November 2020 Invoice Professional Edition Admin Summary
Initial Post
Release Note Summaries
Concur Invoice
Supplier Portal Retirement (19 Oct)The Supplier Portal feature is now retired, and suppliers can no longer use this functionality.
The Supplier Portal enabled suppliers to perform self-serve tasks without needing to interact with their buyer (Concur Invoice client), such as checking the status of an invoice, searching for their buyers and viewing the buyer contact information if direct contact is required.
With the retirement of the Supplier Portal, suppliers who sign into the Supplier Portal will receive a message about the retirement. Clients who try to send the invitation link out to suppliers will also receive a message about the retirement. Clients who are using the Supplier Portal are encouraged to reach out to any suppliers who are actively using it with alternate instructions on how to interact with their buyers.
As Concur Invoice moves forward, we are committed to identifying the best solution to deliver on our clients' business needs.
Business Purpose / Client Benefit: This feature is being retired due to low usage.
Capture Processing
Open as PDF Option Now a Button on Verification PageWhen clients open an invoice as a PDF on the Verification page, they will now do so by clicking the Open as PDF button instead of clicking Actions > Open as PDF.
Business Purpose / Client Benefit: This enhancement reduces the number of clicks the client needs to perform, which reduces the time spent opening invoices.
Invoice Pay
Provider Payment Manager Start and End Date Fields Replaced by Date Range Field (5 Nov)The Start Date and End Date fields that appeared on the Provider Payment Summary page have been replaced with a single Select Date Range field.
Business Purpose / Client Benefit: This change brings more consistency to the Provider Payment Manager page.
Employee Import
720 Alignment With 710 for Negative Approval LimitsThe Authorised Approver with Level Import (Record Type 720) format now accepts negative numbers in field 15 (Approval Limit) to align with the Cost Object Approver Import (Record Type 710) format that already accepted negative numbers.
Business Purpose / Client Benefit: This change improves functional consistency.
Security
Updated: End of Support for Insecure Protocols and Ciphers in F5 Client SSL Profiles for VIPs (7 Oct)These changes are part of the SAP Concur continued commitment to maintaining secure authentication.
In early October, the SAP Concur networking team noted that their configuration of the Content Delivery System had been blocking the protocols in the list that follows for some time.
As such, the notice to clients that we would be making a change to our F5 Client SSL profile was superfluous, as those aspects of the existing profile were not actually available. SAP Concur made changes to the F5 Client SSL profile on 7 October as well, in the interest of maintaining a strong security profile
- SSL v2
- SSL v3
- TLS v1.0
- TLS v1.1
- 3DES cipher suite
Business Purpose / Client Benefit: This update provides ongoing security for our products and services.
Malicious Domains AlertPlease refer to the following table for a list of potential malicious domains. This list is not exhaustive and is meant as an initial warning of the existence of possible fraudulent sites that use some false derivative of the SAP Concur solutions brand within the domain name.
Malicious Domains | |||
---|---|---|---|
concursupport.com | conchur.com | congur.com | concus.com |
concurhr.com | conbur.com | conur.com | concur.red |
concurlogin.com | soncur.com | concur.one | cconcur.com |
concur.vip | concue.com | confur.com | concur.social |
conchr.com | concut.com | boncur.com | concur.nz |
concurr.com | concur.ae | concor.com | oncur.com |
concure.com | conciur.com | concur.me | concuur.com |
concura.com | concur.is | concur.digital | cioncur.com |
cooncur.com | concur.consulting | concar.com | concur.solutions |
concurl.com | concur.tech | concur.pro | concurf.com |
concurb.com | concur.biz | concur.gr | cponcur.com |
concurn.com | concur.design | concir.com | concup.com |
concuri.com | cuncur.com | cancur.com | concru.com |
concurs.com | concur.cm | voncur.com | cpncur.com |
concurz.com | concur.cc | concwr.com | connectconcur.com |
concuir.com | concr.com | comncur.com | concur.jp |
doncur.com | concur.sk | concur.ch | colcur.com |
conccur.com | condur.com | concur.so | concer.com |
concur.store | concur.bz | concur.be | conaur.com |
concur.az | concur.by | cencur.com | coincur.com |
cocur.com | consur.com | corcur.com | cocnur.com |
WHAT SHOULD CUSTOMERS DO?
Customers should avoid these domains in the context of working with SAP Concur solutions. While some domains may be registered, it is recommended to err on the side of caution.
Business Purpose / Client Benefit: This alert provides ongoing security for our products and services.
Authentication
Single Sign-On (SSO) Self-Service OptionThese changes are part of the SAP Concur continued commitment to maintaining secure authentication.
With the November release, SAP Concur is adding a Single Sign-On (SSO) self-service tool to SAP Concur products. This new tool enables clients to set up SSO for their organisation without assistance from SAP Concur support. SSO is currently supported for Concur Expense, Concur Invoice, Concur Request and Concur Travel.
- Username and password
- SSO with Identity Provider (IdP) credentials, such as a user's login credentials for their organisation
The new SSO self-service tool will eventually replace the existing SSO configuration process, enabling clients to implement SSO at their organisation. The existing SSO configuration process and the new SSO self-service tool will both be available until everyone has migrated to the new SSO self-service tool.
- A self-service option for setting up SSO at your organisation; this new feature is automatically available to all clients
- The new SAP Concur SAML v2 SSO (SAML v2) service, which complies with SAML 2.0 and is a current industry standard
- Encrypted SAML assertion to address privacy and security concerns
- Enforcement of SSO at the company level (the ability to select SSO as optional is also available)
- The ability to upload multiple Identity Provider (IdP) metadata
- The ability to download SAP Concur Service Provider metadata
Business Purpose / Client Benefit: This feature provides new SAP Concur clients with a self-service option for setting up SSO. It also provides an option for existing SSO clients who must eventually migrate to the new SAML v2 service to manage SSO for their users.
