Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle®...

69
Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0) F12374-02 December 2019

Transcript of Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle®...

Page 1: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Oracle® Identity GovernanceConfiguring the SAP SuccessFactorsApplication

Release 12c (12.2.1.3.0)F12374-02December 2019

Page 2: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Oracle Identity Governance Configuring the SAP SuccessFactors Application, Release 12c (12.2.1.3.0)

F12374-02

Copyright © 2018, 2019, Oracle and/or its affiliates. All rights reserved.

Primary Author: Alankrita Prakash

Contributors: Akash Sharma

This software and related documentation are provided under a license agreement containing restrictions onuse and disclosure and are protected by intellectual property laws. Except as expressly permitted in yourlicense agreement or allowed by law, you may not use, copy, reproduce, translate, broadcast, modify,license, transmit, distribute, exhibit, perform, publish, or display any part, in any form, or by any means.Reverse engineering, disassembly, or decompilation of this software, unless required by law forinteroperability, is prohibited.

The information contained herein is subject to change without notice and is not warranted to be error-free. Ifyou find any errors, please report them to us in writing.

If this is software or related documentation that is delivered to the U.S. Government or anyone licensing it onbehalf of the U.S. Government, then the following notice is applicable:

U.S. GOVERNMENT END USERS: Oracle programs, including any operating system, integrated software,any programs installed on the hardware, and/or documentation, delivered to U.S. Government end users are"commercial computer software" pursuant to the applicable Federal Acquisition Regulation and agency-specific supplemental regulations. As such, use, duplication, disclosure, modification, and adaptation of theprograms, including any operating system, integrated software, any programs installed on the hardware,and/or documentation, shall be subject to license terms and license restrictions applicable to the programs.No other rights are granted to the U.S. Government.

This software or hardware is developed for general use in a variety of information management applications.It is not developed or intended for use in any inherently dangerous applications, including applications thatmay create a risk of personal injury. If you use this software or hardware in dangerous applications, then youshall be responsible to take all appropriate fail-safe, backup, redundancy, and other measures to ensure itssafe use. Oracle Corporation and its affiliates disclaim any liability for any damages caused by use of thissoftware or hardware in dangerous applications.

Oracle and Java are registered trademarks of Oracle and/or its affiliates. Other names may be trademarks oftheir respective owners.

Intel and Intel Xeon are trademarks or registered trademarks of Intel Corporation. All SPARC trademarks areused under license and are trademarks or registered trademarks of SPARC International, Inc. AMD, Opteron,the AMD logo, and the AMD Opteron logo are trademarks or registered trademarks of Advanced MicroDevices. UNIX is a registered trademark of The Open Group.

This software or hardware and documentation may provide access to or information about content, products,and services from third parties. Oracle Corporation and its affiliates are not responsible for and expresslydisclaim all warranties of any kind with respect to third-party content, products, and services unless otherwiseset forth in an applicable agreement between you and Oracle. Oracle Corporation and its affiliates will not beresponsible for any loss, costs, or damages incurred due to your access to or use of third-party content,products, or services, except as set forth in an applicable agreement between you and Oracle.

Page 3: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Contents

Preface

Audience viii

Documentation Accessibility viii

Related Documents viii

Conventions ix

What’s New in This Guide?

Software Updates x

Documentation-Specific Updates x

1 About the SAP SuccessFactors Connector

1.1 Certified Components 1-2

1.2 Usage Recommendation 1-2

1.3 Certified Languages 1-2

1.4 Supported Connector Operations 1-3

1.5 Connector Architecture 1-4

1.6 Use Cases Supported by the Connector 1-5

1.7 Connector Features 1-6

1.7.1 Full and Incremental Reconciliation 1-7

1.7.2 Support for Trusted Source Reconciliation 1-7

1.7.3 Limited Reconciliation 1-7

1.7.4 Support for the Connector Server 1-7

1.7.5 Transformation and Validation of Account Data 1-8

2 Creating an Application by Using the SAP SuccessFactorsConnector

2.1 Process Flow for Creating an Application By Using the Connector 2-1

2.2 Prerequisites for Creating an Application By Using the Connector 2-3

2.2.1 Registering the Client Application 2-3

2.2.2 Downloading the Connector Installation Package 2-3

iii

Page 4: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

2.3 Creating an Application By Using the Connector 2-4

3 Configuring the SAP SuccessFactors Connector

3.1 Basic Configuration Parameters 3-1

3.2 Advanced Setting Parameters 3-4

3.3 Attribute Mappings 3-6

3.3.1 Attribute Mappings for the Target Application 3-6

3.3.2 Attribute Mappings for the Authoritative Application 3-10

3.4 Correlation Rules 3-11

3.4.1 Correlation Rules for the Target Application 3-11

3.4.2 Correlation Rules for an Authoritative Application 3-13

3.5 Reconciliation Jobs 3-15

4 Performing the Postconfiguration Tasks for the SAPSuccessFactors Connector

4.1 Configuring Oracle Identity Governance 4-1

4.1.1 Creating and Activating a Sandbox 4-1

4.1.2 Creating a New UI Form 4-2

4.1.3 Publishing a Sandbox 4-2

4.1.4 Updating an Existing Application Instance with a New Form 4-2

4.2 Harvesting Entitlements and Sync Catalog 4-3

4.3 Managing Logging 4-3

4.3.1 Understanding Log Levels 4-4

4.3.2 Enabling Logging 4-5

4.4 Configuring the IT Resource for the Connector Server 4-6

4.5 Localizing Field Labels in UI Forms 4-7

4.6 Configuring SSL 4-9

5 Using the SAP SuccessFactors Connector

5.1 Configuring Reconciliation 5-1

5.1.1 Performing Full and Incremental Reconciliation for the Connector 5-1

5.1.2 Performing Limited Reconciliation for the Connector 5-2

5.2 Configuring Reconciliation Jobs 5-2

5.3 Guidelines on Performing Provisioning Operations 5-3

5.4 Performing Provisioning Operations 5-3

5.5 Uninstalling the Connector 5-4

iv

Page 5: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

6 Extending the Functionality of the SAP SuccessFactors Connector

6.1 Configuring Transformation and Validation of Data 6-1

6.2 Configuring Action Scripts 6-3

6.3 Configuring the Connector for Multiple Installations of the Target System 6-3

6.4 Understanding OData API Dictionary 6-4

6.4.1 About OData API Dictionary 6-4

6.4.2 Viewing OData API Dictionary in the SAP SuccessFactors Connector 6-4

6.4.3 Adding Custom Attributes and Object Entities in Oracle IdentityGovernance 6-5

6.4.4 Providing Values in Static Lookups 6-6

7 Upgrading the SAP SuccessFactors Connector

7.1 Upgrade Steps 7-1

7.2 Postupgrade Steps 7-2

8 Known Issues and Workarounds for the SAP SuccessFactorsConnector

8.1 Support for Delete User Operation 8-1

8.2 Support for Removing Child Attributes 8-1

8.3 Support for Translation of Termination Date 8-1

A Files and Directories on the SAP SuccessFactors ConnectorInstallation Package

v

Page 6: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

List of Figures

1-1 Architecture of the SuccessFactors Connector 1-4

2-1 Overall Flow of the Process for Creating an Application By Using the Connector 2-2

