SAP IDM 7.2 Questions

Hi,
I just recently started with SAP IDM and have a few Questions, maybe someone has the time to explain, thanks in advance!
- What for is VDS (Virtual Directory Server)? I can write directly into AD? why another target system?
- If I create a Role in Identity Center for testing its available on the idm portal http://localhost:50000/idm but not in /useradmin or Umeadmin?
- Repository, does it matter in which repository I upload (CSV Import) users? I have multiple repositories and didn't understand the exact purpose of a repository?
- Org Units? how can I create Org Units and assign roles for inheritance? is this only available on a Netweaver AS ABAP installation? (I installed AS JAVA) According this link: Indirect Role Assignment Using Organizational Management (OM) - Identity Management - SAP Library
Thanks, Patrick

Hi Patrick,
here is some answers:
Main purpose of VDS is to be an interface INTO IdM. It is an LDAP interface into the data stored in IdM database. It allows you for example to search, read, write and authenticate to IdM data via LDAP interface.
IdM has its own UI (http:host:port/idm). You are not supposed to see business roles in useradmin of the J2EE. It is objects known to IdM, not to the J2EE.
Repositories are objects representing mostly a source or target system. For example AD could be a source system where you get users from. An ABAP client can be a target system where you provision users to. Uploading users is just a way of creating users that you cannot get from some other source system like HCM, AD or ABAP. It depends on your scenarios and user life cycle where you get your user information from (source system) and where you provision to (target system).
The link you shared regarding the org units is not really related to IdM as a product. If you do some automatic assignments in ABAP directly, you might need to reconcile with IdM. IdM is supposed to be a central user administration tool. If you have information about org units in IdM and want to use it to automatically assign authorizations you can do that for example by using dynamic groups.
IdM is a very powerful tool opening a lot of possibilities as you can basically implement every requirement if you only have the required information available somewhere. It might be helpful for you to have someone to answer all your questions and help you solving your requirements in best way in the beginning, enabling you to use it in the most efficient way.
Regards
Norman

Similar Messages

  • Authentication Question in SAP IDM 7.1

    Hi All,
    I am currently working on SAP IDM 7.1 , My requirement is to set authentication question in SAP IDM and enforce the same at the first time login of the user. Presently I am setting my authentication question answer in OOB attributes -- MX_AUTH_Q01   - Q05.
    For the first time login user i am getting the default password change screen , thereafter i need to enforce Set Authentication for every user , logged in for first time. Please, suggest if SAP provides any feature like this to  set authentication question, at the time of login. Thanks in advance
    Regards
    Swati Pandey

    Hi Christian,
    I have implemented the security question using the same concept i.e by limiting access to process throgh access control.  Now, my requirement is to store Dynamic question in user profile, i.e users can store his/her own custom question /answer. Do we have any such facility in sap idm, presently the auth question provided are static for each user profile.
    Thanks
    Swati Pandey

  • SAP IDM 7.0 connecting to SAP GRC 10.1

    Hi Gurus,
    I was looking into connecting SAP IDM 7.0 with SAP GRC AC 10.1 and I cannot find a suitable connector for this.
    Could any of you provide some guidance on how to make this connections.
    Thanks and Regards,
    Juan

    If i remember correctly the 7.0 version had only mx_provision, mx_deprovision and mx_modify -tasks so the integration would have be built on these tasks. As there is no validate add task to hang the GRC call GRC would have to do provisioning.
    7.0 datamodel is different than 7.2, I haven't studied in detail but would guess there is enough difference also in the tables that store tasks/jobs etc that the 7.2 GRC provisioning framework would not   even import to 7.0. You would need to set-up a 7.2 on the side to study the framework to see how to duplicate the tasks..
    VDS in the middle is another thing as it would need to be able to communicate with your custom connector in 7.0.
    If you must stick with 7.0 maybe the GRC connector of 7.1 is worth a try.. But you would probably need also older VDS.
    Depending on the level of your existing customisations and what data from 7.0 is worth keeping the upgrade to 7.2 is not necessarily big thing compared to the effort of building the interim custom interface.. The real question is how big and complex is your 7.0 implementation?
    regards, Tero

