cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

User change logs in Identity Authentication Service

former_member85790
Participant
0 Kudos
1,529

Hi all,

Is there a way to report on change history for User Management in the Identity Authentication Service? In particular we are attempting to identify when and by whom a user was changed/deleted, but I've had no luck finding documentation on where this may be logged.

Kind regards,
Adam

Accepted Solutions (0)

Answers (2)

Answers (2)

karthikj2
Product and Topic Expert
Product and Topic Expert
0 Kudos

It is possible to Access the audit logs for changes in the personal data, successful, and failed authentications for Identity Authentication tenants on both the SAP, and the AWS and Azure infrastructures in the Audit Log Service in SAP BTP, Cloud Foundry.

  1. To view the audit logs for Identity Authentication tenants in the SAP infrastructures, generate a Client ID and Client Secret for audit logs in the Administration Console for Identity Authentication first. After that, obtain an access token, and then call the audit log retrieval API to access the data.
  2. To access the audit logs, follow the procedures described here, under the section "Access Audit Logs". The following KBA shows how to use Postman to retrieve the logs: 2913940 - How to use Postman to get IAS audit log
  3. For Identity Authentication tenants in the AWS and Azure infrastructures follow this instruction: Access Audit Logs (AWS, Azure Infrastructure).

To verify the infrastructure of your Identity Authentication tenant, cross-check Regional Availability with the region of your tenant on https://iamtenants.accounts.cloud.sap/.

SAP Note Reference : https://me.sap.com/notes/0002753412

kaus19d
Active Contributor
0 Kudos
former_member85790
Participant
0 Kudos

Hi Kaushik,

This is in regard to the Cloud Platform Identity Authentication Service, not IDM, so unfortunately the links aren't applicable.

If there's any further information I can provide, I'd be happy to do so, but I'm not aware of anything unique about our instance that would be relevant; I would expect any answer to this question would be applicable to any customer of the service.

kaus19d
Active Contributor
0 Kudos

Hi Adam Champken,

Sorry, did not catch first what you were actually looking for. If I am not wrong, you are looking & working for in the below areas,

https://youtu.be/ntPHNXXw2h8

https://help.sap.com/doc/a7f50a08218845019a5eb5d0ba826691/Cloud/en-US/SAP_Cloud_Identity_Service_en....

https://help.sap.com/viewer/6d6d63354d1242d185ab4830fc04feb1/Cloud/en-US/9d96aae577f845708b53ebd18da...

https://digitalmarketplace-sapcpprd.s3.eu-central-1.amazonaws.com/-36dRyAWfYpgzAnOWj3NToU4baCLc3WFNT...

For now, I think, with the help of below process, you can export the Users and Import Combine & check

https://<tenant ID>.accounts.ondemand.com/admin

In case, you are finding difficulty in getting the details, You can also raise a OSS under Component BC-IAM-IDS as per below,

https://help.sap.com/viewer/6d6d63354d1242d185ab4830fc04feb1/Cloud/en-US/a299d84aebe44e61ab93dcde160...

I will try finding into more deep & try to get more details on this from my colleagues & update you

Thanks,

Kaushik