Technology Blogs by SAP
Learn how to extend and personalize SAP applications. Follow the SAP technology blog for insights into SAP BTP, ABAP, SAP Analytics Cloud, SAP HANA, and more.
cancel
Showing results for 
Search instead for 
Did you mean: 
istvanbokor
Advisor
Advisor
As an SAP customer, would you like to see all of your Identity Authentication and Identity Provisioning tenants in one place, with the region, tenant type, creation date, and administrators?

It is now possible! You can use the URL:



https://iamtenants.accounts.cloud.sap/


You need to authenticate with your S user ID (using SAP ID Service), and after successful authentication, we bring you the list to show the SAP Cloud Identity Services tenants belonging to your customer ID!


 

For Identity Authentication you can see all administrators who have Manage Tenant administrator role - so these people are the ones whom you can contact if there is a need to add an additional admin. The list also shows the status of the administrators: new or active.

For Identity Provisioning the same applies - in case you would like to be an Identity Provisioning tenant administrator, contact any of the administrators to add others.

The users and e-mails are masked if the domain of the authenticated user is different from the domain of the tenant administrators.


Please note, that SAP adds additional administrators, in case existing admin is not available, for example, left the company. Adding additional admin is a self-service and it is exclusively in the hands of the current administrators. Please only raise incidents to SAP if something is wrong with the assigned tenants (for example type/region), or if existing admins are not available anymore. In these cases please specify the reason for the incident. Components: BC-IAM-IDS for Identity Authentication, BC-IAM-IPS for Identity Provisioning.

If you do not remember the password of your administrator account, trigger the Forgot password procedure, as SAP is not resending any activation e-mail.

Good to know

Another thing to recall: to this SAP Cloud Identity Services - Tenants application and to Identity Provisioning you log in with your S user, but Identity Authentication uses a different (your company-owned) user store, and you need to use e-mail addresses to log in. The Administration Console of the Identity Authentication tenant has the pattern: https://<tenant ID>.accounts.ondemand.com/admin

Also, regarding obtaining a new tenant:

Identity Authentication provides one productive and one test tenant per customer, regardless of the number of contracts signed in which Identity Authentication is included or bundled (except for SAP SuccessFactors). For more info, see Tenant Model and Licensing.

The scope of your Identity Provisioning bundle tenant can be extended when you purchase more bundled SAP cloud solutions. In this case, your first bundle tenant will be extended with the newly purchased SAP cloud solution and all the relevant provisioning systems for this solution. You will not get additional tenants (except for SAP SuccessFactors). See Bundle Tenants and Connectors.

----------

KBA 3035908 - How to get the Identity Authentication tenant administrator information?

KBA 2959974 - IPS tenant administrator is unknown / not available for IPS tenant management

Viewing Assigned Tenants and Administrators
18 Comments
SCHNEIDERT
Active Contributor
Nice to know, thanks Istvan! 🙂
christian102094
Participant
Very useful! Would be nice to have a link to the ".../admin" directly from the app.
LutzR
Active Contributor

Hi istvan.bokor ,

this looks like promising functionality. Unfortunately the list stays empty for me (though I am involved in administration of a 2-dgit number of IAS tenants). I guess that I would have to switch customer number like in Cloud Availability Center. But there is no way to switch. The switch is missing.

Incident? Which component?

influence.sap.com?

BR, Lutz

istvanbokor
Advisor
Advisor
Hello Lutz,

The tenants are shown based on customer IDs linked to S user ID. If your e-mail is connected to multiple S user IDs, make sure that at login you use S user ID as an identifier and not e-mail, so that you can see the tenants belonging to the desired customer ID.

Best regards,
István
LutzR
Active Contributor
0 Kudos

Hi istvan.bokor ,

unfortunately it does not work this way in a large group of companies with several customer IDs. Did you get my PM?

BR, Lutz

istvanbokor
Advisor
Advisor
Hi lutz.rottmann2,

It seems the issue is specific for your user only. We are checking internally, and once we have the finding, we will reply to you via mail.

Best regards,
Istvan
hiteshkumarbil
Explorer
0 Kudos
Hi Istvan,

Currently we have IAS tenants running on SAP side and IPS tenants in our Global account. We still have not migrated to Cloud Identity Service which will replatform the whole thing - having IAS and IPS services on same infrastructure.

But when I access link https://iamtenants.accounts.cloud.sap/ its header says "Cloud Identity Service". It is little confusing. This dashboard is just a dashboard to show all IAS and IPS tenants (irrespective wheather those are running on same tenant or different place) OR it part of migration approach to host IAS and IPS on same infrastructure?

