Skip to content

Commit

Permalink
Update from SAP DITA CMS (squashed):
Browse files Browse the repository at this point in the history
commit e087ddd77f23a198c22958b2766258da6d8f1da0
Author: REDACTED
Date:   Wed Jun 12 16:45:42 2024 +0000

    Update from SAP DITA CMS 2024-06-12 16:45:42
    Project: dita-all/jjq1673438782153
    Project map: c2f780f61c744155b0bd42b6f38fb70c.ditamap
    Output: loio9fe952ba277c471bbad80cd40548bb84
    Language: en-US
    Builddable map: 19ee09fc9a3b40ca9fbee8a11f97f767.ditamap

commit 0494fb96939fe7e067dee74fe7bdff20854da546
Author: REDACTED
Date:   Wed Jun 12 16:27:55 2024 +0000

    Update from SAP DITA CMS 2024-06-12 16:27:55
    Project: dita-all/jjq1673438782153
    Project map: c2f780f61c744155b0bd42b6f38fb70c.ditamap
    Output: loio9fe952ba277c471bbad80cd40548bb84
    Language: en-US
    Builddable map: 19ee09fc9a3b40ca9fbee8a11f97f767.ditamap

commit 11ae2ce235779ab0d3f5929d7e9159893d22ce41
Author: REDACTED
Date:   Wed Jun 12 15:58:25 2024 +0000

    Update from SAP DITA CMS 2024-06-12 15:58:25
    Project: dita-all/jjq1673438782153
    Project map: c2f780f61c744155b0bd42b6f38fb70c.ditamap
    Output: loio9fe952ba277c471bbad80cd40548bb84
    Language: en-US
    Builddable map: 19ee09fc9a3b40ca9fbee8a11f97f767.ditamap

##################################################
[Remaining squash message was removed before commit...]
  • Loading branch information
ditaccms-bot committed Jun 12, 2024
1 parent 8bdb7d3 commit e540d5d
Show file tree
Hide file tree
Showing 24 changed files with 484 additions and 482 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ You have to model the sample “Benefits” Java application as a module into th
> ### Caution:
> The *technical-user* property results in the *systemUser* property in the destination that is created. The *systemUser* property is deprecated and will be removed soon. We recommend that you work on behalf of specific \(named\) users instead of working with a technical user.
>
> See [OAuth SAML Bearer Assertion Authentication](https://help.sap.com/viewer/cca91383641e40ffbe03bdc78f00f681/Cloud/en-US/c69ea6aacd714ad2ae8ceb5fc3ceea56.html "Create and configure an OAuth SAML Bearer Assertion destination for an application in the Cloud Foundry environment.") :arrow_upper_right:.
> See [OAuth SAML Bearer Assertion Authentication](https://help.sap.com/viewer/cca91383641e40ffbe03bdc78f00f681/Cloud/en-US/c69ea6aacd714ad2ae8ceb5fc3ceea56.html "Create and configure an OAuth SAML Bearer Assertion destination for an application.") :arrow_upper_right:.
> ### Example:
> ```
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@ During the refresh:
>
> Note that the *System User* property is deprecated and will be removed soon. We recommend that you work on behalf of specific \(named\) users instead of working with a technical user.
>
> See [OAuth SAML Bearer Assertion Authentication](https://help.sap.com/viewer/cca91383641e40ffbe03bdc78f00f681/Cloud/en-US/c69ea6aacd714ad2ae8ceb5fc3ceea56.html "Create and configure an OAuth SAML Bearer Assertion destination for an application in the Cloud Foundry environment.") :arrow_upper_right:.
> See [OAuth SAML Bearer Assertion Authentication](https://help.sap.com/viewer/cca91383641e40ffbe03bdc78f00f681/Cloud/en-US/c69ea6aacd714ad2ae8ceb5fc3ceea56.html "Create and configure an OAuth SAML Bearer Assertion destination for an application.") :arrow_upper_right:.
- The *Extensions Admin* role and the *Extensions Administrators* group are recreated if they do not already exist, and the *Extensions Admin* role is reassigned to the *Extensions Administrators* group.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -148,7 +148,7 @@ ID of the technical user for the connection.
> ### Caution:
> This property is deprecated and will be removed soon. We recommend that you work on behalf of specific \(named\) users instead of working with a technical user.
>
> See [OAuth SAML Bearer Assertion Authentication](https://help.sap.com/viewer/cca91383641e40ffbe03bdc78f00f681/Cloud/en-US/c69ea6aacd714ad2ae8ceb5fc3ceea56.html "Create and configure an OAuth SAML Bearer Assertion destination for an application in the Cloud Foundry environment.") :arrow_upper_right:.
> See [OAuth SAML Bearer Assertion Authentication](https://help.sap.com/viewer/cca91383641e40ffbe03bdc78f00f681/Cloud/en-US/c69ea6aacd714ad2ae8ceb5fc3ceea56.html "Create and configure an OAuth SAML Bearer Assertion destination for an application.") :arrow_upper_right:.


