Concur Invoice Professional Edition Administration Help

November 2019 Request Professional Edition Admin Summary

Initial Post

Release Note Summaries

The items in this section are summaries of the release notes for this month. The Professional Edition release notes are accessible from What's New - Professional Edition.

Request

Authentication: New SAP Concur Sign In Page (31 October)

These changes are part of the SAP Concur continued commitment to maintaining secure authentication.

SAP Concur now has a new Sign In page, providing a new login experience for both direct SAP Concur username/password users and Single Sign-On (SSO) users. SSO users will start the SP-initiated SSO login process at www.concursolutions.com. This change was made on 31 October, 2019 (not in the scheduled monthly release). Initially, the new Sign In page is visible to only a small percentage of users. Availability will gradually increase throughout November 2019, until all SAP Concur users have the option to use the new Sign In page.

The new SAP Concur Sign In page features a two-step login process that provides enhanced security, meets current industry standards and provides a better login success rate.

Business Purpose / Client Benefit: This feature provides better security and a faster, convenient experience for users logging in to SAP Concur products and services.

Authentication: Single Sign-On (SSO) Self-Service Option Date Change – STATUS UPDATE

This feature is no longer targeted for October 2019 and is not targeted for the current release. This Release Note has been moved to the Shared Planned Changes Release Notes (English only).

Connected List Data Type Now Available for Expense Attendee Form - Retracted

In the November 2019 release notes, the Connected List Data Type Now Available for Expense Attendee Form release note was accidentally published before the official release of this new functionality, which is currently targeted for a future release.

The Connected List data type functionality is part of the planned future direction of the product that is currently on our longer-range roadmap. More information will be published about this functionality when the entire feature is ready to be officially released.

This connected list functionality will not be universally supported for attendee records, and will only be available for very specific use cases for employee attendees (SYSEMP).

Email Reminder for Requests Nearing Expiration

When pre-authorised requests have not been fully expensed and the request's number of active days remaining is nearing zero, an email reminder can now be configured to send employees an email reminder to submit expense entries for the remaining request amounts. The email reminder can be configured to trigger the reminder based on the request's total remaining amount and the request's expiration date.

Business Purpose / Client Benefit: This update provides additional email notification configurability to ensure employees can be reminded to finish submitting expense entries for a request before the request expires.

File Transfer Updates: New SAP Concur IP Address (EMEA) (23 November, 2019)

This release note is intended for technical staff responsible for file transmissions with SAP Concur. For our customers and suppliers participating in data exchange through various secure file transfer protocols, SAP Concur is making changes that provide greater security for those file transfers.

SAP Concur will change the IP address for st-eu.concursolutions.com from 84.14.175.233 to 46.243.56.11 on 23 November, 2019 during the maintenance window in the region Europe, the Middle East and Africa (EMEA).

Clients whose file transfers protocols use the SAP Concur DNS endpoint (st-eu.concursolutions.com) to connect are not impacted by this change.

Clients who connect via IP address will need to connect to the SAP Concur DNS endpoint (st-eu.concursolutions.com) or the new IP address as of 23 November, 2019.

SAP Concur recommends connecting to DNS endpoint st-eu.concursolutions.com to avoid connection issues if the SAP Concur IP address changes.

This announcement pertains to the following file transfer DNS endpoint:

  • st-eu.concursolutions.com

Business Purpose / Client Benefit: This change provides greater security for file transfers.

File Transfer Updates: Source IP Checking (EMEA)

This feature is no longer targeted for the current release. This Release Note has been moved to the Shared Planned Changes Release Notes (English only).

File Transfer Updates: Support Ended for Unsecure SSH Protocol Algorithms/Ciphers (14 October, 2019)

This release note is intended for technical staff responsible for file transmissions with SAP Concur. For our customers and suppliers participating in data exchange through various secure file transfer protocols, SAP Concur made changes that provide greater security for those file transfers.

As of 8 AM PDT, 14 October, 2019, SAP Concur no longer supports the following unsecure SSH protocol algorithms/ciphers:

  • (key exchange) diffie-hellman-group-exchange-sha1
  • (encryption) aes128-cbc
  • (encryption) aes192-cbc
  • (encryption) aes256-cbc
  • (message authentication code) hmac-md5
  • (message authentication code) hmac-sha1-96
  • (message authentication code) hmac-md5-96

This announcement pertains to the following file transfer DNS endpoints:

  • st.concursolutions.com
  • st-eu.concursolutions.com
  • st-cge.concursolutions.com
  • st-cge-dr.concursolutions.com
  • vs.concursolutions.com
  • vs.concurcdc.cn

If assistance is required, please contact SAP Concur support.

For more information, refer to the Shared: File Transfer for Customers and Vendors User Guide (English Only).

Business Purpose / Client Benefit: These changes provide greater security for file transfers.

**Ongoing** Authentication: Deprecation of HMAC Initiates Migration to SSO Self-Service

These changes are part of the SAP Concur continued commitment to maintaining secure authentication.

SAP Concur will soon begin the deprecation process of removing Hash-Based Message Authentication Code (HMAC) as an SSO option. The replacement service for HMAC is SAML SSO, a self-service method of setup whereby client admins have access within SAP Concur to complete their SAML connections.

