px=400" role="button" title="csilva1_0-1762298187782.png" alt="csilva1_0-1762298187782.png" /></span></P><P>&nbsp;</P><P>Does anyone know if this is possible?</P><P>If it is, could you guide me on the configuration I should change?</P> 2025-11-05T00:22:07.991000+01:00 https://community.sap.com/t5/enterprise-resource-planning-q-a/sap-auth-and-security-project-work-implementation/qaq-p/14270728 SAP Auth and Security Project work / Implementation 2025-11-17T08:20:27.729000+01:00 ECONRADIE https://community.sap.com/t5/user/viewprofilepage/user-id/1401836 <P>Hi Security Team,</P><P>I’ve been working as an SAP Authorizations &amp; Security Consultant for the past nine years, primarily supporting ECC environments and managing day-to-day user access operations. I’m now looking to broaden my expertise beyond BAU activities and deepen my knowledge in areas such as:</P><UL><LI><P>SAP GRC implementation</P></LI><LI><P>Rule set design and optimization</P></LI><LI><P>SAP role-build methodologies and best-practice frameworks</P></LI><LI><P>Overall project-based security design and governance</P></LI></UL><P>If anyone could recommend tools, materials, frameworks, or learning paths that would help strengthen my understanding of these project-focused areas, I would really appreciate it.</P><P>Thank you in advance.</P> 2025-11-17T08:20:27.729000+01:00 https://community.sap.com/t5/technology-q-a/ias-user-mail/qaq-p/14276469 IAS User Mail 2025-11-24T23:20:32.916000+01:00 tskwin https://community.sap.com/t5/user/viewprofilepage/user-id/823618 <P class="lia-align-left" style="text-align : left;">Hello everyone,</P><P>some of my users are provisioned from Azure → IAS, while others are created locally in IAS.</P><P>What options are available to send activation/verification emails to both types of users (no mail server is configured)?</P><P>Many Thanks</P><P>Best Regards</P> 2025-11-24T23:20:32.916000+01:00 https://community.sap.com/t5/technology-q-a/sap-btp-integration-suite-cloud-to-sap-s4-private-cloud/qaq-p/14280578 SAP BTP Integration Suite Cloud to SAP S4 Private Cloud 2025-11-30T18:21:37.643000+01:00 rajeshps https://community.sap.com/t5/user/viewprofilepage/user-id/157724 <P>Dear All,</P><P>Good Day!</P><P>Is there any documentation/steps to integrate <STRONG>SAP BTP Integration Suite Cloud to SAP S4 Private Cloud</STRONG> via Oauth2.0 Bearer Token.</P><P>Am not finding any documentation from SAP.</P><P>Thanks and Regards,</P><P>Rajesh PS</P> 2025-11-30T18:21:37.643000+01:00 https://community.sap.com/t5/technology-q-a/error-while-connecting-from-sap-btp-integration-suite-to-sap-s4-cloud-odata/qaq-p/14280585 Error: While connecting from SAP BTP Integration Suite to SAP S4 Cloud Odata 2025-11-30T19:42:29.722000+01:00 rajeshps https://community.sap.com/t5/user/viewprofilepage/user-id/157724 <P>Hello Team,</P><P>&nbsp;</P><P>I'm getting below error while connecting from SAP BTP Integration Suite Cloud to SAP S4 Cloud Odata service.</P><P>"<SPAN>com.sap.gateway.core.ip.component.odata.exception.OsciException: HTTP Request failed with error : &lt;HOST&gt;: No address associated with hostname, cause: java.net.UnknownHostException: &lt;HOST&gt;: No address associated with hostname</SPAN>"</P><P>&nbsp;</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rajeshps_1-1764527895212.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/346799iDD39DE0DFCDC769F/image-size/medium?v=v2&amp;px=400" role="button" title="rajeshps_1-1764527895212.png" alt="rajeshps_1-1764527895212.png" /></span></P><P>&nbsp;</P><P>&nbsp;</P><P>Thanks and Regards,</P><P>Rajesh PS</P> 2025-11-30T19:42:29.722000+01:00 https://community.sap.com/t5/technology-q-a/add-indexes-in-sql-db-sap-idm/qaq-p/14287242 Add Indexes in SQL DB SAP IDM 2025-12-09T17:31:33.318000+01:00 annpilote https://community.sap.com/t5/user/viewprofilepage/user-id/634675 <P>Simple question here</P><P>is it ok or permit&nbsp; to add indexe on some tables like these on sql DB IDM&nbsp;</P><P>MXI_link_audit<BR />mxi_entry<BR />MXP_AUDIT<BR /><SPAN>JOB_EXECUTION</SPAN></P><P>&nbsp;</P><P>&nbsp;</P><P>&nbsp;</P> 2025-12-09T17:31:33.318000+01:00 https://community.sap.com/t5/technology-q-a/sap-ias-admin-console/qaq-p/14287300 SAP IAS Admin Console 2025-12-09T20:09:22.861000+01:00 tskwin https://community.sap.com/t5/user/viewprofilepage/user-id/823618 <P>Hello everyone,</P><P>What would be the best way to secure the SAP IAS Administration Console?