|
| 1 | +<!-- loio61879409f6024c5cad78d5e36ce3657c --> |
| 2 | + |
| 3 | +# Accessing the Administration Console |
| 4 | + |
| 5 | +Problems with the signing in to the administration console for SAP Cloud Identity Services. |
| 6 | + |
| 7 | +You can reach the tenant administration console via the URL https://<tenant ID\>.accounts.ondemand.com/admin pattern. |
| 8 | + |
| 9 | +You must be an administrator user. |
| 10 | + |
| 11 | +The Sign In screen appears correctly |
| 12 | + |
| 13 | + |
| 14 | + |
| 15 | +but you face one of the following problems: |
| 16 | + |
| 17 | + |
| 18 | + |
| 19 | +<a name="loio61879409f6024c5cad78d5e36ce3657c__section_xrm_yhl_ndc"/> |
| 20 | + |
| 21 | +## I don't know who the tenant administrator is? |
| 22 | + |
| 23 | +**Symptom:** |
| 24 | + |
| 25 | +You don't know who is the tenant administrator? |
| 26 | + |
| 27 | +**Solution:** |
| 28 | + |
| 29 | +See KBA 3035908 - [https://launchpad.support.sap.com/\#/notes/3035908](https://launchpad.support.sap.com/#/notes/3035908) |
| 30 | + |
| 31 | + |
| 32 | + |
| 33 | +### Contact an existing administrator for the tenant. |
| 34 | + |
| 35 | +Cloud Identity Services does not use for authentication the users registered in the SAP Service Marketplace, but maintains an own user store for administrators and users. |
| 36 | + |
| 37 | +Once you purchase a customer or partner account in SAP BTP, a user account for Identity Authentication is created for the contact person specified in the Order Form. The contact person is the first **tenant administrator** in the administration console for Cloud Identity Services. He or she receives an activation e-mail for the administration console account. The subject of the e-mail is: **Activate Your Account for Administration Console**. The **first**administrator activates the account and continues to the administration console for Identity Authentication via the console's URL. |
| 38 | + |
| 39 | +The first administrator can add new tenant administrators. |
| 40 | + |
| 41 | +See also: **KBA 2774108**- [Identity Authentication Service tenant specific request only possible for customer owning the tenant](https://launchpad.support.sap.com/#/notes/2774108) |
| 42 | + |
| 43 | +**Useful Links** |
| 44 | + |
| 45 | +- [Access Admin Console](../access-admin-console-2609e81.md) |
| 46 | +- [Reset Password](../User-Guide/reset-password-c821f3f.md) |
| 47 | +- [Activate Your Account](../activate-your-account-cc03ecc.md) |
| 48 | +- [Access Admin Console](../access-admin-console-2609e81.md) |
| 49 | +- [Manage Administrators](../manage-administrators-3bddea4.md) |
| 50 | + |
| 51 | + |
| 52 | + |
| 53 | +<a name="loio61879409f6024c5cad78d5e36ce3657c__section_m3j_43l_ndc"/> |
| 54 | + |
| 55 | +## I can't login to Administration Console of custom Cloud Identity Services tenant with S-user |
| 56 | + |
| 57 | +**Symptom:** |
| 58 | + |
| 59 | +Logging into the Administration Console of an Identity Authentication tenant with an S-user is unsuccessful. |
| 60 | + |
| 61 | +**Solution:** |
| 62 | + |
| 63 | +See KBA **2424064**- [Cannot login to Administration Console of custom Identity Authentication tenant with S-user](https://launchpad.support.sap.com/#/notes/2424064). |
| 64 | + |
| 65 | + |
| 66 | + |
| 67 | +<a name="loio61879409f6024c5cad78d5e36ce3657c__section_uxn_2ll_ndc"/> |
| 68 | + |
| 69 | +## Admin console is not accessible due to network problem |
| 70 | + |
| 71 | +**Symptom:** |
| 72 | + |
| 73 | +The administration console can't be accessed - the browser throws `ERR_EMPTY_RESPONSE`, or similar error message \(`ERR_TIMED_OUT`, `took too long to respond`, etc\). |
| 74 | + |
| 75 | +Timeout-related errors can also be seen on the browser. |
| 76 | + |
| 77 | +**Solution:** |
| 78 | + |
| 79 | +See KBA 2918278 - [IAS tenant is not accessible due to network problem](https://launchpad.support.sap.com/#/notes/2918278). |
| 80 | + |
| 81 | +This KBA provides some hints on how to investigate further. |
| 82 | + |
| 83 | + |
| 84 | + |
| 85 | +<a name="loio61879409f6024c5cad78d5e36ce3657c__section_q3m_tll_ndc"/> |
| 86 | + |
| 87 | +## Email activation problem |
| 88 | + |