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -112,7 +112,7 @@ Delete API credentials

[Working with External Resource Providers Using the btp CLI](working-with-external-resource-providers-using-the-btp-cli-48d7688.md "Use the SAP BTP command line interface (btp CLI) to get details, or to create or delete resource provider instances in a global account.")

[Managing Trust from SAP BTP to an Identity Authentication Tenant](managing-trust-from-sap-btp-to-an-identity-authentication-tenant-6140107.md "SAP BTP supports identity federation. Its concept is to reuse the user bases of identity providers. To use a custom identity provider, your global account or subaccount in SAP BTP must have a trust relationship to the identity provider you want to use.")
[Managing Trust from SAP BTP to an SAP Cloud Identity Services Tenant](managing-trust-from-sap-btp-to-an-sap-cloud-identity-services-tenant-6140107.md "SAP BTP supports identity federation. Its concept is to reuse the user bases of identity providers. To use a custom identity provider, your global account or subaccount in SAP BTP must have a trust relationship to the identity provider you want to use.")

[Managing Users and Their Authorizations Using the btp CLI](managing-users-and-their-authorizations-using-the-btp-cli-94bb593.md "User authorizations are managed by assigning role collections to users (for example, Subaccount Administrator). Use the SAP BTP command-line interface (btp CLI) to manage roles and role collections, and to assign role collections to users.")

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,7 @@ Update the security settings of a subaccount

[Working with External Resource Providers Using the btp CLI](working-with-external-resource-providers-using-the-btp-cli-48d7688.md "Use the SAP BTP command line interface (btp CLI) to get details, or to create or delete resource provider instances in a global account.")

[Managing Trust from SAP BTP to an Identity Authentication Tenant](managing-trust-from-sap-btp-to-an-identity-authentication-tenant-6140107.md "SAP BTP supports identity federation. Its concept is to reuse the user bases of identity providers. To use a custom identity provider, your global account or subaccount in SAP BTP must have a trust relationship to the identity provider you want to use.")
[Managing Trust from SAP BTP to an SAP Cloud Identity Services Tenant](managing-trust-from-sap-btp-to-an-sap-cloud-identity-services-tenant-6140107.md "SAP BTP supports identity federation. Its concept is to reuse the user bases of identity providers. To use a custom identity provider, your global account or subaccount in SAP BTP must have a trust relationship to the identity provider you want to use.")

[Managing Users and Their Authorizations Using the btp CLI](managing-users-and-their-authorizations-using-the-btp-cli-94bb593.md "User authorizations are managed by assigning role collections to users (for example, Subaccount Administrator). Use the SAP BTP command-line interface (btp CLI) to manage roles and role collections, and to assign role collections to users.")

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -115,7 +115,7 @@ List the existing signing keys for access tokens and indicates which key is curr

[Working with External Resource Providers Using the btp CLI](working-with-external-resource-providers-using-the-btp-cli-48d7688.md "Use the SAP BTP command line interface (btp CLI) to get details, or to create or delete resource provider instances in a global account.")

