The following is a summary of the steps you need to take in Identity and Access Management. For detailed information, see the application help or the Web Assistant within the apps.
What do I need to use IBP as an administrator?
First, you need a customized URL for SAP Integrated Business Planning and the administrator credentials that you can use to log on to IBP. You can find all of this information in an email sent to the IT contact named in the IBP contract:
Second, you need a customized URL for the SAP Cloud Identity Administration Console. You can find this information in a second email sent to the IT contact named in the IBP contract:
If it was not you who received this email, the person who received it can create an administrator user for you in IBP, upload it to IAS, and then IAS will send a similar email to you as well.
What are the prerequisites for authenticating IBP users?
The prerequisites depend on the identity provider you are using:
- If you wish to use SAP Cloud Identity Authentication service (IAS), you must create all users there as well. You can create users in IAS either manually or by uploading the IBP users you created.
- If you wish to use a corporate identity provider (IdP) you must create all users there as well, configure it as a trusted IdP, and choose it in IAS to be used as the identity provider.
For details, see Step 3 under How can I create a new user.
What is the password policy in IBP?
The use of passwords in SAP Integrated Business Planning is defined by the enterprise password policy applied in IAS.
For more information, see SAP Help Portal, under SAP Cloud Platform Identity Authentication Service > Operation Guide > Configure Applications > Set a Password Policy for an Application.
Can an administrator change the password of other users?
No. The administrator can only set the initial passwords or just send activation e-mails while creating the business users:
Later only the user can change his password. This can be done on the Logon screen of IAS via Forgot Password:
How can I create a business user?
- First you need to create an employee in the system.
You can create just one employee at a time the following way:
- Open the Maintain Employee app.
- Click Add.
- Fill in the required fields. For Employee ID, enter the unique name or ID generally used at your organization to identify the employee.
- You can also choose to upload several employees to the system in a single CSV file as follows:
- Select Upload above the list of employees.
- In the window that opens, choose a delimiter for the CSV file and select the Download Template link.
- Add your employees to an Excel worksheet according to the downloaded template and save the file in CSV format using the chosen delimiter (comma or semicolon). Make sure that you specify a unique email address for each employee.
- Select Browse, look up your CSV file and choose Upload.
2. Create a business user based on the employee:
- Open the Maintain Business Users app.
- Click New.
- Search for the employee you just created and select it. The business user is created immediately.
e. Fill in the required fields. The User ID is provided by the system automatically. It is also displayed in the User Name field but there you must replace it with the login name defined for that user in the corporate identity provider. If you are not using a corporate identity provider, you can leave the user name as it is, or you can replace it with the Employee ID, for example.
f. Assign any required business role to the user you created. To do so, choose Add and select the business roles from the list that opens.
3. If you are using IAS, proceed as follows:
a. Remain in IBP and download the list of users into a CSV file using the Download button in the Maintain Business Users app.
b. Log on to the Cloud Identity Administration Console of IAS and upload the CSV file using the Import Users app:
The user will receive an email with a URL that directs them to the IAS logon screen:
After activation, the user can choose a password for IAS. Once they log on to IAS, they are automatically redirected to SAP Integrated Business Planning.
If you are using a corporate IdP, proceed as follows:
- Create the same user in the corporate IdP.
b. Log on to the SAP Cloud Identity Administration Console in IAS.
c. Open the Corporate Identity Providers app and add your corporate IdP in the set of trusted identity providers. For more information, see the application help for IAS.
d. Open the Applications app.
e. Select the URL for IBP.
f. Click Identity Provider under Authenticating Identity Provider.
g. Choose your corporate IdP from the list.
Your corporate IdP is now configured to act as a proxy for IAS. As a result, the users are copied to the corporate IdP automatically.
How can I limit the apps that a person can use?
- Open the Maintain Business Roles app in IBP.
- Create a business role:
- Click New.
- Fill in the required fields.
3. Assign those business catalogs to the role that provide access to the required apps:
- Click the Assigned Business Catalogs tab
- Click Add.
c. Select the business catalogs you want to assign.
d. Click OK or Apply. If you click Apply, the window remains open and you can continue adding more business catalogs.
e. Click Save on the main screen of the app to activate it.
4. Assign the business user you created for the person to the business role that provides access to the required apps:
- Click the Assigned Business Users tab.
- Click Add.
c. Select the business user you want to assign.
d. Click OK or Apply.
If the business role already exists when you create or edit the business user, you can also choose a different approach:
- Open the Maintain Business Users app.
- Select the business user to which you want to assign the business role.
- Click Add at the top of the Assigned Business Roles section.
d. Choose the required business role.
e. Click OK or Apply.
Can I download the content of a business role?
The Maintain Business Roles app shows the content of business roles, and you can download them in a file. You can upload the file in a new system and the roles will be created in the new system.
How can I limit what data a person can see in the apps?
- Open the Maintain Business Roles app.
- Select a business role that is assigned to the business user you created for the person in question.
- Click Maintain Restrictions at the top of the screen.
4. Specify the rights for read and/or write access. For read access, you can choose Restricted or Unrestricted. For write access, you can also choose No Access.
