SAP Knowledge Base Article - Preview

3220053 - Shadow user remains in BTP CF subaccount after user get deleted from Identity Provider


Within BTP Cloud Foundry (CF) subaccount, XSUAA is configured to use external Identity Provider other than SAP ID Service, such as Identity Authentication Service (IAS) or AzureAD...etc. Notice shadow user not get deleted automatically when delete user from Identity Provider side. However due to data privacy, need to delete such inactive user from CF subaccount.



  • SAP BTP Cloud Foundry (CF)
  • SAP Identity Authentication Service (IAS)
  • SAP Identity Provisioning Service (IPS)


SAP BTP, Neo environment 1.0


user deletion, user update, attribute, change, left, leave, company, name, mail, id, security, kept, period, inactivity, automatically , KBA , BC-CP-CF-SEC-IAM , UAA, Authentication, Authorization, Trust Mgmnt , BC-IAM-IDS , Identity Authentication Service , BC-IAM-IPS , Identity Provisioning Service (IPS) , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.