Symptom
- Identity Provisioning (IPS) user sync from SuccessFactors to SAP Analytics Cloud (Stories in People Analytics) fails with a generic error message "400, Response: {"schemas":["urn:ietf:params:scim:api:messages:2.0:Error"],"status":"400","scimType":"invalidValue","detail":"Request is unparsable, syntactically incorrect, or violates schema."}"
- The help guides for Enabling Story Reports | SAP Help Portal and Identity Provisioning were followed SAP Analytics Cloud | SAP Help Portal
Environment
- SuccessFactors Platform Analytics
- User Provisioning
Reproducing the Issue
- Migrate SuccessFactors IPS source from OData to SCIM (sf.api.version = 2) and run Refresh Synthetic Group Data in SuccessFactors.
- Recreate or use existing SAC IPS target and run IPS read/write (or simulation) job from SuccessFactors to SAC.
- Observe that users are not created/updated in SAC and IPS logs contain HTTP 400/429/500 errors listed in Symptom.
Cause
- SAC SCIM v2 (/api/v1/scim2) is not supported for SuccessFactors embedded SAC tenants; using sac.api.version = 2 leads to generic SCIM 400 errors.
- This is a known issue as not embedded Analytics offerings of SAP Analytics Cloud do not implement the SCIM 2.0 specification in its entirety.
Please refer to the remainder of this document for details on what is supported.
Resolution
- In KBA 3648460 - Issues while synchronizing users between SF and SAC through IAS/IPS - SAP for Me & 3206522 - Not all SCIM Endpoints from the SCIM specification are available in the SAP Analytics Cloud User and Team Provisioning API - SAP for Me limitations are listed regarding the limitations present when using sac.api.version = 2.
- If your IPS target is SuccessFactors, it is currently recommended that you use SCIM1.
See Also
- Refer to: Upgrade from OData IPS connector to SCIM IPS connector
- Refer to: 3402232 - Provisioning users to SAC target system using V2 API causes 400 error
- Refer to: 3648460 - Issues while synchronizing users between SuccessFactors and SAC through IAS/IPS
- Refer to: 3206522 - Not all SCIM endpoints are available in SAC User and Team Provisioning API
- Refer to: 2969829 - Story Reports/IAS - User Sync failing due to missing or duplicate email IDs in SuccessFactors
- Refer to: 3623071 - IPS job fails for IAS target: Unknown value for name.honorificPrefix
- Refer to: 3390153 - IPS to IAS fails: Value not supported for honorificPrefix
- Refer to: 2719566 - How to export job logs, systems and self-analyze for Identity Provisioning
- Refer to: 3308246 - Transformation rule to set unique dummy emails for SuccessFactors Source API v2
Keywords
ips, successfactors, sac, stories in people analytics, scim v2, scim v1, sac.api.version, sf.api.version, provisioning, invalidSyntax, invalidPath, invalidValue, http 429, http 500, csrf token path, groups attribute, roles mapping, honorificPrefix, update ias/ips job, refresh synthetic group data , KBA , LOD-ANA-LS , Licensing and Full User Equivalent , Problem
Product
SAP Analytics Cloud all versions
SAP Knowledge Base Article - Public