</P><P>Is it a good idea to restrict access to a specific IP range (e.g. only the company network)? I’m concerned about locking myself out in case the IP address changes.</P><P>Or would it be better to implement 2FA for an admin group containing all admins? In that case, there’s also the risk of locking myself out.</P><P>I would appreciate your experiences and tips!</P><P>Many Thanks&nbsp;</P><P>Best Regards</P> 2025-12-09T20:09:22.861000+01:00 https://community.sap.com/t5/technology-q-a/sac-sso-merging-existing-users-without-losing-content/qaq-p/14292993 SAC SSO: Merging existing users without losing content 2025-12-18T07:38:29.547000+01:00 tskwin https://community.sap.com/t5/user/viewprofilepage/user-id/823618 <P>Hi Experts,</P><P>we have IAS configured as a proxy. Users are provisioned from a custom IdP to IAS and then created dynamically in SAC (attribute = User ID) via SSO .</P><P>In SAC, there are already manually created users with existing content.<BR />The SSO users and the manually created users in SAC have different User IDs, which is historical.</P><P>Our goal is to switch fully to SSO and replace or merge the existing SAC users without losing user content (stories, private objects, settings).</P><P>Currently, we face the following issues:</P><UL><LI><P>SAC does not allow duplicate email addresses when a new SSO user is created (different User ID, but same email address).</P></LI><LI><P>When we assign roles manually in SAC to an SSO user, they are removed at the next login.</P></LI></UL><P>Our questions:</P><UL><LI><P>What is the recommended approach to dynamically create SSO users in SAC and transfer or replace existing content from the old user to the new SSO user?</P></LI><LI><P>Is there a simple or supported way to migrate or merge existing SAC users with the new SSO users?</P></LI><LI>How are Owner property handled when SSO is activated, and what should be considered to avoid issues with access or content ownership?</LI></UL><P>Thank you very much for your help and experience.</P><P>Best regards</P> 2025-12-18T07:38:29.547000+01:00 https://community.sap.com/t5/technology-q-a/high-skip-audit-numbers-in-audit-table/qaq-p/14306994 High-skip Audit numbers in Audit table 2026-01-14T04:53:37.784000+01:00 plaban_sahoo28 https://community.sap.com/t5/user/viewprofilepage/user-id/795565 <P>Hi All, in IDM 8 there is a very high increase in Audit numbers in the mxp_audit table. i.e 100000 numbers have been skipped twice. This has happened after the Audit tables were cleaned up due to Audit overflow.</P><P>Please suggest as to why this skip has&nbsp;happened&nbsp;</P><P>Regards</P><P>Plaban</P> 2026-01-14T04:53:37.784000+01:00 https://community.sap.com/t5/technology-q-a/should-financial-platforms-assume-user-understanding-or-technically-prove/qaq-p/14308977 Should Financial Platforms Assume User Understanding — or Technically Prove It Before Execution? 2026-01-16T22:25:49.594000+01:00 VerFiComplianceEDU https://community.sap.com/t5/user/viewprofilepage/user-id/2274914 <DIV>&nbsp;</DIV><DIV>&nbsp;</DIV><DIV>Across financial, enterprise, and transactional systems, most platforms still rely on a critical assumption:<BR /><BR />That a user’s identity verification and acceptance of terms implies understanding.<BR /><BR />From a systems-design perspective, this assumption feels increasingly fragile.<BR /><BR />In high-impact workflows — payments, financial commitments, contract execution, irreversible actions — identity alone does not establish comprehension, intent, or informed consent. Yet most platforms treat it as sufficient.<BR /><BR />My question is architectural, not philosophical:<BR /><BR />• Should platforms remain passive recorders of identity and clicks?<BR />• Or should they actively enforce verified comprehension before allowing execution?<BR />• If so, where should that verification live — UI layer, middleware, or as a system-of-record?<BR />• How would such a model integrate with existing enterprise identity, audit, and compliance frameworks?<BR /><BR />I’m interested in how SAP architects and enterprise developers think about this tradeoff as systems move toward higher automation, AI-driven decisions, and irreversible digital actions.