[Managing Trust from SAP BTP to an Identity Authentication Tenant](managing-trust-from-sap-btp-to-an-identity-authentication-tenant-6140107.md "SAP BTP supports identity federation. Its concept is to reuse the user bases of identity providers. To use a custom identity provider, your global account or subaccount in SAP BTP must have a trust relationship to the identity provider you want to use.")
[Managing Trust from SAP BTP to an SAP Cloud Identity Services Tenant](managing-trust-from-sap-btp-to-an-sap-cloud-identity-services-tenant-6140107.md "SAP BTP supports identity federation. Its concept is to reuse the user bases of identity providers. To use a custom identity provider, your global account or subaccount in SAP BTP must have a trust relationship to the identity provider you want to use.")

[Managing Users and Their Authorizations Using the btp CLI](managing-users-and-their-authorizations-using-the-btp-cli-94bb593.md "User authorizations are managed by assigning role collections to users (for example, Subaccount Administrator). Use the SAP BTP command-line interface (btp CLI) to manage roles and role collections, and to assign role collections to users.")

Expand Down
Original file line number Diff line number Diff line change
@@ -1,31 +1,31 @@
<!-- loio6140107ac5da428a930cfefd73468628 -->

# Managing Trust from SAP BTP to an Identity Authentication Tenant
# Managing Trust from SAP BTP to an SAP Cloud Identity Services Tenant

SAP BTP supports identity federation. Its concept is to reuse the user bases of identity providers. To use a custom identity provider, your global account or subaccount in SAP BTP must have a trust relationship to the identity provider you want to use.

> ### Note:
> We recommend that you always use SAP Cloud Identity Services - Identity Authentication as a single identity provider for SAP BTP. If you use corporate identity providers, connect them to your Identity Authentication tenant, which then acts as a hub.
> We recommend that you always use SAP Cloud Identity Services as a single identity provider for SAP BTP. If you use corporate identity providers, connect them to your SAP Cloud Identity Services tenant, which then acts as a hub.


<a name="loio6140107ac5da428a930cfefd73468628__section_zmw_mz2_tvb"/>

## Prerequisites

- You have a tenant of SAP Cloud Identity Services - Identity Authentication.
- You have a tenant of SAP Cloud Identity Services.

For more information, see [Tenant Model and Licensing](https://help.sap.com/docs/IDENTITY_AUTHENTICATION/6d6d63354d1242d185ab4830fc04feb1/93160ebd2dcb40e98aadcbb9a970f2b9.html?version=Cloud) in the documentation for Identity Authentication.
For more information, see [Tenant Model and Licensing](https://help.sap.com/docs/IDENTITY_AUTHENTICATION/6d6d63354d1242d185ab4830fc04feb1/93160ebd2dcb40e98aadcbb9a970f2b9.html?version=Cloud) in the documentation for SAP Cloud Identity Services.

- The Identity Authentication tenant is associated with the customer IDs of the relevant global account of SAP BTP.
- The SAP Cloud Identity Services tenant is associated with the customer IDs of the relevant global account of SAP BTP.

For more information, see [**Reuse SAP Cloud Identity Services Tenants for Different Customer IDs**](https://help.sap.com/docs/identity-authentication/identity-authentication/reuse-sap-cloud-identity-services-tenants-for-different-customer-ids) in the documentation for Identity Authentication.
For more information, see [**Reuse SAP Cloud Identity Services Tenants for Different Customer IDs**](https://help.sap.com/docs/identity-authentication/identity-authentication/reuse-sap-cloud-identity-services-tenants-for-different-customer-ids) in the documentation for SAP Cloud Identity Services.

- Make sure that the email addresses of all users in your identity provider are unique and correct.


> ### Note:
> We recommend that you request your own Identity Authentication tenant \(see [Getting a Tenant](https://help.sap.com/docs/IDENTITY_AUTHENTICATION/6d6d63354d1242d185ab4830fc04feb1/93160ebd2dcb40e98aadcbb9a970f2b9.html#getting-a-tenant)\).
> We recommend that you request your own SAP Cloud Identity Services tenant \(see [Getting a Tenant](https://help.sap.com/docs/IDENTITY_AUTHENTICATION/6d6d63354d1242d185ab4830fc04feb1/93160ebd2dcb40e98aadcbb9a970f2b9.html#getting-a-tenant)\).