3-1 Default Attribute Mappings for SAP SuccessFactors Target User Account 3-9

3-2 Default Attributes for SAP SuccessFactors Authoritative Application 3-11

3-3 Simple Correlation Rule for SAP SuccessFactors Application 3-12

3-4 Predefined Situations and Responses for SAP SuccessFactors Target Application 3-13

3-5 Simple Correlation Rule for SAP SuccessFactors Authoritative Application 3-14

3-6 Predefined Situations and Responses for the SAP SuccessFactors Authoritative

Application 3-15

6-1 OData API Entities 6-5

6-2 Providing Values in a Static Lookup 6-7

vi

Page 7: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

List of Tables

1-1 Certified Components 1-2

1-2 Supported Connector Operations 1-3

1-3 Supported Connector Features Matrix 1-6

3-1 Parameters in the Basic Configuration 3-2

3-2 Advanced Setting Parameters for the SAP SuccessFactors 3-4

3-3 Default Attributes for SAP SuccessFactors Target Application 3-7

3-4 Default Attributes for SAP SuccessFactors Authoritative Application 3-10

3-5 Predefined Identity Correlation Rule for SAP SuccessFactors Connector 3-12

3-6 Predefined Situations and Responses for SAP SuccessFactors Target Application 3-13

3-7 Predefined Identity Correlation Rule for SAP SuccessFactors Authoritative Application 3-14

3-8 Predefined Situations and Responses for SAP SuccessFactors Authoritative Application 3-15

3-9 Parameters of the Scheduled Job for Target User Reconciliation 3-16

3-10 Parameters of the Scheduled Job for Authoritative User Reconciliation 3-16

3-11 Parameters of the Scheduled Jobs for Lookup Field Synchronization 3-17

4-1 Log Levels and ODL Message Type:Level Combinations 4-4

4-2 Log Levels and ODL Message Type:Level Combinations 4-4

4-3 Parameters of the IT Resource for the SAP SuccessFactors Connector Server 4-7

A-1 Files and Directories in the Connector Installation Package A-1

vii

Page 8: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Preface

This guide describes the connector that is used to onboard SAP SuccessFactorsapplications to Oracle Identity Governance.

AudienceThis guide is intended for resource administrators and target system integration teams.

Documentation AccessibilityFor information about Oracle's commitment to accessibility, visit the OracleAccessibility Program website at http://www.oracle.com/pls/topic/lookup?ctx=acc&id=docacc.

Access to Oracle Support

Oracle customers that have purchased support have access to electronic supportthrough My Oracle Support. For information, visit http://www.oracle.com/pls/topic/lookup?ctx=acc&id=info or visit http://www.oracle.com/pls/topic/lookup?ctx=acc&id=trs if you are hearing impaired.

Related DocumentsFor information about installing and using Oracle Identity Governance 12.2.1.3.0, visitthe following Oracle Help Center page:

http://docs.oracle.com/middleware/12213/oig/index.html

For information about installing and using Oracle Identity Manager 11.1.2.3, visit thefollowing Oracle Help Center page:

http://docs.oracle.com/cd/E52734_01/index.html

For information about Oracle Identity Governance Connectors 12.2.1.3.0documentation, visit the following Oracle Help Center page:

http://docs.oracle.com/middleware/oig-connectors-12213/index.html

For information about Oracle Identity Manager Connectors 11.1.1 documentation, visitthe following Oracle Help Center page:

http://docs.oracle.com/cd/E22999_01/index.htm

Preface

viii

Page 9: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

ConventionsThe following text conventions are used in this document:

Convention Meaning

boldface Boldface type indicates graphical user interface elements associatedwith an action, or terms defined in text or the glossary.

italic Italic type indicates book titles, emphasis, or placeholder variables forwhich you supply particular values.

monospace Monospace type indicates commands within a paragraph, URLs, codein examples, text that appears on the screen, or text that you enter.

Preface

ix

Page 10: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

What’s New in This Guide?

These are the updates made to the software and documentation for release12.2.1.3.0.

The updates discussed in this chapter are divided into the following categories:

• Software Updates

This section provides details on the updates made to the connector software.

• Documentation-Specific Updates

This section provides details on the major changes that are made to this guide.These changes are not related to software updates.

Software UpdatesThese are the updates made to the connector software.

Software Updates in Release 12.2.1.3.0

The following is the software update in release 12.2.1.3.0:

Support for Onboarding Applications Using the Connector

From this release onward, the connector bundle includes application onboardingtemplates required for performing connector operations on the SAP SuccessFactorstarget. This helps in quicker onboarding of the applications for SAP SuccessFactorsinto Oracle Identity Governance by using an intuitive UI.

Documentation-Specific UpdatesThese are the updates made to the connector documentation.

Documentation-Specific Updates in Release 12.2.1.3.0

The following are the documentation-specific updates for revision "02" of the guide:

• The "Oracle Identity Governance or Oracle Identity Manager" row of Table 1-1 hasbeen updated to include support for Oracle Identity Governance release 12c PS4(12.2.1.4.0).

• The "Oracle Identity Governance or Oracle Identity Manager JDK", "ConnectorServer", and "Connector Server JDK" rows of Table 1-1 have been updated.

• Several broken links were fixed throughout the document.

The following is a documentation-specific update for revision "01" of the guide:

What’s New in This Guide?

x

Page 11: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

This is the first release of this connector. Therefore, there are no documentation-specific updates in this release.

What’s New in This Guide?

xi

Page 12: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

1About the SAP SuccessFactors Connector

Oracle Identity Governance is a centralized identity management solution thatprovides self service, compliance, provisioning and password management servicesfor applications residing on-premise or on the Cloud. Oracle Identity Governanceconnectors are used to integrate Oracle identity Governance with the external identity-aware applications.

The SAP SuccessFactors connector lets you create and onboard SAPSuccessFactors applications in Oracle Identity Governance.

Note:

In this guide, the connector that is deployed using the Applications optionon the Manage tab of Identity Self Service is referred to as an AOBapplication. The connector that is deployed using the Manage Connectoroption in Oracle Identity System Administration is referred to as a CI-basedconnector (Connector Installer-based connector).

From Oracle Identity Governance release 12.2.1.3.0 onward, connector deployment ishandled using the application onboarding capability of Oracle Identity Self Service.This capability lets business users to onboard applications with minimum details andeffort. The connector installation package includes a collection of predefined templates(XML files) that contain all the information required for provisioning and reconcilingdata from a given application or target system. These templates also include basicconnectivity and configuration details specific to your target system. The connectoruses information from these predefined templates allowing you to onboard yourapplications quickly and easily using only a single and simplified UI.

Application onboarding is the process of registering or associating an applicationwith Oracle Identity Governance and making that application available for provisioningand reconciliation of user information.

