Overview
Using the Access on Hire2Retire
you can provision and deprovision users on SAP Cloud Identity Services.
Read the official documentation of SAP Cloud Identity Services here.
Define Role Definition¶
Provisioning Type¶
Define Role(s)¶
You can assign a Role to any user based on their AD attributes. You can define complex conditions using AND and OR logic. You can also use the Group memberships in AD to define Roles. For example: In Figure 2, user(s) with Department "Sales" and jobTitle "Manager" will get provisioned. Only users who get a Role assigned based on the conditions, will be provisioned. If the user is unassigned from a role based on their updated profile in AD/Entra ID, and you have selected to deprovision using Hire2Retire, user will be deprovisioned from SAP Cloud Identity Services.
You can enable the "Do not deprovision upon change of role" checkbox to prevent users from being deprovisioned on SAP Cloud Identity Services due to a role mismatch.
Process All Employees¶
All user(s) will be provisioned on SAP Cloud Identity Services.
Provision User¶
You can decide to either provision or deprovision user(s) using Access.
-
Provisioning - You can provision one or more user(s) to the SAP Cloud Identity Services according to the requirement. User(s) can be created, updated or reactivated in provisioning operation.
-
Deprovisioning - You can deprovision one or more user(s) according to the requirement. User accounts will be deactivated on SAP Cloud Identity Services upon deprovisioning.
Map attributes on SAP Cloud Identity Services¶
You can select the attributes provided by SAP Cloud Identity Services that you want to populate. You can map values from AD/Entra ID/Hybrid to populate these attributes. You can also use Hire2Retire's powerful data transformation capabilities using Excel Style functions.