Skip to Content
avatar image
Former Member

User group Field (User Group for Authorization Checks) of users through IDM via IDM 7.2/8.0?

Hello experts

i have a big doubt , that i have to populate t User group Field (User Group for Authorization Checks) in ABAB system of users via IDM 7.2/8.0.

I'm using standard abab connector package.

i'm unable to Map attributes b/w AS ABAB and SAP IDM 7.2 for this field. I tried to use some field/attribute name like user group, usergroup, even parameter name, but no luck , i could'nt do it.

The other User group (Groups/User Group Assignments) provided by SAP (which is not relevant for authorization check) is mapped as usergroups and IDM attribute for this is MX_USER_CATEGORY.

Still could'nt find the field with values,

whenever i use to update user profile , this user group(authorization checks ), left empty

and we are manually filling out .

Kindly help out to resolve this issue !!

Thanks!!

Mano

Add comment
10|10000 characters needed characters exceeded

  • Get RSS Feed

4 Answers

  • avatar image
    Former Member
    Aug 01, 2017 at 06:15 PM

    Mano:

    From the pass CreateABAPUser the pass attribute is CompanyId and IdM attribute is MX_ADMIN_UNIT.

    Regards

    Andy

    Add comment
    10|10000 characters needed characters exceeded

  • Aug 01, 2017 at 11:07 AM

    Hello Mano,

    I think the ABAP connector attribute you're looking for is "CompanyId". At least that is the one we are filling with the SAP user group.

    .

    Regards,

    Steffi.

    Add comment
    10|10000 characters needed characters exceeded

    • You need access to the management console to implement and/or check this. The admin UI won't help you here.

      Also this is an old thread and you're hijacking it. If you have questions, it's always better (and also following the Rules of Engagement) to create a new question and link to other threads/discussions/blogs that relate to it instead posting in an old question. ;)

      .

      Regards,

      Steffi.

  • Dec 20, 2017 at 11:12 AM

    Hi Mano,

    1. check whether the mentioned user group is available in abap system

    2. check whether user group is available in idm helpvalues table

    3. check whether usergroup is maintained for the user via attribute MX_ADMIN_UNIT

    4. check whether %MX_ADMIN_UNIT% is maintained for companyId attribute in the destination tab of create/modify abap user pass

    It would be easy to help you, if you can share screenshot of destination tab of create/modify ABAP user Pass.

    Regards,

    Deva

    Add comment
    10|10000 characters needed characters exceeded

  • avatar image
    Former Member
    Dec 19, 2017 at 01:44 PM

    Hello Steffi,

    actually we tried, but it is not populating in the ABAB system , so, we just created group and moving them manually to that group .

    regards

    Mano..

    Add comment
    10|10000 characters needed characters exceeded

    • "but we could not use that authorization check (user group(authorization checks ))"

      But that sounds like an issue with the groups and not with IDM, who is just used to write the user groups to the backend accounts. Or I'm misunderstanding your issue.

      .

      Regards,

      Steffi.