cancel
Showing results for 
Search instead for 
Did you mean: 

BTP Authentication API is not updated when user is deactivated at Cloud Identity Services

sreehari_vpillai
Active Contributor

Hi .

I use the authentication API to get the list of sub account users. These users are created as shadow users for Cloud identity Services.

But when I deactivate a user at cloud identity services , corresponding sub account is not "aware" of this deactivation . The API ( /Users ) still shows that user is Active ( active : true ) . Any luck here ?

Sreehari

Ivan-Mirisola
Product and Topic Expert
Product and Topic Expert

Hi sreehari.vpillai,

This seems to be a topic for a ticket at SAP support. Have you opened one yet?

Best regards,
Ivan

sreehari_vpillai
Active Contributor
martinfrick
Product and Topic Expert
Product and Topic Expert
0 Kudos

Hi sreehari.vpillai,

I'm not exactly a guru on this topic, but I reckon the two solutions might not be as connected as you're thinking. So here's what I'm thinking - even if your Shadow User stays "Active" in your Subaccount, it should no longer be able to access any app if it's "deactivated" in the Cloud Identity Service, seeing as the login process goes through SAP IAS. But please correct me if I've misunderstood your setup. I totally get where you're coming from - a "sync" feature would be awesome... But it seems like - for now - you might have to "deactivate" the user in both areas using API calls or the Cockpit.

All the best,

Martin

sreehari_vpillai
Active Contributor
0 Kudos

martinfrick I was building an API to pull the list of users active in the sub account in a multi tenant scenario . SAP responded to set up a sync service or to manually delete the user from sub account for the API to function. A user deleted / deactivated in the CIS is not automatically synced .

martinfrick
Product and Topic Expert
Product and Topic Expert

Hi sreehari.vpillai, thanks for the additional context. I somehow missed the incident link... I hope that the API-based deletion approach or a sync via e.g., SAP IPS is a viable alternative for you. Best! Martin

Accepted Solutions (0)

Answers (0)