Expand Down Expand Up @@ -97,7 +97,7 @@ Get details about a trust configuration
<tr>
<td valign="top">

Establish trust from a global account or subaccount to an Identity Authentication tenant to which you can connect this global account or subaccount
Establish trust from a global account or subaccount to an SAP Cloud Identity Services tenant to which you can connect this global account or subaccount

</td>
<td valign="top">
Expand Down Expand Up @@ -165,7 +165,7 @@ Migrate from SAML trust to OpenID Connect trust
<tr>
<td valign="top">

Roll back the migration of an existing SAML trust with any identity provider to OpenID Connect trust with an Identity Authentication tenant
Roll back the migration of an existing SAML trust with any identity provider to OpenID Connect trust with an SAP Cloud Identity Services tenant

</td>
<td valign="top">
Expand All @@ -185,7 +185,7 @@ Roll back the migration of an existing SAML trust with any identity provider to

<a name="loio6140107ac5da428a930cfefd73468628__section_vmj_cjj_rhb"/>

## Finding Available Identity Authentication Tenants
## Finding Available SAP Cloud Identity Services Tenants


<table>
Expand All @@ -209,7 +209,7 @@ Command help
<tr>
<td valign="top">

List all Identity Authentication
List all SAP Cloud Identity Services

</td>
<td valign="top">
Expand All @@ -226,7 +226,7 @@ List all Identity Authentication
<tr>
<td valign="top">

Get details about an Identity Authentication tenant that is available for a global account or a subaccount
Get details about an SAP Cloud Identity Services tenant that is available for a global account or a subaccount

</td>
<td valign="top">
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -418,7 +418,7 @@ Delete a role collection

[Working with External Resource Providers Using the btp CLI](working-with-external-resource-providers-using-the-btp-cli-48d7688.md "Use the SAP BTP command line interface (btp CLI) to get details, or to create or delete resource provider instances in a global account.")

[Managing Trust from SAP BTP to an Identity Authentication Tenant](managing-trust-from-sap-btp-to-an-identity-authentication-tenant-6140107.md "SAP BTP supports identity federation. Its concept is to reuse the user bases of identity providers. To use a custom identity provider, your global account or subaccount in SAP BTP must have a trust relationship to the identity provider you want to use.")
[Managing Trust from SAP BTP to an SAP Cloud Identity Services Tenant](managing-trust-from-sap-btp-to-an-sap-cloud-identity-services-tenant-6140107.md "SAP BTP supports identity federation. Its concept is to reuse the user bases of identity providers. To use a custom identity provider, your global account or subaccount in SAP BTP must have a trust relationship to the identity provider you want to use.")

[Managing Signing Keys for Access Tokens](managing-signing-keys-for-access-tokens-dfca1d3.md "Use the SAP BTP command line interface (btp CLI) to manage signing keys for access tokens in the subaccount.")

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -242,6 +242,8 @@ The *Costs and Usage* page uses the same terminology that is used in your monthl
> - In the cost and usage charts, estimated values are used for the period between the last balance statement and the current date. These are displayed as striped bars.
>
> These estimates are based on resource usage values before computation for billing and might change after the next balance statement is issued. The estimated values are not projected or forecast values.
>
> - Some SAP BTP services report their billing and usage at the global account level, and not at the subaccount level. Such services will be listed in the *Costs and Usage* page under a reserved account entity named `REPORTED-AT-GLOBAL-ACCOUNT-LEVEL` with the ID `DEFAULT_SA`.
Here are some useful tips that are common to both the *Billing* and *Usage* views:

Expand Down Expand Up @@ -541,6 +543,8 @@ To export your usage and cost data to a Microsoft Excel spreadsheet document, us

> ### Note:
> All of the information for the selected period is extracted to the Microsoft Excel document. It does not consider any of the filters you may have applied to the tables.
>
> Cost information is exported only if your global account uses the consumption-based commercial information.
The exported document contains several sheets \(tabs\). The sheets that are included depend on the commercial model that is used by your global account as shown in the following table:

