Symptom
- Trust relationship established between SAP Business Technology Platform Cloud Foundry global account or subaccount and SAP Cloud Identity Authentication Service (IAS), with IAS acting as the Identity Provider (IdP).
- Role collections are assigned to an IAS group instead of being assigned directly to individual users in the BTP cockpit.
- Users belonging to the IAS group do not receive the expected role collections.
- The role collection assignment to the IAS group does not take effect.
"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."
Read more...
Environment
- SAP Business Technology Platform - Cloud Foundry environment
- SAP Cloud Identity service
Product
BTP all versions ; SAP Cloud Identity Services all versions
Keywords
platform idp, role collection mapping, group mapping, role mapping, btp cockpit, reflect, not working, role assignment, custom idp, establish trust, group name , KBA , BC-CP-CF-SEC-IAM , UAA, Authentication, Authorization, Trust Mgmnt , BC-IAM-IDS , Identity Authentication Service , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview