The security recommendation is, before adding further platform users from the default identity provider to your global account, first get and connect your custom tenant of SAP Cloud Identity services to the account. Then either create users for yourself and other people in your tenant or connect it to your corporate identity provider. Finally add relevant users from your custom identity provider to your SAP BTP account and assign authorizations to them.
Note
Note

In a Global Account, you can create platform users and assign predefined role collections to them.
To create a user, you need to navigate to Security→Users, and choose the Create button in the top-right corner.
When creating a new user, you always must specify the identity provider. You can change the identity provider in the Identity Provider field.

There's one predefined role collection for administrative tasks and one for read-only access to the Global Account.
With the Global Account Administrator role collection, the user can perform the following tasks:
- Create new and edit existing Subaccounts, within the Global Account
- Manage entitlements
- Manage users
- Manage role collections
With the Global Account Viewer role, the user only gets read access to the mentioned items.
With the authorizations from predefined roles for Global Accounts, the user is not permitted to access any Subaccount that has been not created by them.