For example, you can specify restricted write access for one planning area only.
Note that the default restriction values are the following:
Write: No access
5. Specify restriction values for the access types you set as Restricted:
Look up the relevant restriction area. For example, if you want a certain key figure to be visible only in one specific planning area, look up the Key Figures restriction area.
If you can’t see a restriction area on the screen, it is not available for the catalogs you assigned to that business role.
Choose the values for the various fields within the restriction area. For example, if you want the key figures to be editable, do the following:
i. Choose the pencil icon next to Planning Area.
ii. Select the name of the planning area that you want to provide write access to.
iii. Click OK.
The restrictions are eventually added up - a business user has access to everything that the business roles assigned to it have access to.
6. Add new restriction areas (optional).
For example, if you want to specify that a business role should have write access to two different key figures in two different planning areas, you need to add the Key Figure restriction area to that business role twice (or once more if it is listed for that role by default).
How can I restrict the available data by master data type attributes?
- Open the Manage Permission Filters app.
- Click New.
- Specify general information and some filter criteria. For example, if you want a person to only see information related to the PFA product family, specify in the filter that the PRDFAMILY should be equal to PFA.
4. Click Save.
5. Open the Maintain Business Roles app.
6. Click a business role that is assigned to the business user you created for the person in question.
7. Set the Read access type as Restricted.
8. Look up the General restriction area in the Read section.
If you can’t see this restriction area on the screen, it is not available for the catalogs you assigned to that business role.
9. Choose the pencil icon next to Permission Filter ID field.
10. Select the name of the permission filter that you want to apply.
11. Click OK.
Are any standard business roles delivered with IBP?
SAP delivers only business roles templates. You can find them in the Business Roles Templates App and can use them in the Maintain Business Roles app after choosing Create from Template on the main page.
Can I edit the tile groups on the Fiori Launchpad?
Yes and no. IBP is delivered with predefined business catalogs that allow access to the tiles and through them the apps. By adding business roles to a business user you can add tiles to their launchpad. You can also personalize your own launchpad by adding new groups or changing the content of the groups. However, you cannot change the launchpad the same way for other users.
How can I assign permission filters to business users?
You can assign permission filters to users in several ways:
By direct user assignment to individual users (in the Permission Filters app)
By indirect user assignment
To user groups (in the Permission Filters app)
To business roles (in the Maintain Business Roles app)
First assign the filter to the business role in the form of a restriction, then assign the business role to the business user.
You can assign multiple permission filters to a single user at once. All of those filters are combined to give the user access to all the data defined by the union of the sets of attribute combinations that each of them allows.
I am using a Corporate Identity Provider. Do I have to upload users to IAS?
No. If you configure your identity provider to act as a proxy for IAS, the users are copied to the corporate identity provider automatically. For more information, see the 2nd part of Step 3 in the answer to the question How can I create a business user?
Do users need a Corporate Identity Provider to log on to IBP?
No. IBP provides access to SAP Cloud Identity Authentication service (IAS), which allows users to authenticate themselves without SSO or some other corporate identity provider.
What are the different ways of provisioning a user in the SAP IBP system?
Users can be provisioned in the SAP IBP system using the following methods:
Creating a single user – Create a user via ‘Maintain Employee’ and ‘Maintain Business User’ Apps in the SAP IBP system.
Mass upload of users – Upload a CSV file via ‘Maintain Employee’ App in the SAP IBP system. This will create an employee and corresponding business user within the SAP IBP System.
SOAP Service - The communication scenario Identity Management Integration (SAP_COM_0093) allows you to provision business users and assign roles to business users from an External Identity Management System. SOAP services - MANAGEBUSINESSUSERIN and QUERYBUSINESSUSERIN are available for this purpose. Check SAP API hub for more details (https://api.sap.com/api/MANAGEBUSINESSUSERIN/overview).
SAP Cloud Platform Identity Provisioning Service - The communication scenario SAP Cloud Platform Identity Provisioning Integration (SAP_COM_0193) allows you to connect SAP Cloud Platform Identity Provisioning Service with SAP Integrated Business Planning.
Can we use an external identity provider to authenticate users?
We want to use an external identity provider to authenticate users. Do we still need SAP Cloud Identity Authentication Service?
Yes. You can use an external identity provider to authenticate users. In such a scenario, you must configure SAP Cloud Identity Authentication Service in a proxy mode to redirect the authentication to an external identity provider. For more details see Corporate Identity Providers.
What is the difference between User ID and User Name?
User ID is a technical ID - CBXYZ, generated by the IBP system. The User Name is like an alias, and it is used in IAS or in the corporate IdP.
What is the difference between Communication Scenario SAP_COM_0093 and Communication Scenario SAP_COM_0193?
Communication Scenario SAP_COM_0093 is valid for provisioning users and business roles assignments in SAP IBP via SOAP Service.
Communication Scenario SAP_COM_0193 is used exclusively for provisioning users in SAP IBP via SAP Cloud Platform Identity Provisioning Service product.
Do you support SAP IBP and SAP Governance, Risk and Compliance (SAP GRC) integration scenario?