The following topics provide a high-level overview of the SAP SuccessFactorsconnector:

• Certified Components

• Usage Recommendation

• Certified Languages

• Supported Connector Operations

• Connector Architecture

• Use Cases Supported by the Connector

• Connector Features

1-1

Page 13: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

1.1 Certified ComponentsThese are the software components and their versions required for installing and usingthe SuccessFactors connector.

Table 1-1 Certified Components

Component Requirement for AOBApplication

Requirement for CI-BasedConnector

Oracle Identity Manager orOracle Identity Governance

You can use any one of thefollowing releases:• Oracle Identity

Governance release 12cPS4 (12.2.1.4.0)

• Oracle IdentityGovernance 12c(12.2.1.3.0)

You can use one of thefollowing releases:

• Oracle IdentityGovernance release 12cPS4 (12.2.1.4.0)

• Oracle IdentityGovernance 12c(12.2.1.3.0)

• Oracle Identity Manager11g Release 2 PS3 BP06(11.1.2.3.6)

• Oracle Identity Manager11g Release 2 PS2 BP09(11.1.2.2.9)

Oracle Identity Governance orOracle Identity Manager JDK

JDK 1.8 or later JDK 1.8 or later

Target systems SAP SuccessFactors SAP SuccessFactors

Connector Server 11.1.2.1.0 or later 11.1.2.1.0 or later

Connector Server JDK JDK 1.8 or later JDK 1.8 or later

1.2 Usage RecommendationThese are the recommendations for the SAP SuccessFactors connector version thatyou can deploy and use depending on the Oracle Identity Governance or OracleIdentity Manager version that you are using.

• If you are using Oracle Identity Governance 12c (12.2.1.3.0), then use the latest12.2.1.x version of this connector. Deploy the connector using the Applicationsoption on the Manage tab of Identity Self Service.

• If you are using any of the Oracle Identity Manager releases listed in the“Requirement for CI-Based Connector” column in Table 1-1, then use the 11.1.xversion of the SAP SuccessFactors connector. If you want to use the 12.1.xversion of this connector, then you can install and use it only in the CI-basedmode. If you want to use the AOB application, then you must upgrade to OracleIdentity Governance release 12.2.1.3.0.

1.3 Certified LanguagesThese are the languages that the connector supports.

• Arabic

Chapter 1Certified Components

1-2

Page 14: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

• Chinese (Simplified)

• Chinese (Traditional)

• Czech

• Danish

• Dutch

• English

• Finnish

• French

• French (Canadian)

• German

• Greek

• Hebrew

• Hungarian

• Italian

• Japanese

• Korean

• Norwegian

• Polish

• Portuguese

• Portuguese (Brazilian)

• Romanian

• Russian

• Slovak

• Spanish

• Swedish

• Thai

• Turkish

1.4 Supported Connector OperationsThese are the list of operations that the connector supports for your target system.

Table 1-2 Supported Connector Operations

Operation Supported

User Management

Create user Yes

Update user Yes

Chapter 1Supported Connector Operations

1-3

Page 15: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 1-2 (Cont.) Supported Connector Operations

Operation Supported

Delete User Yes

Note: In the current release, delete operationis not supported by the target application.When you execute a user-delete operationfrom the connector application, the deleteduser gets disabled on the target application.

Enable User Yes

Disable User Yes

Test Connection Yes

1.5 Connector ArchitectureThe SuccessFactors connector is implemented by using the Identity ConnectorFramework (ICF).

The ICF is a component that is required in order to use Identity Connector. ICFprovides basic reconciliation and provisioning operations that are common to allOracle Identity Governance connectors. In addition, ICF provides common featuresthat developers would otherwise need to implement on their own, such as, buffering,time outs, and filtering. ICF is distributed together with Oracle Identity Governance.Therefore, you do not need to configure or modify ICF.

Figure 1-1 shows the architecture of the SuccessFactors connector.

Figure 1-1 Architecture of the SuccessFactors Connector

The connector is configured to run in one of the following modes:

• Identity reconciliation

Identity reconciliation is also known as authoritative. In this mode, the targetsystem is used as an authoritative source and users are directly created and

Chapter 1Connector Architecture

1-4

Page 16: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

modified on Oracle Identity Governance by reconciliation jobs. Duringreconciliation, a scheduled task invokes an ICF operation. ICF inturn invokes asearch operation on the SuccessFactors Connector Bundle and then the bundlecalls the OData API for reconciliation operation. The API extracts user records thatmatch the reconciliation criteria and hands them over through the bundle and ICFback to the scheduled task, which brings the records to Oracle IdentityGovernance.

Each user record fetched from the target system is compared with existing OracleIdentity Governance Users. If a match is found between the target system recordand the Oracle Identity Governance User, then the Oracle Identity GovernanceUser attributes are updated with changes made to the target system record. If nomatch is found, then the target system record is used to create an Oracle IdentityGovernance User.

• Account management

Account management is also known as target resource management. In thismode, the target system is used as a target resource and the connector enablesthe following operations:

– Provisioning

Provisioning involves creating and updating users on the target systemthrough Oracle Identity Governance. During provisioning, the adapters invokeICF operation, ICF inturn invokes create operation on the SuccessFactorsIdentity Connector Bundle and then the bundle calls the target system API forprovisioning operations. The API on the target system accepts provisioningdata from the bundle, carries out the required operation on the target system,and returns the response from the target system back to the bundle, whichpasses it to the adapters.

– Target resource reconciliation

During reconciliation, a scheduled task invokes an ICF operation. ICF inturninvokes a search operation on the SuccessFactors Identity Connector Bundleand then the bundle calls the target system API for reconciliation operation.The API extracts user records that match the reconciliation criteria and handsthem over through the bundle and ICF back to the scheduled task, whichbrings the records to Oracle Identity Governance.

Each record fetched from the target system is compared with SuccessFactorsresources that are already provisioned to Oracle Identity Governance Users. Ifa match is found, then the update made to the SuccessFactors record fromthe target system is copied to the SuccessFactors resource in Oracle IdentityGovernance. If no match is found, then the user ID of the record is comparedwith the user ID of each Oracle Identity Governance User. If a match is found,then data in the target system record is used to provision a SuccessFactorsresource to the Oracle Identity Governance User.

1.6 Use Cases Supported by the ConnectorThe SAP SuccessFactors application uses the Software as a Service (SaaS) modeland supports full human resource lifecycle functions on a single platform. The SAPSuccessFactors application allows an organization to make various data-driven peoplemanagement decisions. The SAP SuccessFactors connector integrates Oracle IdentityGovernance with SuccessFactors application.

Chapter 1Use Cases Supported by the Connector

1-5

Page 17: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

The SAP SuccessFactors connector standardizes service processes and implementsautomation to replace manual tasks. The SuccessFactors connector enables you touse SuccessFactors either as a managed (target) resource or as an authoritative(trusted) source of identity data for Oracle Identity Governance. Multiple instances ofSuccessFactors solution can use a single connector bundle.

