SAP IDM with MS Active Directory (OU names in Arabic)

Dear Gurus,
With SAP IDM , we need to integrate with MS Active directory such a way that SAP IDM only fetches users who have “SAP” in one of the AD field. That means do not read entire AD but only fetches users in SAP who have “SAP” tagged in one of the AD field.
Is it possible ? We tried that in SAP LDAP connector but its not possible in LDAP connector in SAP as LDAP connector is reading through all the users in our CUA system.
Question is it possible through SAP IDM that we use some thing (maybe  BAPI) to restrict users and do not read all users but only users having “SAP” in one of the AD field.
Also note that our AD has some OU's name in Arabic.
Regards,

If you want to filter this in the ADS Initial Load job then you can modify the repository LDAP Filter:
(&(objectclass=person)(orgUnit=SAP))
Replace orgUnit=SAP with your your attribute and tag.
Br,
Chris

Similar Messages

  • SSO All SAP solution with windows Active directory

    Dear Experts,
    We have multiple sap solution like
    SAP ERP EHP7
    SAP BW
    SAPBO
    SAP EES/MMS
    SAP Solution Manager
    And all solutions based on Operating system AIX and database is DB2
    We want to configure SSO ( using windows 2012 active directory users ) with all above systems and it's clients.
    Kindly guide me how to achieve SSO using Windows 2013 active directory users.
    DO we need LDAP between Active directory and all servers ?
    we need additional SAP license
    please guide me
    Regards

    Hello
    You can use SAP Single Sign-on 2.0 solution by SAP to integrate all your systems with SSO. The solution contains all what is required for configuring SSO in SAP ABAP and Java Systems. To know more, you may refer:
    1. SAP NetWeaver Single Sign-On 2.0 – SAP Help Portal Page
    2. Implementing SAP NetWeaver Single Sign-On 2.0 Based on Kerberos Tokens 1/4 - YouTube
    3.Implementing SAP NetWeaver Single Sign-On 2.0 Based on Kerberos Tokens 2/4 - YouTube
    4.  Implementing SAP NetWeaver Single Sign-On 2.0 Based on Kerberos Tokens 3/4 - YouTube
    5. Implementing SAP NetWeaver Single Sign-On 2.0 Based on Kerberos Tokens 4/4 - YouTube
    You will have to buy license for SAP Single Sign-on 2.0.
    Regards,
    Tapan

  • Active Directory Domain Name Convention

    Hi All
    I'm creating a brand new domain for a new company I have just started at. We currently use Office 365 so sharepoint and Exchange are both in the cloud and our website is also outsourced.
    I am now rolling out our first DC on Windows 2012 Server and I'm find conflicting reports on what naming convention I should use for AD with use with hosted exchange.
    Most seem to point at using a subdomain of our main site, like corp.mydomain.com whereas I come from a background using Server 2003 where its always been mydomain.local
    Can anyone advise me on this one and are there any additional thoughts around implementing with an existing Office 365 setup?

    It seems that mydomain.local is recommended less often (if not discouraged) because certificates from a third-party CA will no longer accept internal domain names, like mydomain.local, in the near future.
    Some links on this subject:
    http://social.technet.microsoft.com/Forums/exchange/en-US/a460ee18-e674-4c14-b4e8-33afd9ddb2a0/change-local-to-com-to-resolve-ssl-certificate-mismatch?forum=exchange2010
    http://www.digicert.com/internal-names.htm
    http://exchangeserverpro.com/ssl-requirements-for-exchange-when-certificate-authorities-wont-issue-certificate/
    In any case Office 365 will not interact with internal names. If you use such a name currently, you'd have to configure a UPN suffix allowing users to connect with the external name. This link might
    explain it better:
    http://www.messageops.com/documentation/office-365-documentation/active-directory-federation-services-design-planning-for-office-365
    In particular:
    "It is common for organizations to use one domain name internally and a different domain name externally. A best practice was to have your internal Active Directory domain name have a .local or a .corp suffix.  With Office 365, the UPN suffix must match
    your external domain name which you have registered and verified within Office 365.  In these types of situations it is necessary to add a UPN (User Principle Name) suffix to the Active Directory."
    Please mark as helpful if you find my contribution useful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you.

  • 802.1x PEAP Machine Authentication with MS Active Directory

    802.1x PEAP Machine and User Authentication with MS Active Directory:
    I have a simple pilot-text environment, with
    - Microsoft XP Client,
    - Cisco 2960 Switch,
    - ACS Solution Engine (4.1.4)
    - MS Active Directory on Win 2003 Server
    The Remote Agent (at 4.1.4) is on the same server as the MS AD.
    User Authentication works correctly, but Machine Authentication fails.
    Failed machine authenticaton is reported in the "Failed Attempts" log of the ACS SE.
    The Remote Agent shows an error:
    See Attachment.
    Without Port-Security the XP workstation is able to log on to the domain.
    Many thanks for any indication.
    Regards,
    Stephan Imhof

    Is host/TestClientMan.Test.local the name of the machine? What does the AAA tell for you the reason it fails?

  • Is it possible to get the active directory user name of the person

    Is it possible to get the active directory user name of the person who is logged onto a windows computer, when they are using your coldfusion site, the same way asp pages can do that?

    SECOND TRY TO POST THIS REPLY
    You have to turn on "Windows Integrated Security" and turn off anonymous login in the IIS web server, once that condition is met the cgi.AUTH_USER variable will be popluated with the domain/username of the user logged into the cient computer.
    If the user is using a windows browser on a windows client computer this will be done silently in the background.  Otherwise they will normally be presented with a login dialog box by the browser.

  • OracleApps HRMS-R12.1.3 Integration with MS Active Directory (win 2008 R2)

    Dear Friends,
    we are using Oracle Apps R12.1.3 and the Microsoft Active Directory : Windows 2008 R2
    we have the following requirement:
    (1)From Oracle Apps to Active Directory.
    -Employee master information needs to be interfaced to Active Directory on a regular interval which should be updated in the active directory.
    (2)From Active Directory to Oracle system.
    -Whenever new email address for an employee is created in Active directory, the information needs to flow to Oracle HRMS.
    Please let us know the method to achieve with minimal latest oracle softwares?
    can it be done over coding from oracle apps without new softwares?
    Is Oracle Apps R12.1.3 certified with Windows 2008 R2 Active Directory?
    Regards,
    DB

    user564706 wrote:
    Dear Friends,
    we are using Oracle Apps R12.1.3 and the Microsoft Active Directory : Windows 2008 R2
    we have the following requirement:
    (1)From Oracle Apps to Active Directory.
    -Employee master information needs to be interfaced to Active Directory on a regular interval which should be updated in the active directory.
    (2)From Active Directory to Oracle system.
    -Whenever new email address for an employee is created in Active directory, the information needs to flow to Oracle HRMS.
    Please let us know the method to achieve with minimal latest oracle softwares?
    can it be done over coding from oracle apps without new softwares?
    Is Oracle Apps R12.1.3 certified with Windows 2008 R2 Active Directory?
    Regards,
    DBPlease update your original thread(s) instead of creating new one(s) -- Integrate Oracle Apps R12 with Microsoft Active Directory
    Thanks,
    Hussein

  • Portal Integration with Microsoft Active Directory

    We are working on a project to integrate Oracle9iAS Portal with Microsoft Active Directory. I am wondering if anyone has any experience with this and hence suggestions. Particularly, I'm wondering if its possible and how to use Active Directory to manage the Portal user accounts and group relationships?

    Please note that we finally got this working. For Active Directories sake, I would suggest using userPrincipalName or sAMAccountName as the Unique Attribute. Also, note that Active Directory uses OUs for organization, not CNs, so the search base should be either just the DN of the domain or an OU in the domain. Also, be sure to specify the full DN of the Bind DN as in CN=Administrator,CN=Users,DN=domain,DN=com

  • SSO (single sign on) on NetWeaver 7.0 Enterprise Portal based on spnego with Microsoft Active Directory

    Hi,
    we are using SAP Netweaver Enterprise Portal 7.0 (SP25) based on Windows 2008 R2/Oracle 11g.
    When we setup the Portal, we used the UME of the ECC - ABAP.
    The portal is used internally only.
    Now we want to provide SSO.
    User authenticate against Windows Active Directory (Windows 2003).
    We thought SSO via spnego would be the best solution.
    Any better alternates, we should use?
    We are following the SAP documentation:
    SAP-Bibliothek - Benutzerauthentifizierung und Single Sign-On
    We still want to create users in ABAP and assign them the portal roles. LDAP access should only have read access, to verify the security token from Active Directory.
    When we setup the portal from scratch using ABAP as its UME, in the system configuration, LDAP can't be selected/add as data source.
    In case we understand the documentation correctly, we would now need to add LDAP via the configtool for read access.
    What is not clear to us, when we active now LDAP via config tool, if we would now lose the ABAP connection.
    Is there a tutorial for SSO Netweaver 7.0 EP, like for EP 7.3, available?
    In 7.3 SSO is pretty simple to get it running, thanks to the many tutorials here and on the internet.
    Thanks for your help.
    Best regards
    Carlos Behlau

    Hi,
    I was able to generate the key via ktab program.
    But when I am enable SSO, nothing is happening when I try to log-on via SSO to the portal.
    I installed WebDiag tool on the portal server and ran trace.
    The users are located in domain: company.com of activate directory.
    The Java AS are located in domain: sap.company.com of activate directory.
    The sap.company.com domain acts as child of company.com.
    When I check the WebDiag trace, I see for the SPNegoLoginModule - the entry "... no key (etype: 23) for realm sap.company.com available ..."
    I would except company.com as realm key, as the keytabs have been generated on the domain controller of company.com.
    Is it possible to get SSO with child domain running?
    Based on the statement of the network folks, child and father domain having a trust.
    Thanks for your help.
    Best regards
    Carlos

  • SAP ECC 6.0 / Active Directory Password synchronization

    Hello,
    We have a need to synchronize our users Windows passwords (AD) to our SAP systems (ECC 6.0, BW 3.5, and SCM 5.0).  We do not use CUA and currently do not use a Portal and are not looking at doing SSO.  We simply want to have one repository (AD) that will manage passwords for our Windows apps as well as our SAP systems.  So far, we have not found a way to do this.  SAP Note 603208 says this kind of synchronizing is not possible due to encryptions, among other things.  However, we did find a white paper that stated the following:
    ~snip
    <i>The Management Agents delivered with MIIS generally support password management: <b>they can take a password from some source (either from a user password change from the Windows interface, or from a self-service web-based password reset interface) and can set the same password in the various connected systems</b>. The Management Agent developed by Oxford is no exception. To change a password in an R/3 System the Susr_User_Change_Password_Rfc function can be used, but this is only possible if the old password is known and the SAP system allows the password change for this user. In cases where the old password is not known (for example the setting of an initial password) the password can be reset using the BAPI_User_change function.</i>~snip
    Does anyone have any information on how we can achieve the password synchronization between Active Directory and Abap-based SAP Systems?
    I very much appreciate your time and help.
    Paul

    Paul,
    You can achieve this using "common authentication". Since Active Directory uses Kerberos, if you allow your SAP systems to support Kerberos authentication as well, then you will be able to logon to Windows workstation, and use the Kerberos credentials issued by Active Directory during this logon to log the user onto SAP.
    This is common, and easy to acheive. You need to use the SNC capability which is provided in SAP GUI and also in SAP ABAP engine, and you also need a GSS-API library for both workstations and for the SAP servers that implements the Kerberos protocol. If your SAP server is running on Windows Servers then you can get this GSS-API library from SAP, but if (like many companies) you are running SAP ECC, BW, SCM etc. on UNIX or Linux servers then you need to license a third-party product which provides the GSS-API library etc. I represent a vendor (CyberSafe) that provides this exact product, but you can also find other vendors by looking on SAP partner website, under SNC certified products list. If you want to find out more about our product, please ask me offline by getting my email address from my business card.
    I hope this helps. Of course, if there are any questions for me related to this which are appropriate for public viewing then please ask them via this forum instead of via email.
    Regards,
    Tim

  • Active Directory - DS Name Cache rate hit thershold

    Hi Team,
    I would like the information for DS Name Cache Rate Hit  threshold limit. What is threshold limit so that I can understand there is some issues.
    Our monitoring systems is throwing alerts for DS Name Cache rate hit low its saying <80% on domain controllers. Also  I have checked all domain controllers the DS Name Cache rate hit being changing in the flection of second 0 to 85 to 100 not
    constant.
    Also the memory and normal.
    So can someone explain how I need analyze in more details so that ensure the alert valid or not.
    Monitoring systems alerts come and clears automatically.
    Could you please help me analyze this issue.
    D.K Konar. NMS

    Did  you gave a look to that? http://social.technet.microsoft.com/Forums/en-US/9d7b4fa2-ba0f-412e-981a-dbfafa0e55d2/ds-name-cache-hit-rate?forum=winserverDS
    This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
    Get Active Directory User Last Logon
    Create an Active Directory test domain similar to the production one
    Management of test accounts in an Active Directory production domain - Part I
    Management of test accounts in an Active Directory production domain - Part II
    Management of test accounts in an Active Directory production domain - Part III
    Reset Active Directory user password

  • OWLCS install - trying to use with my Active Directory

    Experts,
    I'm new to OWLCS but am very familiar with the Oracle Fusion Middleware 11g Stack. My end goal is to integrate OWLCS with WebCenter Spaces 11g (11.1.1.3). I have a Dev Environment where I have installed OWLCS (11.1.1.2) following the steps outlined in the Installation Guide, Oracle® WebLogic Communication Services Installation Guide 11g Release 1 (11.1.1) E13808-01.
    I followed the instructions to setup an All-in-One Managed Server. I have an Admin server (owcs_AdminServer) and managed server (wlcs_server1) defined and started. I've also followed the instructions to update my Realm to "mycompany.com" and also remembered to update the /etc/hosts file with "mycompany.com".
    I followed the remainder of the guide to test the installation with an Oracle Communicator Client.... I added test users using launch_sash, I successfully connected and saw my presence change and was able to communicat with another test user.
    That was fine for testing... but, I need this connected to our LDAP (Active Directory) and then eventually to integrate with WebCenter Spaces. This is where I get lost...
    I started following the Admin Guide, Configure Authentication Provider for OWLCS, in Section 5. But I'm confused over what type of authentication that is needed? Do I setup for Digest Authentication?
    Being not quite sure, I started to follow the steps 5.7.4 Steps for Configuring Digest Authentication. First, I could not change my LDAP provider to store unecrypted passwords so I didn't change anything to the existing LDAP.
    In 5.7.4.2 Reconfigure the DefaultAuthenticator Provider, I followed steps to change the DefaultAuthentication flag to "sufficient".
    Next, I followed 5.7.4.3 and created an LDAP authentication provider for my Active Directory LDAP server. I checked my Users and Groups after restarting the Admin server and I can see my users and groups in the MyRealm Security Realm .
    Here is where I need help... My LDAP admin is telling me that our LDAP cannot pass unencrypted passwords... so what are my options?
    Do I really have to setup DigestAuthentication? What is the Credential Attribute Name that Active Directory LDAP users use?
    Do I have to create a new Digest Authenticator?
    I also have a few questions regarding the settings to Oracle Communicator but will wait until the above is resolved. I have some confusion on the settings on Oracle Communicator once the above is working. And then next, getting it to work with WebCenter Spaces.
    Thanks in advance,
    Phil

    Hi Phil,
    Integration with Active Directory is not supported for OWLCS. We support LDAP integration with Oracle Internet Directory (OID) only.
    Please refer to section 5.12 in the Admin Guide at:
    http://download.oracle.com/docs/cd/E14571_01/doc.1111/e13806/securityoverview.htm#CJAJEFHF
    There are several steps which need to be followed carefully to configure OWLCS with OID, including installing Static Verifier and modifying OWLCS server instance.
    Please also keep in mind that OWLCS is not available for production use; it is limited to development, testing, and non-production use only. It is not licensable at this time for middleware customers.

  • ACS 5.1 with Windows Active Directory

    Hi All,
    I installed ACS 5.1 in vmware server successfully. I have problem while intergrating cisco acs with microsoft Windows 2008 active directory. I already verfied all the related parameters like Domain name, user rights to join in AD, DNS name resolve and IP-Address.
    But, I can able to add any system into my domain without any issues and this is not happening in Cisco ACS 5.1 version.While testing the Active Directory - Test connection it prompts with error message " Can not resolve network address".
    Please help me from this issue.
    Regards
    Mani

    Hi
    Have you setup the correct DNS servers and domain name in the ACS and also do you have an entry in the DNS for the ACS server?
    Dave

  • ACS Integration with Microsoft Active Directory Services

    Hello Everyone,
    I've been tasked to design the integration of ACS with MS AD. What I want to know is the below assuming I have a software ACS or a ACS device and the protocol for authentication is Radius
    - What is the criteria for the AD to integrate with ACS software of appliance
    - Should that AD be hosted on the domain controller or not?
    - If not, on what (Domain Controller, Tree, Forest, Branch, Flower, Fruit  ) should the AD be hosted on?
    - What will I have to do to authenticate users logging into Cisco Security Manager with ACS integrated with AD?
    - Are there any other dependencies that I will have to categorically mention in my design document?
    Thanks,
    Rishi

    In ACS v5.x, there is a screen for integrating the ACS with AD. 
         (Users and Identity Stores > External Identity Stores > Active Directory)
    Just enter the local domain name (domain.com) and a valid AD administrator account username and password, and the ACS will connect to the domain.  This allows you to use existing AD credentials to login and administer your network devices. 
    Tying the ACS to AD really only takes one screen and less than a minute, but you will still have to tell the ACS which AD groups get which permissions (for example, read-only or read-write access), and you will have to setup a search sequence (Users and Identity Stores > Identity Store Sequences) to tell ACS to first look at AD for credentials, then check the local ACS user database for valid accounts.  The permissions part is still fairly quick, and it only takes me about 45 minutes to build an ACS from scratch including all AD integration and custom RADIUS attributes for some of our devices. 
    The authentication would occur like this:
    User SSH/telnet/console to device
    Device contacts ACS using TACACS or RADIUS
    User receives login prompt and enters AD credentials
    Devices sends credentials to ACS
    ACS validates credentials in AD
    ACS sends authentication OK message to Device
    Device logs user in.
    Command Authorization looks something like this:
    User enters a command
    Device sends command authorization request to ACS
    ACS looks at which AD group the user belongs to and looks up permissions configured in ACS for that group
    Based on the permissions you have assigned, ACS either sends an allow or deny message to the Device
    Device allows or denies the user command.
    Criteria:  We use an ACS 5.2 virtual machine and have had it work perfectly with Server 2003 and Server 2008.
    AD is hosted on our local domain controller (Bonus:  no planting of flowers required!)
    Dependencies: 
    Issue:  The Device looks to ACS.  ACS looks to AD.  If AD fails, users cannot use their AD credentials to login.
              Device ---> ACS ---> AD
    Solution:  Configure the Device to look at ACS first, then a local table if ACS is not available.  Also, configure the ACS to look at AD first, then a local ACS account list if AD is not available.  (You can configure local user accounts on the Device and in the ACS) 
              Device ---> ACS ---> AD
              Device ---> ACS ---> AD ---> ACS local
              Device ---> ACS ---> AD ---> ACS local ---> Device local
    The new version of Cisco ACS is UNIX-based, and you can download a free trial to load up and try before you buy.  It is far FAR superior to the old ACS v3.3 that we had for years.
    I hope this helps for your design document!
    --Chris

  • How to populate drop down list in infopath 2010 with form Active Directory resources.

    I want to populate drop down list in infopath 2010 with Active directory resources.
    Kindly let me know how to do this.

    Actually I posted an alternative approach, whoops. This is the Web service way, but both will work;
    http://blog.mangroveweb.com/pre-populating-an-infopath-from-with-mysql-data-using-a-net-web-service/using-sharepoints-getuserprofilebyname-web-service-to-retrieve-ad-account-information/
    w: http://www.the-north.com/sharepoint | t: @JMcAllisterCH | YouTube: http://www.youtube.com/user/JamieMcAllisterMVP

  • How to deploy EUS  using OVD with existing active directory ?

    Hi,
    I am new in Oracle FMW and want to explore more into it,
    I have existing MS active directory with users and group policies defined there  and I need to implement the solution for  all users  to authenticate in oracle Database (11gR2) via AD.
    and after searching reading some docs I came to know that It can be done by  "EUS deployment using AD and OVD".
    Now I am bit confused for where to start Please guide me . My env is as follows
    I have existing MS AD server (win2003) and oracle Database 11gR2 on HP unix..So Do I need another server (Win2003/2008) to install OVD or can I install OVD on existing AD server.
    What exactly software required to install OVD as I have downloded software from e delivery site "Oracle Identity and Access Management 11g (11.1.1.7.0)"  
    Is it same or do i need to download other one?

    Check this:
    Installing and Configuring Oracle Virtual Directory
    OIM Image: OID and OVD 11g Basic Install Steps
    Oracle&amp;reg; Fusion Middleware
    Middleware Technologies : Installing Oracle Virtual Directory

Maybe you are looking for

  • Scrolling horizontal line of distortion when in hardware mirror mode

    This distorted line that appears while using Dashboard or Expose only happens when my dual screens are in mirror mode. I've tried all the obvious but have now lost countless hours trying to figure out this problem: replaced video card, replaced Mini

  • My usb port gives power but doesn't work

    Hello, I have a 13 inch Macbook pro and my usb ports stopped working yesterday they worked fine but today I plugged in my mouse but it didn't work. It lights up but doesnt work, after that I tried diffrent mouses same problem they light up but no mov

  • How to setup iMessage correctly to avoid double replys

    Hi there. I have just installed Mountain Lion on my macbook air. I also have an iPhone. I now have connected my account with iMessage on the macbook. I am using the same account on my iPhone. So far so good. I then start a chat in iMessage from my ma

  • HT5957 iOS 7.0.2 upgrade issue

    After a failed attempt to upgrade to iOS 7.0.2 through iTunes, my iPad 2 is stuck on the screen with the iTunes logo and 30 pin adapter logo.  I have tried to do a hard reset, but the device keeps coming back to the same screen.  Any suggestions?

  • Software disks don't open, linksys router software wont autorun, none of my

    none of the disks inserted autorun, and I have my prefferences set to open DVD player, Itunes etc, but when I insert a software cd nothing happens, when I click the Icon, iy asks what program to open with...what gives????