| 89 | +As a tenant administrator you can reach the administrator console via the URL https://<tenant ID\>.accounts.ondemand.com/admin or https://<tenant ID\>.accounts.cloud.sap/admin pattern. |
| 90 | + |
| 91 | +`Tenant ID` is an automatically generated ID by the system. The URL is in the activation e-mail received by you. |
| 92 | + |
| 93 | +Check your inbox for an e-mail from **notification@sapnetworkmail.com**. |
| 94 | + |
| 95 | +**Useful Links** |
| 96 | + |
| 97 | +[Activate Your Account](../activate-your-account-cc03ecc.md) |
| 98 | + |
| 99 | + |
| 100 | + |
| 101 | +### I have activated my account but still face problems |
| 102 | + |
| 103 | +You see the following error after you’ve clicked the activation email link: |
| 104 | + |
| 105 | + |
| 106 | + |
| 107 | +This message means that Cloud Identity Services is already activated. |
| 108 | + |
| 109 | +Use the "Forgot Password" functionality to gain access to your tenant. For more information, see [Reset Password](../User-Guide/reset-password-c821f3f.md). |
| 110 | + |
| 111 | + |
| 112 | + |
| 113 | +### I haven't activated my account or didn't receive any email |
| 114 | + |
| 115 | +**Open your inbox and search for an email from *notification@sapnetworkmail.com***. The email contains the URL to activate your account. |
| 116 | + |
| 117 | +- **If the URL is expired** |
| 118 | + - The system sends you a new activation e-mail. Follow the procedure to activate your account. |
| 119 | + |
| 120 | +- **If the link is invalid or already used, or you haven't received an e-mail** |
| 121 | + - Check your spam folder |
| 122 | + - Contact an existing administrator for the tenant to ask the following |
| 123 | + |
| 124 | + - Whether an activation email was sent \(or if only an initial password was set, since in this case no email is sent\). |
| 125 | + - To resend the activation e-mail \(*Admin Console* \> *User Management* \> *select the user* \> *Authentication* \> *Password Details* \> *Password Details* \> *Send Email*. See also [Send Reset Password Email](../Operation-Guide/send-reset-password-email-da55abf.md). |
| 126 | + |
| 127 | + |
| 128 | + |
| 129 | +See also: **KBA 2517844** - [How to get the activation e-mail of an Identity Authentication tenant](https://launchpad.support.sap.com/#/notes/2517844). |
| 130 | + |
| 131 | + |
| 132 | + |
| 133 | +<a name="loio61879409f6024c5cad78d5e36ce3657c__section_vkp_zpl_ndc"/> |
| 134 | + |
| 135 | +## Error "Sorry, we could not authenticate you. Try again." |
| 136 | + |
| 137 | +This is a general error, and it can be the symptom of many different situations. You try to sign in: |
| 138 | + |
| 139 | + |
| 140 | + |
| 141 | +### .. after an LDAP user store is configured. |
| 142 | + |
| 143 | +The user is locked when configuring LDAP user store on SAP BTP |
| 144 | + |
| 145 | +You have configured an LDAP scenario based on the [Configure SAP BTP When Connecting to an LDAP User Store documentation](https://help.sap.com/viewer/6d6d63354d1242d185ab4830fc04feb1/Cloud/en-US/461d71c148594608b9c8b6d016e0a0c5.html#loiof48d4ea4ec4747ac8425385ded5d1e25). |
| 146 | + |
| 147 | +However, when you attempt to log on, you see "Sorry, we could not authenticate you. Try again." |
| 148 | + |
| 149 | +There is an issue in the connection between the SAP Cloud Connector and the corporate user store due to an issue with the system user which is used to access the corporate user store. |
| 150 | + |
| 151 | +See KBA: [2680867](https://i7p.wdf.sap.corp/sap/support/notes/2680867)- Check if the system user is locked when configuring and LDAP user store on SAP BTP |
| 152 | + |
| 153 | + |
| 154 | + |
| 155 | +### … with S-user credentials |
| 156 | + |
| 157 | +You are trying, without success, to login to the admin console as an S-user. |
| 158 | + |
| 159 | +There are no S-users used in custom tenants. S-users can only log on to `accounts.sap.com`, which belongs to SAP. |
| 160 | + |
| 161 | +In a custom own tenant, you can sign in using your **email** address and password. |
| 162 | + |
| 163 | +See KBA, [2424064](https://i7p.wdf.sap.corp/sap/support/notes/2424064) - Cannot login to admin console of custom Identity Authentication tenant with S-user |
| 164 | + |
| 165 | + |
| 166 | + |
