Central store-based provisioning enables the automatic provisioning of application-specific groups from the Identity Directory to the target systems whenever changes occur. These changes include user assignments or modifications of group attributes.
Note
Currently, application-specific groups are supported for
|
Create Application-Specific Groups or Assign Application-Specific Groups to existing Group
you can create application-specific groups in the Identity Directory of your SAP Cloud Identity Services tenant and provision them afterward to target systems of your choice.
Operating with application-specific groups by Identity Provisioning service requires having a source system with set property ips.application.id. By running provisioning jobs from such source system you can create, update, and delete application-specific groups in the Identity Directory of your SAP Cloud Identity Services tenant, depending on the values of their attributes.
Enable or Disable Central Store-Based Provisioning
You can enable or disable the Central Store-Based Provisioning option in the administration console for SAP Cloud Identity Services.
- Under Applications and Resources, choose the Applications tile.
- Choose the application that you want
- Under the Provisioning tab, enable or disable the Central Store-Based Provisioning option
- Once the application has been updated, the system displays the message Application <name of application> updated.
When you enable the Central Store-Based Provisioning for a specific application, whenever you update an application-specific group associated with this application, a provisioning of the updates is triggered, there is no need to run manual or scheduled jobs in the Identity Provisioning
IPS Transformation Changes
Select the relevant source system, open the Properties tab, choose Edit and add the property ips.application.id =6f187cce-2f51-4efd-9bf4-9a8aabdd1c9c
Monitor Central Store Logs
Central Store Logs provide information about the application-specific groups that have been provisioned from the Identity Directory to your target systems.
Note
Central Store Logs are enabled and will appear under Provisioning Logs whenever changes to application-specific groups occur in the Identity Directory, such as assigning users or modifying group attributes. |
select your Identity Provisioning ---> Provisioning Logs ---> Central Store Logs
from New blog articles in SAP Community https://ift.tt/EtNfUrM