SAP Cloud Identity Services - Identity Provisioning Company
Total Page:16
File Type:pdf, Size:1020Kb
PUBLIC 2021-10-01 SAP Cloud Identity Services - Identity Provisioning company. All rights reserved. All rights company. affiliate THE BEST RUN 2021 SAP SE or an SAP SE or an SAP SAP 2021 © Content 1 SAP Cloud Identity Services – Identity Provisioning .................................4 1.1 What Is Identity Provisioning?....................................................4 Tenant Model............................................................. 7 Regional Availability.........................................................8 Disaster Recovery/High Availability............................................. 11 1.2 What's New for Identity Provisioning...............................................13 Release Notes – 2020.......................................................21 Release Notes – 2019.......................................................21 Release Notes – 2018.......................................................22 Release Notes – 2017.......................................................26 Release Notes – 2016.......................................................39 1.3 Concepts..................................................................42 System Types............................................................43 Properties...............................................................48 Transformations..........................................................159 1.4 Initial Setup...............................................................200 Obtain a Bundle Tenant.................................................... 202 Access the Identity Provisioning UI (Bundles).....................................206 Provisioning Systems for Bundle Tenants........................................208 1.5 Bundle Tenants and Connectors.................................................211 SAP Business Technology Platform Bundle.......................................212 SAP Commissions Bundle...................................................214 SAP Cloud Identity Access Governance Bundle....................................214 SAP Integrated Business Planning for Supply Chain Bundle...........................216 SAP Jam Collaboration Bundle............................................... 218 SAP Marketing Cloud Bundle.................................................219 SAP SuccessFactors Bundle.................................................220 SAP S/4HANA Cloud Bundle.................................................222 Sales Cloud – Analytics & AI Bundle........................................... 223 1.6 Standalone Tenants and Connectors..............................................224 Use a Standalone Tenant................................................... 225 Access the Identity Provisioning UI (Standalone)...................................227 1.7 Supported Systems......................................................... 232 Source Systems..........................................................235 Target Systems..........................................................401 Proxy Systems...........................................................581 SAP Cloud Identity Services - Identity Provisioning 2 PUBLIC Content 1.8 Operations................................................................916 Add a System........................................................... 916 Edit a System............................................................918 Delete a System..........................................................919 Enable and Disable Systems.................................................919 Export and Import Systems................................................. 920 Manage Properties ....................................................... 921 Manage Deleted Entities....................................................923 Manage Transformations...................................................925 Manage Full and Delta Read................................................. 926 Connecting to On-Premise Systems........................................... 930 Start and Stop Provisioning Jobs..............................................932 Manage Authorizations (Standalone) ..........................................934 Manage Authorizations (Bundles).............................................936 Reset an Identity Provisioning Tenant...........................................938 Reset an Identity Provisioning System..........................................939 1.9 Specific Scenarios..........................................................940 Real-Time Provisioning: Identity Authentication................................... 940 Hybrid Scenario: SAP Identity Management......................................947 Local Identity Directory.................................................... 949 1.10 Security..................................................................977 Communication Security................................................... 978 Customer Data.......................................................... 978 Authentication and Roles...................................................980 Job Logs...............................................................981 Data Protection and Privacy................................................. 981 1.11 Monitoring and Troubleshooting.................................................987 View Provisioning Job Logs..................................................988 Manage Provisioning Job Logs............................................... 990 Manage Job Notifications...................................................992 Access Audit Logs (Bundles).................................................994 1.12 Service Offboarding......................................................... 995 Reset the Identity Provisioning (Bundles)........................................995 Reset/Remove the Identity Provisioning (Standalone)...............................995 1.13 Getting Support............................................................996 SAP Cloud Identity Services - Identity Provisioning Content PUBLIC 3 1 SAP Cloud Identity Services – Identity Provisioning Get Started What's New What Is Identity Provisioning? [page Release Notes – 2021 [page 13] 4] Release Notes – 2020 Tenant Model [page 7] Release Notes – 2019 Initial Setup [page 200] Release Notes – 2018 [page 22] Release Notes – 2017 [page 26] Release Notes – 2016 [page 39] Scenarios Resources Supported Systems [page 232] Operations [page 916] Local Identity Directory [page 951] Security [page 977] Hybrid Scenario: SAP Identity Manage Monitoring and Troubleshooting [page 987] ment [page 947] Getting Support [page 996] Real-Time Provisioning: Identity Au Disclaimer thentication [page 940] Legal Disclosure Copyright and Trademarks 1.1 What Is Identity Provisioning? Manage identity lifecycle processes for cloud and on-premise systems. The Identity Provisioning service automates identity lifecycle processes. It helps you provision identities and their authorizations to various cloud and on-premise business applications. SAP Cloud Identity Services - Identity Provisioning 4 PUBLIC SAP Cloud Identity Services – Identity Provisioning Environment The Identity Provisioning service runs only in the SAP BTP, Neo environment. Features User and Group Provision users and groups between multiple supported cloud and on-premise Provisioning systems, both SAP and non-SAP. User and Group Filtering Configure default transformations or filtering properties to control what data to be provisioned and what to be skipped. Full and Delta Read Run a provisioning job in full mode to read all entities from a source system, or in Mode delta read mode - to read only the modified data. Job Logging View and export job logs from the Identity Provisioning administration console. Logs display details about the job status and the provisioned entities. Notifications Subscribe to a source system to receive notifications for the status of provisioning jobs. Overview Graphic Use Cases Identity Provisioning supports the following use cases: ● Provisioning from Source to Target Systems [page 43] The main use case of Identity Provisioning is to read users and groups from a source system and provision them to a target system. Filtering and/or mapping are applied during job execution. ● Hybrid Integration with Identity Management Systems [page 947] Identity Provisioning can be used for integrating cloud solutions with on-premise or cloud identity management systems that support SCIM 2.0 standard, such as SAP Identity Management and SAP Cloud Identity Access Governance. SAP Cloud Identity Services - Identity Provisioning SAP Cloud Identity Services – Identity Provisioning PUBLIC 5 In a hybrid integration scenario, Identity Provisioning acts as a proxy between a cloud solution and an on- premise or cloud system. This means the Identity Provisioning is used for configuring and exposing the cloud solution as a proxy system and connect it to the external identity management system without making a direct connection between them. ● Real-Time Provisioning from Identity Authentication [page 940] Identity Provisioning can be used for immediate, real-time provisioning of Identity Authentication users to any target system. Unlike the standard provisioning, where reading and writing of users is triggered by jobs, real-time provisioning is triggered by events (such as, user self-registration or user modification in Identity Authentication). ● Storing Users and Groups in Local Identity Directory [page 949] Identity Provisioning is mainly used for provisioning users