
Perform the following steps to set up the SAP Cloud Identity Access Governance - Privileged Access Management:
- Create reason code in the Reason Code app of SAP Cloud Identity Access Governance Fiori Launchpad.
- Create business role in the Business Roles app of SAP Cloud Identity Access Governance Fiori Launchpad.
- Create, maintain, and activate PAM ID in the Maintain Privileged Access app of SAP Cloud Identity Access Governance Fiori Launchpad.
- Trigger the Provisioning job in the Job Scheduler app of SAP Cloud Identity Access Governance Fiori Launchpad.
Step 1: Create reason code in the Reason Code app of SAP Cloud Identity Access Governance Fiori Launchpad

The creation of business-related reason codes is a mandatory task in this scenario because it is required for starting the privileged access session using the launchpad of privilege access management in ABAP systems.
Perform the following steps:
- Open SAP Cloud Identity Access Governance Fiori Launchpad (FLP).
- Navigate to Administration→Request Reason.
- Create new entry using + button.
- Provide the necessary information:
- Name = Any name>
- Description = <Any description>
- Type = Privileged Access Session
- In the displayed section, Assigned Applications, specify which system or application can use the reason code.
- Create new list entry using the + button.
You can choose only those on-premise system that have been registered in the Applications app of SAP Cloud Identity Access Governance Fiori Launchpad.
- Select the application that you want to assign.
- Choose Select.
- Choose Save and Activate.
Note
Without activation, the newly created reason code will not be published to the respective application.
Step 2: Create business role in the Business Roles app of SAP Cloud Identity Access Governance Fiori Launchpad

You have to create privileged access management related business roles, which will be used for assignment to a dedicated PAM ID (see section Prerequisites for the setup of SAP Cloud Identity Access Governance - Privileged Access Management in this unit).
The business role and its content (technical roles with specific authorizations and transaction codes) will be used to determine the required activities for the PAM ID.
Perform the following steps to create a business role:
- Open SAP Cloud Identity Access Governance Fiori Launchpad (FLP).
- Navigate to Role Designer→Business Roles.
- Create the new entry using the + button.
- Provide the necessary information:
- Business Role = <Any name>
- Description = <Any description>
- Business Process = <Select an available business process from the dropdown list>
- In the Access section, add the PAM related technical roles, which have been created in the respective target system.
Note
At least you have to add the roles that are necessary for PAM ID to perform the privileged access management session and the activities that need to be executed. - Choose the + button.
- Search for the specific role(s), you want to add.
- Use the + button to add / assign it to the business role.
Note
Assign as much roles as needed. - In the Other Attributes section, enter the following:
- Content Approvers = <Select the proper person, who should act as approver>
Note
You can add as much content approvers as you want. Only those persons are listed who are assigned to the specific SAP Cloud Identity Access Governance group.
The content approver will have no further tasks in the PAM process.
- Assignment Approvers = <Select the proper person, who should act as approver>
Note
You can add as much assignment approvers as you want. Only those persons are listed who are assigned to the specific SAP Cloud Identity Access Governance group.
The assignment approver will have no further tasks in the PAM process.
- (Optional): Business Subprocess = <Select an available business subprocess from the dropdown list>
- (Optional): Criticality = <Select an available criticality from the dropdown list>
- (Optional): Long Description = <Any long description>
- Content Approvers = <Select the proper person, who should act as approver>
- Choose Save and Activate.
Note
Step 3: Create, Maintain and Activate PAM ID in SAP Cloud Identity Access Governance Fiori Launchpad

PAM IDs are specific users (or user accounts) that are needed to start a privileged access session. Instead of utilizing his own user account, the PAM user (who is the end-user) switches to a designated PAM ID, which is created solely for this purpose.
To create a PAM ID, perform the following steps:
- Open SAP Cloud Identity Access Governance Fiori Launchpad (FLP).
- Navigate to Privileged Access Management→Maintain Privileged Access.
- Create new PAM ID using the + button.
- Provide the necessary information:
- Name = <Any name>
- Description = <Any description>
- Optional: Long Description = <Any long description>
- Business role = <Select the previously created business role, which is designated for this new PAM ID>
- Criticality = <Select an available criticality from the dropdown list>
- Duration in days = <Enter the maximum number of days for which you would like to have a PAM ID>
- In the Allowed Activities section, enter the relevant activities that have to be performed by this PAM ID.
Note
The selectable activities are based on the assigned business role and its included technical roles. You can add as much activities as needed. - In the Approvers/Reviewers section, select the proper person, who should act as approver and / or reviewer.
- Approver
- Responsible for the approval of the PAM ID to the PAM user.
- Reviewer
- Responsible for reviewing the log protocol.
Note
The approver and reviewer can be a single person. You can add as much approvers / reviewers as you want. Only those persons are listed who are assigned to the specific SAP Cloud Identity Access Governance group. - Choose Save and Activate.
Note
Without activation, the newly created PAM ID cannot be requested using access request.
Note
When a PAM ID is activated, it has the status In Process. In this status, no additional changes can be made to the data submitted. After the PAM ID is created in the respective target system, its status changes to Active (this can be done using the Provisioning job, see also next step).
Step 4: Trigger "Provisioning" Job in SAP Cloud Identity Access Governance Fiori Launchpad

When you have created and activated the PAM ID, it is not fully available in the respective target system (its status is still In Process). To make it available and switch its status to Active, you have to provision the PAM ID to the specific ABAP target system. To do so, you have to trigger the provisioning job in the SAP Cloud Identity Access Governance Fiori Launchpad.
Schedule the following job category:Provisioningused to trigger the provisioning of SAP Cloud Identity Access Governance data. In this case, it is necessary to provision the newly created PAM ID to the respective target system and to finally activate it for further usage - for example, end-user is able to request the PAM ID through an access request.
To schedule a provisioning job, perform the following steps:
- Open SAP Cloud Identity Access Governance Fiori Launchpad (FLP).
- Navigate to Administration→Job Scheduler.
- Schedule the job and provide the following information:
- Job name: <Any Job name>
Note
No spaces are allowed. - Job category: Provisioning
- Recurring Job: Yes or No
Note
The selection depends on your needs. - Start immediately: Yes or No
Note
The selection depends on your needs.
- Job name: <Any Job name>
- Choose Schedule Job.
- Check the job status in Job History List.