<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: Microsoft Active Directory Integration in Technology Q&amp;A</title>
    <link>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120739#M4099412</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not aware of any way you can sync users and passwords between AD and a SAP ABAP System. However, you can sync the user data (e.g. job title, email address) using the LDAP connector.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Jun 2015 11:55:09 GMT</pubDate>
    <dc:creator>tim_alsop</dc:creator>
    <dc:date>2015-06-08T11:55:09Z</dc:date>
    <item>
      <title>Microsoft Active Directory Integration</title>
      <link>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaq-p/11120733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hi experts&lt;/P&gt;&lt;P&gt;We have two issue for our customer:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1-Integration of SAP User Administration into Microsoft Active Directory: Our customer wants to &lt;SPAN class="hps"&gt;synchronize&lt;/SPAN&gt; their SAP users and passwords with Microsoft Active Directory but they dont want to use Single Sign-on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2-Creating and Synchronize Users in Active Directory from Employee Data Stored in SAP HR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We found two document related with this issue but their version is very old. Is there any new version of this document or we have to use different technology (for example Netweaver Identity Management)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Related links are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="3434" __jive_macro_name="document" class="jive_macro_document jive_macro" data-orig-content="Integration of SAP Central User Administration into Microsoft Active Directory" href="https://community.sap.com/" modifiedtitle="true" title="Integration of SAP Central User Administration into Microsoft Active Directory"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="3431" __jive_macro_name="document" class="jive_macro_document jive_macro" data-orig-content="Creating Users in Active Directory from Employee Data Stored in SAP HR.pdf" href="https://community.sap.com/" modifiedtitle="true" title="Creating Users in Active Directory from Employee Data Stored in SAP HR.pdf"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Jun 2015 22:44:44 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaq-p/11120733</guid>
      <dc:creator>former_member397702</dc:creator>
      <dc:date>2015-06-06T22:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Active Directory Integration</title>
      <link>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120734#M4099407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hande,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well you reference old documents, but you don't mention what version of IDM is to be used.&amp;nbsp; If it's 7.2, then the documents should be fairly relevant, but you might need to make a few tweaks.&amp;nbsp; If it's version 8, then it's anybody's game.&amp;nbsp; Documentation is coming at a slow, but steady pace.&amp;nbsp; Your best bet in that case is to do your research and ask questions here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Password management is pretty much the same.&amp;nbsp; I'd suggest looking at &lt;A __default_attr="17112" __jive_macro_name="document" class="jive_macro_document jive_macro" data-orig-content="SAP NetWeaver Identity Management Password Hook Configuration Guide" href="https://community.sap.com/"&gt;&lt;/A&gt; and &lt;A __default_attr="17111" __jive_macro_name="document" class="jive_macro_document jive_macro" data-orig-content="SAP NetWeaver Identity Management Identity Center Implementation Guide - Self-Service Password Reset" href="https://community.sap.com/" modifiedtitle="true" title="SAP NetWeaver Identity Management Identity Center Implementation Guide - Self-Service Password Reset "&gt;&lt;/A&gt;for the best information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally, from a consulting point of view, I would want to understand why they don't want to use SSO (Several excellent reasons exist, but it's good to understand) SSO in some way, shape, or form should be a part of any long range Identity and Access Management plan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Jun 2015 01:49:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120734#M4099407</guid>
      <dc:creator>former_member2987</dc:creator>
      <dc:date>2015-06-07T01:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Active Directory Integration</title>
      <link>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120735#M4099408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Regarding 1. You can use an authentication product so that when a user logs onto the SAP system the SAP system (via the authentication product) is able to check the users password against Active Directory. This is much more secure than using the password hook to synchronise passwords between systems. If you want to you can configure some users to get SSO, whilst others are required to enter their Active Directory password each time they logon. Or you might want all users to enter AD credentials.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Jun 2015 06:16:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120735#M4099408</guid>
      <dc:creator>tim_alsop</dc:creator>
      <dc:date>2015-06-07T06:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Active Directory Integration</title>
