In this blog I will write about the CUA replacement process. The topics will cover what you have to consider during this process.
The Central User Administration (CUA) is no longer the strategic solution from SAP to centrally manage users and authorizations. The replacement with the new SAP NetWeaver Identity Management 7.2 (IdM) provides benefits in following main areas:
Following blog focuses on the step-by-step CUA replacement process, which needs to be well-planned for a smooth shift towards SAP IdM.
Knowledge / experience in the following areas are helpful:
For a successful CUA replacement, following areas need to be considered:
1. Connecting CUA to IdM
In our case we assume that SAP IdM is already set-up. First, we would connect towards CUA using the SAP ABAP repository template for the system connection and the job templates for data import to SAP IdM. The job should be adapted to map fields according to the distribution model. The information from the child systems is retrieved via CUA in this step.
When IdM administrative masks and other workflows are configured, the data can be checked. In addition, the distribution model needs to be adapted. The provisioning can be switched on step-by-step for certain attributes / roles / users to test the functionality from a leading IdM and distribute via CUA. This helps the users to be trained and gain knowledge about IdM. CUA can still be used for certain reports or other custom functionalities. In this case, a reconciliation process inside IdM needs to be configured.
In addition, other leading and target systems could be integrated to already use new IdM functionalities, e.g. with HR data and a business role model for CUA, SAP Java systems and the company directory.
2. Connecting CUA Child Systems to IdM
From now on the child systems will be connected one after another to IdM. The general steps for a connection to a child system are:
This downtime between CUA and IdM administration could take up to a few hours when you have large amounts of data in each child system.
3. Shutdown the CUA
After the last child system is disconnected from the CUA, the CUA itself can be disconnected from the IdM and turned off.
A full replacement of the CUA by SAP IdM has a lot of advantages, e.g. integrating non-SAP systems, using delegated workflows and more flexible distribution rules. Therefore, the mentioned areas need to be evaluated to get the best out of the new IdM functionalities.
After setting up SAP IdM, the CUA is first connected to IdM. This solution can be tested by still having the administration possibilities inside the CUA - if needed. Afterwards, the child systems are disconnected from the CUA and connected towards IdM. This process can be changed and optimized to own needs. With the shutdown of the CUA, the full advantages of IdM can be used.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
User | Count |
---|---|
7 | |
5 | |
5 | |
5 | |
5 | |
4 | |
4 | |
4 | |
3 | |
3 |