No. SAP IBP is a cloud product and can’t be integrated with SAP Governance, Risk and Compliance (SAP GRC).
Do you support SAP IBP and SAP Cloud Platform Identity Provisioning Service integration scenario?
Yes. Users can be provisioned in SAP IBP system via SAP Cloud Platform Identity Provisioning Service. Communication Scenario SAP_COM_0193 is used for this purpose.
Do you support SAP and SAP Identity Access Governance integration scenario?
Do you support SAP IBP and SAP JAM integration?
Yes. You can find detailed information on this topic at SAP JAM Integration Guide.
Can we restrict the number of users which are provisioned to JAM?
You can restrict the users which are provisioned to JAM if you use SAP Cloud Platform Identity Provisioning Service
For detailed information see the section on Limiting the Set of Provisioned Users under Provisioning Users to SAP JAM.
How can I download the list of IBP Business Users?
The Maintain Business Users Fiori app provides a list of IBP Business Users and you can download this information.
How can I see SAP Delivered Business Catalogs?
All the business catalogs delivered by SAP can be viewed in the Business Catalogs Fiori App.
How do I find information about which Fiori Apps (IBP Applications) are assigned to a business catalog?
The Business Catalogs and IAM Information System Fiori Apps provide this information.
How can I see SAP delivered Business Role Templates?
All the business role templates delivered by SAP can be viewed in the ‘Business Role Template’ Fiori App.
As an initial set-up, we have uploaded users in SAP Identity Authentication Service and we now want to onboard additional users; what will happen to the existing users?
Additional new users will be created. Existing users will remain unchanged. If you upload the existing user information again, the old information in the SAP system will be overwritten.
How can I see the SAP technical users in my SAP IBP system?
The Display Technical Users Fiori App provides the list of SAP technical users.
How can I run an authorization trace in the SAP IBP system?
The Display Authorization Trace Fiori App can be used to run authorization trace.
Can we restrict the validity of a business role?
You can’t restrict the validity of a business role. However, you can restrict the validity of a business user.
Can we perform SOD/Risk analysis for IBP Roles?
Can we transport IBP business roles from a test to a production system?
Transport of business roles is not supported in IBP. In the Maintain Business Role App, you can download the roles from the test system to a file and upload them in the production system via the same App.
Where can I find information about the relationship between applications, business roles, business catalogs and business users?
The IAM Information System Fiori app provides this information.
Can we transport permission filters?
Yes, you can transport permission filters via the Transport Model Entities App.
Can we transport attribute permission filters?
Yes, you can transport attribute permissions via the Transport Model Entities app.
How are the business role restrictions different from permission filters?
Business role restrictions and permission filters works together. The user always needs write access for key-figures in the role restriction. In permission filter, you can restrict this further by defining the Write Filter criteria.
Is there a way to trace the permission filter restriction?
Can a Business User log in to the Excel Add-in?
In order to log-in into the Excel Add-in, the following conditions must be satisfied:
- User must be assigned to a permission filter for the planning area or in the business, role restriction filed for the permission filter should be set to ‘Unrestricted’
- User must be assigned a role with defined restrictions for key figures of the planning area
- The required restriction types for logging into Excel Add-in are delivered in the business catalog SAP_IBP_BC_EXCEL_ADDIN_PC (Basic Planning Tasks).
Can a user have display only access to the Maintain Business Roles or Maintain Business Users Apps?
Yes. You create a business role with the business catalogs SAP_CORE_BC_IAM_RM (Identity and Access Management - Role Management) and SAP_CORE_BC_IAM_UM (Identity and Access Management - User Management) and set the Read Access to Unrestricted and Write Access to No Access. Assign the role to the user.
Can we download information related to employees?
Download functionality is available in the Maintain Business User Fiori App in the SAP IBP system.
Issue: I created a new employee in IBP, then created a new business user for the employee, and I uploaded the user to IAS. Yet the employee did not receive a notification email from IAS.
Solution: Check if the email address you entered for the employee is correct. If it is not, delete both the business user and the employee and create them again from scratch. If the email is correct, there is probably a technical issue - please delete the user in the User Management app of IAS and create it there again.
Issue: When logging in, I am sometimes taken to the IBP logon page, sometimes to IAS.
Solution: Make sure you are using the right URL as stated in the onboarding email.
Issue: I am having problems when trying to log on to IBP or IAS.
Solution: Clear the cache of the web browser.
Issue: I changed an email in the Maintain Employee app but received an error message saying that the employee ID already exists.
Solution: Delete the employee and create it again. Always make sure you enter the correct email when you create an employee.
Issue: I am having problems when trying to create a business user.
Solution: Make sure the employee ID you entered in the Maintain Employee app is identical with the user name you entered in the Maintain Business Users app.
Issue: I cannot get to the IAS logon page from IBP.
Solution: Refresh your web browser.
Issue: I downloaded the list of business users in the Maintain Business Users app but it does not contain all users.
Solution: Make sure you did not delete the employees that the missing business users are based on. Always delete the business users before deleting the corresponding employees.