SAP Knowledge Base Article - Public

3589982 - Error 403 and COE_GENERAL_FORBIDDEN when connecting EC to ECP via PTP in SAP SuccessFactors Platform

Symptom

While trying to upsert EmployeeDataReplicationConfirmation entity the following error is presented: COE_GENERAL_FORBIDDEN - [COE0020]No permission! You don’t have permission to view the user.

Cause

API user doesn't have all necessary permission to upsert EmployeeDataReplicationConfirmation object.

Resolution

Provide all permissions to the API user as per guide Granting Permissions for the Data Replication Monitor.

CategoryPermission
Under Administrator Permissions, select the Employee Central API category.Select the Employee Central Foundation OData API (read-only) permission.
Under Administrator Permissions, select the Metadata Framework category.Select the Access to non-secured objects permission.

This permission allows a user to access information provided by MDF objects (such as the Replication Target System) which are not set to secured when viewing data replication records in the Data Replication Monitor.

Under Administrator Permissions, select the Manage Integration Tools category.Select the following:
  • Access to Data Replication Monitor

    This permission allows a user to access the Data Replication Monitor.

  • Delete Records from Data Replication Monitor

    Grant this permission only if the user shall be able to delete entries from the Data Replication Monitor.

  • Mass Export from Data Replication Monitor

    Grant this permission only if the user shall be able to mass export entries from the Data Replication Monitor.

Under Administrator Permissions, select the Manage Hires category.

Select the Include Inactive Employees in the Search permission.

Under User Permissions, select the General User Permission category.Select the following:
  • Live Profile Access

    This permission allows a user to access the employee file from records in Data Replication Monitor.

  • Company Info Access  User Search

    This permission enables the user to use the Employee Search field of Data Replication Monitor.

Under User Permissions, select the Employee Data category.
Under Employment Details, select the View option for:
  • Employment Details MSS

  • Assignment Id External

Under HR Information, select the View option for the Biographical Information field.

Under Employee Profile, select select the View option for:
  • First Name

  • Last Name

  • Status

  • Display Name (if the General Display Name feature is active)

These settings are required to display the name information correctly.

Under User Permissions, select the Employee Central Effective Dated Entities category.

Under Job Information, select the View Current option for these fields:

  • Company
  • Country of Company
  • Location
  • Employee Class
  • Pay Group

Under Compensation Information, select the View Current option for the field:

  • Pay Group

These settings are required to ensure that the user can see all expected records when using the respective filter options.

If you have secured the Employee Data Replication Status (EmployeeDataReplicationElement) object in the object definition, you can choose the Permission Category, for example SAP System Configuration, which controls the category in the Permission Roles page. In the Permission Roles page, select the View and the Edit options to be able to reprocess and delete entries from the Data Replication Monitor.

If you have additionally secured one of the following objects in the object definition, you need to grant at least View permission to your Data Replication Monitor role:
  • Country/Region (Country)
  • Employee Data Replication Confirmation (EmployeeDataReplicationConfirmation)
  • Employee Data Replication Confirmation Error Message (EmployeeDataReplicationConfirmationErrorMessage)
  • Translations (GOLocalizedData)
  • Legal Entity (LegalEntity)
  • Picklist (PickList)
  • Picklist Value (PickListValue)
  • Replication Target System (ReplicationTargetSystem)

If you replicate time-related data, and if you have additionally secured the objects Data Replication Proxy Planned Working Time (DataReplicationProxyPlannedWorkingTime) and Data Replication Proxy (DataReplicationProxy) in the object definition, then you need to grant the Edit permission to your Data Replication Monitor role.

Keywords

SAP SuccessFactors Platform, EC, ECP, PTP, OData, Error 403, COE_GENERAL_FORBIDDEN, HTTP Request denied, No permission, REST query, HTTP status code 403, You don’t have permission to view the user, upsert, EmployeeDataReplicationConfirmation , KBA , LOD-SF-INT-DRM , Data Replication Monitor , LOD-SF-INT-ODATA , OData API Framework , Problem

Product

SAP SuccessFactors HCM Suite all versions