October 2021 Travel Professional Edition Admin Summary
Initial Post
Release Note Summaries
Authentication Administration
CES SSO Deprecated (29 Oct)SAP Concur will decommission Concur Expense Service (CES) SSO on 29 October, 2021.
SAP Concur now provides a Single Sign-On self-service option that enables client admins to set up their SAML v2 connections without involving an SAP Concur admin.
This change provides better security and improved support for users logging in to SAP Concur products and services.
New Company Request Token Self-Service ToolA new Company Request Token self-service tool is now available to SAP Concur admins who have been assigned the Company Admin or Web Services Admin role.
The Company Request Token self-service tool enables clients to generate the Company Request Token that is required to request a JSON web token (JWT) when connecting to APIs on the SAP Concur platform.
The Company Request Token self-service tool enables clients to generate Company Request Tokens without contacting SAP Concur support. This tool also enables clients to generate a replacement Company Request Token without assistance from SAP Concur support if their Company Request Token expires or is lost.
Client Web Services
Register Partner Application Page No Longer Active (21 Aug)On 21 August, the Register Partner Application page was deactivated.
With the October release, a new application management self-service tool has replaced the Register Partner Application page.
Clients with SAP Concur Client Web Services can contact Client Web Services to register new applications.
Clients who do not have SAP Concur Client Web Services can contact SAP Concur support to obtain an App ID as needed.
The Register Partner Application page was used to create OAuth 1.0 (legacy) applications. OAuth 1.0 was deprecated on 4 February 2017.
The new self-service tool for application management enables clients to create OAuth 2.0 compliant applications.
Self-Service Tool for Application ManagementBeginning with the October release, clients who have SAP Concur Client Web Services can request access to a new application management self-service tool, OAuth 2.0 Application Management. This self-service tool is enabled by the Client Web Services team for SAP Concur Web Services clients who request it.
When enabled, the tool is available from the Authentication Administration page to admin users who have been assigned the Web Services Admin role.
The OAuth 2.0 Application Management tool enables clients to generate Client IDs (App IDs) and Client Secrets without contacting SAP Concur support.
Flight
Travelfusion Supplier Update – GOL AirlinesConcur Travel has offered GOL Airlines direct connect content via Travelfusion, in addition to GDS content. In September 2021, GOL migrated to a new system. This new connection is now available in Concur Travel.
In order to maintain access to the direct connect content, customers are required to obtain new credentials from the airline. Customers who have GWS or older API credentials are required to obtain new SWS API credentials.
Concur Travel will continue to provide GOL Airlines’ special content offerings for direct connect customers.
Updates to UK DBEIS (DEFRA) Carbon Dioxide Emissions Model for AirConcur Travel helps customers reduce carbon emissions. By displaying carbon emissions data in their air option display, travellers can make more environmentally sustainable air travel choices.
Previously, customers could select from two existing carbon emission models:
- Concur Modifications of CE (Netherlands)
- DEFRA modified by World Resources Institute
As the science behind these models continues to evolve, the factors by which carbon dioxide emissions are calculated also evolves. Concur Travel has replaced the DEFRA emissions model with the latest information published by the UK Department for Business, Energy & Industrial Strategy (UK DBEIS). The Concur Modifications of CE (Netherlands) model remain unchanged.
Customers can now select from the following carbon emission models:
- Concur Modifications of CE (Netherlands)
- UK DBEIS (DEFRA)
Concur Travel has also adopted a new unit for carbon dioxide emissions called the “carbon dioxide equivalent” or “CO2e”. Carbon dioxide equivalent is a term for describing different greenhouse gases in a common unit. For any quantity and type of greenhouse gas, the carbon dioxide equivalent indicates the amount of carbon dioxide that would have the equivalent global warming impact.
Accurate carbon dioxide emissions help inform policy and secure carbon offsets.
SAP Concur App Centre
Ability to Disable/Hide Enterprise ApplicationsWith the October 2021 release, administrators will be able to control which Enterprise Applications are visible and/or active in their company’s SAP Concur App Centre. Prior to this release, administrators could disable and hide User Applications within the SAP Concur App Centre. This update expands that functionality to Enterprise Applications.
If any employees are connected to an application via the SAP Concur App Centre, disabling the application will break those connections and block future connections.
