SAP Knowledge Base Article - Public

2186617 - Creating a New Super Admin User in SuccessFactors

Symptom

  • How to login to the SuccessFactors system as an admin user
  • How to reset a super admin user password
  • How to create an admin user from Provisioning
  • How to get initial admin user access for SuccessFactors

Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental.

Environment

SAP SuccessFactors HCM Suite

Resolution

Please be informed that SAP Technical Support does not have the ability to reset password for existing user accounts in SuccessFactors systems. This task falls under the scope of the administrator of the account, and has been highlighted in KBA 2345110 - Configuring Password Reset for the Login Page in SuccessFactors.

As described in the KBA 2517118 - SAP SuccessFactors New Instance/Re-activation request, Product Support is not responsible for providing new instance credentials. When the instance is first created, Email notifications with initial tenant access details are automatically sent to the company's IT Contact Person maintained in the contract.

[A] Creating a new super admin user from the SuccessFactors backend (Provisioning)

Steps to create a new super admin user in SuccessFactors: Creating a Super Admin User in Provisioning
Note: If the single recipient e-mail feature is enabled, the e-mail with the credentials will not be sent to the created user.

The above steps require access to SuccessFactors Provisioning. If you do not have any partner engaged with the required Provisioning access to perform these steps, please check section [B].

Additionally, if the SuccessFactors tenant is Identity Authentication Service (IAS) integrated, please check instructions in section [C].

Finally, to get access to all admin tools post SuccessFactors login with the newly created super admin user, please check section [D]. 

[B] Engaging Technical Support for super admin creation

Super Admin creation from Provisioning is performed by Technical Support when:

    • The initial email notification containing the System and access details is not received after the tenant is created, normally caused due to incorrect IT Contact details.
    • The initial IT Contact is not available to utilize their system access, and the access needs to be granted to a new contact.

How to engage support for this?

    1. Submit a support case under component LOD-SF-PLT-ADM.
    2. Include the required details:
      • E-mail address where the credentials will be sent to:
      • Company ID:
      • Data Center where the new user will be created:
      • Reason why a new admin user needs to be created:
      • Explicit written customer approval:
    3. Support will then create a Super Admin user and share the corresponding access details to the provided email address.

Same instructions as above apply to SAP Partners/Consultants without access to Provisioning. NotePlease add the customer approval and the reason why a new admin user needs to be created - it could be either via a customer updating the case or attach the approval email from customer to the case.

Additionally, if the SuccessFactors tenant is Identity Authentication Service (IAS) integrated, please check instructions in section [C].

Finally, to get access to all admin tools post SuccessFactors login with the newly created super admin user, please check section [D].

[C] Additional steps needed when the SuccessFactors tenant is Identity Authentication Service (IAS) integrated

In SuccessFactors tenants that are integrated with IAS, the above super admin creation alone will not be enough for login. With IAS enabled, an Admin user account needs to be created in the connected IAS tenant, matching the Username of the newly created SuccessFactors admin user in the IAS Login Name field.

  1. Access your IAS Admin Console
    • The URL is similar to https://<your-ias-tenant>.accounts.ondemand.com/admin. 
    • If there aren't admins available, check in https://iamtenants.accounts.cloud.sap by logging in with an S-user.

  2. Make the user Available in IAS by running the Read Job in Identity Provisioning Service (IPS) (recommended)

    1. In the IAS Admin Console, navigate to Identity Provisioning
    2. Go to Source Systems and select your SuccessFactors source system
    3. Navigate to Jobs > Read Job
    4. Click Run Job to execute a delta sync and load the new user into IAS

    Note: The Read Job performs a delta sync (changed records only). If this is the first sync or it does not pick up the user, consider running a Resync Job for a full sync instead. For more details, refer to KBA 3079849 — Using IPS to run sync jobs.

  3. Set the Password for the User in IAS

    1. In the IAS Admin Console, navigate to User Management
    2. Search for and select the newly created user
    3. Under Authentication, select Set Initial Password
    4. Define a password and communicate it securely to the user

Note: If you’re using a third-party IdP integrated with IAS, make sure to add the user there as well. Otherwise, you’ll need to temporarily disable SSO so the newly created user can sign in.

[D] How to get access to SuccessFactors admin tools post login?

The super admin user created in SuccessFactors will not have access to all admin tools by default. 

Upon logging in, the first step would be to add the user to the "Manage RBP Admin Access" page and you can enable the following permissions: View Group, View Role, Edit Group, and Edit Role. A detailed guide on this can be found in 

Post above steps, the added user will have the access to use the four features below:

    • Manage Permission Groups
    • Manage Permission Roles
    • User Role Search
    • RBP Troubleshooting

With access to these features, the user can create permission groups and permission roles.

For more information and guidance, you may also check out
KBA 2855466 - What are the actions to perform when a new Super Admin was provided by Support Team

Important Notes:

What Changed in the 1H26 Release: Previously combined into one tool, Manage RBP Admin Access and Manage Super Admin Access have now been split into two separate tools.

  • Manage RBP Admin Access: To access the RBP tools (e.g., Manage Permission Roles, Manage Permission Groups), locate the newly created super admin user in Manage RBP Admin Access. Refer to Help Guide - Managing RBP Admin Access for more details.
  • Manage Super Admin Access: This self-service tool that allows administrators to manage Super Admin access for both Learning and Platform from a single unified page. Refer to KBA 3730679 - [1H 2026] Manage Super Admin Access for more details. 

See Also

  • KBA 2855466 - What are the actions to perform when a new Super Admin was provided by Support Team
  • KBA 2345110 - Configuring Password Reset for the Login Page in SuccessFactors
  • KBA 2517118 - SAP SuccessFactors New Instance/Re-activation request 
  • KBA 2344584 - How to add access to Role-Based Permission Admin features
  • KBA 3730679 - [1H 2026] Manage Super Admin Access
  • KBA 3646482 - What is the difference between SuccessFactors Super Administrator (SF-HCM) and SuccessFactors Cloud Administrator (SAP for Me)?
  • KBA 2674362 - People/Action Search Box Not Showing or Showing Just Search SAP Jam
  • KBA 2701509 - How to enable OR disable Admin Center
  • Help Guide - Managing Instance Access: Super Administrators
  • Help Guide - Managing RBP Admin Access

Keywords

sf, administrator, admin permissions, new user, all access, provisioning, super, admin, SuccessFactors, sf, sfsf , sf sf, SuccessFactors, bizx, superuser, super admin, admin user, sfadmin, adminsf , KBA , LOD-SF-PLT-ADM , Admin user creation , How To

Product

SAP SuccessFactors HCM Suite 2605