Describing SAP Fieldglass Configuration Manager Features and Updates

Objective

After completing this lesson, you will be able to describe new or updated features in SAP Fieldglass related to Configuration Manager

Editable Default Company Configurations in Configuration Manager Self-Service Dashboard

Overview & Use Case

As an enhancement to the Configuration Manager functionality within SAP Fieldglass, applicable users can now edit default company configuration settings directly within the Company Configuration tile on the Self-Service Dashboard. Previously, these settings were read-only and required SAP Fieldglass support to modify.

This change improves the flexibility and efficiency of managing company-level configurations, reducing overhead and lead-time for Configuration Managers who often need to make quick or frequent updates. For customers who utilize Configuration Mover and require management of Company Configuration settings when performing implementation tasks, this change allows settings to be managed in a more streamlined and centralized manner.

UI Impact & Workflow Changes

When editing configurations via the Configuration Manager role and Company Configuration tile, Default fields that were formerly locked and not editable by the Configuration Manager user, are now unlocked and can be controlled by the associated user role.

Edit Company Configuration page displaying a configuration table with four columns: Enable, Configuration, Settings, and two action columns labeled Lock Settings and Hide from UI. The Configuration column lists various default settings including Default Currency, Default Time Zone, Default Date Format, and many others. The Lock Setting column displays a lock icon for each listed item. The lock is displayed as being unlocked.

Configuration Steps

When a Configuration Manager logs into the Self-Service Dashboard, they will navigate to the Company Configuration tile. Upon opening the interface, they will be presented with a list of company configurations enabled for the organization, which they will have the ability to configure and manage in the manner required for the organization.

Upon scrolling through the editable options, the Configuration Manager will locate the following configurations, which are now editable:

Default Date Format – Default Time Format – Default Number Format – Default Language

The user can make the necessary changes to the configuration values and save those modifications for the buyer company.

API Monitor Tile for Configuration Managers

Overview & Use Case

Within the self-service dashboard, Configuration Managers can now view the API Monitor page, which displays API requests made by their associated buyer company. This improvement enhances the level of visibility associated to integrations at the API connection level, giving buyers access to more data for API request tracking and troubleshooting.

UI Impact & Workflow Changes

Once enabled, a new API Monitor card will display for Configuration Manager Users.

A Self-Service Dashboard interface displaying the Configuration Tools section with a category filter dropdown set to All on the right side. The main content area shows six configuration tool cards arranged in a 3x2 grid, each containing a title, description, and category tag. The cards are: Allowed IP Addresses; API Application; API Monitor; App Activity Subscriptions w; BTP Business Rules Payload; and Business Rules.

When selected, a list of recent API connections will display confirming request details like the Duration and Source.

API Monitor interface with filtering options at the top and a data table below. The filter section includes four fields: a Date range selector, a URI text input field, an Http Method dropdown menu, and a Source dropdown menu. To the right of these filters is a blue Apply Filters button. Below the filters, the interface displays Items (2) indicating two records are shown, with a download icon on the right. The data table contains seven columns: Date, URI, Http Method, Duration (ms), Application Name, Request Type, and Source. Two rows of data are displayed.

Rotation Enforcement for Encryption Keys

Overview & Use Case

In an effort to strengthen security and align with industry best practices, a new policy requiring PGP and SSH encryption key rotation has been introduced within the Configuration Manager functionality. With this enhancement, SAP Fieldglass now enforces the expiration of PGP and SSH encryption keys every six months.

The regular rotation of encryption keys helps minimize the risk of unauthorized access by limiting the lifespan of cryptographic credentials. It also ensures compliance with evolving security standards and reduces the impact of potential key compromise. Rotating regularly is a best practice in cybersecurity.

Configuration Steps

To comply with the newly established policy, a Configuration Manager user with appropriate access should enter the email address for all users who should be notified and set a notification schedule for each applicable key and certificate. They can achieve this by following the listed steps below:

  • In the Self-Service Dashboard, a user will navigate to the Encryption Keys and Certificates tile.
  • Within the tile, they will select Manage Email Notifications.
  • They will then need to select an Asset Category from the list. Alternately, they can select All Assets if notifications should be delivered to the same group for all assets.
  • Ther user will then select Edit and enter the email addresses for all users who should be notified
    • At least two (2) addresses per company is recommended
    • The Notification Timing will be set to 90 days, which is when notifications will begin, and will then continue to be sent at regular intervals up until expiration.
  • The user will select Update to save the changes.
Image of the email notification page associated to the Encryption Keys and Certificates tile from the Configuration Manager self-service dashboard. Image highlights the Email Addresses section, as well as the Notification Timing selection dropdown.

To prevent disruption, Configuration Managers should ensure that expiration notifications are properly configured to be sent to the appropriate users in advance. PKI and Symmetric encryption keys are already being auto-rotated and would not require any additional action. If e-mail notifications are not configured for the buyer company, and the associated keys expire, it could impact associated integrations until a connection is re-established.