**Ongoing** Deprecation of Director SAML Service and Migration to SAML v2These changes are part of the SAP Concur continued commitment to maintaining secure authentication.
Support for the Director SAML service is being deprecated. Travel Management Companies (TMCs) and SAP Concur personnel will soon begin assisting clients who currently use Director SAML to migrate to SAP Concur SAML v2 SSO (SAML v2).
Clients currently using Director SAML are encouraged to migrate to SAML V2 as soon as possible.
- SAP Concur technicians and TMCs assist existing SAP Concur clients to migrate from the Director SAML service to SAML V2.
- All clients that currently rely on the Director SAML service have migrated from Director SAML to SAML V2.
- The client identifies an admin to act as the SSO admin and assigns the proper permission/role.
- The SSO admin coordinates with their SAP Concur technician to obtain the SAP Concur SP metadata.
- The SSO admin configures the SSO settings at the IdP based on information from SP metadata.
- The SSO admin retrieves IdP metadata from the IdP and delivers the metadata to the SAP Concur technician.
- The SSO admin adds a few testing users and tests the new SSO connection.
- With successful testing, the company rolls out SSO to their SAP Concur users.
Business Purpose / Client Benefit: This change provides better security and improved support for users logging in to SAP Concur products and services.
**Ongoing** Deprecation of HMAC and Migration to SAML v2 and the SSO Self-Service ToolThese changes are part of the SAP Concur continued commitment to maintaining secure authentication.
SAP Concur support for Hash-Based Message Authentication Code (HMAC) is being deprecated. Travel Management Companies (TMCs) and SAP Concur personnel are currently assisting clients who use HMAC to migrate to SAP Concur SAML v2 SSO (SAML v2).
In November of 2020, SAP Concur plans to provide a self-service tool that will enable client admins to set up their SAML v2 connections without involving an SAP Concur support representative.
The HMAC deprecation includes two phases:
- Clients must have an identity provider (IdP) or a custom SAML 2.0 compliant solution.
- Clients begin testing authentication using SAML v2.
- TMCs prepare to onboard new SAP Concur clients to SAML v2.
- Once the SSO self-service tool is available, clients will be notified of the official deprecation date of HMAC via release notes. As of the official deprecation date, no new clients can be onboarded using HMAC; new clients must be onboarded to SAML v2.
- Existing clients using HMAC must migrate to SAML v2.
- TMCs have migrated all existing SAP Concur clients from the HMAC service to SAML v2.
- The HMAC service is deprecated. Phase II is targeted to end mid-year in 2021.
Business Purpose / Client Benefit: This change provides better security and improved support for users logging in to SAP Concur products and services.
File Transfer Updates
Support for Two SSH Transfer Ciphers Removed from File Transfer for Customers and Suppliers (13 Oct)This release note is intended for technical staff responsible for file transmissions with SAP Concur solutions. For our customers and suppliers participating in data exchange through various secure file transfer protocols, we are making changes that provide greater security for those file transfers.
- 3des-cbc
- blowfish-cbc
- st.concursolutions.com
- st-eu.concursolutions.com
Business Purpose / Client Benefit: These changes provide greater security for file transfers.
**Ongoing** SAP Concur Legacy File Move MigrationThis Release Note is intended for the technical staff responsible for file transmissions with SAP Concur. For our clients and suppliers participating in data exchange, SAP Concur is maintaining our file transfer subsystem to provide greater security for those file transfers.
SAP Concur will begin migrating entities that currently use a legacy process for moving files to a more efficient and secure file routing process that relies on APIs.
- With the legacy process, clients had to wait for the file move schedule to run at a specified time. With the more efficient and secure API-based process, extracts and other outbound files from SAP Concur will be available within the existing overnight processing period shortly after the files are created.
- st.concursolutions.com
- st.concursolutions.com
Business Purpose / Client Benefit: These changes provide greater security and efficiency for file transfers.
User Interface
Updating Country and Countries LabelsInstances of Country or Countries on the user interface are being updated to Country/Region and Countries/Regions, respectively.
Business Purpose / Client Benefit: This change provides a better global user experience.
Authorised Support Contacts
Online Scheduling for SAP Concur SupportSAP Concur support has implemented an online scheduling feature that allows Authorised Support Contacts (ASCs) to schedule a meeting with a support engineer.
Business Purpose / Client Benefit: Online scheduling makes it easier for ASCs to schedule a meeting with an SAP Concur support engineer.
Planned Change Summaries
The items in this section are summaries of the changes targeted for future releases. SAP Concur reserves the right to postpone implementation of – or completely remove – any enhancement/change mentioned here.
IMPORTANT: These Planned Changes might not list all of the upcoming enhancements and modifications that affect this SAP Concur product or service. The Planned Changes that apply to multiple SAP Concur products and/or services are listed in a consolidated document. Please review the additional Planned Changes admin summaries available in the November 2020 Shared Planned Changes Professional Edition Admin Summary.
Concur Invoice
**Planned Changes** Download as Excel From All Sent to Purchasing List View on My Invoices PageIn a future release, clients will be able to export data by clicking the Download as Excel link in the All Sent to Purchasing list view on the My Invoices page:
There is no maximum number of items that can be exported, but the export process might take some time if there are many items to be exported.
Business Purpose / Client Benefit: This feature provides clients with flexibility in how they work with invoice data.
Client Notifications
SAP Concur Non-Affiliated Subprocessors
The list of non-affiliated subprocessors is available here: SAP Concur list of Subprocessors (English Only)
Monthly Browser Certifications
Monthly browser certifications, both current and planned, are available with the other SAP Concur monthly release notes, accessible from What's New - Professional Edition