|
NOTE:
|
If a central user administration is connected to One Identity Manager, regular synchronization is only required with the central system. The synchronization configuration is created for the client labeled as central system. The CUACentral user administration. Application Link Enabling (ALE) distribution model is loaded during synchronization and tries to assign all clients, which are configured as child systems, to the central system in One Identity Manager. All clients in the same SAP system as the central system are automatically added in One Identity Manager in the process and assigned to the central system (in CUA central system). All clients in another SAP system, must already exist in One Identity Manager at this point in time.
If a text comparison of roles and profiles between child and central systems was executed the target system in the target system, the child system roles and profiles are taken into account by synchronization. These roles and profiles are assigned to the originating client in the One Identity Manager.
Roles and profile are saved in the table USRSYSACTT with respect to language by text comparison of roles and profiles in the target system. Only roles and profile matching the login language of the administrative account for synchronization are read from the table USRSYSACTT during synchronization with One Identity Manager. If single roles and profiles are not maintained in this language, they are not transferred to One Identity Manager. In order to map all roles and profiles from child systems in One Identity Manager, they must all be all maintained in the language specified as login language in the central system.
To set up an initial synchronization project for central user administration
Proceed as described in section Creating a Synchronization Project for initial Synchronization of an SAP Client. The following anomalies apply:
All clients from the selected system and their license data are loaded.
|
NOTE: Do not synchronize using schedules. Re-synchronizing is only necessary, if the active price lists for charging licenses were changed in the target system. |
Proceed as described in section Creating a Synchronization Project for initial Synchronization of an SAP Client. The following anomalies apply:
Certain administrative task in SAP R/3 required that the child system is temporarily excluded from the central user administration. If these child system are synchronized during this period, the SAP roles and SAP profile of the temporarily excluded child system are marked as outstanding or deleted in the One Identity Manager database. To prevent this, remove the child system from the synchronization scope.
SAP roles and profiles are removed from the synchronization scope by deleting the ALE model name in the client. The client properties are synchronized anyway. To ensure that the ALE model name is not reintroduced, disable the rule for mapping this schema property.
To exclude a child system from synchronization
Open the synchronization project in the Synchronization EditorOne Identity Manager tool for configuring target system synchronization..
You must reactivate synchronization of the child system's SAP role and profiles the moment it becomes part of the central user administration again.
To re-include a child system in synchronization
The child system is only synchronized if the same ALE model named is entered in the central system and the child system.
Open the synchronization project in the SynchronizationThe process of comparing data between One Identity Manager and a target system. Objects and their properties are compared by fixed rules. Synchronization results in the identical data situation in the target system and One Identity Manager database. Editor.
For more information about editing synchronization steps, see One Identity Manager Target SystemAn instance of a target system in which the employees managed by One Identity Manager have access to network resources. Example: An Active Directory domain X for target system type "Active Directory", a directory Y for target system type "LDAP", a client Z for target system type "SAP R/3". Synchronization Reference Guide.
SynchronizationThe process of comparing data between One Identity Manager and a target system. Objects and their properties are compared by fixed rules. Synchronization results in the identical data situation in the target system and One Identity Manager database. results are summarized in the synchronization log. You can specify the extent of the synchronization log for each system connection individually. One Identity Manager provides several reports in which the synchronization results are organized under different criteria.
To display a synchronization log
Logs for all completed synchronization runs are displayed in the navigation view.
An analysis of the synchronization is shown as a report. You can save the report.
To display a provisioning log.
Logs for all completed provisioning processes are displayed in the navigation view.
Select a log by double-clicking on it.
An analysis of the provisioning is show as a report. You can save the report.
The log is marked in color in the navigation view. This mark shows you the execution status of the synchronization/provisioning.
Synchronization logs are stored for a fixed length of time. The retention period is set in the configuration parameter "DPR\Journal\LifeTime" and its sub parameters.
To modify the retention period for synchronization logs
You have used the Synchronization EditorOne Identity Manager tool for configuring target system synchronization. to set up a synchronization project for initial synchronization of an SAP client. You can use this synchronization project to load SAP objects into the One Identity Manager database. If you manage user accounts and their authorizations with One Identity Manager, changes are provisioned in the SAP environment.
You must customize the synchronization configuration in order to compare the SAP R/3 database with the regularly and to synchronize changes.
|
IMPORTANT: As long as synchronization is running, you must not start another synchronization for the same target system. This applies especially, if the same synchronization objects would be processed.
|
For more detailed information about configuring synchronization, see the One Identity Manager Target SystemAn instance of a target system in which the employees managed by One Identity Manager have access to network resources. Example: An Active Directory domain X for target system type "Active Directory", a directory Y for target system type "LDAP", a client Z for target system type "SAP R/3". Synchronization
The process of comparing data between One Identity Manager and a target system. Objects and their properties are compared by fixed rules. Synchronization results in the identical data situation in the target system and One Identity Manager database. Reference Guide.
© ALL RIGHTS RESERVED. Feedback Terms of Use Privacy