SAP Knowledge Base Article - Preview

3447239 - Role collection that is assigned to group of IAS doesn't take effect in BTP account

Symptom

  • Trust relationship established between SAP Business Technology Platform Cloud Foundry global account or subaccount and SAP Cloud Identity Authentication Service (IAS), with IAS acting as the Identity Provider (IdP).
  • Role collections are assigned to an IAS group instead of being assigned directly to individual users in the BTP cockpit.
  • Users belonging to the IAS group do not receive the expected role collections.
  • The role collection assignment to the IAS group does not take effect.

"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."


Read more...

Environment

  • SAP Business Technology Platform - Cloud Foundry environment
  • SAP Cloud Identity service

Product

BTP all versions ; SAP Cloud Identity Services all versions

Keywords

platform idp, role collection mapping, group mapping, role mapping, btp cockpit, reflect, not working, role assignment, custom idp, establish trust, group name , KBA , BC-CP-CF-SEC-IAM , UAA, Authentication, Authorization, Trust Mgmnt , BC-IAM-IDS , Identity Authentication Service , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.