Skip to content

Commit 70622d1

Browse files
Merge pull request #221419 from v-missam/sap
remove group references
2 parents 6a72e32 + b265e4a commit 70622d1

File tree

1 file changed

+9
-9
lines changed

1 file changed

+9
-9
lines changed

articles/active-directory/saas-apps/sap-cloud-platform-identity-authentication-provisioning-tutorial.md

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ ms.author: thwimmer
1515

1616
# Tutorial: Configure SAP Cloud Platform Identity Authentication for automatic user provisioning
1717

18-
The objective of this tutorial is to demonstrate the steps to be performed in SAP Cloud Platform Identity Authentication and Azure Active Directory (Azure AD) to configure Azure AD to automatically provision and de-provision users and/or groups to SAP Cloud Platform Identity Authentication.
18+
The objective of this tutorial is to demonstrate the steps to be performed in SAP Cloud Platform Identity Authentication and Azure Active Directory (Azure AD) to configure Azure AD to automatically provision and de-provision users to SAP Cloud Platform Identity Authentication.
1919

2020
> [!NOTE]
2121
> This tutorial describes a connector built on top of the Azure AD User Provisioning Service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Azure Active Directory](../app-provisioning/user-provisioning.md).
@@ -35,14 +35,14 @@ The scenario outlined in this tutorial assumes that you already have the followi
3535
3636
## Assigning users to SAP Cloud Platform Identity Authentication
3737

38-
Azure Active Directory uses a concept called *assignments* to determine which users should receive access to selected apps. In the context of automatic user provisioning, only the users and/or groups that have been assigned to an application in Azure AD are synchronized.
38+
Azure Active Directory uses a concept called *assignments* to determine which users should receive access to selected apps. In the context of automatic user provisioning, only the users that have been assigned to an application in Azure AD are synchronized.
3939

40-
Before configuring and enabling automatic user provisioning, you should decide which users and/or groups in Azure AD need access to SAP Cloud Platform Identity Authentication. Once decided, you can assign these users and/or groups to SAP Cloud Platform Identity Authentication by following the instructions here:
41-
* [Assign a user or group to an enterprise app](../manage-apps/assign-user-or-group-access-portal.md)
40+
Before configuring and enabling automatic user provisioning, you should decide which users in Azure AD need access to SAP Cloud Platform Identity Authentication. Once decided, you can assign these users to SAP Cloud Platform Identity Authentication by following the instructions here:
41+
* [Assign a user to an enterprise app](../manage-apps/assign-user-or-group-access-portal.md)
4242

4343
## Important tips for assigning users to SAP Cloud Platform Identity Authentication
4444

45-
* It is recommended that a single Azure AD user is assigned to SAP Cloud Platform Identity Authentication to test the automatic user provisioning configuration. Additional users and/or groups may be assigned later.
45+
* It is recommended that a single Azure AD user is assigned to SAP Cloud Platform Identity Authentication to test the automatic user provisioning configuration. Additional users may be assigned later.
4646

4747
* When assigning a user to SAP Cloud Platform Identity Authentication, you must select any valid application-specific role (if available) in the assignment dialog. Users with the **Default Access** role are excluded from provisioning.
4848

@@ -57,7 +57,7 @@ Before configuring and enabling automatic user provisioning, you should decide w
5757
> [!NOTE]
5858
> The admininistrator user in SAP Cloud Platform Identity Authentication must be of type **System**. Creating a normal administrator user can lead to *unauthorized* errors while provisioning.
5959
60-
3. Under Configure Authorizations, switch on the toggle button against **Manage Users** and **Manage Groups**.
60+
3. Under Configure Authorizations, switch on the toggle button against **Manage Users**.
6161

6262
![SAP Cloud Platform Identity Authentication Add SCIM](media/sap-cloud-platform-identity-authentication-provisioning-tutorial/configurationauth.png)
6363

@@ -89,7 +89,7 @@ Before configuring SAP Cloud Platform Identity Authentication for automatic user
8989

9090
## Configuring automatic user provisioning to SAP Cloud Platform Identity Authentication
9191

92-
This section guides you through the steps to configure the Azure AD provisioning service to create, update, and disable users and/or groups in SAP Cloud Platform Identity Authentication based on user and/or group assignments in Azure AD.
92+
This section guides you through the steps to configure the Azure AD provisioning service to create, update, and disable users in SAP Cloud Platform Identity Authentication based on users assignments in Azure AD.
9393

9494
> [!TIP]
9595
> You may also choose to enable SAML-based single sign-on for SAP Cloud Platform Identity Authentication, following the instructions provided in the [SAP Cloud Platform Identity Authentication Single sign-on tutorial](./sap-hana-cloud-platform-identity-authentication-tutorial.md). Single sign-on can be configured independently of automatic user provisioning, though these two features compliment each other
@@ -136,15 +136,15 @@ This section guides you through the steps to configure the Azure AD provisioning
136136

137137
![Provisioning Status Toggled On](common/provisioning-toggle-on.png)
138138

139-
12. Define the users and/or groups that you would like to provision to SAP Cloud Platform Identity Authentication by choosing the desired values in **Scope** in the **Settings** section.
139+
12. Define the users that you would like to provision to SAP Cloud Platform Identity Authentication by choosing the desired values in **Scope** in the **Settings** section.
140140

141141
![Provisioning Scope](common/provisioning-scope.png)
142142

143143
13. When you are ready to provision, click **Save**.
144144

145145
![Saving Provisioning Configuration](common/provisioning-configuration-save.png)
146146

147-
This operation starts the initial synchronization of all users and/or groups defined in **Scope** in the **Settings** section. The initial sync takes longer to perform than subsequent syncs, which occur approximately every 40 minutes as long as the Azure AD provisioning service is running. You can use the **Synchronization Details** section to monitor progress and follow links to provisioning activity report, which describes all actions performed by the Azure AD provisioning service on SAP Cloud Platform Identity Authentication.
147+
This operation starts the initial synchronization of all users defined in **Scope** in the **Settings** section. The initial sync takes longer to perform than subsequent syncs, which occur approximately every 40 minutes as long as the Azure AD provisioning service is running. You can use the **Synchronization Details** section to monitor progress and follow links to provisioning activity report, which describes all actions performed by the Azure AD provisioning service on SAP Cloud Platform Identity Authentication.
148148

149149
For more information on how to read the Azure AD provisioning logs, see [Reporting on automatic user account provisioning](../app-provisioning/check-status-user-account-provisioning.md).
150150

0 commit comments

Comments
 (0)