Single  Sign on Issue for new Portal Users

We are implementing ESS on EP 6.0. the architecture is like EP 6.0 - ITS - R/3.
and we want to implement the single sign-on. so that when the users login the portal, the Portal Authenticates the user and then portal uses just the Portal UserID and logs in ITS/R3 without verifying the SAP PWD. Portal ID and SAP ID are same.
The single sign on is working fine for those users who already have an SAP ID.
we need to create new R/3 ID's for the new employees. and we don't wanna let the employees login in directly to R/3.
When we create a new ID in R/3 and login for the first time in R/3, it asks to change the password.
since the new employees won't be using R/3 and they login through portal and b'cos we implemented single signon, the portal tries to login in r/3 using the Portal ID/R3 ID, but the SAP R/3 ID is not actived since the user did not change the password, the SSO is failing.
We didn't wanna assign the R/3 ID a password. since it will be an audit issue.
Can anybody give any suggestions, so that the administrator need not assign a password and the users need not login in r/3 and change the pwd for the first time.
Hope you understand my problem, if u need any clarification, let me know..
Thanks.

Hi Gopi-
You can override the password check when a valid logon ticket is presented by setting the profile parameter:
login/pasword_change_for_SSO   0
using RZ10 in the instance profiles.  (Requires a restart of R/3)
This overrides the password prompt/check when the user presents a valid logon ticket. 
Hope this helps you out.
Thanks,
Marty

Similar Messages

  • Create new portal-user with webservice

    Hi,
    I'm trying to develop a ejb-webservice which is creating a new Portal-User.
    The webservice is working so far, I made methods like getDisplayName() which is returning the display name to a logonId and so on. All this is working. I'm using the component sap.security.api.sda for this.
    Problem: User-creation is not working. I think the problem might be, that a webservice is not authorized to create users? Or putting it in another way: Is it possible that a webservice is "logging in" at the portal, or sohehow authorizing itself?
    Thanks and regards
    Jan Hempel

    Hi Detlev,
    thanks for Your answer.
    It seems like that the problem was caused by using array-parameters in the webservice-method?!
    Strange, but after removing the array-parameter from the method it worked! Before the webservice never returned anything, not an error or anything else.
    Well, strange enough, but I can live with that.
    regards
    Jan

  • Execute Webdynpro4Abap Application with same ERP-User for all portal-users?

    Hi,
    is it possible to let a Webdynpro4Abap application run with only one ERP-User for all portal-users? Therefore not needing an ERP-license for every portal-user?
    Somekind of mapping maybe?
    Regards
    Jan

    Jan,
    It is possible but it all depends on the type of application .If you want to show same data for all users you can use one user but if data is different for all users then you cannot go with this approach.
    to configure single backend user for your application go to tcode SICF and look for that application and go to logon data tab by double clicking and give one common user details
    Thanks
    Bala Duvvuri

  • New Portal User options are disabled when trying to create a new User

    Hi All,
    I am trying to create a new portal user profile using the administrator login. While doing that, I am getting all the options ( used to create the new user ) as disabled. Can anybody let me know the reason & solution of such a problem.
    or
    Anyone can provide me the document on how to create the new profile on portal. Thanks.
    Best Regards,
    Chander Kararia
    Edited by: Chander Kararia on Jan 15, 2009 7:26 AM

    Hi Chander,
    I just want to know if you are able to modify the attributes of an existing user. If not then you have been assigned the User Admin role (read only). Please check that. If yes then revert.
    Regards.
    Rajat

  • Implementing Single Sign-On support for the Oracle E-Business suite

    Implement Single Sign-On support for the Oracle E-Business suite
    I want implement Single Sign-On support for the Oracle E-Business suite.
    Operationg System : linux/Solaris
    Oracle E-Business suite : 11.5.10
    Oracle Application Server : 10gAS(latest availble)
    Type of integration : SSO and OID with 11i
    No third party SSO or LDAP
    Qusetions
    1.If my SSO Server is down can i login to applications(11i) using normal mode(default login http://servername.xxxx.com:8000/).
    2. Is it possible to have appilications (11i) in Linux/Solaris and 10gAS in windows.
    Please answer...
    NOTE:
    I am following Oracle METALINK Doc.Id 233436.1 and 261914.1.
    Thank you.
    MARK

    You couldn't login into server But You can use the following login
    http://servername.xxxx.com:8000/AppsLocalLogin.jsp
    For this you need to enable the Appslocallogin Profile option

  • How to change the UWL refresh rate for all portal users.

