Human Capital Management Blogs by SAP
Get insider info on SAP SuccessFactors HCM suite for core HR and payroll, time and attendance, talent management, employee experience management, and more in this SAP blog.
cancel
Showing results for 
Search instead for 
Did you mean: 
yogananda
Product and Topic Expert
Product and Topic Expert

Dear All,

In this blog,  you'll learn how to create Teams , Teams folder, Assigning Users to Teams and SAML Attribute Mapping for Users to determine respective folder access in your Embedded Analytics tenant.

The following diagram shows an example where Team 1 is assigned permissions to Team 1 Folder. All users that belong to Team 1 are granted permissions to Team1 Folder, and assigned the SCA_Viewer role, in addition to any roles or permissions they have been granted individually.

About Teams

Teams are groups of users that may collaborate on the same stories and share access to folders or objects in Embedded Analytics Cloud.

How to Create Teams

There are multiple ways to create teams in SAP Commissions - Embedded Analytics Cloud.

Teams can be created using the Teams page, or using SAML attribute mappings. Both methods for creating teams are described below.


Creating Teams from UI

From the side navigation, go to   Security     Teams, and choose     (Create Team).

Enter a unique Team Name.

Only the following characters are permitted: uppercase and lowercase letters, numbers, underscores, hash marks, and ampersands. Spaces are not allowed in the team name. The maximum length is 127 characters.
    1. Enter a Description.

Select Create a Folder to add a folder for team files under the System folder.

Members of your team automatically have full access to this folder. However, they cannot delete or export it.
  1. In the Members area, use  (Add Members) to search for existing users to add to this team.
    The Select User dialog opens.
  1. Scroll through the list of users or search for a particular user.
  1. Select  (Down), to the right of the Search area, to show more options.
    You can choose to see your users listed by Display NameID and Display Name, or ID.
  1. Choose  (Sort) to sort the list of users.

Select each user you want to add to the team.
When you are done, choose OK to return to the Create Team dialog.

You can use the controls in the Members area to add or remove users from the list. Use the Search control to find a particular user, if your list is long.

Choose Create when you are done.

Go to Homepage, you can see Team1 folder is created and you can add your reports to the Team1 folder for Users to view.

Final Result

The new team appears in the list. The user ID of the current session is automatically added to each team you create during the session.


Assign Users to Teams Using SAML Attributes

You can automatically assign users to teams based on their SAML attributes if you are using a custom identity provider.

Procedure

    1. From the side navigation, go to  Security   Teams.

Select the team you want to assign users to, and then select  (Open SAML Team Mapping).
The Create SAML Mapping dialog appears.

    1. Choose a SAML AttributeCondition and enter the Value that the attribute should correspond to.
    1. Optional: Select  (New Mapping Definition) to add multiple conditions.

Choose the Conditions Logic to apply to the attributes.

Select AND if you want all the conditions to be applied to users. Select OR if you want at least one of the conditions to be applied to users.

Select Save.

Note

Value is case sensitive.

Final Result :

The SAML mapping is created. Users will be added to the team only after they have logged out and back into SAP Analytics Cloud. The SAML user mapping you created will appear in the Teams list.


Each User can store the Teams Name in Custom Attribute 1 to till Custom Attribute 5 (Reserved for SAC)

Go to SAP IAS EA Application to enable Custom Attributes


 

Limitations

Currently only first 5 IAS Custom Attributes are allowed & available for SAML Mapping

References


https://help.sap.com/doc/00f68c2e08b941f081002fd3691d86a7/2021.6/en-US/f6ccc71dda15465291d528912ca3e...

https://help.sap.com/doc/00f68c2e08b941f081002fd3691d86a7/2021.6/en-US/3651184dad944aa2b361ad029a7a8...

9 Comments
darcyrose
Discoverer
0 Kudos

Thanks for this great post! I have not figured out how to get the Custom Attribute to show in Embedded Analytics. Currently the only options in the drop-down are email, family_name, given_name. Can you explain how to get the custom attributes to show?



Only default attributes are showing

krishnayeluri
Advisor
Advisor
Yet another useful post from you. Thanks, Yoga.

I'm eager to know the answer to Darcy's question above.
0 Kudos
Hi Darcy, the prerequisite for e.g. the attribute custom1 to occur on the above screen is:

1. The custom1 attribute is added to the SAML assertion in the IdP.
2. An SSO login to SAC was done where the custom1 attribute was included in the SAML assertion.

This is my experience with Datasphere which seems to use the very same concept as SAC.

Hope that helps

Hermann
darcyrose
Discoverer
0 Kudos
Hi Hermann,

I believe I have set the attributes in IAS to be added. The UI looks slightly different from above, but this is what I have. So far, still no new attributes showing (I'm hoping for either Custom Attribute 1 or Groups). Is there anywhere else where I need to make a change?



Attributes for the application in IAS


Thanks,

Darcy

 
0 Kudos
Hi Darcy, my impression with Datasphere/SAC was, that it only lists SAML attributes in the SAML mapping screen that it actually saw coming in. I would suggest to check with a browser extension like "SAML Chrome Panel" if the IAS SAML assertion contains the custom1 and groups attributes.
Regards
Hermann
darcyrose
Discoverer
0 Kudos
Hi Hermann,

Thanks for your help with this. I ran SAML Tracer and it appears the attributes are being passed. Do you have any other ideas?


SAML Trace showing attributes being passed


Thanks!

Darcy
0 Kudos
Hi Darcy,
SAC doesn't seem to support the "groups" attribute. To see it in SAC, you would need to use another custom attribute like custom2. The custom1 attribute looks good to me. If you still don't see the custom1 attribute in SAC, you may want to open a customer ticket for SAC.
Regards
Hermann
darcyrose
Discoverer
0 Kudos
Hi Hermann,

Sounds good, thank you. I do have a ticket open, so hopefully we can get it resolved!

Thanks,

Darcy
philipholtom
Participant
0 Kudos

Hi Darcy

I'm interested to see if you got a resolution to this issue. I'm also seeing a similar thing, the attribute is passed through on the SAML assertion but EA seems to be ignoring it....

Did you get this one solved via support or was it something else?

Regards

Phil.