User Management is an example scenario which the SuccessFactors connectorfacilitates:

User Management

An organization using SuccessFactors wants to integrate with Oracle IdentityGovernance to manage the employee provisioning operations. The organization wantsto manage its employee information (add and update functions) by creating them inthe target system using Oracle Identity Governance. The organization also wants tosynchronize employee updates performed directly in the target system with OracleIdentity Governance. In such a scenario, a quick and an easy way is to install theSuccessFactors connector and configure it with your target system by providingconnection information in the IT resource.

The SuccessFactors connector is used to manage various employee attributes suchas email id, hire-date, and job-level.

1.7 Connector FeaturesThe features of the connector include support for connector server, full reconciliation,incremental reconciliation, limited reconciliation, and reconciliation of updates toaccount data.

Table 1-3 provides the list of features supported by the AOB application and CI-basedconnector.

Table 1-3 Supported Connector Features Matrix

Feature AOB Application CI-Based Connector

Full reconciliation Yes Yes

Incremental reconciliation Yes Yes

Support for Trusted SourceReconciliation

Yes Yes

Limited reconciliation Yes Yes

Use connector server Yes Yes

Clone applications or createnew application instances

Yes Yes

Transformation and validationof account data

Yes Yes

Reconcile user account status Yes Yes

Test Connection Yes No

Perform connector operationsin multiple domains

Yes Yes

The following topics provide more information on the features of the AOB application:

• Full and Incremental Reconciliation

Chapter 1Connector Features

1-6

Page 18: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

• Support for Trusted Source Reconciliation

• Limited Reconciliation

• Support for the Connector Server

• Transformation and Validation of Account Data

1.7.1 Full and Incremental ReconciliationAfter you create the connector, you can perform full reconciliation to bring all existinguser data from the target system to Oracle Identity Governance. After the first fullreconciliation run, you can configure your connector for incremental reconciliation. Inincremental reconciliation, only records that are added or modified after the lastreconciliation run are fetched into Oracle Identity Governance.

See Performing Full and Incremental Reconciliation for the Connector.

Note:

The connector supports incremental reconciliation if the target systemcontains an attribute that holds the timestamp at which an object is createdor modified.

1.7.2 Support for Trusted Source ReconciliationThe SuccessFactors connector can be configured as a trusted source for reconciliationof records into Oracle Identity Governance.

1.7.3 Limited ReconciliationTo limit or filter the records that are fetched into Oracle Identity Governance during areconciliation run, you can specify the subset of added or modified target systemrecords that must be reconciled.

You can set a reconciliation filter as the value of the Filter Suffix attribute of the userreconciliation scheduled job. The Filter Suffix attribute helps you to assign filters to theAPI based on which you get a filtered response from the target system.

See Performing Limited Reconciliation for the Connector

1.7.4 Support for the Connector ServerConnector Server is one of the features provided by ICF. By using one or moreconnector servers, the connector architecture permits your application to communicatewith externally deployed bundles.

A Java connector server is useful when you do not wish to execute a Java connectorbundle in the same VM as your application. It can be beneficial to run a Javaconnector on a different host for performance improvements.

For information about installing, configuring, and running the Connector Server, andthen installing the connector in a Connector Server, see Using an Identity Connector

Chapter 1Connector Features

1-7

Page 19: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Server in Oracle Fusion Middleware Developing and Customizing Applications forOracle Identity Governance.

1.7.5 Transformation and Validation of Account DataYou can configure transformation and validation of account data that is brought into orsent from Oracle Identity Governance during reconciliation and provisioning operationsby writing Groovy scripts while creating your application.

For more information, see Validation and Transformation of Provisioning andReconciliation Attributes in Oracle Fusion Middleware Performing Self Service Taskswith Oracle Identity Governance.

Chapter 1Connector Features

1-8

Page 20: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

2Creating an Application by Using the SAPSuccessFactors Connector

Learn about onboarding applications using the connector and the prerequisites fordoing so.

• Process Flow for Creating an Application By Using the Connector

• Prerequisites for Creating an Application By Using the Connector

• Creating an Application By Using the Connector

2.1 Process Flow for Creating an Application By Using theConnector

From Oracle Identity Governance release 12.2.1.3.0 onward, connector deployment ishandled using the application onboarding capability of Identity Self Service.

Figure 2-1 is a flowchart depicting high-level steps for creating an application in OracleIdentity Governance by using the connector installation package.

2-1

Page 21: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Figure 2-1 Overall Flow of the Process for Creating an Application By Using the Connector

Chapter 2Process Flow for Creating an Application By Using the Connector

2-2

Page 22: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

2.2 Prerequisites for Creating an Application By Using theConnector

Learn about the tasks that you must complete before you create the application.

• Registering the Client Application

• Downloading the Connector Installation Package

2.2.1 Registering the Client ApplicationRegistering the client application (that is, the SuccessFactors connector) with thetarget system is a step that is performed so that the connector can access the RESTAPIs. The step includes client application registration, certificate generation, andobtaining clientid and client secret attributes.

Registering the client application involves performing the following tasks on the targetsystem:

Note:

The detailed instructions for performing these preinstallation tasks areavailable in SuccessFactors product documentation at https://support.sap.com/documentation.html/

1. Register your client application with SuccessFactors to provide a secure sign inand authorization of your services. You can register your client application bycreating an application in the SuccessFactors Manage OAuth2 Client Applicationspage.

2. While creating an application, ensure that you provide information in themandatory fields. Fields such as Application Name, Description, Application URL,Common Name (CN), and Validity (Days) are mandatory fields required for theSuccessFactors connector. As a best practice, SuccessFactors recommends touse your company ID as the Common Name (CN) field information. As part ofregistering your client application, a Certificate.pem file gets generated.

3. Make a note of the clientId and client secret information. Post applicationregistration, from the Manage OAuth2 Client Application page you can view theclientId and client secret information. The clientId and client secret info is requiredwhile configuring the Basic Configuration parameters at the time of applicationcreation.

2.2.2 Downloading the Connector Installation PackageYou can obtain the installation package for your connector on the Oracle TechnologyNetwork (OTN) website.

To download the connector installation package:

1. Navigate to the OTN website at http://www.oracle.com/technetwork/middleware/id-mgmt/downloads/connectors-101674.html.

Chapter 2Prerequisites for Creating an Application By Using the Connector

2-3

Page 23: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

2. Click OTN License Agreement and read the license agreement.

3. Select the Accept License Agreement option.

You must accept the license agreement before you can download the installationpackage.

4. Download and save the installation package to any directory on the computerhosting Oracle Identity Governance.

5. Extract the contents of the installation package to any directory on the computerhosting Oracle Identity Governance. This creates a directory namedCONNECTOR_NAME-RELEASE_NUMBER. For example,successfactors-12.2.1.3.0

6. Copy the CONNECTOR_NAME-RELEASE_NUMBER directory to theOIM_HOME/server/ConnectorDefaultDirectory directory.

2.3 Creating an Application By Using the ConnectorYou can onboard an application into Oracle Identity Governance from the connectorpackage by creating a Target application. To do so, you must log in to Identity SelfService and then choose the Applications box on the Manage tab.

