SAP Knowledge Base Article - Public

2806979 - Communication Arrangement / API User Locked - Error 401

Symptom

Communication Arrangements not working and returning error 401: Not Authorized.

Environment

S/4HANA Public Cloud Systems using Communication arrangements integrating with API's or any other interfaces.

Cause

Communication user is locked due to 3 or more failed attempts.

Resolution

If your user is locked due to unknown circumstances this would cause any communication scenario to fail and not work properly. To correct it would be required to unlock communication user and need to follow below mentioned procedure.

Pre-requistes before performing procedure would be to have SAP_BCR_CORE_IAM role assigned to your user. Please ask admin user in your organization to create a custom role from this standard role and assign it to your user.

Once pre-requisite is completed  you need to perform below actions:

  1. Login to your S/4HANA Public Cloud system URL with your credentials. Example - https://myXXXXXX.s4hana.ondemand.com/
  2. Open application Maintain Communication Users.
  3. Search for technical user maintained in your communication scenario by either providing User Name or User ID.
  4. Select that particular user by selecting check box on left side of User Name.
  5. You would see Unlock icon enabled and not greyed out on bottom right side of your screen. If your user is not locked then this icon would be greyed out.
  6. Click on Unlock button to enable communication user again.

Test communication scenario / API integration again to confirm user is unlocked and working fine.

The default configuration for communication user is 5 failed attempts before it is locked. But to enhance security policy in public cloud environment this value is reduced to 3 failed attempts. This value cannot be changed by customers directly from frontend URL as it is maintained in backend application server profile parameter. This value is valid for complete landscape of S/4HANA Public Cloud Landscape so it cannot be modified even by S4HANA Cloud Operation team for a specific system.

Note: Default setting for failed login attempts of technical user's is 3 (Cannot be changed).

See Also

https://help.sap.com/saphelp_nwmobile71/helpdata/en/43/e3589a7c484d9be10000000a155369/content.htm?no_cache=true

Keywords

Communication Arrangement, Communication User, Locked, Failed attempts, API Interface, 401 Unauthorized, S/4HANA Cloud, Technical User, Role, Login , KBA , XX-S4C-OPR-INC , S/4HANA Cloud Availability, Performance and Administration , Problem

Product

SAP S/4HANA Cloud Public Edition all versions ; SAP S/4HANA Cloud all versions