  • SAP IDM - GRC Integration Scenario Query

    Hello Experts
    I want to understand if the following scenario is possible or not. Or if any alternate is available. Please share your thoughts..
    Current Situation:
    SAP IDM 7.2, SP9, Patch 11, in use with SAP Provisioning Framework 2 and GRC Provisioning Framework 2
    SAP GRC Access Control 10.1
    Both systems installed, configured and connected (web service connection works well)
    Desired scenario:
    Business Roles will be requested for assignment in IDM. For each privilege that is contained in the Business Role, IDM will trigger the Risk Analysis task and GRC will perform a risk analysis (privilege grouping not yet defined).
    If the GRC risk analysis does not discover a risk, IDM will continue the assignment process of the privileges (or rather Business Role) following the approval workflow defined in IDM.
    If the GRC risk analysis discovers a risk, IDM will trigger the AC Validation task and GRC will create a validation request. This request has to be mitigated in GRC. The result will be handed over to IDM and will there be processed accordingly.
    Problem:
    In IDM only one task from the GRC Provisioning Framework 2 can be triggered when a privilege will be requested for assignment. In our case it’s the “AC Validation – Risk Analysis only” task:
    …and the “AC Validation” task:
    Using the “Risk Analysis only” task processes the pending value object right after receiving the GRC response. This prevents us from post-processing or modifying the pending value object. The assignment will directly be assigned or rejected.
    That means we can either have a risk analysis only OR we’ll have a GRC AC validation request for any privilege assignment request! This is not the foreseen scenario. We want to perform a risk analysis for eacht privilege assignment and if a risk is detected in GRC, a mitigation request shall be started in GRC.
    Question:
    How can this problem be solved? Is the desired scenario feasible?
    Thanks a lot in advance.
    Regards,
    Krishna.

    Hi Krishna,
    I suppose AC Validation – Risk Analysis only" should suffice your requirement from IDM side.
    IDM prepares risk analysis request, submits the request to GRC and process the output of risk analysis.
    Rest to be config'd in SAP GRC side. GRC should receive the request from IDM, performs risk analysis and creates request for remediation and send out of request to IDM. Did you check with your SAP GRC Consultant if workflows and WS are correctly configured in GRC side?
    Kind regards,
    Jai

  • ActiveDirectory - SAP IDM integration in Identity Life cycle Management

    Hi Experts
    In our landscape SAP HCM is supposed to be  the  leading data source and SAP IDM takes identity information from SAP HCM.  From SAP IDM it will provision into Active directory and other third party systems, Sap systems.
    Here are the questions
    1) How  can we leverage on the investment on Active directory after  SAP IDM -Active directory investment ?  I mean after SAP IDM comes to a landscape,  Active directory will only be used to login to domain and for authentication if for java system Active directory have been set as user data source.  What are the other advantages of Active directory- SAP IDM integration as Active directory will not be leading data source and identity information will be in identity store.?
    2) After the user details are taken from SAP HCM system, will  the user record will be created in SAP IDM on Identity store ?  Is it where we actually assign the SAP IDM business role and the related technical role  to the  user? 
    3) Suppose if we assign a business role " employee " , will IDM actually create user id in all target system and assign all the technical roles? . Or we have to manually select each repository for target system in Identity center and  select the privileges and provision it ?  Will there be any automated feature that after assigning the business role to identity in identity store users and roles get automatically provisioned on all the target systems?
    Thank you in advance for your help.