The following is the high-level procedure to create an application by using theconnector:

Note:

For detailed information on each of the steps in this procedure, see CreatingApplications of Oracle Fusion Middleware Performing Self Service Taskswith Oracle Identity Governance.

1. Create an application in Identity Self Service. The high-level steps are as follows:

a. Log in to Identity Self Service either by using the System Administrationaccount or an account with the ApplicationInstanceAdministrator adminrole.

b. Ensure that the Connector Package option is selected when creating anapplication.

c. Update the basic configuration parameters to include connectivity-relatedinformation.

d. If required, update the advanced setting parameters to update configurationentries related to connector operations.

e. Review the default user account attribute mappings. If required, add newattributes or you can edit or delete existing attributes.

f. Review the provisioning, reconciliation, organization, and catalog settings foryour application and customize them if required. For example, you cancustomize the default correlation rules for your application if required.

g. Review the details of the application and click Finish to submit the applicationdetails.

The application is created in Oracle Identity Governance.

Chapter 2Creating an Application By Using the Connector

2-4

Page 24: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

h. When you are prompted whether you want to create a default request form,click Yes or No.

If you click Yes, then the default form is automatically created and is attachedwith the newly created application. The default form is created with the samename as the application. The default form cannot be modified later. Therefore,if you want to customize it, click No to manually create a new form and attachit with your application.

2. Verify reconciliation and provisioning operations on the newly created application.

See Also:

• Configuring the SAP SuccessFactors Connector for details on basicconfiguration and advanced settings parameters, default user accountattribute mappings, default correlation rules, and reconciliation jobs thatare predefined for this connector

• Configuring Oracle Identity Governance for details on creating a newform and associating it with your application, if you chose not to createthe default form

Chapter 2Creating an Application By Using the Connector

2-5

Page 25: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

3Configuring the SAP SuccessFactorsConnector

While creating an application, you must configure connection-related parameters thatthe connector uses to connect Oracle Identity Governance with your target system andperform connector operations. In addition, you can view and edit attribute mappingsbetween the process form fields in Oracle Identity Governance and target systemcolumns, predefined correlation rules, situations and responses, and reconciliationjobs.

This section contains the following topics:

• Basic Configuration Parameters

• Advanced Setting Parameters

• Attribute Mappings

• Correlation Rules

• Reconciliation Jobs

3.1 Basic Configuration ParametersThese are the connection-related parameters that Oracle Identity Governance requiresto connect to the SAP SuccessFactor target application.

Note:

• Unless specified, the parameters in the table are applicable to bothtarget and authoritative applications.

• In the following table, attributes marked as mandatory are applicableonly for Basic authentication. For oauth_saml authentication, allattributes are mandatory except the password, port and ConnectorServer Name attributes.

3-1

Page 26: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 3-1 Parameters in the Basic Configuration

Parameter Mandatory? Description

authenticationType Yes Type of authentication used byyour target system. Thisconnector supports the targetsystem OAuth2.0 clientcredentials.

Default value: oauth_saml

Note: Based on requirement,the default value can bemodified to Basicauthentication.

companyId Yes Enter the company ID for userprovisioning. During licensingof SuccessFactors solution, aunique company ID isprovided. The OData API usesthe company ID attribute tovalidate your access token.

Host Yes Enter the host name of thecomputer hosting your targetsystem.

Samplevalue: apisalesdemo4.successfactors.com

sslEnabled Yes If the target system requiresSSL connectivity, then set thevalue of this parameterto true. Otherwise set thevalue to false.

Default value: true

username Yes Enter the username which haspermissions to perform all theIdentity Management featuresusing APIs.

When you purchase aSandbox, this username isprovided by the SAPSuccessFactors organization.

Sample value: johnsmith

authenticationServerUrl No Enter the URL of theauthentication server thatvalidates the client ID andclient secret for your targetsystem.

Samplevalue: https://apisalesdemo4.successfactors.com/oauth/token?

Chapter 3Basic Configuration Parameters

3-2

Page 27: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 3-1 (Cont.) Parameters in the Basic Configuration

Parameter Mandatory? Description

authorizationUrl No Authorization URL is the URLwhich returns the accesstoken. Ensure that you providecorrect parameters and theirvalues to receive an accesstoken.

Sample value:https://apisalesdemo4.successfactors.com/oauth/idp

clientId No Enter the client identifier (aunique string) issued by theauthorization server to yourclient application during theregistration process. Youobtained the client ID whileperforming.

clientUrl No This is the attribute thatprovides the Sandbox URL.This Sandbox URL needs tobe registered with the targetresource.

Sample value: https://apisalesdemo4.successfactors.com

privateKeyLocation No Enter location of thecertificate.

During the client applicationcreation process, a certificategets stored.

Connector Server Name No If you have deployed theSuccessFactors connector inthe Connector Server, thenenter the name of the ITresource for the ConnectorServer.

Chapter 3Basic Configuration Parameters

3-3

Page 28: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 3-1 (Cont.) Parameters in the Basic Configuration

Parameter Mandatory? Description

grantType No The most important step for anapplication in the OAuth flowis how the application receivesan access token (andoptionally a refresh token). Agrant type is the mechanismused to retrieve the token.OAuth defines severaldifferent access grant typesthat represent differentauthorization mechanisms.

Default value:urn:ietf:params:oauth:grant-type:saml2-bearer

Password Yes Enter the password of thecomputer hosting your targetsystem.

Port No Enter the port number atwhich the target system islistening.

Sample value: 443

3.2 Advanced Setting ParametersThe advanced setting parameters for the SAP SuccessFactors configuration varydepending on whether you are creating a target application or an authoritativeapplication These are the configuration-related entries that the connector uses duringreconciliation and provisioning operations.

Note:

• Unless specified, the parameters in the table are applicable to bothtarget and authoritative applications.

• All parameters in the below table are mandatory.

Table 3-2 Advanced Setting Parameters for the SAP SuccessFactors

Parameter Description

lookupUrl This the endpoint URL used to reconcilelookup data from the target system.

Default value: /odata/v2/FOJobCode?$select=externalCode,name,jobFunction,jobLevel

Chapter 3Advanced Setting Parameters

3-4

Page 29: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 3-2 (Cont.) Advanced Setting Parameters for the SAP SuccessFactors

Parameter Description

upsertUrl This entry holds the value of endpoint URLthat is used for performing any upsertoperation on the user account.

Default value: /odata/v2/upsert

reconUrl This entry holds the value of endpoint URLthat is used to reconcile users from the targetresource.

Default value:

/odata/v2/User?$format=JSON&$filter=status%20ne%20'p'

userUrl This entry holds the value of endpoint URLthat is used to perform the create useroperation.

Default value: /odata/v2/User

Bundle Name This entry holds the name of the connectorbundle.

Default value:org.identityconnectors.successfactors

Bundle Version This entry holds the version of the connectorbundle.

