<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: Manager for IAG Workflow in Technology Q&amp;A</title>
    <link>https://community.sap.com/t5/technology-q-a/manager-for-iag-workflow/qaa-p/12616895#M4732286</link>
    <description>&lt;P&gt;Hello Subbu, &lt;/P&gt;&lt;P&gt;you actually do not need to maintain this manually. There is a function in IPS that you can use (providing you use IPS between Azure AD and IAS). The function is called resolveEntityIds. Have a look at this note as an example :  &lt;A href="https://launchpad.support.sap.com/#/notes/3046724"&gt;3046724 - How to provision the manager from SAP SuccessFactors to Identity Authentication&lt;/A&gt; .&lt;/P&gt;&lt;P&gt;This note does not 1:1 apply to your case as you would have a different user source but you can get an idea about what the function does. Here  is the IPS documentation for this function : &lt;A href="https://help.sap.com/docs/IDENTITY_PROVISIONING/f48e822d6d484fa5ade7dda78b64d9f5/0cdac7ce593548d38b5a78dbf1bb444c.html?locale=en-US&amp;amp;version=Cloud#resolveentityids" target="test_blank"&gt;https://help.sap.com/docs/IDENTITY_PROVISIONING/f48e822d6d484fa5ade7dda78b64d9f5/0cdac7ce593548d38b5a78dbf1bb444c.html?locale=en-US&amp;amp;version=Cloud#resolveentityids&lt;/A&gt;   &lt;/P&gt;&lt;P&gt;Also, if you are performing a direct provisioning into the SAP Cloud Identity Services, keep in mind that : &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;For the &lt;A href="https://api.sap.com/api/IAS_SCIM/overview"&gt;SCIM API V1&lt;/A&gt; one needs the P-number of the manager in the payload &lt;/LI&gt;&lt;LI&gt;For the &lt;A href="https://api.sap.com/api/IdDS_SCIM/resource"&gt;SCIM API V2 (Identity Directory) &lt;/A&gt; one needs the id/userUUID of the manager in the payload&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Kind Regards, &lt;/P&gt;&lt;P&gt;Sonia&lt;/P&gt;</description>
    <pubDate>Mon, 14 Nov 2022 13:34:25 GMT</pubDate>
    <dc:creator>SoniaPetrescu</dc:creator>
    <dc:date>2022-11-14T13:34:25Z</dc:date>
    <item>
      <title>Manager for IAG Workflow</title>
      <link>https://community.sap.com/t5/technology-q-a/manager-for-iag-workflow/qaq-p/12616894</link>
      <description>&lt;P&gt;Hello Experts,&lt;/P&gt;
  &lt;P&gt;As per the below SAP Note, if we maintain the manager information for the user in IAS then the data can be automatically retrieved in the access request. We would like to utilize the manager information for Access Request and Access Certification workflows.&lt;/P&gt;
  &lt;P&gt;&lt;A href="https://launchpad.support.sap.com/#/notes/2924629"&gt;https://launchpad.support.sap.com/#/notes/2924629&lt;/A&gt;&lt;/P&gt;
  &lt;P&gt;The issue here is that this field would only accept the P-User (User ID) as the manager, a number generated by IAS itself. It is practically impossible to maintain this value for every employee manually, especially because the manager's information may keep changing in HR from time to time.&lt;/P&gt;
  &lt;P&gt;Even if we set up Azure AD as a source for IAS user provisioning, how do we handle the transformations to change this value to the P-User in IAS for the manager ID retrieved from AD? &lt;/P&gt;
  &lt;P&gt;If any of you have experience handling this requirement then your input is greatly appreciated.&lt;/P&gt;
  &lt;P&gt;Regards,&lt;/P&gt;
  &lt;P&gt;Subbu Iyer&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2022 22:18:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/manager-for-iag-workflow/qaq-p/12616894</guid>
      <dc:creator>SubbuIyer</dc:creator>
      <dc:date>2022-11-11T22:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Manager for IAG Workflow</title>
      <link>https://community.sap.com/t5/technology-q-a/manager-for-iag-workflow/qaa-p/12616895#M4732286</link>
      <description>&lt;P&gt;Hello Subbu, &lt;/P&gt;&lt;P&gt;you actually do not need to maintain this manually. There is a function in IPS that you can use (providing you use IPS between Azure AD and IAS). The function is called resolveEntityIds. Have a look at this note as an example :  &lt;A href="https://launchpad.support.sap.com/#/notes/3046724"&gt;3046724 - How to provision the manager from SAP SuccessFactors to Identity Authentication&lt;/A&gt; .&lt;/P&gt;&lt;P&gt;This note does not 1:1 apply to your case as you would have a different user source but you can get an idea about what the function does. Here  is the IPS documentation for this function : &lt;A href="https://help.sap.com/docs/IDENTITY_PROVISIONING/f48e822d6d484fa5ade7dda78b64d9f5/0cdac7ce593548d38b5a78dbf1bb444c.html?locale=en-US&amp;amp;version=Cloud#resolveentityids" target="test_blank"&gt;https://help.sap.com/docs/IDENTITY_PROVISIONING/f48e822d6d484fa5ade7dda78b64d9f5/0cdac7ce593548d38b5a78dbf1bb444c.html?locale=en-US&amp;amp;version=Cloud#resolveentityids&lt;/A&gt;   &lt;/P&gt;&lt;P&gt;Also, if you are performing a direct provisioning into the SAP Cloud Identity Services, keep in mind that : &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;For the &lt;A href="https://api.sap.com/api/IAS_SCIM/overview"&gt;SCIM API V1&lt;/A&gt; one needs the P-number of the manager in the payload &lt;/LI&gt;&lt;LI&gt;For the &lt;A href="https://api.sap.com/api/IdDS_SCIM/resource"&gt;SCIM API V2 (Identity Directory) &lt;/A&gt; one needs the id/userUUID of the manager in the payload&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Kind Regards, &lt;/P&gt;&lt;P&gt;Sonia&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2022 13:34:25 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/manager-for-iag-workflow/qaa-p/12616895#M4732286</guid>
      <dc:creator>SoniaPetrescu</dc:creator>
      <dc:date>2022-11-14T13:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: Manager for IAG Workflow</title>
      <link>https://community.sap.com/t5/technology-q-a/manager-for-iag-workflow/qaa-p/12616896#M4732287</link>
      <description>&lt;P&gt;Thanks Sonia.&lt;/P&gt;&lt;P&gt;Apparently, IPS does not currently have the capability to read the manager information from Azure (SAP Note 3235598).&lt;/P&gt;&lt;P&gt;Do you know in the absence of SuccessFactors, which are the systems that IPS can read the information from? We spent quite a lot of effort working with the Azure team in setting up the connection and then we discovered this SAP Note. The customer has on-premise MS AD and Okta with Manager information. There is also Workday which has this information.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Subbu Iyer&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 22:37:47 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/manager-for-iag-workflow/qaa-p/12616896#M4732287</guid>
      <dc:creator>SubbuIyer</dc:creator>
      <dc:date>2022-12-09T22:37:47Z</dc:date>
    </item>
  </channel>
</rss>