    Hi Matt,
    Thank you very much.
    Only change we have is before approval it should go to GRC AC check all the compliance   and only after that it is approved and it should come back to SAP IDM  .
    I am actually looking for a tutorial which actually shows how you assign a business role and the whole procedure of SAP IDM automatically provisioning to target systems which you have just explained.  I suppose there is no such exact tutorial and I want to know how we can configure this on SAP IDM . Any  specific clues?
    Also  I am describing the exact steps that will follow . Correct me if I am wrong.
    1) User id will be created on AD with same user name and password as it is in Identity store. Will be assigned AD groups
    2) Create same user in Portal and make the user data source as AD and will assign the technical role portal as per the business role definition
    3) create same user in all abap systems and set abap database as user data source and assign the technical role needed as per the business role definition
    4) Create same user in third party systems  and with the privileges on their target systems as per the business role definition.
    With this provisioning stops. I suppose all the above steps will be automatically done by SAP IDM with no manual interaction required after final approval. Correct me if I am wrong.
    So some other information i wanted is
    1) When you assign business role at work flow,  how exactly SAP IDM  know about the target systems that user should be created and  assigned roles and made their authentication source.
    for eg:- for  a  business role "employee"  should get  access to ERP with role X,  AD with group Y, Portal with role Z.  So in work flow when business role employee is assigned  how SAP IDM will know that user should be created on to ERP with role X,  AD with group Y, Portal with role Z. Can you explain technically along with  detail steps? Or how exactly we configure a business role which knows the target systems and their techical roles.
    Thank you once again for the fabulous help . You/Matthew is a tremendous  help in understanding SAP IDM better.

  • Reg: SAP IDM License

    Hello Experts,
    As I came to know SAP IDM is free with Netweaver license , Can somebody let me know the licensing term for SAP IDM ?
    If I use IDM for only provisioning to SAP system then would it be free or will be there be any license cost ?
    And how licensing differs when we connect IDM with Non-SAP systems i.e AD ?
    Regards
    Deepak Gupta

    Hello Deepak,
                         IdM is covered under the main license for the netweaver based product you are installing. There are no additional fees for connecting to non SAP (or other SAP) systems.
    I Hope this helps. If you have further license questions then please open a support incident under the component XX-SER-LAS.
    Best regards,
    Chris
    SAP Active Global Support

  • SAP IDM vs Microsoft Forefront Client(FIM)

    Hi experts,
    Actually my companyBig Company) is planning to implement tool for Identity Management but there are couple of options which we are thinking of considering particularly the last  2 options are SAP IDM and Microsoft Forefront(FIM) ... But I am not able to enough information or comparision points that will help me in convincing to my sr management to finally say to one of these tool.
    I would really appreciate a quick response, if some one can explain the comparisions points among these 2 tools.
    Thanks
    SAP_Enthu

    Hi All ,
    Just to add to my previous question as currently we have MS Active Directory already and as per plan implementing SAP in almost all areas entreprise wide with GRC. So with this background , I will appreciate the advantages and disadvantages of SAP IDM 7.1(might use 7.2 if it comes within next 3 months as planned) with MS Forefront IDM(FIM 2010) in terms of Technical , functionally , architecture ,economic point of view.
    This will help in selecting the best tool among them.
    Thanks
    SAP_Enthu

  • SAP IDM vs SAP GRC

    Hi All,
    One basic question is coming again and again due to overlapping features of SAP IDM and SAP GRC. Why SAP IDM is required when all most all use cases can be fulfilled by SAP GRC? Is there any document available which can tell me why customer can choose IDM when he already has GRC?
    1. SAP IDM and GRC both can accomplish access request and provisioning.
    2. SAP IDM and GRC both has capability of risk management.
    Then why SAP IDM is required?
    Thanks,
    Dhiman Paul.