Default value: 12.3.0

Connector Name This entry holds the name of the connector.

Default value:org.identityconnectors.successfactors.SuccessFactorsConnector

customURIs This entry holds the customURIs of theconnector.

Default value: "EmpJob=/odata/v2/EmpJob?$filter=userId%20eq%20'(Username)'","PerPersonal=/odata/v2/PerPersonal?$filter=personIdExternal%20eq%20'(Username)'","UserEntity=/odata/v2/User?$filter=status%20ne%20'p'%20and%20userId%20eq%20'(Username)'","EmpEmployment=/odata/v2/EmpEmployment?$filter=userId%20eq%20'(Username)'","PerPerson=/odata/v2/PerPerson?$filter=personIdExternal%20eq%20'(Username)'"

Chapter 3Advanced Setting Parameters

3-5

Page 30: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 3-2 (Cont.) Advanced Setting Parameters for the SAP SuccessFactors

Parameter Description

objectMetadatas This entry holds a comma separated list ofobject metadata information. Duringprovisioning, each object requires a metadataentry in the payload. The metadata value isunique for each object entity.

Default value:

"UserEntity={\"uri\":\"User('Username')\"}","PerPerson={\"uri\":\"PerPerson('Username')\"}","EmpEmployment={\"uri\":\"EmpEmployment(personIdExternal='Username',userId='Username')\"}","EmpJob={\"uri\":\"EmpJob(userId='Username',startDate=datetime'DateTime')\"}","PerPersonal={\"uri\":\"PerPersonal(personIdExternal='Username',startDate=datetime'DateTime')\"}"

3.3 Attribute MappingsThe attribute mappings on the Schema page vary depending on whether you arecreating a target application or a trusted application.

• Attribute Mappings for the Target Application

• Attribute Mappings for the Authoritative Application

3.3.1 Attribute Mappings for the Target ApplicationThe schema page for a target application displays the default schema (provided by theconnector) that maps Oracle Identity Governance attributes to target system columns.The connector uses these mappings during reconciliation and provisioning operations.

Default Attributes for SAP SuccessFactors Target Application

Table 3-3 lists the user-specific attribute mappings between the process form fields inOracle Identity Governance and SAP SuccessFactors target application columns.

If required, you can edit the default attribute mappings by adding new attributes ordeleting existing attributes as described in Creating a Target Application in OracleFusion Middleware Performing Self Service Tasks with Oracle Identity Governance.

Chapter 3Attribute Mappings

3-6

Page 31: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 3-3 Default Attributes for SAP SuccessFactors Target Application

DisplayName

TargetAttribute

DataType

MandatoryProvisioningProperty?

ProvisionField?

ReconField?

KeyField?

CaseInsensitive?

Username __NAME__

String Yes Yes Yes Yes Yes

Password UserEntity.password

String No Yes No No NA

Server Long Yes No Yes Yes NA

FirstName

PerPersonal.firstName

String Yes Yes Yes No NA

LastName

PerPersonal.lastName

String Yes Yes Yes No NA

Email UserEntity.email

String No Yes Yes No NA

Country UserEntity.country

String No Yes Yes No NA

State UserEntity.state

String No Yes Yes No NA

City UserEntity.city

String No Yes Yes No NA

Citizenship

UserEntity.citizenship

String No Yes Yes No NA

EmployeeId

UserEntity.empId

String No Yes Yes No NA

HR UserEntity.hr

String No Yes Yes No NA

Job Level UserEntity.jobLevel

String No Yes Yes No NA

Gender PerPersonal.gender

String No Yes Yes No NA

Company EmpJob.company

String Yes Yes Yes No NA

Department

EmpJob.department

String No Yes Yes No NA

JobClassification

EmpJob.jobCode

String Yes Yes Yes No NA

Division EmpJob.division

String No Yes Yes No NA

Location EmpJob.location

String No Yes Yes No NA

EventReason

EmpJob.eventReason

String Yes Yes Yes No NA

Chapter 3Attribute Mappings

3-7

Page 32: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 3-3 (Cont.) Default Attributes for SAP SuccessFactors Target Application

DisplayName

TargetAttribute

DataType

MandatoryProvisioningProperty?

ProvisionField?

ReconField?

KeyField?

CaseInsensitive?

BusinessUnit

EmpJob.businessUnit

String Yes Yes Yes No NA

Supervisor

EmpJob.managerId

String Yes Yes Yes No NA

Hire Date EmpEmployment.startDate

String Yes Yes Yes No NA

Termination Date

EmpEmployment.endDate

String No No Yes No NA

Person Id __UID__ String No Yes Yes No NA

Married UserEntity.married

String No Yes Yes No NA

Status __ENABLE__

String No No Yes No NA

Figure 3-1 shows the default User account attribute mappings.

Chapter 3Attribute Mappings

3-8

Page 33: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Figure 3-1 Default Attribute Mappings for SAP SuccessFactors Target User Account

Chapter 3Attribute Mappings

3-9

Page 34: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

3.3.2 Attribute Mappings for the Authoritative ApplicationThe Schema page for an authoritative application displays the default schema(provided by the connector) that maps Oracle Identity Governance attributes to targetsystem columns. The connector uses these mappings during reconciliation operations.

Table 3-4 lists the user-specific attribute mappings between the reconciliation fields inOracle Identity Governance and SAP SuccessFactors columns. The table also lists thedata type for a given attribute and specified whether it is a mandatory attribute forreconciliation.

If required, you can edit the default attribute mappings by adding new attributes ordeleting existing attributes as described in Creating an Authoritative Application inOracle Fusion Middleware Performing Self Service Tasks with Oracle IdentityGovernance.

You may use the default schema that has been set for you or update and change itbefore continuing to the next step.

The Organization Name, Xellerate Type, and Role identity attributes are mandatoryfields on the OIG User form. They cannot be left blank during reconciliation. The targetattribute mappings for these identity attributes are empty by default because there areno corresponding columns in the target system.

Table 3-4 Default Attributes for SAP SuccessFactors Authoritative Application

IdentityDisplayName

TargetAttribute

Data Type MandatoryReconProperty?

Recon Field? Default Valuefor IdentityDisplayName

End Date EmpEmployment.endDate

Date No Yes NA

Hire Date EmpEmployment.startDate

Date No Yes NA

Role String No Yes Full-Time

OrganizationName

String No Yes XellerateUsers

Xellerate Type String No Yes End-User

First Name PerPersonal.firstName

String No Yes NA

Last Name PerPersonal.lastName

String No Yes NA

User Login __NAME__ String No Yes NA

Display Name __UID__ String No Yes NA

Status __ENABLE__ String No Yes NA

Email UserEntity.email

String No Yes NA

Figure 3-2 shows the default User account attribute mappings.

Chapter 3Attribute Mappings

3-10

Page 35: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Figure 3-2 Default Attributes for SAP SuccessFactors Authoritative Application

3.4 Correlation RulesLearn about the predefined rules, responses and situations for Target and Trustedapplications. The connector use these rules and responses for performingreconciliation.

