Initial Setup of Bundle Tenants

Set up the systems for your provisioning scenario and run the provisioning jobs.

Prerequisites

  • You have purchased an SAP cloud solution bundled with Identity Authentication and Identity Provisioning services. For more information, see Obtain a Bundle Tenant.

  • Bundle tenants created after March 15, 2022, run on the infrastructure of SAP Cloud Identity Services.

    Bundle tenants created before March 15, 2022, run on SAP BTP, Neo environment.

    For more information, see Tenant Infrastructure

Procedure

  1. Log on to the Identity Provisioning user interface (UI). For more information, see Access your Identity Provisioning bundle tenant.

  2. Set up the source, target, and proxy systems for your provisioning scenario. For more information on the availability of provisioning systems in bundle tenants, see Provisioning Systems for Bundle Tenants

    In bundle tenants, some source and target systems are preconfigured. This means, the connection to the relevant source and target systems is automatically set up and you can run provisioning jobs. To add and configure more systems relevant for your bundle, see Add New Systems.

    When adding a system, Identity Provisioning works as follows:

    • Identity Provisioning in default mode: Provision user data from source to target systems.

      You add source and target systems only. This could be one source connected to one or multiple target systems, or one target connected to one or multiple source systems. For more information, see: Source Systems and Target Systems.

    • Identity Provisioning in proxy mode: Provision user data to and from а central identity management solution and a system with proxy configuration.

      You add a proxy system and you have an external identity management system (such as, SAP Identity Management) in place. For more information, see: Proxy Systems.

  3. Configure the connection details for your systems if they are not automatically set in your bundle tenant. You have the following options:

    • Add properties in the Identity Provisioning UI and provide the required connection information. For more information, refer to the respective provisioning systems (connectors) listed under Supported Systems section where mandatory properties are specified.

    • Create a destination in your subaccount in SAP BTP cockpit and select it for the given provisioning system in the Identity Provisioning UI.

      If your bundle tenant is running on SAP BTP, Neo environment, the Identity Provisioning admin user must have the Manage Destinations role assigned. For more information, see Manage Authorizations in Neo Environment → Bundle Tenants.

      If your bundle tenant is running on the infrastructure of SAP Cloud Identity Services, connectivity destinations can only be created for SAP Application Server ABAP provisioning systems. For more information, see SAP Application Server ABAP.

  4. Define what data you want to provision. You have the following options:

    • Adapt the default transformation logic or use it as-is. For more information, see: Transformations.

    • Configure filtering properties for users and groups. For more information, see: Properties.

  5. Run a provisioning job manually or set a time interval for scheduled jobs. For more information, see: Start and Stop Provisioning Jobs.