| 167 | +### Sign in fails after successful activation with error: "Sorry, we could not authenticate you. Try again." |
| 168 | + |
| 169 | +**Symptom:** |
| 170 | + |
| 171 | +The user login fails after the activation link is called and the password update was successful. |
| 172 | + |
| 173 | +The user receives the following message: |
| 174 | + |
| 175 | +***Sorry, we could not authenticate you. Try again.*** |
| 176 | + |
| 177 | +In the [Troubleshooting log](https://launchpad.support.sap.com/#/notes/2942816), the following error is displayed: |
| 178 | + |
| 179 | +***Identity Provider could not process the authentication request received due to error on its own side. The SP user \[<user\_uuid\>\] is with status inactive for Service Provider \[<service\_provider\_url\>\] Caused by: javax.security.auth.login.AccountException: The SP user \[<user\_uuid\>\] is with status inactive for Service Provider \[<service\_provider\_url\>\] Caused by: The SP user \[<user\_uuid\>\] is with status inactive for Service Provider \[<service\_provider\_url\>\]*** |
| 180 | + |
| 181 | +**Solution:** |
| 182 | + |
| 183 | +See KBA 2770797 - [The IAS tenant user login fails after successful activation: Sorry, we could not authenticate you. Try again.](https://launchpad.support.sap.com/#/notes/2770797) |
| 184 | + |
| 185 | + |
| 186 | + |
| 187 | +### You forgot your assword |
| 188 | + |
| 189 | +Use the "Forgot Password" functionality to gain access to your tenant. For more information, see [Reset Password](../User-Guide/reset-password-c821f3f.md). |
| 190 | + |
| 191 | +If you have an account as administrator in Cloud Identity Services, an email with a link to a page where you can reset your password will be sent. Note that the email might take a few minutes to reach your inbox. If you don't have an account as administrator, you won't receive an e-mail. In this case ontact an existing administrator for the tenant. |
| 192 | + |
| 193 | +See also KBA 2517844 - [How to get the activation e-mail of an Identity Authentication tenant](https://launchpad.support.sap.com/#/notes/2517844). |
| 194 | + |
| 195 | + |
| 196 | + |
| 197 | +### You are not an administrator |
| 198 | + |
| 199 | +Cloud Identity Services does not use for authentication the users registered in the SAP Service Marketplace, but maintains an own user store for administrators and users. Only administrators can access the admin console. |
| 200 | + |
| 201 | +Ask an existing administrator to add new tenant administrators. See [Manage Administrators](../manage-administrators-3bddea4.md) and [2570572](https://i7p.wdf.sap.corp/sap/support/notes/2570572) - How to add Administrators to Identity Authentication tenants |
| 202 | + |
| 203 | + |
| 204 | + |
| 205 | +### Error "Used logon identifier is not allowed" |
| 206 | + |
| 207 | +**Symptom** |
| 208 | + |
| 209 | +Logon to the Identity Authentication Administration Console is failing with error: **Sorry, we could not authenticate you. Try again.** Using the forgot password link allows you to reset the password and log in. However, logging off and trying to login again the same error is shown as previously. Only a password reset allows login again for just one user session. |
| 210 | + |
| 211 | +The [Troubleshooting log](https://launchpad.support.sap.com/#/notes/2942816) is showing the following error: |
| 212 | + |
| 213 | +**User authentication failed. Reason: Used logon identifier is not allowed; Identifier: \[ <logon\_identifier\> \]** |
| 214 | + |
| 215 | +**Solution:** |
| 216 | + |
| 217 | +See KBA 2895349 - [Cannot logon to Identity Authentication Administration Console with valid logon identifier and password](https://launchpad.support.sap.com/#/notes/2895349). |
| 218 | + |
| 219 | + |
| 220 | + |
| 221 | +<a name="loio61879409f6024c5cad78d5e36ce3657c__section_s31_fzl_ndc"/> |
| 222 | + |
| 223 | +## Access denied. Sorry... You entered a valid URL, but you are not authorized to view the content. |
| 224 | + |
| 225 | +Immediately after you've logged on to administration console of Cloud Identity Services, you see the message: |
| 226 | + |
| 227 | +"Access Denied |
| 228 | + |