    Hi Portal Experts,
    How to change the UWL refresh rate for all portal users?
    Users can individually change the refresh rate through "Personalise View" in UWL.But we want this to set it for all users(we have 10k portal users).
    It was defaultically set to 5 mins for all users.How to change this to 20 mins.
    Thanks
    Sony.

    1.      Launch the UWL iView configuration page.
    You can access the iView from the UWL administration pages (System Administration ® System Configuration). Navigate to the property editor as follows:
          From the Universal Worklist Systems, choose the system for which you want to edit the properties.
        Choose Edit.
    may be you can get clear help from below help file
    http://help.sap.com/saphelp_nw04s/helpdata/en/eb/101fa0a53244deb955f6f91929e400/frameset.htm
    regards
    nagaraju

  • What is the password for the Portal User in 9i Release 2?

    What is the default password for the Portal User in 9i AS Release 2? I'm assuming this is the equivalent user to the Portal30 user in 3.0.9?
    Thanks.

    Jeremy,
    The default password for the Portal user in the same password as ias_admin. This would be defined at install time through the Oracle Universal Installer. However, if you're asking about identifying the Portal schema password in the database, you can login to the Directory Manager(assuming you're using Windows)and login as
    cn=orcladmin
    password: (ias_admin password)
    Click on (entry management)=>(cn=OracleContext)=>(cn=Products)=>(cn=IAS)=>cn=Infrastructure Databases => ReferenceName=sid:host=>ResourceName=Portal. Click on the entry and look at the orclpasswordattribute.
    Incidentally, you can also find the orasso password by checking the ResourceName=orasso.
    Note:198800.1 on metalink would be a good resource to follow.
    Thanks,
    Sudi Narasimhan
    Oracle9iAS Portal Partner Management
    What is the default password for the Portal User in 9i AS Release 2? I'm assuming this is the equivalent user to the Portal30 user in 3.0.9?
    Thanks.

  • Stacks and other simple issues..... for new Mac user

    My first computer was a commodore 64 with DOS commands and I've been a PC user ever since. You guessed it, Friday I went to the Apple store and bought an iMac! I was up and using it in minutes so I am impressed. However there are a million little things I just can't figure out or that take hours, for example at the Apple store the docking bar when you ran your mouse over the icons they jumped up. Well after a few hours I figured out how to make mine do that! (so cool).
    At the store they showed me "stacks" where i put my mouse on something and I could see, pix or documents or e-mail I had somehow saved there, very handy but if my Mac can do that I sure don't see how.
    Here are my two questions:
    1) how do i make stacks work (is it some program i don't have?)
    2) is there a web site or book or something with all the easy stuff (tips and tricks) in it a brand new Mac user should know? (i hate to keep bothering you all with simple questions)
    Thanks, Susa

    Welcome to Mac.
    1) Just drag any folder to the right hand side of the dotted line (the Trash side) of Dock. Then click. Or click and hold on the stack and choose how your stack displays.
    2) take a look at Mac 101 and Switch 101. There's a wealth of info there.
    Books? "The Missing Manual Leopard Edition" (coming soon) by David Pogue.
    -mj
    [email protected]

  • T440P - Win 8.1 Fingerprint Single Sign on Issue

    Hi,
    I just bought the T440P laptop, and for some reason it never updated to win 8.1 pro from the CDs that were provided. So I installed Win 8.1 x64 Enterperise with Update (provided by my company). I downloaded all the drivers for win 8,1 x64 from the website and installed them. The issue that i am facing is while following the single-sign on guide i have checked (ticked) everything but when the system boots it asks for my fingerprint (power - on password) and then stops at windows login and asks for it again. Why isnt the single sign on working?
    Below images show the settings in the fingerprint Manager Pro 8.01.26(x64). Any help will be apprecaited.
    Also the guide says to click the power-on tick over the enrolled finger print. I cannot find this option, is it even possible to power on the machine (T440P) with the fingerprint with win 8.1 x64 ?
    Thanks,
    Usama

    Hi,
      Using kerberos authentication, users when logged in to windows environment need not enter any user name or password for logging into portal. Check these links for configurations.
    http://help.sap.com/saphelp_nw2004s/helpdata/en/a4/385bef3bd14241b9c4f36bd779537d/frameset.htm
    Regarding SSO between windows and portal
    How To Identify which SSO(Windows Authentication ) is Implemented
    Regards,
    Harini S

  • Mail, Exchange, Acitve Directory and Single-Sign On Issues

    I have a brand new MacBook Air with Mavericks. 10.9.3.
    We are using a single sign on account setup for our machines. I enter my exchange log in details to access my account on my computer. It's labeled as a managed mobile account. When I open Mail, it takes forever to connect with the exchange server and download and sync new email. The activity monitor shows it constantly running. I send an email and it takes minutes until it actually sends. When I try to shut down mail I usually have to force quit it to close the app because it's doing some kind of syncing with the server.
    I have all the same settings on a Mac Mini running 10.9.3 except I'm using a local user/admin sign-on. No issue there. So I think it's something with the single sign on on my Air. Any help would be appreciated!