BR, Hitesh
AlexDong
Product and Topic Expert
Product and Topic Expert
0 Kudos
Hi,

Is it also possible in China mainland area?

I tried using my own applied s user and got a 500 error (I don't have a IAS service).

istvanbokor
Advisor
Advisor
0 Kudos
Hello,

You have not logged in to this portal with S user, but I suppose with I user.

Best regards,
István
BrendanFarthing
Participant
Hi istvan.bokor

What's the difference between type "Test" and type "Additional"?

And is type "Additional" free? i.e. is this the second IAS tenant we can activate for free within our global accounts for testing purposes?

I'm a little confused on the types I see in this list vs what I see when I connect an IAS tenant to our SubAccounts, they don't match. IAS tenants that are listed in this list as "Test" are shown in my Subaccounts as "Trial". And IAS tenants listed as "Additional" in this list are shown as "Enterprise" in my Subaccounts.

Thanks,

Brendan

 
ChrisPaine
Active Contributor
0 Kudos
Hi - just noticed that when you have IPS on combined landscape and haven't nominated any IPS admins from the admin list you get this "This tenant has no registerd administrators. Please open a ticket to request one." But with combined infrastructure this isn't needed. just Admin access to IAS where users can then be flagged as IPS admins.

 

Sorry - tried to insert pictures but upload not working for some reason.

Cheers,

Chris

 

 
istvanbokor
Advisor
Advisor
Hi Chris,

You are right, if IPS is using IAS host URL, it is unnecessary to open an incident.

IAS admin needs to enable the Manage Identity Provisioning role on the IAS admin user as per the guide in order to provide the IPS_ADMIN role for the IPS console through the IAS administration console, see: https://help.sap.com/viewer/f48e822d6d484fa5ade7dda78b64d9f5/Cloud/en-US/544de9b504214372b4479dc1f6b...

We are working on corresponding the message in the iamtenants tool with the above.

Best regards,

István
pkirkendall
Discoverer

istvan.bokor it seems I have the same issue reported by Lutz previously. I can only see one IAS, yet I know I am admin of half a dozen across several different customer numbers. Is there a solution for this? I searched for a note, but saw nothing, and the comments previously are not helpful either.

Thanks in advance.

istvanbokor
Advisor
Advisor
Hello,

The tool checks the company ID assigned to an S user and lists the tenants of this customer ID.

If you are admins on several tenants and they are subsidiaries of each other, I suggest you go to the admin console of these IAS tenants (/admin/#/tenantSettings/info) and assign multiple customer IDs so that the tool can list multiple tenants. If there is no correlation between the customer IDs, probably you need to use different S users for each company and then log out and log in from each.

Best regards,
Istvan
pkirkendall
Discoverer

istvan.bokor thanks for the response. I was able to navigate to that menu and make more of the IAS tenants visible for my S-User in the iamtenants URL.

If you don't mind reaching out via mail, I have some follow-up questions more specific to our landscape.

jasmeen1302
Explorer
0 Kudos
I am geeting an error while accessing the link -  https://iamtenants.accounts.cloud.sap/

please help me - what could be the reason , as i need to find out tenant id inorder to strt with IAS upgrade ?
istvanbokor
Advisor
Advisor
0 Kudos
Hi, what is the error?
Linda1
Participant
0 Kudos

I was following KBA (2791410 - Integrating SuccessFactors with Identity Authentication IAS through the Upgrade Center)  and pasted exactly what it said to put in the filter field "status eq 'active' " except below for context:

" On IPS, update sf.user.filter field as this is a filter of the users that will be read by IPS on SuccessFactors.

  • When created, this field will come with value status eq 'active' and username in 'sf_username1_placeholder','sf_username2_placeholder'.
  • This means that only active users that are on the list will be synced (sf_username1_placeholder and sf_username2_placeholder).
  • You need to change the filter to sync usernames that exist on your instance as a test.
  • The filter should be only status eq 'active' for syncing all users to move forward on the implementation."

I then received this error: 

"Caused by: HTTP operation failed invoking https://api4preview.cert.sapsf.com/rest/iam/scim/v2/Users?startId=initial&count=100&filter=status%20...' with statusCode: 400 and body {"schemas":["urn:ietf:params:scim:api:messages:2.0:Error"],"scimType":"invalidFilter","detail":"The filter expression is invalid.status eq 'active'","status":400} "

 

So the very text the KBA told me to enter as filter is cause an expression is invalid error. Where do I go from here?