-
Non-Product Related Assistance
Request for existing cases, user IDs, Portal navigation support and more
User Management: Purpose, Overview and S-user reuse
Purpose: To explain the overview of Landscape Hub self-service portal’s Users and Contacts application to manage users, assign authorizations (only for S-users) and landscape-specific functions, ensure compliance with landscape-level access requirements and provide consistent add/edit/remove guidance to prevent errors.
Also, Reuse existing S-users from SAP for Me (no new S-users); the Super S-User Administrator onboards these users and assigns authorizations/functions to enable access to Landscape Hub .
1. Introduction
The portal enables administrators to manage user access and authorizations across landscapes using the Users and Contacts application—starting at the 'Users and Contacts' page—to add and remove users, maintain contact information, and assign or edit authorizations and functions.
Landscape Hub’s Users & Contacts reuses existing S-users from SAP for Me—no new S-users are created. The Super S-User Administrator adds existing S-users from SAP For Me and assigns authorizations to enable access.
2. What is this about?
Manage users by adding or removing users, assigning - adding / editing / removing landscape-independent and landscape-dependent authorizations, and managing landscape-level functions.
Note: Authorizations can be assigned to S-users only and not to Contact persons / Distribution Lists.
Reusing existing S-users from SAP for Me: The Super S-User Administrator adds existing S-Users from SAP For Me in Users & Contacts page and assigns authorizations/functions to onboard users and enable Landscape Hub access.
3. Why It Matters?
The portal ensures secure and auditable access to Landscape Hub and landscape-specific capabilities by ensuring the correct user assignments. This helps prevent operational disruptions, automated warnings, and loss of access caused by missing or incorrect authorizations, while supporting compliance, reducing operational risk, and minimizing remediation effort.
Ensures consistent and secure user onboarding by linking existing SAP for Me S-users, eliminating duplicate users, accelerating access provisioning, and centralizing authorization management for the Super S-User Administrator.
4. Key Concepts & Terminology
- S-Users can be assigned authorizations, at customer level (landscape-independent) or at landscape level (landscape-dependent)
- Contact persons and distribution lists are limited to landscape-level functions and cannot be assigned authorizations
- Certain mandatory functions must be assigned to prevent system warnings
- Simply adding a user does not grant access; appropriate authorizations must be explicitly assigned
- Contact Admin can start assigning authorizations / functions to himself and/or other S-Users
- Landscape Hub strictly reuses existing S-users from SAP for Me for onboarding. New S-users are not created within the Landscape Hub. Administrators only add existing users to assign:
1. Authorizations that will provide access to applications within Landscape Hub
2. Functions so that SAP will know whom to contact on the customer side for managing their private cloud landscape
5. Component Overview
Start at the Users and Contacts page (the entry point), click Add New to begin onboarding, complete the User Details page to view/edit data, authorizations, and functions, use the Add Authorizations and Add Functions dialogs to select and save (hover to edit landscape dependent authorizations), monitor Overview warnings for missing mandatory functions, then save and verify.
The "Add New" pop-up in Users & Contacts page features a search bar for finding existing S-users by S-User ID, Name or E-mail address from SAP for Me. It displays a list of S-users for selection, emphasizing that new S-users cannot be created, only existing ones can be added and onboarded to Landscape Hub.
Note: Customer Super S-User Administrator should have Users & Contacts Admin authorization.
6. Benefits / Value for Customer
Enables fast self-service onboarding/offboarding with centralized access control, clear separation of duties, automated missing-function warnings, and auditable changes for security, compliance, and continuity.
Customers gain a centralized "control center" for user management in Landscape Hub. They securely onboard existing SAP for Me S-users, gaining granular control over application access and defining functions, ensuring efficiency and secure communication.
7. Related Applications / Dependencies
Access to Landscape Hub is granted via authorizations managed in Users & Contacts (only S‑users), with landscape specific functions requiring upstream identity provisioning, and external changes may affect available roles and functions.
All the applications within the Landscape Hub shall be accessed by S-Users provided they have right authorizations assigned.
8. Additional Notes
Verify S‑user , Contact person, Distribution List details. Removing a S-User from Landscape Hub deletes their authorizations / functions assigned for Landscape Hub, removes the user from Landscape Hub but does not remove/delete the S-User from SAP For Me.