Create Profile Attributes

When Identity Security Cloud provisions new accounts to a SAP HANA direct connect source, it uses the attributes on the Create Profile page as instructions or a template for what to include in the account. This page is also referred to as the provisioning policy.

Important
This page describes the configuration of the default Create Profile, however, SailPoint recommends that you work with Services to define a Create Profile specific to your company's needs.

The following generators create required information for a new SAP HANA account. You may need to edit the contents.

Account Attribute Generator Description

USER_NAME

Generator

The name of the user that needs to be created.

password

Generator

The password of the user.

FORCE_PWD_CHG_ON_NEXT_LOGON

Disable

Enable this attribute if the user must be requested to change their password at the next login.

IS_RESTRICTED

Disable

Enable this attribute to create a restricted user.

Additional Attributes

The SAP HANA Source supports the following additional attributes:

Account Attribute Generator Description

Disable Password

Static

Sets the password in 'disable' mode. By default, the value is false.

Email Address

Identity Attribute

The email address. It is mapped to the Work Email of the user.

Time Zone

Disabled

The time zone of the user.

Valid From

Disabled

The date/time from when the user account is valid.

Valid Until

Disabled

The date/time until when the user account is valid.

Supported Entitlement Attributes

The SAP HANA source supports the following entitlement attributes while creating or updating an account:

  • CATALOG_ROLES

  • REPOSITORY_ROLES

  • SYSTEM_PRIVILEGES

  • APPLICATION_PRIVILEGES

The SAP HANA source does not aggregate and display as CATALOG_ROLES. The roles are granted to a user in all the schema in the native HANA system (when the role exists in all the schema), however, it is granted to the user in one schema in the native HANA.