Symptom
When upgrading Onboarding external user authentication from Basic Authentication to IAS using the SCIM connector, IAS creates accounts for all matching active onboardees during the first IPS sync job run. By default, each newly created IAS account triggers an account activation email sent to the onboardee.
This article explains on how to manage activation email behavior for existing active onboardees who already have credentials set in SAP SuccessFactors before the migration, and on the supported self-service options available to those users for setting IAS credentials after the sync.
Environment
SAP SuccessFactors Onboarding
Resolution
Two approaches are available for organizations that need to prevent unsolicited activation emails from being sent to existing active onboardees during migration cutover. Both approaches apply specifically to onboardees who already have a password set in SAP SuccessFactors before the upgrade to SCIM. The choice between them depends on whether password continuity is required.
Option 1: Password Migration.
Password migration transfers existing SAP SuccessFactors passwords to IAS before the sync runs. Existing onboardees can log in with their current credentials after cutover without needing to set a new password or receive any email notification.
- Configure the authentication provider in the IAS Administration Console to enable password migration from SAP SuccessFactors. See Help Portal Migrating Passwords from SAP SuccessFactors to Identity Authentication in SAP Cloud Identity Services | SAP Help Portal
- Run a full IPS sync job from IPS Administration > Source Systems > [SF Source System] > Jobs.
NOTE: Password migration is completed on first login. On their first access attempt after the migration, IAS validates the user's SAP SuccessFactors password and migrates it to IAS transparently.
Option 2: Temporary Deactivation of the Activation Email Template
If password migration is not feasible, the IAS Account Activation email template can be temporarily deactivated before running the sync. IAS accounts are created for existing onboardees without triggering activation emails. After the sync completes, the template is re-enabled for new hires going forward. Existing onboardees then use the Forgot Password option on the IAS login page to set their IAS password when they first attempt to access the system.
NOTE: Each affected onboardee must have a valid personal email address registered in the Onboarding process for the Forgot Password flow to work. Verify email addresses are populated before proceeding.
- In the IAS Administration Console, navigate to Email Template Sets and deactivate the IAS Account Activation email template for the Onboarding application. See Help Portal Configuring Activation Email Template in Identity Authentication | SAP Help Portal.
- Run a full IPS sync job from IPS Administration > Source Systems > [SF Source System] > Jobs. IAS accounts are created for all matching active onboardees without triggering activation emails.
- After the sync job completes, re-activate the IAS Account Activation email template in the IAS Administration Console so that new onboardees created going forward continue to receive the standard activation email.
- Communicate to existing onboardees that when they access the Onboarding portal after cutover, they will be redirected to the IAS login page. They must select Forgot Password on the IAS login page to receive a password setup link at their registered email address.
After applying either approach, existing onboardees can access the Onboarding portal using their IAS credentials without having received an unsolicited activation email. New onboardees created after the cutover will continue to receive the standard IAS activation email. If an onboardee cannot complete the Forgot Password flow, verify that a valid personal email address is registered for that user in the Onboarding process.
See Also
- Setting up SAP Identity Authentication for New Hires Using System for Cross-domain Identity Management (SCIM) API | SAP Help Portal
- Configuring Activation Email Template in Identity Authentication | SAP Help Portal
- Migrating Passwords from SAP SuccessFactors to Identity Authentication in SAP Cloud Identity Services | SAP Help Portal
- Handling Customer Migration Scenarios in Identity Authentication | SAP Help Portal
- 3204536 - How to Setup up Identity Authentication Service (IAS) for Onboarding External Users – Onboarding - SAP for Me
- 3281873 - [Onboarding] IAS Main KBA - SAP for Me
Keywords
SAP SuccessFactors Onboarding, OBX, ONB, IAS, Identity Authentication, IPS, Identity Provisioning, onboardee, activation email, account activation, Forgot Password, migration, cutover, Basic Authentication, SCIM, existing users, password migration, email template, IAS Account Activation , KBA , LOD-SF-OBX-IAS , IAS User Authentication , How To
SAP Knowledge Base Article - Public