This update provides greater control to administrators over the apps that appear in their company’s SAP Concur App Centre.
Train
SilverRail OnAccount Payment OnlyIn mid-2021, SilverRail communicated that they would no longer support credit card payments via their own API. Concur Travel has made a corresponding API adjustment to reflect this change, where only SilverRail OnAccount payments are accepted and processed.
Concur Travel bookings related to Payment Services Directive (PSD2) will be available without limitations.
Travel Operations / Technical Essentials
PNR Queue Processing – Required ID RemarksIn order for Concur Travel to process offline bookings and updates to online bookings, specific information must be present in the PNR. Today, both of the following are required pieces of information:
- Company ID (CLIQCID)
- Login ID (CLIQUSER)
However, while both of these have been required historically, SAP Concur did not always reject PNRs when the required fields were missing. With this update, this requirement is now enforced. Any Sabre, Amadeus or Worldspan PNRs missing either of the required pieces of information will be rejected and placed in the error queue. Galileo and Apollo PNRs missing required information will be rejected.
By enforcing data requirements, we are improving data security.
Concur Travel uses the Travel Configuration ID to match trips to the correct configuration. This information is used to identify Compleat-integrated customers. Without it, Concur Travel/Compleat integration features will not be available for these customers.
Miscellaneous
New Permission to Enable Preview of Fiori Light Theme (Professional Edition Only)On 20 September, a new permission, SAP Fiori Theme Preview, was added to the list of permissions in Concur Travel Professional edition. When the SAP Fiori Theme Preview permission is assigned to a user, the user sees a new switch in the header of their SAP Concur site. They will also see a New Theme info bubble.
The switch enables the user to switch from the SAP Concur standard theme to the SAP Fiori Theme. The info bubble displays a brief message about the switch.
The new theme includes changes to visual elements such as fonts, colours and icons. In addition, some top-level tabs and menu items are relocated to the SAP Concur Home menu. These changes are site-wide and apply to all of the user’s SAP Concur products.
The SAP Fiori theme harmonises the look and feel of the SAP Concur UI with the look and feel of other SAP products, providing a more consistent user experience. The permission enables a client admin to allow designated users to preview and test the SAP Fiori theme.
No Default for Date of Birth of Meeting Attendee Companion (Professional Edition Only)Prior to this release, the date of birth for the companion of a meeting attendee was set to 1 January 1980 by default. This date could be changed, but it was often overlooked. This resulted in incorrect reservation data. A default date is no longer applied to the companion’s date of birth.
This change prevents an incorrect data entry for the date of birth in the user’s reservation. The user can now fill out an empty with their companion’s date of birth during booking.
**Ongoing** Mandatory SFTP with SSH Key AuthenticationThis release note is intended for technical staff responsible for file transmissions with SAP Concur products. For SAP Concur customers and suppliers participating in data exchange through various secure file transfer protocols, SAP is making changes that provide greater security for those file transfers.
As of 10 April, 2021, non-SFTP (Secure File Transfer Protocol) protocols and SFTP password authentication are not allowed to connect to SAP Concur for file transfers:
- Non-SFTP file transfer accounts must switch to SFTP with SSH Key Authentication.
- SFTP file transfer accounts that use password authentication must switch to SSH key authentication.
- SFTP password reset requests require the client to provide an SSH key for authentication.
On 12 April, 2021, SAP started disabling non-compliant file transfer connections. The process of disabling non-compliant accounts will continue throughout 2021. If you have multiple file transfer connections configured, this change applies to all of your file transfer connections.
This announcement pertains to the following file transfer DNS endpoints:
- st.concursolutions.com
- st-eu.concursolutions.com
- vs.concursolutions.com
- vs.concurcdc.cn
These changes provide greater security for file transfers.
**Ongoing** Rotating PGP Key Available for File TransfersFiles transferred to SAP Concur products must be encrypted with the SAP Concur public PGP key, concursolutionsrotate.asc.
- Key file is available in client’s root folder.
- Key ID 40AC5D35.
- RSA 4096-bit signing and encryption subkey.
- Key expires every 2 years.
- Client is responsible for replacing the key before it expires.
- Next expiry date: 4 September, 2022.
