My Organization App

The My Organization Application(opens in new tab) is a self-service tool that enables customers and partnerswho are onboarding to Bring Your Own Identity(opens in new tab) (BYOI) and manage their identity setup over time. BYOI allows organizations to connect their existing corporate identity providers with SAP, enabling centralized user management, seamless single sign-on, and a consistent, secure login experience to SAP's digital touchpoints.

 

Procedure

From the sidebar, select Users & Contacts → My Organization card.

Required Authorization

The app is available to company admins. EXPAND, LINKS.

My Organization Card

When you open the Users & Contacts dashboard the My Organization card shows the main information for your company including:

  • The number of total users you have.  
  • The number of potential conflicts you have (the number can be larger than the total users, as one user can have several conflicts).
  • The status of your configuration. 
  • An additional button ‘Configure Company Identity Provider’ button allowing Admins to go directly to setting up their Corporate Identity Provider configuration.
    Note:  This is only displayed when you don't have users with conflicts.

Click on the card to open the My Organization application.

Using the App

The application contains a table containing all users of the company. Any conflicts are are highlighted allowing you to more info about each.

You can also sort and filter the table in View Settings, selecting one or more filter types to filter by.

Conflict Types

TypeDescriptionImpactResolution
ErrorEmail duplicate (within the company ERP ID).Users grouped as 'conflict users' have more than one s-user with the same email in User Management Tool (UMT) for same ERP ID.To resolve, please proceed to UMT and either change the email of one of the S-users or delete a redundant account by re-assigning authorizations to an existing S-user.
WarningEmails outside of the company CCoE.Email address matches the registered domain from onboarding company however belonging to a different CCoE.User admin must review if the user(s) are ready to be migrated to Corporate Identity Provider (IdP) solution. Read more about authentication rules for external domains here.
Warning

Public email domain. Permitted email domains for your company are:

  • yourdomain.de 
  • yourdomain.com. 
The domain of the email address (e.g., example@yahoo.com) does not match your company's registered domains. As a result, the identified user will not be authenticated through the Corporate Identity Provider (IdP).To resolve, please proceed to UMT application and change the email of  of the S-users to corresponding registered domain or delete redundant account. Read more about authentication rules for external domains here.
WarningEmail domain is associated with P-user.P-user email address The email address associated with this P-user belongs to one of the company's registered domains. As a result, the private account created with this user is now managed through the company identity.This user is currently authenticated through a company corporate Identity Provider (IdP). If this is not the intended outcome, please review the email address associated with the P-user and update it to an email address assigned to the individual user.
WarningShared Email(s).The email address support@yourdomain.com is classified as a shared account because it is not assigned to an identifiable individual.S-Users with generic or shared email addresses should either be removed or updated to use an email address assigned to a physical person.