SAP Knowledge Base Article - Public

2944990 - IAS Upgrade error when validating S-User credentials

Symptom

  • Receiving "Invalid S-User. Enter the correct S-User for this company" error message when entering S-user credentials for IAS upgrade
  • Unable to complete "Initiate SuccessFactors SAP Cloud Platform Identity Authentication Service Integration" due to error with S-user
  • Receiving "Invalid username/password" error message when entering S-user credentials for IAS upgrade
  • When attempting to carry out the first IAS related upgrade in Upgrade Center, the below warning is experienced by customer: "We are unable to validate your customer credentials at this time and proceed with the Upgrade to SAP Cloud Identity Authentication Service. Please contact support to report the issue."
  • Error of invalid S-user for a valid S-User, however it is associated with the ERP Customer ID and not with the CRM Customer ID

Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental. 

Environment

  • SAP SuccessFactors HCM Suite
  • SAP Cloud Platform Identity Authentication Service

Reproducing the Issue

  1. Navigate to Upgrade Center
  2. Select "Initiate SuccessFactors Identity Authentication Service Integration"
  3. Pop-up window will appear asking for S-user credentials > enter S-User credentials
  4. Click on "Validate"
  5. Any of the below errors appear:
    • Invalid S-User. Enter the correct S-User for this company
    • Invalid username/password
    • We are unable to validate your customer credentials at this time

Cause

  1. Error "Invalid S-User. Enter the correct S-User for this company" appears if the S-user ID being entered is not tied to the ERP customer number that the BizX system belongs to.
  2. Error "We are unable to validate your customer credentials at this time and proceed with the Upgrade to SAP Cloud Identity Authentication Service. Please contact support to report the issue" is related to a validation recently implemented in SuccessFactors. It's expected for it to be shown when the respective database table — crm_customer_id — don't have the Customer CRM ID information populated.
  3. Error "Invalid username/password" indicates incorrect credentials.

Resolution

Please refer to the information below to identify and address issues related to your S-user ID, depending on the error message received.

Invalid S-User. Enter the correct S-User for this company

This error may occur when the S-user ID is not correctly associated with the customer number that owns the system on which the upgrade is being performed.

To resolve the issue, ensure the following:

  1. The S-user ID is associated with the customer number that owns the system on which the upgrade is being performed.
  2. The S-user ID is associated with the CRM customer ID.
  3. If the S-user ID does not exist or is associated only with an ERP customer ID, request that a new S-user ID be created and associated with the appropriate CRM customer ID.

You can check this in SAP4ME page, if the if your S-User is associated with the customer ID. (This detail must be provided as soon as a ticket is raised to product support)

Sometimes, the account is tied to a Corporate Group Function (CCC) and the user will end up being able to execute functions (for example, report an case , request SSCR keys, and so on) only for the ERP customer number they were assigned to.

To learn more about Corporate Group (CCC) function, check the KBA 2632518 - Information about the SAP Corporate Group (CCC) function

Please note that the SAP Customer Contact/CSP can help informing the S-user that has the administrator role to run the upgrade.

S-user has Universal ID

If your S-user has Universal ID, a potential cause is that the Universal ID password for that S-user ID being used is actually different from SAP IDS password. Therefore, our recommendation would be for the below steps to be followed:

  1. Go to https://accounts.sap.com/
  2. If it requests you to change the password, change it, log out and login to the instance, and try to trigger the upgrade again with the new password
  3. If not: Enter the S-User Id and Password in that page, and login. If the login works, try the exact same Id and Password in the IAS upgrade and then update us.
  4. If the login does not work, use the Forgot Password option to trigger a password reset email, reset password, go back to https://accounts.sap.com and again try the login with the S-user id and new password
  5. if the login works, try the exact same Id and Password in the upgrade and then update us

Note: Universal ID is for "accounts.sap.com" login itself, but the password management might be different internally, leading to the issues with the upgrade. Please proceed with the above and let us know the outcome.

Invalid username/password

  1. Make sure the password being entered is the correct one. In case the password is not being accepted, test resetting the password, as per the KBA 1808560 - How to reset an S-user ID password - SAP for Me 
  2. Important: If your SAP IDS account has Two-Factors Authentication (TFA) enabled then in that password has to be concatenated the IDS password and the current TFA code.
    For example, if the password is “Welc@me1” and the generated valid TFA code is “987345” – it should be provided as a password in SF Upgrade form: “Welc@me1987345
  3. If both the above are correct, and still the error appears while running the upgrades, please submit a support ticket to LOD-SF-PLT-IAS component including a Network Trace for the validation error replication scenario. KBA on how to capture a network trace->KBA 2760505 - How to Generate Network trace and Console Logs in Chrome, IE and Firefox - SAP SuccessFactors
  4. Please make sure the S-user has been granted Cloud Administrator in SAP for Me as per KBA 1282821 - How to determine if my S-user ID is a Super Administrator, Cloud Administrator, or User Administrator - SAP for Me - SAP for Me and KBA 2596214 - How to maintain Super, Cloud, and User Administrator S-user IDs listed in My Important Contacts - SAP for Me - SAP for Me

Please ensure that the installation selected is SuccessFactors (SFSF), as highlighted in the screenshot below.

 
In case of any question or issue, please create a case for XX-SER-FORME. If there is no user who can create a case, please contact SAP Customer Interaction Center(CIC) according to KBA 560499 - Customer Interaction Center: Hotline - Email - Chat - SAP for Me.

This upgrade process does not work for Sales Demos at present. Paid Sales Demos are created with pre-integrated IAS & IPS

Notes for Support: Please check the Internal Memo section of the KBA for troubleshooting guidance and identifying the scenario from application logs. 

If all the above details are correct, create a case with the IAS Team using component LOD-SF-PLT-IAS, and include the Company ID and IAS Instance URL in the case description.

See Also

  • KBA 2843423 - IAS via Upgrade Center | No tenants created nor credentials email received after running the "Create/Initiate [...]" task
  • KBA 2791410 - Integrating SuccessFactors with SAP Cloud Identity Authentication Through the Upgrade Center
  • KBA 1282821 - How to determine if my S-user ID is a Super Administrator, Cloud Administrator, or User Administrator - SAP for Me 
  • KBA 2596214 - How to maintain Super, Cloud, and User Administrator S-user IDs listed in My Important Contacts - SAP for Me 

Keywords

S-user error, upgrade IAS error, IAS initiate issues, upgrade, upgrade center, s user, validation, validate, patch, IAS initiate error, We are unable to validate your customer credentials at this time and proceed with the Upgrade to SAP Cloud Identity Authentication Service. Please contact support to report the issue, Invalid S-User. Enter the correct S-User for this company , KBA , LOD-SF-PLT-IAS , Identity Authentication Services (IAS) With BizX , How To

Product

SAP SuccessFactors HCM Suite 2605

Attachments

Pasted image.png
Pasted image.png
Pasted image.png
Pasted image.png