    Try a restart.
    Do a backup, using either Time Machine or a cloning program, to ensure files/data can be recovered. Two backups are better than one.
    Try setting up another admin user account to see if the same problem continues. If Back-to-My Mac is selected in System Preferences, the Guest account will not work. The intent is to see if it is specific to one account or a system wide problem. This account can be deleted later.
    Isolating an issue by using another user account
    If the problem is still there, try booting into the Safe Mode using your normal account.  Disconnect all peripherals except those needed for the test. Shut down the computer and then power it back up after waiting 10 seconds. Immediately after hearing the startup chime, hold down the shift key and continue to hold it until the gray Apple icon and a progress bar appear. The boot up is significantly slower than normal. This will reset some caches, forces a directory check, and disables all startup and login items, among other things. When you reboot normally, the initial reboot may be slower than normal. If the system operates normally, there may be 3rd party applications which are causing a problem. Try deleting/disabling the third party applications after a restart by using the application un-installer. For each disable/delete, you will need to restart if you don't do them all at once.
    Safe Mode
    Safe Mode - About
    General information.
    Isolating issues in Mac OS X
    Step by Step to Fix Your Mac
    You also have 90 day telephone support from Apple Support.
    Apple Support Contact
    Apple Support contact - Telephone

  • Single Sign on feature for flex porlet?

    Hi All,
    I would like to create a portlets using flex & blaze dataservice. I need to know if i use Oracle Application Server Portal,
    can i get single sign on support?
    i have seen the new oracle metalink has been created & deployed in oracle App server. i think that is a porlet?
    Am i correct?
    Can i get sso support for flex?
    Thank you all.
    Edited by: ADFBCUser on Mar 22, 2009 11:37 PM

    Hi,
    I would very much like to know how one can incorporate a flex module into Portal. Sample code and steps would be absolutely great. I just need a simple app example to get going.
    Frank

  • Wireless Network Policy Single Sign On Issue with Windows 8.1 only

    I'll try to set this up as best I can. I have a laptop with a fresh Windows 8.1 install on it. It is on my domain, and I have a single GPO applied to it. In the GPO under Computer Configuration -> Windows Settings -> Security Settings ->
    Wireless Network Policies I have created a Windows Vista or later policy. In the policy I have configured single sign on.  I log into a local account on the laptop and plug it into a wired connection. I then run gpupdate on it. At that point I unplug
    the network cable, and log off. Now, from the login screen I click Other user, and it looks like the screenshot below.
    Notice that "Windows will try to connect to" is present. I can login using domain credentials, and single sign on works perfectly. Now if I reboot the machine, the "Windows will try to connect to" is gone and single sign
    on does not work. If I log in with a local account and log out. The "Windows will try to connect to" is present again. I can login normally using domain credentials, and single sign on works perfectly again.
    One other note: I installed a fresh copy of Windows 7 on the same model laptop, and put it in the same OU with that single GPO. Single sign on works perfectly with the Windows 7 machine every time. Including after reboots. Thank you, in advance,
    for any advice or comments. I will be happy to provide additional information if it is needed.

    I managed to get this to work properly in my environment. I realized that I needed to export the wireless profile from the Group Policy editor and import it on the client (by using Group Policy). I realized this while reading through this article:
    https://technet.microsoft.com/en-gb/magazine/2007.11.cableguy.aspx
    You can see the "Export..." button in the screenshot posted by keyserag above. Select the profile name, in the Group Policy editor Properties dialog, i.e. the item that keyserag has blurred in his screenshot, then click the "Export..."
    button. You will be prompted to save the XML file. 
    I use Computer Configuration > Preferences > Windows Settings > Files to copy the XML file to the clients:
    Destination: %WindowsDir%\WirelessProfileExportFileName.XML
    I then use Computer Configuration > Preferences > Control Panel Settings > Scheduled Tasks to run netsh and import the profile:
    Action: netsh wlan add profile filename="%WindowsDir%\WirelessProfileExportFileName.XML"
    The PCs using my policies are now ready to logon without any need for additional manual actions.
    I've left out some detail here, I assume everyone will do something a little different anyway. Let me know if you need more help with this.

  • Report on portal User ID and Assign Roles for all portal users

    Hi!
    I would like to know , is there way that we can get a report which shows all the portal user ids with there assign portal roles. If we can't get this from portal. Can we get it from Oracle database ?
    What are the oracle tables and fields which store this information?
    If nay one have a custom develop iview for this please let me know
    Thanks
    Ramesh

    Hi Ramesh,
    as Pascal stated (and as I did above), if developing within the portal is not really new for you, playing around with the UME API is really more or less trivial.
    Check Portal User and Role info as well as User to Role listing for similar requests and code hints / further links.
    Hope it helps
    Detlev

  • Change default security settings for new Discoverer users? How?

    Hello, using Discoverer 10g with SSO integration.
    I've created two roles and create in advance users in the DB user, granting them
    one of the two roles. The two roles privileges for Discoverer are already configured.
    This way, when I create the user in the DB before launching Disco, granting the user one or the other role, I should be all set about what the user can or cannot do on Discoverer (Plus).
    So far the theory :)
    The problem is that the full permission given by Discoverer to each new user override the role settings, so each new user can do everything (instead one of the roles forbids saving and sharing, for example).
    I have to go to Disco Admin and uncheck the "Plus/Viewer" checkbox for the user to make roles actually work as expected.
    How can I set Discoverer user default as "Cannot do anything" on Plus/Viewer so that roles apply without further admin intervention?
    Thanks
    Mario

    Thanks a lot Rod.
    The problem here is we need to allow portal users the ability to access Discoverer Plus without using Disco Admin: once a user is registered in the SSO, he should be able to connect successfully to Discoverer.
    So we need creating user privileges on behalf of Disco Admin.
    Tough job, but it seems it ca be done.
    Regards,
    Mario

  • Printing help for new MAC user

    I am a new MAC user trying convince myself this is better than a PC. I have been trying to 3 hours to figure out how to print in color with a document I've created in Pages. I am connected to a HP Photosmart wireless printer. Can someone help me?

    jersey45 wrote:
    I am a new MAC user trying convince myself this is better than a PC. I have been trying to 3 hours to figure out how to print in color with a document I've created in Pages. I am connected to a HP Photosmart wireless printer. Can someone help me?
    Hi jersey,
    Welcome to Apple Discussions and the Pages '09 forum.
    Is this strictly a Pages/HP Photosmart issue, or do other applications share this inability to print in colour to this printer?
    About the only advice I can offer is to:
    1.
    Check the HP site for any updated drivers for your printer. Download and install if any are found.
    2.
    Check the printer's settings in the Print dialogue. Your printer may offer the choice, here or in it's utility application, to print using only the black toner cartridge.
    3.
    Try opening Pages from a different user account, and printing a new document from there. Success would indicate the issue lies in your user account, probably in a corrupted Pages preference (.plist) file.Go back to your usual account, locate the file and drag it to the trash. Try printing again from your usual account.
    If these don't help, I'd suggest reposting your question in the Printing, Faxing and Scanning forum in the Mac OS X v10.6 (Snow Leopard) section of Discussions.
    Regards,
    Barry

Maybe you are looking for

  • Issue while Removing a role

    Hi, Here is my scenario. User 'test1' is created by assigning a role (say A). Role A has AD and database table resource assigned, so there are 2 resources assigned to the user i.e. AD and a database table resource. (This is the exisitng process, I ca

  • Macbook Pro running slower and making more noise.

    Problem description: Hey everyone, I have noticed that my macbook pro has been running slowly. Sometimes firefox freezes and never unfreezes and whenever I play videos my computer runs slower than usual. I have started turning off my laptop whenever

  • Simple JFrame Doubt

    Why is the jextfield on the jframe so small. Also How do I update the textField of MyButton JFrame from JButtonActionListener? import java.awt.FlowLayout; import javax.swing.JButton; import javax.swing.JFrame; import javax.swing.JTextField; public cl

  • How to find the columns and tables used in a stored procedure?

    Hi, Can someone suggest how to find the columns and tables used within a stored procedure? Thanks VBK

  • Creating a gradient

    First off I am very new to Illustrator.  Just learning.  I was wathing a following along with a tutorial for creating a gradient.  The user was creating the gradient inside a rectangle.  WIthin the gradient options on his screen, there was a list of