To give further users access to SAP Cloud ALM, you need to create or import users in your Identity Authentication tenant. For users to sign in to SAP Cloud ALM, they must be maintained in both the Identity Authentication tenant and SAP Cloud ALM.
In SAP Cloud ALM, the Identity Authentication service (IAS) assumes the role of the identity provider. This means that business users sign in to SAP Cloud ALM with the mechanisms and credentials defined in the Identity Authentication tenant.
The next slide shows the URL of the SAP Cloud Identity Service (SAP CIS) and how to create users:

To create a user, perform the following steps:
- In the administration console of the SAP Cloud Identity Services, open the User Management app.
- Choose + Add .
- Fill in the required fields.
- Choose +Add.
By default, the user receives an e-mail with the login credentials.
Hint
You can also use an existing corporate identity provider (LDAP), in which case you need to set up Identity Authentication as a proxy. If you federate with a corporate identity provider, maintain users there and provision them to IAS via Identity Provisioning (IPS).
Changing to a corporate identity provider while already using the SAP Cloud ALM productively can invalidate user IDs and cause users in SAP Cloud ALM to be deactivated.
For more information, refer to the SAP Help Portal's SAP Cloud Identity Services page.