      <link>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120736#M4099409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Matt&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;Netweaver IDentity Management is not used. We are trying to integrate AD an ERP directly.&lt;/P&gt;&lt;P&gt;They don't want to use SSO because most of users use same terminal server or pc.&lt;/P&gt;&lt;P&gt;Best Regards...&lt;/P&gt;&lt;P&gt;Hande&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jun 2015 07:47:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120736#M4099409</guid>
      <dc:creator>former_member397702</dc:creator>
      <dc:date>2015-06-08T07:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Active Directory Integration</title>
      <link>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120737#M4099410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To solve this you need to use a product that can authenticate users on shared workstations using AD credentials. See my answer left on Jun 7th.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jun 2015 07:56:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120737#M4099410</guid>
      <dc:creator>tim_alsop</dc:creator>
      <dc:date>2015-06-08T07:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Active Directory Integration</title>
      <link>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120738#M4099411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim&lt;/P&gt;&lt;P&gt;Many thanks for your reply. But i want to know is there any way to &lt;SPAN class="hps"&gt;synchronize users, passwords and &lt;SPAN class="hps"&gt;synchronize personel data &lt;/SPAN&gt;without using any product.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps"&gt;Best Regards...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps"&gt;Hande &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jun 2015 10:33:07 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120738#M4099411</guid>
      <dc:creator>former_member397702</dc:creator>
      <dc:date>2015-06-08T10:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Active Directory Integration</title>
      <link>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120739#M4099412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not aware of any way you can sync users and passwords between AD and a SAP ABAP System. However, you can sync the user data (e.g. job title, email address) using the LDAP connector.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jun 2015 11:55:09 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120739#M4099412</guid>
      <dc:creator>tim_alsop</dc:creator>
      <dc:date>2015-06-08T11:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Active Directory Integration</title>
      <link>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120740#M4099413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hande,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for letting us know.&amp;nbsp; You might want to move this conversation to another forum then, unless you are speaking of SAP SSO.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jun 2015 14:18:10 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120740#M4099413</guid>
      <dc:creator>former_member2987</dc:creator>
      <dc:date>2015-06-08T14:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Active Directory Integration</title>
      <link>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120741#M4099414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hande,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Kerberos SNC authentication options available with the product SAP Single Sign-On are documented on &lt;A href="http://help.sap.com/saphelp_nwsso20/helpdata/en/8b/5500efc24147758cbf918cd829bbdb/frameset.htm" target="_blank"&gt;help.sap.com&lt;/A&gt; .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm pretty sure there will be a mode that fits to your scenario. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Christian &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jun 2015 12:01:09 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120741#M4099414</guid>
      <dc:creator>Christian_Cohrs1</dc:creator>
      <dc:date>2015-06-18T12:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Active Directory Integration</title>
      <link>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120742#M4099415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hande,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can imagine implementing a password hook on your domain controller: &lt;A href="https://msdn.microsoft.com/en-us/library/ms721876%28v=vs.85%29.aspx?f=255&amp;amp;MSPPError=-2147217396" title="https://msdn.microsoft.com/en-us/library/ms721876%28v=vs.85%29.aspx?f=255&amp;amp;MSPPError=-2147217396"&gt;PasswordChangeNotify callback function (Windows)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;which would then update the SAP password for a user on all defined SAP instances via RFC call to BAPI_USER_CHANGE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All the above would require some 200-300 lines of code, however from a security standpoint, I strongly discourage you of implementing that. Your active directory passwords are safe as long as you keep them on the domain controller and you do not touch them. Any attempt like above leads to compromise of user credentials.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either keep the authentication separate or go for SSO. Do not synchronize the passwords.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hynek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jul 2015 20:33:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/microsoft-active-directory-integration/qaa-p/11120742#M4099415</guid>
      <dc:creator>hynek_petrak</dc:creator>
      <dc:date>2015-07-21T20:33:22Z</dc:date>
    </item>
  </channel>
</rss>