• Correlation Rules for the Target Application

• Correlation Rules for an Authoritative Application

3.4.1 Correlation Rules for the Target ApplicationWhen you create a target application, the connector uses correlation rules todetermine the identity to which Oracle Identity Governance must assign a resource.

Predefined Identity Correlation Rules

By default, the SAP SuccessFactors connector provides a simple correlation rule whenyou create a target application. The connector uses this correlation rule to comparethe entries in Oracle Identity Governance repository and the target system repository,determine the difference between the two repositories, and apply the latest changes toOracle Identity Governance.

Table 3-5 lists the default simple correlation rule for SAP SuccessFactors connector. Ifrequired, you can edit the default correlation rule or add new rules. You can createcomplex correlation rules also. For more information about adding or editing simple or

Chapter 3Correlation Rules

3-11

Page 36: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

complex correlation rules, see Creating a Target Application in Oracle FusionMiddleware Performing Self Service Tasks with Oracle Identity Governance.

Table 3-5 Predefined Identity Correlation Rule for SAP SuccessFactorsConnector

Target Attribute Element Operator Identity Attribute Case Sensitive?

__NAME__ Equals User Login No

In this identity rule:

• __NAME__ is a single-valued attribute on the target system that identifies the useraccount.

• User Login is the field on the OIM User form.

• Rule operator: AND

Figure 3-3 shows the simple correlation rule for SAP SuccessFactors targetapplication.

Figure 3-3 Simple Correlation Rule for SAP SuccessFactors Application

Predefined Situations and Responses

The SAP SuccessFactors connector provides a default set of situations and responseswhen you create a target application. These situations and responses specify theaction that Oracle Identity Governance must take based on the result of areconciliation event.

Table 3-6 lists the default situations and responses for SAP SuccessFactors targetapplication. If required, you can edit these default situations and responses or add newones. For more information about adding or editing situations and responses, see Creating a Target Application in Oracle Fusion Middleware Performing Self ServiceTasks with Oracle Identity Governance

Chapter 3Correlation Rules

3-12

Page 37: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 3-6 Predefined Situations and Responses for SAP SuccessFactorsTarget Application

Situation Response

No Matches Found None

One Entity Match Found Establish Link

One Process Match Found Establish Link

Figure 3-4 shows the situations and responses for SAP SuccessFactors that theconnector provides by default.

Figure 3-4 Predefined Situations and Responses for SAP SuccessFactors Target Application

3.4.2 Correlation Rules for an Authoritative ApplicationWhen you create an authoritative application, the connector uses correlation rules todetermine the identity to which Oracle Identity Governance must assign a resource.

Predefined Identity Correlation Rules

By default, the SAP SuccessFactors connector provides a simple correlation rule whenyou create an authoritative application. The connector uses this correlation rule tocompare the entries in Oracle Identity Governance repository and the authoritativeapplication repository, determine the difference between the two repositories, andapply the latest changes to Oracle Identity Governance.

Table 3-7 lists the default simple correlation rule for SAP SuccessFactors connector. Ifrequired, you can edit the default correlation rule or add new rules. You can createcomplex correlation rules also. For more information about adding or editing simple orcomplex correlation rules, see Creating a Target Application in Oracle FusionMiddleware Performing Self Service Tasks with Oracle Identity Governance.

Chapter 3Correlation Rules

3-13

Page 38: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 3-7 Predefined Identity Correlation Rule for SAP SuccessFactorsAuthoritative Application

AuthoritativeAttribute

Element Operator Identity Attribute Case Sensitive?

_Name_ Equals User Login No

In the correlation rule element:

• __Name__ is an attribute on the target system that uniquely identifies the useraccount.

• User Login is the field on the OIM User form.

• Rule operator: AND

Figure 3-5 shows the simple correlation rule for SAP SuccessFactors Authoritativeapplication.

Figure 3-5 Simple Correlation Rule for SAP SuccessFactors Authoritative Application

Predefined Situations and Responses

The SAP SuccessFactors connector provides a default set of situations and responseswhen you create an authoritative application. These situations and responses specifythe action that Oracle Identity Governance must take based on the result of areconciliation event.

Table 3-8 lists the default situations and responses for SAP SuccessFactorsAuthoritative Application. If required, you can edit these default situations andresponses or add new ones. For more information about adding or editing situationsand responses, see Creating a Target Application in Oracle Fusion MiddlewarePerforming Self Service Tasks with Oracle Identity Governance.

Chapter 3Correlation Rules

3-14

Page 39: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 3-8 Predefined Situations and Responses for SAP SuccessFactorsAuthoritative Application

Situation Response

No Matches Found Create User

One Entity Match Found Establish Link

One Process Match Found Establish Link

Figure 3-6 shows the situations and responses for SAP SuccessFactors that theconnector provides by default.

Figure 3-6 Predefined Situations and Responses for the SAP SuccessFactors AuthoritativeApplication

3.5 Reconciliation JobsThese are the reconciliation jobs that are automatically created in Oracle IdentityGovernance after you create the application.

Depending on whether you want to implement authoritative source or target resourcereconciliation, you must specify values for the attributes of one of the following userreconciliation scheduled jobs.

• SAP SuccessFactors Target Resource User Reconciliation

This scheduled job is used to reconcile user data in the target resource (accountmanagement) mode of the connector.

• SAP SuccessFactors Authoritative User Reconciliation

This scheduled job is used to reconcile user data in an authoritative source(identity management) mode of the connector.

User Reconciliation Job

Table 3-10 describes the parameters of Target User Reconciliation job.

Chapter 3Reconciliation Jobs

3-15

Page 40: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 3-9 Parameters of the Scheduled Job for Target User Reconciliation

Attribute Description

Application Name Name of the application you created for yourtarget system. This value is the same as thevalue that you provided for the ApplicationName field while creating your targetapplication.

Do not modify this value.

Object Type Type of object you want to reconcile.

Default value: User

Filter Suffix Enter the search filter for fetching user recordsfrom the target system during a reconciliationrun.

Sample value: userId eq 'personId'

Note: This sample value is not mandatory andis used for limited reconciliation.

Scheduled Task Name Name of the scheduled job.

Note: For the scheduled job included with thisconnector, you must not change the value ofthis attribute. However, if you create a new jobor create a copy of the job, then enter theunique name for that scheduled job as thevalue of this attribute.

Incremental Recon Attribute Name of the target system column that holdsholds the timestamp at which the user recordwas modified.

Default value: lastModifiedDateTime

Latest Token The parameter holds the value of the targetsystem column that is specified as the value ofthe Incremental Recon Attribute parameter.The Latest Token parameter is used forinternal purposes. By default, this value isempty.

Table 3-10 describes the parameters of Authoritative User Reconciliation job.

Table 3-10 Parameters of the Scheduled Job for Authoritative UserReconciliation

Attribute Description

Application Name Name of the application you created for yourtrusted application. This value is the same asthe value that you provided for the ApplicationName field while creating your trustedapplication.

Do not modify this value.

