-
Notifications
You must be signed in to change notification settings - Fork 9
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Feedback for "User Groups" #16
Comments
Hi Pieter, |
Hi Valentin, It does, yes. Thank you. IAS should make a distinction between manually assigned groups and IPS assigned groups. Pieter |
Hi Pieter, |
SAP Work Zone requires admins to be of a certain IAS group (Workzone_Admin). Instead of adding this authorization-only differentiator in a dummy attribute/property somewhere in the source system, it's easier to maintain these admin roles directly in IAS. A.t.m., the Work Zone admins loose their permissions as soon as anyone runs the "Resync Job". Without the option to keep the group assignments when executing "Resync Job", directly editing user groups could only be useful/safe if IAS is used without it being target system of IPS. IAS is a 'special' target in that sense, since it's used as a user store (including group assignments) for the SSO flows (which is not the case for other targets). |
Hi Pieter,
|
Hi Valentin, Interesting. In this case I'm in the "manage the group only in the admin console" scenario. Are you saying that for a "Resync Job", IPS only considers deleting the user group assignments for those groups that are part in the transformation for that target system? If so, that would be great and the only thing possibly missing is this being documented. Edit: just tested this and all users that still exist in the source system lost their "Workzone_Admin" group assignment. The IAS target system does not write to the "Workzone_Admin" group. Best regards, Pieter |
Hi Pieter, My name is Ivelina Kiryakova. I’m covering the IPS documentation. You may probably know that a Resync job makes a full replace of users and groups in the target system with users and groups from the source system. Normally, it is used to fix inconsistent data between both systems. Could this be the reason for losing the assignments? Can you test one of the IPS recently released functionality described in Enabling Group Assignment and the following blog. Hope this helps. Best regards, |
Yes, I do think that the group assignments are deleted due to the "Resync Job".
With this info, Valentin was giving me some hope that the group assignment deletions would be limited to those groups that are part of the transformation of the said target system (IAS in this case). So this is not the case after all? The group assignment solution would require us to have a mapping between a permission group (switch SF source to SCIM) and maintain the WZ admin permissions via a dummy SF group. I was hoping to have a solution by directly maintaining the assignment in IAS. |
Thank you for your valuable feedback contribution, @piejanssens! So that we can recognize your contribution in SAP Community, please tell us your SAP Community profile URL in a reply to this comment; don't include any other text, just the URL on its own, like this:
Thanks! |
https://help.sap.com/docs/IDENTITY_AUTHENTICATION/6d6d63354d1242d185ab4830fc04feb1/ddd067c899f94e2f9006cc4dd417be80.html
I'm looking for documentation about how IPS jobs can affect user group removal.
Cfr. https://answers.sap.com/questions/13847171/when-are-ias-user-groups-assignments-automatically.html
Not sure why it got downvoted, but I'm still looking for information on this.
Best regards,
Pieter
The text was updated successfully, but these errors were encountered: