Supported Features
The SAP Direct connector supports the following features:
Account Management
-
Manages SAP users as Accounts
-
Aggregation, Partitioning Aggregation, Delta Aggregation, Refresh Accounts, and Pass-Through Authentication
For more information on Delta Aggregation and Partitioning Aggregation, refer to Delta Aggregation and Partitioning Aggregation respectively. -
Create, Update, and Delete
-
Enable, Disable, and Unlock
-
Change Password
-
Add and Remove Entitlements
Entitlements are Roles (for user), Profiles (for user), UserGroup (User group of the user), and ContractualUserType (Licenses of the user).
-
Add and Remove Contractual User Type ID
-
Read and update the SAP UUID (Global User ID) associated with SAP Direct Accounts.
-
Add and Remove the EmployeeID assigned to an Account
-
Manage the Indirect Roles assigned to the accounts via Organization Data.
For more information, refer to Supported Features.
Account - Group Management
-
Manages SAP Roles as Account-Groups
-
Manages SAP Profiles as Account-Groups
-
Aggregate and Refresh Groups
Notes
The following table lists the special considerations of certain supported features:
Supported Features |
Notes |
Pass Through Authentication |
If Pass-Through authentication is enabled, the user can login through |
Aggregation |
|
Change Password |
For more information, refer to SAP note https://service.sap.com/sap/support/notes/1287410 (SAP Service marketplace login required). |
Manages SAP Profiles as Account-Groups |
A few system composite profiles might have child profiles which are not present in SAP system. For example, for each release composite profile |
Account - Group Aggregation |
In Account-Group aggregation for SAP CUA landscape, IdentityIQ for SAP ERP will not fetch child roles, child profiles of any composite role and profile, as CUA system does not maintain child level roles and profile details for child subsystems. Same way it will not fetch TCodes and Generated Profile for group object type. |