Reconciliation from SAP UM is removing the IT Resource Prefix from the Role System Name field. This prevents Access Policy Harvesting from Identifying those Roles for Harvesting
(Doc ID 2724449.1)
Last updated on NOVEMBER 05, 2020
Applies to:Identity Manager - Version 126.96.36.199.200108.2108 and later
Information in this document applies to any platform.
SAP UM connector is installed via Application Onboarding in OIG 12c. User accounts and entitlements are provisioned correctly to SAP. When that user is retrieved by reconciliation, the 'name' associated with the account or entitlement is returned from SAP without the IT Resource prefix.
Provisioned as this: '24~MANAGER'
Reconciled back as: 'MANAGER'
If the Evaluate User Policy job is run to handle the Access Policy Harvesting, this account or entitlement will not match with the lookup values stored in the Access Policy and no harvesting will occur.
New implementation, first use of Application Onboarding
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!
In this Document