Preparing the Onboarding and Technical Setup

Objectives

After completing this lesson, you will be able to:
  • Onboard Users for SAP Cloud ALM usage in the Identity Authentication Service
  • Assign roles to users in SAP Cloud ALM
  • Set Up Landscape Management

Onboarding Users

The figure illustrates the position of the onboarding support within the complete support process.
The figure shows the entry page of the Setup and Administration guide.

Required Setup for SAP Cloud ALM to On-Board Users in Your Identity Authentication Service

Before you can use SAP Cloud ALM, you must create or import users in the Identity Authentication tenant.

​Procedure

  1. In the tenant's administration console for Identity Authentication, open the User Management.
  2. Choose + Add User.
  3. Fill in the required fields.
  4. Remember the email address, as you need it to assign roles to the user later.
  5. Choose Save.
  6. Select Send activation e-mail.
  7. Save your entries.

​Prerequisites

  • Your Identity Authentication tenant has been activated.
  • In your Identity Authentication tenant, you have a user with the role Manage Users. If you don't have this authorization, the tenant administrator can assign the role to you. If you don’t know who your tenant administrator is, create an incident on component BC-IAM-IDS.

Note

If you've already defined users elsewhere in your landscape, you can also import them to the Identity Authentication service by using various tools, such as SAP Identity Management and the Identity Provisioning service.

See Onboard Users in the Identity Authentication Service.

SAP Cloud ALM for Implementation Expert Portal

Screenshots of information sources. Information is provided in the next paragraph.

Hint

Make sure you follow the required setup described on the SAP HELP PORTAL or follow Video-Guided Setup

Be aware: Cloud ALM needs a productive Identity Authentication tenant.

Partners must use S-User assigned to the correct customer number.

Check Additional Resources:

Blog First log in to SAP Cloud ALM.

YouTube Video How to Request SAP Cloud ALM.

Expert Portal SAP Cloud ALM for Implementations.

For setup and administration for SAP Cloud ALM, see Required Setup for SAP Cloud ALM in the SAP Help Portal.

Before you can use SAP Cloud ALM, you must create or import users in the Identity Authentication tenant.

In SAP Cloud ALM, the Identity Authentication service assumes the role of the identity provider. This means that business users log on to SAP Cloud ALM with the mechanisms and credentials defined in the Identity Authentication tenant.

Authorization Roles

The following table explains the differences between Identity, authorization roles, and project roles:

Identity Versus Authorization Roles Versus Project Roles

 IdentityAuthorization RolesProject Roles
Describes​Who are you?​What are you allowed to do?​What is your role?
Uses​User ID, email, first name, last name, password​View or Edit authorization for different purposes​Textual definition of your purpose in the project
Process​Managed by the Identity Authentication Service (IAS)​Roles available in SAP Cloud ALM User Management are predefined as role collections in the subaccount in the SAP BTP cockpit (SAP Authorization and Trust Management service)​Defined in SAP Cloud ALM – predelivered roles based on SAP Activate, definition of customer specific roles possible

After onboarding your users to the Identity Authentication tenant, you must add them to SAP Cloud ALM and assign roles to them.

You can assign roles to users directly…

  • in the SAP Cloud ALM User Management app (recommended).

  • or in the SAP BTP cockpit.

The graphic shows the tile to start the SAP Cloud ALM User Management app.

The figure shows the tile to start the SAP Cloud ALM User Management app.

Screenshot shows where to enter roles.

Prerequisites

  • The identities of the users to whom you want to assign roles already exist in the identity provider (IAS).
  • Your user has the authorization role Cross Global Administrator or User Administrator

Procedure

  1. Access SAP Cloud ALM.
  2. Open the User Management app (in Administration section).
  3. To go to the user list, choose (Users).
  4. Choose Add User.
  5. Enter the user ID and/or email address.
  6. Select a type for your user.
  7. Assign one or multiple authorization roles to the user.
  8. Save.

Role Collections

SAP Cloud ALM offers a simplified user management approach by using predefined authorization roles.

You don't have to configure any role collections yourself. Instead, you can simply assign the relevant role collections to the users based on their tasks and requirements.

See SAP Cloud ALM Setup, Roles.

System Landscape

The figure shows the entry page of the Landscape Management app.

Store and manage technical information about cloud services and on-premise systems in your IT infrastructure.

Define your project landscape according to your implementation scenario.

Screenshot of different views of the Landscape Management app.

Private Cloud Tenants are automatically connected and displayed in SAP Cloud ALM Landscape Management.

On-Premise Systems and Private Cloud Tenants must be connected via the ST-PI Plug-In.

This connectivity must be configured in the managed system: support.sap.com/setup-managed-services

Screenshot of the details of a private cloud.

Typical for the private cloud is to have a four-system landscape with a preproduction system for a stable integration test environment:

  • (Starter system)
  • Development system
  • Test system
  • Preproduction system
  • Production system

Log in to track your progress & complete quizzes