SAP Cloud Identity Services
Play the video to gather more information on SAP Cloud Identity Services.
After completing this lesson, you will be able to:
Play the video to gather more information on SAP Cloud Identity Services.
Access to business applications is controlled by role-based authorization management. Business Roles are assigned to Business Users to grant access to the required applications and functionality needed for their job requirements.
Learn how to find business roles for a scope item.
Get to know more about the Authorization Concept by selecting each step.
The Business Catalog defines which access categories are available (Value Help, Read, Write), and for which fields restriction values can be maintained. The fields vary per catalog, as they are based on the fields within the apps in the catalog. The Business Role aggregates restrictions for all Business Catalogs.
Administrators define a restriction based on a supported field (for example, company code, country, controlling area, and so on). Supported restriction fields vary per Business Catalog, as they are based on the fields within the apps in the catalog. You can restrict data access for the Value Help, Read, and Write categories separately.
To apply General Restrictions, an Administrator should first make a copy of the SAP Standard Business Role, or create a new role based on the SAP Standard Business Role Template. For example, if you need to restrict access in the Accounts Payable Accountant Business Role for some users to only Company Code 1710 (United States), and for some users to only Company Code 1010 (Germany), you will create two new Business Roles based on the SAP Standard Accounts Payable Accountant role.
You should name the roles accordingly (for example, Accounts Payable Accountant_1710). In the first business role, you edit the role and maintain the restriction value(s) for the entire Business Role (for example, define the Company Code field = 1710). Then, you may edit the individual business catalogs within the role and define the access category (for example, Value Help, Read, Write) as Restricted.
When you create a new Business Role, the Read access is set to Unrestricted (*) and Write access is set to No Access by default. When an access category is Restricted, you must select a specific field value (for example, Company Code = 1710) or grant unrestricted access (*). If you leave fields empty within a business catalog, a user will have No Access to the field in the business catalog's granted apps.
The Manage Workforce app, is used to create and update worker information for both employees and contingent workers, including work agreements and changing employment situations. This app enables you to upload/edit employee information independent of an HR system of record.
During an implementation project, the Manage Workforce app is used to create business users for the project team members in the SAP S/4HANA Cloud starter system. After logging into the starter system, the implementation consultants use this app to create additional test users to demonstrate business processes in the Fit-to-Standard workshops. This app is also used to create the initial users in the development, test, and production systems during the implementation project.
Once the integration with a customer's HR system of record (e.g. SAP SuccessFactors Employee Central) is activated, the Manage Workforce app becomes read-only to ensure there is only one HR data source. Changes to users must be done directly in the HR system of record after the integration is activated.
You can use the app to do the following:
Learn how to create a business user.
The Maintain Business Users app can be used to change user settings and assign business roles to business users.
You can use this app to do the following:
Learn how to assign a business role to a business user.
With the Display Technical Users app, you can display all technical users in the system. Technical users can be services that are used to automate tasks in the system (for example, print queue user to pull print jobs remotely), or the support users of the software provider or hosting provider to access the system if troubleshooting is required to resolve an incident.
The Maintain Business Roles app is used to create and edit business roles, add business catalogs to the roles, and maintain access restrictions. You define business roles by combining predefined business catalogs and, if necessary, define value help, read and write access by maintaining values for restriction fields. You use business roles to control the access to your applications. The predefined catalogs contain the actual authorizations that allow users to access apps and allow to define instance-based restrictions where necessary. Business catalogs bundle authorizations for a specific business area. Once you have created a business role, you can assign it to multiple business users who perform similar business tasks.
Learn how to create a business role and assign an SAP-delivered Fiori Space to the role.
Learn how to download business roles from one system and upload them to another system.
Play the following short video to get an overview of the delivered business role templates and their use.
Play the following short video to get an overview of the Business Catalogs, their status and usage
Due to ongoing development of new features and new apps, SAP needs to periodically revise existing business catalogs. This means that some business catalogs are deprecated and replaced by new ones, and you may need to assign business roles and business users to these new catalogs. Rather than disappearing, deprecated business catalogs are identified as being obsolete, which allows you to identify them at a glance. You can also check how many deprecated business catalogs you still have in use with the Business Catalogs app. This app lets you change assignments from the old, deprecated business catalogs to the new, active catalogs quickly and easily.
With the IAM Information System app, you can display information about the usage of business roles, business catalogs, business users and restrictions, and how they are related. For example, you can use this app to check if a business user is using a particular app and to check which authorizations he or she has.
With the Display Restriction Types app, you can display the assignment of restrictions to restriction fields and business catalogs.
With the Display Authorization Trace app, you can enable an authorization trace for a business user to analyze if any authorizations are missing or insufficient. This app allows you to activate or deactivate a trace and display the authorization check results, including already assigned authorizations and failed checks.