IAG Access Analysis - Integration
IAG Access Analysis - Integration
Configuring SAP Cloud Identity Access Governance, access analysis service to analyze user access for
target applications (on-premise and cloud).
PUBLIC
2019_Feb_28
About This Guide
This guide is intended for administrators to assist in setup and integration of the access analysis service
and target applications. This guide is to be used in conjunction with the SAP Cloud Identity Access
Governance administrator guide.
Document History
Provides details about the changes made in each version of this document.
Date Description
February 28, 2019 Initial version
The diagram below illustrates the architectural components of SAP Cloud Identity Access
Governance (IAG) solution and services.
The IAG solution is a service on the SAP Cloud Platform. It integrates with other SAP Cloud Platform
services and connects with cloud and on-premise target applications.
6
In IAG, view results in Access Analysis app
Prerequisites
Ensure the following are setup and working before starting the integration procedure:
• Working target application (cloud or on-premise)
• In SCP, you have set up OAuth to maintain security for IAG services internal communication
(refer to IAG Admin Guide)
• In SCP, you have set up user authentication with SAP Cloud Identity Authentication Service
(refer to IAG Admin Guide)
• You have authorization and access to IAG administration apps
Note: Sections marked (on-premise only) are applicable only for SAP ERP on-premise
scenarios. Sections without this tag are applicable for all scenarios. For cloud-only integration
scenarios begin at Section 1.2 Create Destinations for Target Applications.
1) For each target system, install the SAP Cloud Platform Connector. ( see Installing SAP Cloud
Platform Connector)
2) Configure the SAP Cloud Platform Connector.
a. Login to your SAP Cloud Platform Connector and create a new account.
Go to Account Dashboard and click Add Account.
b. Enter the following details and save the data:
§ Landscape Host: Enter the URL for the data center for your IAG account.
§ Account Name: Enter the SCP subaccount technical name.
To locate the name, open SCP, open the subaccount, and navigate to the Subaccount
Information section.
e. Select the above system mapping and add SIAG for Function Module Name, and
Prefix for Naming Policy
After you save the destination in the Cloud Connector, it automatically creates the same in SCP >
Connectivity > Cloud Connector.
1. In SCP, go to your tenant, and in the left pane click Connectivity > Destinations.
2. Click New Destination.
3. In the Type field, select the communication type you are using.
· For on-premise, select RFC
· For cloud applications, select HTTP
Note: Each type has its own information. For information specific to your implementation, see
the Administrator Guide – Integration Scenarios.
1. Open the Fiori Launchpad for IAG, and open the Job Scheduler app.
2. Create and run the job of category Repository Sync.
To create your own custom business function groups, go to Step 4 Set Up Custom Business
Function Groups (optional). After creating the custom business function groups, follow the
instructions in Step 3 to set up rules.
1. On the IAG launchpad, open the Rule Setup app.
1. In the IAG launchpad, click Business Function Groups app. And click the plus sign (+) to add a
business function group.
2. Enter information for the business function group and click Save.
Note: The name is case sensitive.
4. On the edit screen, click the plus sign (+), add the systems, and then save.
· open the Access Analysis app to view access by user and remediate risks
· open the Analyze User Access app to view user access including functions
You can export the results to a spreadsheet.
Hyperlinks
Some links are classified by an icon and/or a mouseover text. These links provide additional information.
About the icons:
● Links with the icon: You are entering a Web site that is not hosted by SAP. By using such links, you
agree (unless expressly stated otherwise in your agreements with SAP) to this:
● The content of the linked-to site is not SAP documentation. You may not infer any product
claims against SAP based on this information.
● SAP does not agree or disagree with the content on the linked-to site, nor does SAP warrant
the availability and correctness. SAP shall not be liable for any damages caused by the use of
such content unless damages have been caused by SAP's gross negligence or willful misconduct.
● Links with the icon : You are leaving the documentation for that particular SAP product or service
and are entering a SAP-hosted Web site. By using such links, you agree that (unless expressly stated
otherwise in your agreements with SAP) you may not infer any product claims against SAP based on this
information.
Example Code
Any software coding and/or code snippets are examples. They are not for productive use. The example
code is only intended to better explain and visualize the syntax and phrasing rules. SAP does not warrant
the correctness and completeness of the example code. SAP shall not be liable for errors or damages
caused by the use of example code unless damages have been caused by SAP's gross negligence or
willful misconduct.
Gender-Related Language
We try not to use gender-specific word forms and formulations. As appropriate for context and
readability, SAP may use masculine word forms to refer to all genders.