- SAP Concur plans to replace the current rotating public PGP key in the client’s root folder 90 days before the expiration date.
The SAP Concur legacy PGP key (key ID D4D727C0) remains supported for existing clients but will be deprecated in the future.
SAP Concur strongly recommends that clients use the more secure rotating public PGP key for file transfers. To facilitate the use of the more secure rotating public PGP key for file transfers, SAP Concur added the key to existing client’s home folders on Friday 15 January 2021.
This announcement pertains to the following file transfer DNS endpoints:
- st.concursolutions.com
- mft-us.concursolutions.com
- vs.concursolutions.com
- st-eu.concursolutions.com
- mft-eu.concursolutions.com
The rotating public PGP key provides greater security for file transfers.
**Ongoing** SAP Concur Homepage ChangesIn Q4 2021, SAP Concur began redirecting clients to a new homepage. The appearance of the new homepage is identical to the previous SAP Concur homepage. The new homepage has enhanced functionality when services become temporarily unavailable.
The roll out of the new homepage is phased:
- Phase 1: At the beginning of Q4, SAP Concur began redirecting Concur Expense, Concur Invoice and Concur Request clients in the US Datacentre to the new homepage.
- Phase 2: In November 2021, SAP Concur will begin redirecting Concur Expense, Concur Invoice and Concur Request clients in the EU Datacentre to the new homepage.
- Phase 3: In Q2 of 2022, SAP Concur will begin redirecting the remaining clients in the US and EU datacentres to the new homepage. The remaining clients include those with Concur Travel standalone or Concur Travel with Expense, Invoice and/or Request.
This change ensures that the SAP Concur homepage is available even when some services are unavailable and improves the consistency of the sign-in experience.
**Ongoing** SAP Concur Legacy File Move MigrationThis release note is intended for the technical staff responsible for file migrations with SAP Concur solutions. For our customers and suppliers participating in data exchange, SAP Concur solutions is maintaining our file transfer subsystem to provide greater security for those file transfers.
SAP Concur is in the process of migrating entities that currently use a legacy process for moving files to a more efficient and secure file routing process that relies on APIs.
Clients whose entities are currently configured to use the legacy process will be migrated to the more efficient process sometime between now and 24 January 2022. After they are migrated to the more efficient process, clients will see the following improvement:
- With the legacy process, clients had to wait for the file move schedule to run at a specified time. With the more efficient and secure API-based process, extracts and other outbound files from SAP Concur solutions will be available within the existing overnight processing period shortly after the files are created.
This announcement pertains to the following file transfer DNS endpoints:
- st.concursolutions.com
These changes provide greater security and efficiency for file transfers.
Planned Change Summaries
The items in this section are summaries of the changes targeted for future releases. SAP Concur reserves the right to postpone implementation of – or completely remove – any enhancement/change mentioned here.
IMPORTANT: These Planned Changes may not be all of the upcoming enhancements and modifications that affect this SAP Concur product or service. The Planned Changes that apply to multiple SAP Concur products and/or services are in a consolidated document. Please review the additional Planned Changes admin summaries available in the October 2021 Shared Planned Changes Professional Edition Admin Summary.
Profile
**Planned Changes** XML Profile Sync No Longer Available as of 31 Dec, 2021The XML Profile Sync, which is used to synchronise Concur Travel user profile data with TMC partners, will no longer be available, and this is targeted for the end of 2021. We advise all partners to engage with SAP Concur representatives to adopt the Travel Profile v2 API for managing Concur Travel user profiles.
The XML Profile Sync was officially decommissioned in 2016 due to instability and other issues. The Travel Profile v2 API was built to replace this legacy synchronisation process. It has now reached such a level of stability and maturity that there is no longer any reason to maintain multiple profile sync options.
Client Notifications
Accessibility Updates
SAP implements changes to better meet current Web Content Accessibility Guidelines (WCAG). Information about accessibility-related changes made to SAP Concur solutions is published on a quarterly basis. You can review the quarterly updates on the Accessibility Updates (English only) page.
SAP Concur Non-Affiliated Subprocessors
The list of non-affiliated subprocessors is available here: SAP Concur list of Subprocessors (English Only)
Supported Browsers
Supported browsers are available with the other SAP Concur monthly release notes, accessible from What's New - Professional Edition
