How can I trigger a post-creation workflow via SAP SuccessFactors to Active Directory user provisioning?

Michael Liben 261 Reputation points
2022-10-21T17:14:21.913+00:00

The SAP SuccessFactors to Active Directory user provisioning agent provisions users to Active Directory. Subsequently Azure AD Connect provisions the user in Azure/M365. Since the SAP provisioning agent creates the user with a password that is not logged, the user needs to change or reset their password to authenticate.

I can create an on-premises application that scans new user in on-premises Active Directory, set the password to a new random value, and convey that password to the user or user's manager via email but that's a stand-alone on-premises custom application the client needs to own/maintain.

We have personal mobile and email information available to pre-register authentication methods in Azure. I can create an on-premises application that scans new user in on-premises Active Directory and check the consistency GUID as a signal the Azure object has been created and register the methods(s). However, this is still a stand-alone on-premises custom application the client needs to own/maintain.

Appreciate any guidance on how to improve upon these possible solutions.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Accepted answer
  1. Danny Zollner 10,801 Reputation points Microsoft Employee Moderator
    2022-10-21T19:52:49.503+00:00

    I think what you're looking for is our new Lifecycle Workflows feature. See documentation here: https://learn.microsoft.com/en-us/azure/active-directory/governance/what-are-lifecycle-workflows

    I don't know that you'll be able to do the plaintext password via email thing, but I think you can leverage the Temporary Access Pass (TAP) feature in its place, in combination with Lifecycle Workflows.


2 additional answers

Sort by: Most helpful
  1. ROYALEXPRESSTRAVELS 0 Reputation points
    2022-10-22T06:19:51.623+00:00

    Hello zollnerD
    I hope you are fine yes I am here for looking my workflow azure if u help me then reply. I find a link in your post azure...... Before I click this tell. Me about your self

    Thanks

    warm regards.......

    Syed bilal shah

    Ceo
    THE ROYAL EXPRESS TRAVELS

    0 comments No comments

  2. Thrinatha Appanna 0 Reputation points
    2024-08-27T21:14:38.19+00:00

    we would like to move terminated users into separate OU and TAP solution is for only cloud logins, we need to find a way to set password for AD account.

    Please advise.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.