Clients currently using HMAC are encouraged to migrate to the SSO self-service tool as soon as it is released (targeted for Q1 2020). The new SSO self-service tool allows multiple portals (Identity Providers) to be added.

The HMAC deprecation includes two phases:

PHASE I:

  • Clients need to have an Identity Provider (IdP) or a custom SAML 2.0 solution.
  • Clients begin testing the new SSO self-service tool.
  • Clients prepare for onboarding new clients using the new SSO self-service tool, which is targeted for release in Q1 2020.
  • Once the SSO tool is available, customers will be notified via release notes about the official deprecation date of HMAC. As of the official deprecation date, no new clients can be onboarded using HMAC; new clients must be onboarded using the new SSO self-service tool.
  • Existing clients using HMAC need to be migrated using the new SSO self-service tool.

PHASE II:

  • Clients continue migrating existing HMAC clients to the new SSO self-service tool.
  • Shut down the HMAC service after everyone has migrated from HMAC to the new SSO self-service tool. Phase II is targeted to end mid-year 2020.

Business Purpose / Client Benefit: This change provides better security and improved support for users logging in to SAP Concur products and services.

Planned Change Summaries

The items in this section are summaries of the changes targeted for future releases. SAP Concur reserves the right to postpone implementation of – or completely remove – any enhancement/change mentioned here.

Next Generation (NextGen) Request

**Planned Changes** New User Interface for Concur Request End Users

SAP Concur is dedicated to the consistent improvement of our products, not only the features they provide, but also the experience of using those features. How users interact with technology changes over time, along with needs and expectations. We are constantly listening to our customers and soliciting feedback on how we can improve the user experience.

NextGen Request is the continued evolution of the SAP Concur user experience. It was built from extensive user research and data analytics that include 680 1:1 conversations, 58 usability studies, 3,000+ survey responses and 1.3B monthly user actions.

Customers will have the ability to preview and then opt in to NextGen Request before the mandatory cutover.

Business Purpose / Client Benefit: The result is the next generation of the Concur Request user interface designed to provide a modern, consistent and streamlined user experience. This technology not only provides an enhanced UI, but also allows SAP Concur to react more quickly to customer requests to meet changing needs as they happen.

SAP Concur Platform

**Planned Changes** Concur Request APIs v4

SAP Concur will soon be releasing Concur Request v4 APIs for clients and partners. We are targeting to release v4 in December 2019.

With v4, Concur has made great enhancements to the existing Request endpoints, and now provides the ability for a client and/or a partner to interact with Concur Request to do the following:

  • Get the list of existing requests

  • Get detailed information of an existing request

  • Create, read, update or delete an existing request

  • Move an existing request through the approval flow with one of the following available actions: Submit, Approve, Recall, Cancel, Close or Reopen

  • Get the list of expected expenses (including trip segments) attached to a request

  • Create, Read, Update or Delete an expected expense for a request

  • Get information of a travel agency office

  • Get the list of active Request policies for a given user

BACKGROUND

SAP is continuing to invest heavily in APIs and tools to simplify end-to-end integration.

At SAP Concur, we strongly believe that an open ecosystem expands your view. An open ecosystem dynamically connects your internal systems, spend and partner data to reveal powerful insights that empower you to run your business better.

Explore the capabilities listed above and consider how the APIs could help you simplify some of your existing processes, such as:

  • Automatically creating a Concur Travel Request for any off-site training approved through your Human Resources system
  • Exposing authorisation requests pending approvals onto your internal corporate portal “Manager” widget

PERMISSIONS

In addition to the existing user-level permissions, the Concur Request v4 APIs are based on the most recent secured Authentication service and SAP Concur’s new Oauth2 framework, which manages the authorisation for company-level permissions. Clients and/or partners can now use a single token/permission to interact with Request on behalf of all company users.

Business Purpose / Client Benefit: These enhancements will provide more options and abilities for developers using SAP Concur's platform with Request.

**Planned Changes** Deprecation of Existing Concur Request APIs (v1.0, v3.0, v3.1)

SAP Concur will be deprecating the existing Concur Request APIs (v1.0, v3.0 and v3.1) in a future release. Those APIs will be replaced by the Concur Request v4 APIs.

Business Purpose / Client Benefit: The Concur Request APIs v1.0, v3.0 and v3.1 only support the previous authentication method, which is not best security practice and does not meet the Oauth2 standards. In addition, the previous versions of the Concur Request APIs provided limited possibilities for moving a Request through the approval workflow, as well as managing custom simple & connected list fields. These issues are resolved with the new Concur Request v4 APIs.

In addition, SAP Concur has run a backward compatibility project between the current Concur Request APIs and the new Concur Request v4 APIs (not ISO-compatibility) in order to have the vast majority of use cases managed in the previous versions also be managed in the Concur Request v4 APIs.

Client Notifications

The items in this section provide reference material for all clients.

SAP Concur Non-Affiliated Subprocessors

The list of non-affiliated subprocessors is available here: SAP Concur list of Subprocessors (English Only)

Monthly Browser Certifications

Monthly browser certifications, both current and planned, are available with the other SAP Concur monthly release notes, accessible from What's New - Professional Edition