Symptom
-
Documents sent from SAP Ariba to SAP S/4HANA Cloud (such as Central RFQ Confirmation, Purchase Orders, or Goods Receipts) are failing.
-
In the Transaction Tracker on SAP Integration Suite, managed gateway for spend management and SAP Business Network (formerly CIG), the transaction status is FAILED.
-
The error log displays the following details: "S4 system response is FAILED and ErrorCode:401 and ErrorResponse: .. Suggested Action: Document failed to deliver to S4HANA System. ErrorCode: CIG-PLT-00649."
-
The issue may occur for various document types, including but not limited to Central RFQ Confirmation.
"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental"
Environment
SAP S/4HANA Cloud Public Edition
Reproducing the Issue
-
Trigger an Inbound Document from Ariba:
-
Perform a standard business action in SAP Ariba that triggers a message to SAP S/4HANA Cloud.
-
-
Monitor Integration Status:
-
Log in to SAP Integration Suite, managed gateway for spend management and SAP Business Network (formerly CIG).
-
Navigate to the Transaction Tracker.
-
Search for the document ID or filter by the Timestamp of the action performed in Step 1.
-
-
Verify Failure:
-
Observe that the transaction status is FAILED.
-
Click on the Error Link or view the Exchanged Document logs.
-
Confirm the error message in the response payload or log details:"S4 system response is FAILED and ErrorCode:401 and ErrorResponse: .. Suggested Action: Document failed to deliver to S4HANA System. ErrorCode: CIG-PLT-00649."
-
Cause
The issue is caused by an authentication failure for the Inbound Communication User configured in SAP S/4HANA Cloud. The password maintained in the CIG connection project does not match the current password of the Communication User in the S/4HANA system (e.g., the password may have expired, been locked, or changed without updating CIG).
Resolution
To resolve the 401 Unauthorized error, you must synchronize the credentials between S/4HANA Cloud and the Managed Gateway (CIG). Follow these steps:
-
Identify the Communication User in S/4HANA Cloud:
-
Log in to your SAP S/4HANA Cloud system.
-
Navigate to the Communication Systems app.
-
Search for the Communication System ID associated with your Ariba integration.
-
Open the system and check the Users for Inbound Communication section to identify the User Name.
-
-
Reset the Password:
-
Navigate to the Maintain Communication Users app.
-
Search for the user identified in Step 1.
-
Select the user and click Change Password.
-
Set a new, complex password and save your changes.
-
-
Update Credentials in CIG (Managed Gateway):
-
Log in to the SAP Integration Suite, managed gateway portal.
-
Go to My Projects and open the relevant integration project.
-
Navigate to the Connections step.
-
Locate the connection for your S/4HANA Cloud system.
-
Update the Password field with the new password you just set in Step 2.
-
Save the changes and deploy the project if necessary (depending on your specific project setup, a connection update might apply immediately, but a redeployment ensures config sync).
-
Keywords
401 error, authorization error, CIG to S/4HANA, Central RFQ Confirmation, CIG-PLT-00649, failed confirmation transaction, inbound communication user, password reset, SAP Ariba Sourcing, SAP Integration Suite, managed gateway for spend management and SAP Business Network, Public Cloud, S/4HANA , KBA , MM-PUR-GF-EDI-2CL , Electronic Data Interchange (Public Cloud) , Problem
SAP Knowledge Base Article - Public