SAP Knowledge Base Article - Public

3782495 - IAM Role Migration Wizard - Developer Extensibility Migration - SAP S/4HANA Cloud Public Edition 2608

Symptom

  • Custom IAM apps created in the context of Developer Extensibility are not displayed in the IAM App tab in the Maintain Business Roles application when attempting to assign specific apps to a business role.
  • When the custom business catalog is assigned to a business role, users can access all apps in the catalog, but it is not possible to assign individual IAM apps to a business role.

Environment

SAP S/4HANA Cloud Public Edition 2608

Reproducing the Issue

  1. Create custom IAM apps in Developer Extensibility.
  2. Create a IAM Business Catalog and assign the custom IAM App.
  3. Assign the IAM Business Catalog to a business role.
  4. Open the Maintain Business Roles application and try to activate/deactivate the IAM App in na Business Role.
  5. Observe that the IAM App cannot be deactivated and it does not appear listed in the IAM Apps tab from the Maintain Business Roles application.

Resolution

As of release 2608, you can start preparing the migration from classical business roles to IAM roles using the new Migrate function in the Maintain Business Roles app.

The IAM Role Migration Wizard is now available and provides an overview of the migration concept along with readiness checks for business roles and their related objects. The wizard helps you identify required preparation steps but doesn't yet support running the full migration.

      

IAM Roles

IAM roles are a new role concept that replaces business roles with improved performance and scalability through simplified design and modern frameworks. Use IAM roles to manage larger numbers of roles and more complex role definitions while migrating existing business roles during the transition period.

General Information

The IAM role is a new role concept that gradually replaces the business role. Its simplified design and use of modern frameworks improve performance and scalability, supporting a larger number of roles and more complex role definitions.

Business roles and IAM roles coexist for several releases during the transition period. Over time, the system deprecates and eventually removes business roles. Therefore, migrate all existing business roles to the new IAM role concept during the transition phase.

IAM Role Features and Migration Details

  • After you migrate a business role, the original business role remains available to ensure reliability and backward compatibility. However, use IAM roles for all future role maintenance activities.
  • To increase transparency and control, the system doesn't update IAM roles automatically during upgrades or transport imports. You must apply any required changes manually.
  • Transporting IAM roles is faster and more stable because you can't modify IAM roles directly in target systems. You maintain all changes exclusively in the development system.
  • You can migrate a business role to an IAM role. However, the system doesn't synchronize changes you make later in the IAM role back to the original business role.
  • IAM role authorizations are based on authorization objects and authorization fields rather than restriction types and restriction fields. During migration, the system converts business role restrictions one-to-one into the corresponding IAM role authorizations.
  • Thoroughly test all migrated IAM roles after you complete the migration process.

                  

Migration of Business Roles to IAM Roles 

If roles are marked as Action Required, perform the necessary migration steps for IAM apps and business catalogs in ABAP development tools for Eclipse. This includes migrating restriction types from business catalogs to IAM apps and completing the catalog migration.

Once all prerequisites are fulfilled, the roles are marked as Ready, allowing you to proceed once full migration support becomes available.

Key Features:
  • New Migrate button in the Maintain Business Roles app
  • IAM Role Migration Wizard for guidance and readiness checks
  • Identification of required migration steps via the readiness status
  • Execution of migration steps for IAM apps and business catalogs in ABAP development tools for Eclipse

       

Developer Extensibility Migration

  1. Navigate to Identity and Access Management in your system in ABAP Development Tools (ADT)
  2. Locate the relevant business catalog and check the migration status of its associated IAM apps.
  3. For each IAM app that is not yet migrated, choose Migrate IAM App.
  4. In the migration wizard:
    • Choose Next

    • Select the restriction types to migrate

    • Choose Next to confirm

    The IAM app status changes to Migrated.

  5. After all IAM apps are migrated, choose Migrate Business Catalog.
  6. Complete the wizard by choosing Next and then Finish.

    The business catalog status changes to Migrated.

  7. Navigate to the Maintain Business Roles app and recheck the readiness status in the IAM Role Migration Wizard. 

    The business catalog should now be marked as Ready.

                 

Key User Extensibility Migration

Key user extensibility migration is not yet available and will be delivered with a later release.

Keywords

iam app not listed, z app id, custom app visibility, assign iam apps to role, business role, business catalog, fine-grained access, display iam apps, catalog assignment, identity and access management, s/4hana cloud, fiori authorization, custom catalog, role maintenance, app assignment , KBA , BC-SRV-APS-IAM , Identity and Access Management , Problem

Product

SAP S/4HANA Cloud Public Edition all versions