    Hi Dhiman,
    SAP IDM is more flexible and is Java based (providing excellent customizations).  GRC 10 is ABAP based and originally designed for Access Control.  As mentioned by Chris, IDM connectors are flexible than GRC & provisioning workflow is highly variable.
    I'd say if there are quite a few number of Legacy systems to be connected for IDM solution, SAP IDM would be an ideal choice than SAP GRC, as it can be implemented with less cost and customization.
    My simple opinion.  There may be other points as well.
    BR,
    Ganesh

  • SAP IDM integration in SLD

    Hi there
    one of our customers raised the question if SAP IDM can be integrated with SLD (system landscape directory)? Obviously, one of the dispatchers showed up in the SLD for one time (maybe during installation).
    best regards
    Matthias

    Hi Billy
    in fact the core components of SAP IDM are not implemented in NetWeaver. They are running on a Windows Server (e.g. the dispatchers). Those are the components we want to register in SLD.
    Only the UI components are running in an NetWeaver AS Java, but this one is already in SLD.
    best regards
    Matthias

  • SAP IDM with MS Active Directory (OU names in Arabic)

    Dear Gurus,
    With SAP IDM , we need to integrate with MS Active directory such a way that SAP IDM only fetches users who have “SAP” in one of the AD field. That means do not read entire AD but only fetches users in SAP who have “SAP” tagged in one of the AD field.
    Is it possible ? We tried that in SAP LDAP connector but its not possible in LDAP connector in SAP as LDAP connector is reading through all the users in our CUA system.
    Question is it possible through SAP IDM that we use some thing (maybe  BAPI) to restrict users and do not read all users but only users having “SAP” in one of the AD field.
    Also note that our AD has some OU's name in Arabic.
    Regards,

    If you want to filter this in the ADS Initial Load job then you can modify the repository LDAP Filter:
    (&(objectclass=person)(orgUnit=SAP))
    Replace orgUnit=SAP with your your attribute and tag.
    Br,
    Chris

  • SAP IDM - Can it be powered by SAP HANA

    Can SAP IDM powered by SAP HANA ? I have seen few Demo's on how SAP HANA can improve Performance drastically . Can IDM be integrated with HANA??

    Jerry,
    Great question.  The answer is not yet.  From what I understand this is planed for a later release of IDM.  Right now about all IDM does with HANA is provision to it.
    Hope this helps!
    Matt

  • Advantage and disadvantages of SAP IDM & Microsoft Identity management Tool

    Hi Folks,
    I am looking some points on SAP IDM and Microsoft tool for Identity Management. I am looking below mention points.
    1. Difference in the feature and prize.
    2. Limitation
    3. Solution architecture for both
    Relevant answers will be rewarded.
    Regards,
    Akshay Shail

    Hi,
    I can add some points about SAP NW IdM. Regarding your question about the prize: If you only connect SAP systems (it can handle all types of SAP ABAP and SAP Java Systems) they don't charge you extra, because it's already in the NetWeaver license. Furthermore, if you use the SAP Central User Administration: It isn't further developed and will be replaced by SAP NW IdM.
    The systems you mentioned can be connected, I think these are basics for everey IdM solution. HR interation is possible with SAP IdM, don't know about the other solution in this point.
    There are some whitepapers and presentations about SAP NW IdM: https://www.sdn.sap.com/irj/sdn/nw-identitymanagement?rid=/webcontent/uuid/f0b68fb1-d8af-2a10-2a8e-cc431c15bb39&anchor=section2.
    Nevertheless, your question about limitations and solution architecture probably needs a PoC if you want to answer them in deep.
    Best regards,
    Nils

  • SAP IDM - SPML integation

    Hi,
    I was trying to integrate SAP IDM with SPML using VDS.
    While configuring VDS for SPML request I am getting an error as follows.
    "Exception: Could not load external 'attrClass' or one of its referenced classes"
    I am getting this error while starting the identity service in VDS.
    The configuration guide does not talk about adding any other jar/class files.
    Any help in this regard is highly appreciated.
    Thanks in advance.
    Regards
    Sunil

    I know that this thread is old, but when deploying the IdM Identity Service, in conjunction with GRC 10 WebServices (for the CallBack Service functionality), you can't just disable the attribute and continue; you must fix it or else you will not be able to deploy the .ear file needed to further deploy to java (i'll go into detail on this in another post).
    The way, I got past this error was to go Tools - > Options (in VDS) and update the java settings to use the java version I have installed (or as close as I could), I set VDS to use a specified complier (the same compiler for my version of Java - in the same BIN folder) then ensured the classpath was updated with all the classpath's listed in the error (I added them to the Windows CLASSPATH environment variable also):
    The service Compiled and started without issue and I was able to deploy the .ear file out of VDS for Java.
    -ALJ

  • SAP IDM  7.0 integration with third party system

    Hi Experts,
    I know SAP IDM  7.0 can integrate with third party systems and create user ids on most of the third party systems.
    But I need to know regarding If it is possible to integrate with following systems
    1) Microsoft Exchange 2007 (  I know till exchange 2003 SAP  IDM support )
    2)  Microsoft  Active directory 2008 ( I know till Actice directory 2003)
    3) EMC  Documentum 6.5
    4)  ARIS 7.1.0
    5)  BlackBoard, Release 9.0
    6) Oracle 10g  ( Is it possible to create users at oracle level ? or at what level ? )
    7)  Sun Solaris Sparc  ( Is it possible to create users at  OS level )
    If you have information how on this please share. I know that  provisioning framework will have templates for most of the target systems. I want to know if they are available for above systems on SAP IDM 7.0 or if not have we can connect to them?

    Hi Matthew
    Your expertise in SAP IDM is indeed a great help!!
    >Can't see why not, it's all done via SQL commands. I've done similar things with MSSQL
    You mean that there will be oracle 10g drivers/oledb connectors in SAP IDM and in through SQL commands like "create user alfredo identified by alfredos_secret; " we can create user  in oracle database ?. As you said this should be possible.  What about creating user( user management ) in oracle 10g application  like dba or scot  and assigning the privileges in oracle application?
    >might need to do via UNIX scripts, but it can be done
    You mean that Unix scripts will be defined in SAP IDM and SAP IDM will execute these scripts in the Sun Solaris Sparc ?. It should be possible as you said. By the way how we will be able connect to Sun Solaris sparc ?  Is it via  the option "file " under the "Repositories" with repositories wizard  and later executing the file from SAP IDM ?
    Thank you once again for your expert answers on third party systems.

  • SAP PM Direct Certification Question model.

    Hi Experts,
    Could you please provide me SAP PM Direct Certification Question model.
    Thanks in advance.
    Chandru.

    See [here|http://www.sap.com/services/education/certification/certificationrole.epx?context=%5b%5bROLE_TPLM30_05_CER%5d%5d%7c]

Maybe you are looking for

  • Help me to run pkg via procedure

    i have a package :   create or replace PACKAGE SUBS_INS_API_SS IS PROCEDURE SUBSCRIBER_INS_SS     (SOURCE_SYS_ID IN VARCHAR2,     TRACKING_ID   IN VARCHAR2,     ACCOUNT_NO IN VARCHAR2,     prepaidActDevDetails_tab IN prepaidActDeviceDetails_tabobj,  

  • Exit Code 7 for Adobe Premier Elements 10

    I cannot install Premier Elements 10 on my Mac. I have tried many times and it's getting frusterating. I keep recieving this message: Exit Code: 7 -------------------------------------- Summary -------------------------------------- - 0 fatal error(s

  • Change to the Payroll Frequency feature does not update Annual Salary IT8

    We are running a biweekly payroll but in 2009, because of the way the calandar falls we will have 27 pay periods.  The Payroll Frequency feature was changed but for salaried employees, their info type 8 annual salary still shows their biweekly amount

  • N8 not displaying caller name

    My N8 suddenly stopped displaying my contacts caller's names. Why is this & how can I fix it? Nokia N8 on Belle Solved! Go to Solution.

  • Why Adobe dont want support for ArmV6 if there are many devices with these?

    Many people use Android devices with ARMv6 like: Galaxy ace, Motorola Defy, Galaxy y, LG Optimus One, etc, ect. I think that therea are more with ARMv6 that ARMv7 check: http://forum.xda-developers.com/showthread.php?t=1596800 This link you can see t