SAP Knowledge Base Article - Public

3248892 - "A new Learning-only user could not be created" - Learning IAS Real Time User Sync

Symptom

An error is received either before or after IAS activation when enableRealtimeUserSync=true:

  • A new Learning-only user could not be created. Please verify the values from System Administration > Configuration > System Configuration > SAP CLOUD IDENTITY SERVICES > Identity Provisioning section and try again.

Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental.

Environment

SAP SuccessFactors Learning

Reproducing the Issue

Before IAS Activation

  • Learning Administration > System Administration > Security > Activate Identity Authentication Integration > error message when clicking “Test Now” in Step 4 of “Test Real-time User Creation”

After IAS Activation

  • Learning Administration > System Administration > Configuration > System Configuration > SAP CLOUD IDENTITY SERVICES > error message when setting enableRealtimeUserSync=true and clicking Apply Changes.

Cause

There are five possible reasons:

  1. SAC Provisioning Indirectly includes LMS as a source system: In IPS, if the SAC target system is set to “Target system will read entities from all enabled source systems”, it will include LMS. However, provisioning Learning-only users in People Analytics is not supported.
  2. Tech User password for LMS, IAS and IPS are not equal: The tech user password must be the same in LMS, IAS and IPS. If any of these have been changed after provisioning then they all need to be reset to match. The Tech User password needs to be configured in Learning due to API purposes, so when IAS and IPS call LMS, they must have the correct password configured in Learning.
  3. IAS Test User from Previous Attempt is Blocking Activation: If a previous failed attempted has happened to enable real time user sync, then the "ias_test_user_27F5AAEA" user may have been created. Retrying the enablement of real time sync with this user in IAS will continue to make the job fail.
  4. The Learning IPS-mTLS Certificate may have expired: Uploading the renewed LMS mTLS certificate is required to use/enable real time user sync.
  5. Missing permissions on the technical user of the IAS system.

Resolution

Please see above for the five different causes to identify the proper solution that needs to be followed.

  • SAC Provisioning Indirectly includes LMS as a source system:
    1. In Identity Provisioning, navigate to Target Systems > Select SAC > Details tab > Change SAC source system to “SuccessFactors”.
  • Tech User password for LMS, IAS and IPS are not equal.
    1. To resolve this, set the password to the same value across all three systems:
      1. For IAS:
        1. If using NEO Admin: Navigate to Identity Provisioning > Source Systems > Learning (usually named LMS – tenantID). In the Technical User section, change the Technical User Secret (password) to the new password.
        2. If using Converged Admin: Go to SAP LMS - tenantID. Under Secret, if none is listed, create one using the Add button. Provide a description and copy the secret given on the next screen for use in the following steps.
      2. For IPS:
        1. Navigate to Source Systems > select Learning Source system > Properties tab > Modify the Password Property to the new Password.
      3. For Learning:
        1. Learning Administration > Configuration > System Configuration > SAP CLOUD IDENTITY SERVICES > update the "techUserPassword" with the new password. Note that after saving, the password entered from the IAS secret will be hashed/masked.
  • IAS Test User from Previous Attempt is Blocking Activation.
    1. Navigate to IAS > Users & Authorizations > User Management > Search for “ias_test_user_27F5AAEA” > Select and delete the user > Set ‘enableRealtimeUserSync’ to ‘true’ again.
  • The Learning IPS-mTLS Certificate may have expired.
    1. Navigate to the Identity Provisioning admin console and use the "Learning IPS - mTLS Certificate Expiration" KBA (3247849) to check if your LMS source system inbound certificate is expired. Example:
    2. If the certificate has expired, use the KBA above to upload the renewed LMS mTLS certificate and then attempt to enable real time user sync again.
  • Missing permissions on the technical user of the IAS system.

See Also

Keywords

IAS, IPS, LMS, Learning, User, fail, real, time, sync, failure, not, working, activation, enableRealtimeUserSync, source, system, Learning-only, ias_test_user_27F5AAEA , KBA , LOD-SF-LMS-IAS , LMS IAS Integration for External User , Problem

Product

SAP SuccessFactors Learning all versions