Configure User provisioning from Active Directory to SAP Identity Services and S4hana
Dear All,
I'm trying to configure user provisioning in SAP IPS having source as MS Active Directory and Target as IAS and S4hana. The main objective of my project is to provision only specific members/users of different groups required for S4hana business, like HR group/PO Approvers etc.
The main problem I'm facing that while running the IPS job all users from entire Active directly is getting synced and not the specific members of the desired groups.
Could you please help me find the correct properties/attributes that I should be using in SAP IPS source system for Active Directory to filter only the users of specific groups and not all users. Currently I've used several properties to fetch users from groups for example like "ldap.group.filter", "ldap.attribute.dn", "ldap.user.filter" etc but none working as desired.
I have raised concern with SAP as well, but they are saying that have no knowledge of the exact attributes to use from AD to SAP IPS to provision the specific members of any groups.
Appreciate your response on this issue.
Thanks & Regards,
Anwar