SAP Knowledge Base Article - Public

3347863 - User provisioning from IAG failing in SAP Analytics Cloud (SAC)

Symptom

While trying to provision the users in SAC (SAP Analytics Cloud) from IAG (SAP Cloud Identity Access Governance) errors are raised.

Environment

SAP Analytics Cloud 1.0
SAP Cloud Identity Access Governance 2.0

Cause

 Wrong mapping between IAG and SAC SAML user attributes.

Resolution

SAC is case sensitive so e-mails or users like User1@adm.com do not match user1@adm.com, for example.
Also, SAML Mapping setting is a system level configuration set in SAC Security with specific authorization checks.

To check how exactly the mappings are being exchanged between SAC and the IdP (IAG or others), follow KBA 2487567 - Troubleshooting SAML assertions when configuring SAML SSO in SAP Analytics Cloud (SAC)

See Also

2656152 - How to use "Custom SAML User Mapping" option in SAP Analytics Cloud when enabling Single Sign On (SSO)

2954109 - Cannot specify userID when programmatically creating via User-Provisioning API in SAP Analytics Cloud based on SAML SSO & Custom IDP (SAC)

Enable a Custom SAML Identity Provider (SAP Help)

Keywords

email, e-mail, user attribute mapping, write transformation, json , KBA , GRC-IAG , SAP Cloud Identity Access Governance , XX-SER-MCC , Mission Control Center - Knowledge Management , LOD-ANA-ADM , SAC Administration , How To

Product

SAP Analytics Cloud 1.0