Symptom
- How to login to the SuccessFactors system as an admin user
- How to reset a super admin user password
- How to create an admin user from Provisioning
- How to get initial admin user access for SuccessFactors
Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental.
Environment
SAP SuccessFactors HCM Suite
Resolution
Please be informed that SAP Technical Support does not have the ability to reset password for existing user accounts in SuccessFactors systems. This task falls under the scope of the administrator of the account, and has been highlighted in KBA 2345110 - Configuring Password Reset for the Login Page in SuccessFactors.
As described in the KBA 2517118 - SAP SuccessFactors New Instance/Re-activation request, Product Support is not responsible for providing new instance credentials. When the instance is first created, Email notifications with initial tenant access details are automatically sent to the company's IT Contact Person maintained in the contract.
[A] Creating a new super admin user from the SuccessFactors backend (Provisioning)
Steps to create a new super admin user in SuccessFactors: Creating a Super Admin User in Provisioning
Note: If the single recipient e-mail feature is enabled, the e-mail with the credentials will not be sent to the created user.
The above steps require access to SuccessFactors Provisioning. If you do not have any partner engaged with the required Provisioning access to perform these steps, please check section [B].
Additionally, if the SuccessFactors tenant is Identity Authentication Service (IAS) integrated, please check instructions in section [C].
Finally, to get access to all admin tools post SuccessFactors login with the newly created super admin user, please check section [D].
[B] Engaging Technical Support for super admin creation
Super Admin creation from Provisioning is performed by Technical Support when:
-
- The initial email notification containing the System and access details is not received after the tenant is created, normally caused due to incorrect IT Contact details.
- The initial IT Contact is not available to utilize their system access, and the access needs to be granted to a new contact.
How to engage support for this?
-
- Submit a support case under component LOD-SF-PLT-ADM.
- Include the required details:
- E-mail address where the credentials will be sent to:
- Company ID:
- Data Center where the new user will be created:
- Reason why a new admin user needs to be created:
- Explicit written customer approval:
- Support will then create a Super Admin user and share the corresponding access details to the provided email address.
Same instructions as above apply to SAP Partners/Consultants without access to Provisioning. Note: Please add the customer approval and the reason why a new admin user needs to be created - it could be either via a customer updating the case or attach the approval email from customer to the case.
Additionally, if the SuccessFactors tenant is Identity Authentication Service (IAS) integrated, please check instructions in section [C].
Finally, to get access to all admin tools post SuccessFactors login with the newly created super admin user, please check section [D].
[C] Additional steps needed when the SuccessFactors tenant is Identity Authentication Service (IAS) integrated
In SuccessFactors tenants that are integrated with IAS, the above super admin creation alone will not be enough for login. With IAS enabled, an Admin user account needs to be created in the connected IAS tenant, matching the Username of the newly created SuccessFactors admin user in the IAS Login Name field.
- Access your IAS Admin Console
- The URL is similar to https://<your-ias-tenant>.accounts.ondemand.com/admin.
- If there aren't admins available, check in https://iamtenants.accounts.cloud.sap by logging in with an S-user.
- Make the user Available in IAS by running the Read Job in Identity Provisioning Service (IPS) (recommended)
- In the IAS Admin Console, navigate to Identity Provisioning
- Go to Source Systems and select your SuccessFactors source system
- Navigate to Jobs > Read Job
- Click Run Job to execute a delta sync and load the new user into IAS
Note: The Read Job performs a delta sync (changed records only). If this is the first sync or it does not pick up the user, consider running a Resync Job for a full sync instead. For more details, refer to KBA 3079849 — Using IPS to run sync jobs.
-
Set the Password for the User in IAS
- In the IAS Admin Console, navigate to User Management
- Search for and select the newly created user
- Under Authentication, select Set Initial Password
- Define a password and communicate it securely to the user
Note: If you’re using a third-party IdP integrated with IAS, make sure to add the user there as well. Otherwise, you’ll need to temporarily disable SSO so the newly created user can sign in.
[D] How to get access to SuccessFactors admin tools post login?
The super admin user created in SuccessFactors will not have access to all admin tools by default.
Upon logging in, the first step would be to add the user to the "Manage RBP Admin Access" page and you can enable the following permissions: View Group, View Role, Edit Group, and Edit Role. A detailed guide on this can be found in
Post above steps, the added user will have the access to use the four features below:
-
- Manage Permission Groups
- Manage Permission Roles
- User Role Search
- RBP Troubleshooting
With access to these features, the user can create permission groups and permission roles.
For more information and guidance, you may also check out KBA 2855466 - What are the actions to perform when a new Super Admin was provided by Support Team
Important Notes:
What Changed in the 1H26 Release: Previously combined into one tool, Manage RBP Admin Access and Manage Super Admin Access have now been split into two separate tools.
- Manage RBP Admin Access: To access the RBP tools (e.g., Manage Permission Roles, Manage Permission Groups), locate the newly created super admin user in Manage RBP Admin Access. Refer to Help Guide - Managing RBP Admin Access for more details.
- Manage Super Admin Access: This self-service tool that allows administrators to manage Super Admin access for both Learning and Platform from a single unified page. Refer to KBA 3730679 - [1H 2026] Manage Super Admin Access for more details.
See Also
- KBA 2855466 - What are the actions to perform when a new Super Admin was provided by Support Team
- KBA 2345110 - Configuring Password Reset for the Login Page in SuccessFactors
- KBA 2517118 - SAP SuccessFactors New Instance/Re-activation request
- KBA 2344584 - How to add access to Role-Based Permission Admin features
- KBA 3730679 - [1H 2026] Manage Super Admin Access
- KBA 3646482 - What is the difference between SuccessFactors Super Administrator (SF-HCM) and SuccessFactors Cloud Administrator (SAP for Me)?
- KBA 2674362 - People/Action Search Box Not Showing or Showing Just Search SAP Jam
- KBA 2701509 - How to enable OR disable Admin Center
- Help Guide - Managing Instance Access: Super Administrators
- Help Guide - Managing RBP Admin Access
Keywords
sf, administrator, admin permissions, new user, all access, provisioning, super, admin, SuccessFactors, sf, sfsf , sf sf, SuccessFactors, bizx, superuser, super admin, admin user, sfadmin, adminsf , KBA , LOD-SF-PLT-ADM , Admin user creation , How To
SAP Knowledge Base Article - Public