| 229 | +Sorry... You entered a valid URL, but you are not authorized to view the content, contact your system administrator" |
| 230 | + |
| 231 | + |
| 232 | + |
| 233 | +Ask an administrator to configure required authorization, as explained in the following KBA: |
| 234 | + |
| 235 | +[2579343](https://i7p.wdf.sap.corp/sap/support/notes/2579343) - Accessing /admin of custom Identity Authentication tenant ends with "you are not authorized to view the content" |
| 236 | + |
| 237 | + |
| 238 | + |
| 239 | +<a name="loio61879409f6024c5cad78d5e36ce3657c__section_mx1_dcm_ndc"/> |
| 240 | + |
| 241 | +## The identity provider could not process the authentication request received |
| 242 | + |
| 243 | +Cloud Identity Services using the Security Assertion Markup Language \(SAML\) 2.0 as identity provider \(IdP\) fails to process the authentication request. |
| 244 | + |
| 245 | + |
| 246 | + |
| 247 | +Make sure the service provider's name is the same as configured in Cloud Identity Services, acting as IdP: |
| 248 | + |
| 249 | +[2260000](https://i7p.wdf.sap.corp/sap/support/notes/2260000) - Identity provider could not process the authentication request received. |
| 250 | + |
| 251 | +If this does not solve your problem, please open a ticket on BC-IAM-IDS component, and provide the following information: |
| 252 | + |
| 253 | +- - Your tenant ID from https://tenant ID\>.accounts.ondemand.com/admin |
| 254 | +- Your email address |
| 255 | +- The error message you see |
| 256 | +- Attachments of screenshot that show the reproduced error, including the exact timestamp |
| 257 | +- If you solved your issue, a description of the steps you took |
| 258 | +- List of KBAs and SAP Notes, you have used to solve the issue |
| 259 | +- Attachments of SAML traces as per KBA: [2461862](https://launchpad.support.sap.com/#/notes/2461862) - Collecting SAML traces with Chrome or Firefox |
| 260 | + |
| 261 | + |
| 262 | + |
| 263 | + |
| 264 | +<a name="loio61879409f6024c5cad78d5e36ce3657c__section_qhr_hgm_ndc"/> |
| 265 | + |
| 266 | +## Error "Access to this Identity Authentication tenant is blocked, please contact your administrator" |
| 267 | + |
| 268 | +**Symptom:** |
| 269 | + |
| 270 | +Accessing the SAP Cloud Platform Identity Authentication Service \(IAS\) tenant fails with the below error: |
| 271 | + |
| 272 | +***"HTTP Status 403 – Access to this Identity Authentication tenant is blocked, please contact your administrator."*** |
| 273 | + |
| 274 | +**Solution:** |
| 275 | + |
| 276 | +See**KBA** - [https://launchpad.support.sap.com/\#/notes/2909142](https://launchpad.support.sap.com/#/notes/2909142) |
| 277 | + |
| 278 | +**Related Information** |
| 279 | + |
| 280 | + |
| 281 | +[User Import](user-import-6a46913.md "Problems with the user import in the administration console for SAP Cloud Identity Services.") |
| 282 | + |
| 283 | +[Emails](emails-7bde0d5.md "Problems with emails sent for the different application processes.") |
| 284 | + |
| 285 | +[Authentication](authentication-84f28fb.md "Problems with the authentication of the end user and administrator.") |
| 286 | + |
| 287 | +[Application Integration](application-integration-8acf508.md "Problems that different applications integrated with Cloud Identity Services might face.") |
| 288 | + |
| 289 | +[Request, Create and Delete Identity Authentication Tenant](request-create-and-delete-identity-authentication-tenant-b442658.md "Problems related to requesting, creating or deleting a tenant.") |
| 290 | + |
| 291 | +[End user screens](end-user-screens-a3864b5.md "Problems that you might face when working with the end user screen.") |
| 292 | + |
| 293 | +[APIs](apis-29ffc6b.md "Problems that you might face when using the REST APIs of Cloud Identity Services.") |
| 294 | + |
| 295 | +[Corporate Identity Providers](corporate-identity-providers-16ab7db.md "") |
| 296 | + |
| 297 | +[Corporate User Store](corporate-user-store-3ade241.md "") |
| 298 | + |
| 299 | +[Kerberos Authentication](kerberos-authentication-4bb4b24.md "") |
| 300 | + |
| 301 | +[Risk-Based Authentication](risk-based-authentication-bc7de4d.md "") |
| 302 | + |
| 303 | +[Custom Domains](custom-domains-7cb2ea5.md "") |
| 304 | + |
0 commit comments