<BR /><BR />Is “assumed understanding” still defensible at scale — or is it a design gap waiting to be formalized?</DIV><DIV class="">&nbsp;</DIV><DIV class="">&nbsp;</DIV> 2026-01-16T22:25:49.594000+01:00 https://community.sap.com/t5/technology-q-a/azure-name-and-family-name-routing/qaq-p/14310853 Azure name and family name routing 2026-01-20T09:13:52.518000+01:00 YanGerzon https://community.sap.com/t5/user/viewprofilepage/user-id/155034 <P>Hi,<BR /><BR />We have apps deployed to cloud foundy on a global account.<BR />We have apps both in a space and in the HTML 5 repo.<BR />We sometimes use a dedicated approuter and sometimes we deploy our own.<BR /><BR />We have app users that connect using an Azure trust configuration in the subaccount.<BR />We also have platform users using SAP's default IDP to login with an S-user.<BR />This means that when a user wants to use an app or login to BTP cockpit he needs to choose which authentication to use,&nbsp; SAP's default identity provider or the Azure connection.<BR /><BR />I was asked to allow users to login without having to make this selection.<BR />I setup and IAS trust configuration and inside the IAS I defined the Azure IDP and routing based on email hostname.<BR />Now users are greated by the IAS login and when they input their azure email it redirects them to login using azure and when platform users use their email they login directly through IAS versus the users' creds I defined in the IAS.<BR /><BR />The problem:<BR />All our apps get data about the currently logged in user(to the app) via the approuter's /userinfo.<BR />Now after setting up the IAS and the routing, if i log in as an Azure user i see in the devtools im not getting name and family name in the /userinfo any more, only email information.<BR />I tried all orts of manipulations in the IAS but i cant see to get it to display name and family name like it does with a direct azure trust configuration.<BR />Is there any IAS configuration solution to this issue or must we modify all our apps?<BR /><BR /></P> 2026-01-20T09:13:52.518000+01:00 https://community.sap.com/t5/enterprise-resource-planning-q-a/best-practice-for-managing-business-role-changes-after-an-upgrade/qaq-p/14312677 Best Practice for Managing Business Role Changes After an Upgrade 2026-01-22T14:03:24.158000+01:00 ReginaCr https://community.sap.com/t5/user/viewprofilepage/user-id/1800974 <P>Dear community,</P><P>what is in your opinion the best way to manage the changes after an upgrade in consideration of transports of software collections?</P><P>At the moment it seems for me, you have to maintain the changes two times with a 3 landscape system:</P><P class="lia-indent-padding-left-60px" style="padding-left : 60px;">1. Update the business roles in Test system to make the changes available for testing the release</P><P class="lia-indent-padding-left-60px" style="padding-left : 60px;">2. Update the business roles in Q system again after the release was deploy to Q and Productive System to transport the changes with the software collection to all 3 systems</P><P>Is this the correct procedure? Is there a better way which I am missing?</P><P>thank you for your inputs,&nbsp;</P><P>kind regards</P><P>Regina</P><P>&nbsp;</P><P>&nbsp;</P> 2026-01-22T14:03:24.158000+01:00 https://community.sap.com/t5/human-capital-management-q-a/ias-and-onboarding/qaq-p/14315208 IAS and Onboarding 2026-01-27T05:40:49.244000+01:00 kasec https://community.sap.com/t5/user/viewprofilepage/user-id/24230 <P>Hi there</P><P>Is there anywhere in SAP documentation that it mentions IAS set up is mandatory for ONB? Or the best practice approach is to enable IAS for Onboarding authentication for external users?</P><P>SAP support have provided advice that it is NOT recommended to enable IAS for ONB, which I thought was mandatory for ONB?&nbsp;<a href="https://community.sap.com/t5/user/viewprofilepage/user-id/17956">@Gopinath_Murugaiyan</a>&nbsp;are you able to confirm what is best practice when it comes to ONB and IAS and login method for external hires? Should IAS be enabled for onboarding or should it not (i.e. utilise the standard email in SF ONB Email Services)?</P><P>Thanks</P> 2026-01-27T05:40:49.244000+01:00