SAP Knowledge Base Article - Public

3325687 - Automatic user provisioning does not work anymore after implement user provisioning to enable automatic user provisioning from Azure AD into the SAP Analytics Cloud (SAC)

Symptom

Provisioning switches to "quarantining mode" after one hour and does not work anymore after implement user provisioning to enable automatic user provisioning from Azure AD into the SAC

Environment

  • SAP Analytics Cloud (Enterprise) 

Reproducing the Issue

  1. Follow below documentation to implement user provisioning to enable automatic user provisioning from Azure AD into the SAC.

  2. The first hour the user provisioning works, but as the generated token expires after 1 hour, the provisioning switches to "quarantining mode" and does not work anymore.
  3. The following error occurred when adding users automatically.
    => Error (Microsoft):
    We've detected an error while synchronizing to SAC

    While attempting to validate our authorization to access your application, we received this unexpected response: Value cannot be null. Parameter name: values Please check the service.

Cause

This is by design behavior.

Resolution

The oAuth service that SAC provides is fully compliant and feature complete, and follows the industry standard defined here: https://tools.ietf.org/html/rfc6749.

Token life time: the token obtained through client credential grant is meant to be short lived. Long living tokens potentially could expose customer's workflow to security threats if the token somehow lands in the hands of a malicious user. The 60 minute expiry time of the token is to protect the workflows from such treats.

See Also

Your feedback is important to help us improve our knowledge base.

Keywords

SAP Cloud for Planning, sc4p, c4p, cforp, cloudforplanning, Cloud for Analytics, Cloud4Analytics, CloudforAnalytics, Cloud 4 Planning, BOC, SAPBusinessObjectsCloud, BusinessObjectsCloud, BOBJcloud, BOCloud., SAC, SAP AC, Cloud-Analytics, CloudAnalytics, SAPCloudAnalytics,Error, Issue, System, Data, User, Unable, Access, Connection, Sac, Connector, Live, Acquisition, Up, Set, setup, Model, BW, Connect, Story, Tenant, Import, Failed, Using, Working, SAML, SSO, sapanalyticscloud, sap analytical cloud, sap analytical cloud, SAC, sap analyst cloud, connected, failure, stopped, sap analyst cloud , KBA , LOD-ANA-ADM , SAC Administration , Problem

Product

SAP Analytics Cloud 1.0