Expand Down Expand Up @@ -707,7 +711,7 @@ Yes
**Related Information**


<?sap-ot O2O class="- topic/link " href="a5573d7cfaf645c4ae19dafba85888b4.xml" text="" desc="" xtrc="link:1" xtrf="file:/home/builder/src/dita-all/jjq1673438782153/loio9fe952ba277c471bbad80cd40548bb84_en-US/src/content/localization/en-us/f2c01a1a4f084f99b89bdbecf402c1e1.xml" output-class="" outputTopicFile="file:/home/builder/tp.net.sf.dita-ot/2.3/plugins/com.elovirta.dita.markdown_1.3.0/xsl/dita2markdownImpl.xsl" ?>
[Commercial Models](https://help.sap.com/viewer/65de2977205c403bbc107264b8eccf4b/Cloud/en-US/263d40009a5a4237a62e8f5c05ee641e.html "SAP BTP offers two different commercial models for enterprise accounts.") :arrow_upper_right:

[Trial Accounts and Free Tier](https://help.sap.com/viewer/65de2977205c403bbc107264b8eccf4b/Cloud/en-US/046f127f2a614438b616ccfc575fdb16.html "Explore the different options for trying out SAP BTP.") :arrow_upper_right:

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -78,7 +78,7 @@ Assign or update an entitlement to a subaccount or a directory

[Working with External Resource Providers Using the btp CLI](working-with-external-resource-providers-using-the-btp-cli-48d7688.md "Use the SAP BTP command line interface (btp CLI) to get details, or to create or delete resource provider instances in a global account.")

[Managing Trust from SAP BTP to an Identity Authentication Tenant](managing-trust-from-sap-btp-to-an-identity-authentication-tenant-6140107.md "SAP BTP supports identity federation. Its concept is to reuse the user bases of identity providers. To use a custom identity provider, your global account or subaccount in SAP BTP must have a trust relationship to the identity provider you want to use.")
[Managing Trust from SAP BTP to an SAP Cloud Identity Services Tenant](managing-trust-from-sap-btp-to-an-sap-cloud-identity-services-tenant-6140107.md "SAP BTP supports identity federation. Its concept is to reuse the user bases of identity providers. To use a custom identity provider, your global account or subaccount in SAP BTP must have a trust relationship to the identity provider you want to use.")

[Managing Users and Their Authorizations Using the btp CLI](managing-users-and-their-authorizations-using-the-btp-cli-94bb593.md "User authorizations are managed by assigning role collections to users (for example, Subaccount Administrator). Use the SAP BTP command-line interface (btp CLI) to manage roles and role collections, and to assign role collections to users.")

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -158,7 +158,7 @@ Delete environment instances of a subaccount

[Working with External Resource Providers Using the btp CLI](working-with-external-resource-providers-using-the-btp-cli-48d7688.md "Use the SAP BTP command line interface (btp CLI) to get details, or to create or delete resource provider instances in a global account.")

[Managing Trust from SAP BTP to an Identity Authentication Tenant](managing-trust-from-sap-btp-to-an-identity-authentication-tenant-6140107.md "SAP BTP supports identity federation. Its concept is to reuse the user bases of identity providers. To use a custom identity provider, your global account or subaccount in SAP BTP must have a trust relationship to the identity provider you want to use.")
[Managing Trust from SAP BTP to an SAP Cloud Identity Services Tenant](managing-trust-from-sap-btp-to-an-sap-cloud-identity-services-tenant-6140107.md "SAP BTP supports identity federation. Its concept is to reuse the user bases of identity providers. To use a custom identity provider, your global account or subaccount in SAP BTP must have a trust relationship to the identity provider you want to use.")

[Managing Users and Their Authorizations Using the btp CLI](managing-users-and-their-authorizations-using-the-btp-cli-94bb593.md "User authorizations are managed by assigning role collections to users (for example, Subaccount Administrator). Use the SAP BTP command-line interface (btp CLI) to manage roles and role collections, and to assign role collections to users.")

Expand Down
Loading

0 comments on commit e540d5d

Please sign in to comment.