Financial Management Blog Posts by Members
Dive into a treasure trove of SAP financial management wisdom shared by a vibrant community of bloggers. Submit a blog post of your own to share knowledge.
cancel
Showing results for 
Search instead for 
Did you mean: 
debashish-sarma
Explorer
3,397

Introduction: In this blog, we'll explore a few selected issues and their resolutions from a recent SAP Cloud Identity Access Governance (IAG) implementation project. This post aims to provide actionable insights to overcome similar challenges in your own IAG endeavors.

1. Provisioning of PAM ID resulting into following error:

"Privileged Access XXX_FF assignment to XYZ Failed with Invalid connector: XYY"

debashishsarma_6-1720536380134.png

Resolution: Please make sure that the system which is configured in the tile “Applications” in IAG and used by PAM is created in the target system in SM59 with the same Destination name. For instance, if the application name in IAG is “S4HANA123”, then in the target system in SM59, an RFC destination of type 3 with the same name “S4HANA123” needs to be configured.

2. Error during PAM ID provisioning (java.lang.NullPointerException: cannot invoke “com.sap.conn.jco.JCoFunction.getImportParameterList()” because 'funcIAGTools” is null)

debashishsarma_7-1720536380167.png

Resolution: Implement S-Note 3207285 in the backend S/4 HANA system as mentioned in the KBA ‘3238751 - IAG - PAM ID stuck in Status 'in Process'. 

3. User cannot create Access Requests & PAM Requests in IAG. Error: "Sorry, a technical error occurred. Please try again later.{ "message": "HTTP request failed", "headers": { "DataServiceVersion": "1.0", "Content-Type": "application/json", "Content-Length": "180" }, "statusCode": "403", "statusText": "Forbidden", "responseText": "{\"error\": {\"code\":\"authCheckFailed\",\"message\":{\"lang\":\"en\",\"value\":\"Logged in user and created by User are different. Therefore request content is invalid and cannot be created\"}}}" }"

Resolution: The attributes configured in IAS for the IAG application should be the only attributes as mentioned in the SAP Help documentation below.

Set Up Assertion-based Groups for IdentityAuthentication and Role Collection Mapping | SAP Help Port...

4. Approvers not receiving requests in MY inbox application

Resolution: Change the subject identifier to "User ID" in IAS for IAG application. Reference: 2929135 - IAG - Access Request is not visible in approver's Inbox

debashishsarma_8-1720536380184.png

5. Email notifications are not getting triggered in IAG

Resolution: To enable the Notifications, it is required to have own SMTP server. Below 2 Destinations need to be created in the IAG Subaccount of BTP as per the instructions mentioned in KBA 3148288

a) Destination name: bpmworkflowruntime_mail

b) Destination name: parameters_destination

 6. URL links to Access Request inbox in IAG email notifications do not work.

Resolution: Please update the URL maintained in SAP BTP Cockpit, for the connector Parameters_Destination. The IAG launchpad URL format should be 'https://...hana.ondemand.com'.

Note: Do not include a trailing slash ('/') at the end of the URL.

debashishsarma_9-1720536380190.png

7. Access Request Submission results in 500 Internal Server Error

debashishsarma_0-1720537570478.png

Resolution: This issue is with USER ID mapping in IAG. When submitting access request, we need to ensure that the user ID matches with that of the one in target application system.

8. My Information tile is not showing User details or throwing error message "No Information available"

debashishsarma_11-1720536380205.png

Resolution: Please make sure that the standard user group (IAG_USER) is created in IAS tenant and it has been assigned to users. Run the SCI user group sync in IAG once the assignment has been completed for all users in IAS. You can refer to the KBA 2790280 for more details.

Stay tuned for upcoming posts.

SAP Cloud Identity Access Governance Governance, Risk, Compliance (GRC), and Cybersecurity 

6 Comments
Raffaella
Discoverer
0 Kudos

Hi,

regarding point nr 7,

what should I exactly check and where?

Thanks, Raffaella

yashkhanna
Explorer
0 Kudos

hi debashish-sarma - 

We are facing issue in attaching the file to the ATTACHMENT section in the access request. When we raise access request and try to attach file we get error message "Document failed to upload" and then after few seconds the request gets submitted automatically, and we can see the attached file in the request.

The issue is when we access the same request and try to open the attachement we are getting message "Document is not available for download" and we are unable to open the attachement.

Did you encounter this or aware of the resolution.

Regards,

Yash

 

debashish-sarma
Explorer
0 Kudos

Hello @Raffaella,

Could you verify if the "USER_ID" application parameter is set to "LOGIN_NAME" in the IAG "Configuration" tile?

Afterwards, please locate the user in IAS who is experiencing issues with access request submission. Ensure that their user ID is correctly entered in the "Login Name" field in "User Management". This ID should correspond with the one in the target system.

Run the Repository Sync job for the IAS application to sync this change in user data from IAS to IAG and then try creating the access request again.

Hope it should resolve your issue. Thanks!

Raffaella
Discoverer
0 Kudos

Dear Debashish,

I did recommended checks and are fine.

What is not working is the RepositorySync job providing following error message:

Error occurred during group sync: Service call return code : 422

SCI sysnc is working without errors.

Thanks.

debashish-sarma
Explorer
0 Kudos

Hi @Raffaella,

422 error in repo sync appears to be missing configuration issue with the integration. Have you checked and validated the necessary configuration steps?

Thanks,

Debashish

 

sujit_gawade
Explorer
0 Kudos

Hi Debashish,

While scheduing the PAM review or PAM log synch job, i am getting this screen as soon as I select job category "Privileged Access Log Sync Job" or "Privileged Access Log Review Job".

How to get rid of this error?

sujit_gawade_0-1744367936924.png

Thank you,

Best Regards,

Sujit Gawade.

Labels in this area