Chapter 3Reconciliation Jobs

3-16

Page 41: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 3-10 (Cont.) Parameters of the Scheduled Job for Authoritative UserReconciliation

Attribute Description

Scheduled Task Name This parameter holds the name of thescheduled task.

Default value: <Application Name>Trusted User Reconciliation

Filter Suffix Enter the search filter for fetching user recordsfrom the target system during a reconciliationrun.

Sample value: 0

Object Type Type of object you want to reconcile.

Default value: User

Incremental Recon Attribute Name of the target system column that holdsholds the timestamp at which the user recordwas modified.

Default value: lastModifiedDateTime

Latest Token The parameter holds the value of the targetsystem column that is specified as the value ofthe Incremental Recon Attribute. The LatestToken parameter is used for internal purposes.By default, this value is empty.

Reconciliation Jobs for Lookup Field Synchronization

These lookup definitions are used as an input source for lookup fields in OracleIdentity Governance.

The following scheduled jobs are used for lookup fields synchronization:

• SuccessFactors HR Lookup Reconciliation Scheduled Job

• SuccessFactors JobLevel Lookup Reconciliation Scheduled Job

• SuccessFactors Supervisor Lookup Reconciliation Scheduled Job

These reconciliation jobs are available only for a target application. The parameters forall the reconciliation jobs are the same.

The parameters for all the scheduled jobs for lookup field synchronization are thesame. Table 3-11describes the parameters of the scheduled jobs.

Table 3-11 Parameters of the Scheduled Jobs for Lookup FieldSynchronization

Attribute Description

Application Name Name of the application you created for yourtarget system. This value is the same as thevalue that you provided for the ApplicationName field while creating your targetapplication.

Do not modify this value.

Chapter 3Reconciliation Jobs

3-17

Page 42: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 3-11 (Cont.) Parameters of the Scheduled Jobs for Lookup FieldSynchronization

Attribute Description

Lookup Name Enter the name of the lookup definition inOracle Identity Governance that must bepopulated with values fetched from the targetsystem.

Object Type Type of object you want to reconcile.

Sample values: HR, JobLevel,Supervisor

Code Key Attribute Name of the connector attribute that is used topopulate the Code Key column of the lookupdefinition (specified as the value of the LookupName attribute).Default value: __UID__

Decode Attribute Name of the connector attribute that is used topopulate the Decode column of the lookupdefinition (specified as the value of the LookupName attribute).Default value :__NAME__

Chapter 3Reconciliation Jobs

3-18

Page 43: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

4Performing the Postconfiguration Tasks forthe SAP SuccessFactors Connector

These are the tasks that you must perform after creating an application in OracleIdentity Governance..

The following topics discuss the Postconfiguration procedures:

• Configuring Oracle Identity Governance

• Harvesting Entitlements and Sync Catalog

• Managing Logging

• Configuring the IT Resource for the Connector Server

• Localizing Field Labels in UI Forms

• Configuring SSL

4.1 Configuring Oracle Identity GovernanceDuring application creation, if you did not choose to create a default form, then youmust create a UI form for the application that you created by using the connector.

Note:

Perform the procedures described in this section only if you did not choose tocreate the default form during creating the application.

The following topics describe the procedures to configure Oracle Identity Governance:

• Creating and Activating a Sandbox

• Creating a New UI Form

• Publishing a Sandbox

• Updating an Existing Application Instance with a New Form

4.1.1 Creating and Activating a SandboxYou must create and activate a sandbox to begin using the customization and formmanagement features. You can then publish the sandbox to make the customizationsavailable to other users.

See Creating a Sandbox and Activating a Sandbox in Oracle Fusion MiddlewareDeveloping and Customizing Applications for Oracle Identity Governance.

4-1

Page 44: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

4.1.2 Creating a New UI FormYou can use Form Designer in Oracle Identity System Administration to create andmanage application instance forms.

See Creating Forms By Using the Form Designer in Oracle Fusion MiddlewareAdministering Oracle Identity Governance.

While creating the UI form, ensure that you select the resource object correspondingto the newly created application that you want to associate the form with. In addition,select the Generate Entitlement Forms check box.

4.1.3 Publishing a SandboxBefore publishing a sandbox, perform this procedure as a best practice to validate allsandbox changes made till this stage as it is difficult to revert the changes after asandbox is published.

1. In Identity System Administration, deactivate the sandbox.

2. Log out of Identity System Administration.

3. Log in to Identity Self Service using the xelsysadm user credentials and thenactivate the sandbox that you deactivated in Step 1.

4. In the Catalog, ensure that the application instance form for your resource appearswith correct fields.

5. Publish the sandbox. See Publishing a Sandbox in Oracle Fusion MiddlewareDeveloping and Customizing Applications for Oracle Identity Governance.

4.1.4 Updating an Existing Application Instance with a New FormFor any changes that you do in the schema of your application in Identity Self Service,you must create a new UI form and update the changes in an application instance.

To update an existing application instance with a new form:

1. Create and activate a sandbox.

2. Create a new UI form for the resource.

3. Open the existing application instance.

4. In the Form field, select the new UI form that you created.

5. Save the application instance.

6. Publish the sandbox.

Chapter 4Configuring Oracle Identity Governance

4-2

Page 45: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

See Also:

• Creating a Sandbox and Activating a Sandbox in Oracle FusionMiddleware Developing and Customizing Applications for Oracle IdentityGovernance

• Creating Forms By Using the Form Designer in Oracle FusionMiddleware Administering Oracle Identity Governance

• Publishing a Sandbox in Oracle Fusion Middleware Developing andCustomizing Applications for Oracle Identity Governance

4.2 Harvesting Entitlements and Sync CatalogYou can populate Entitlement schema from child process form table, and harvestroles, application instances, and entitlements into catalog. You can also load catalogmetadata.

To harvest entitlements and sync catalog:

1. Run the scheduled jobs for lookup field synchronization.

2. Run the Entitlement List scheduled job to populate Entitlement Assignmentschema from child process form table.

3. Run the Catalog Synchronization Job scheduled job.

See Also:

• Reconciliation Jobs for more information on lookup fieldsynchronization list

• Predefined Scheduled Tasks in Oracle Fusion MiddlewareAdministering Oracle Identity Goverance for information about theEntitlement List and Catalog Synchronization Job scheduled jobs

4.3 Managing LoggingOracle Identity Governance uses the Oracle Diagnostic Logging (ODL) logging servicefor recording all types of events pertaining to the connector.

The following topics provide detailed information about logging:

• Understanding Log Levels

• Enabling Logging

Chapter 4Harvesting Entitlements and Sync Catalog

4-3

Page 46: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

4.3.1 Understanding Log LevelsWhen you enable logging, Oracle Identity Governance automatically stores in a log fileinformation about events that occur during the course of provisioning andreconciliation operations.

ODL is the principle logging service used by Oracle Identity Governance and is basedon java.util.logger. To specify the type of event for which you want logging to takeplace, you can set the log level to one of the following:

• SEVERE.intValue()+100

This level enables logging of information about fatal errors.

• SEVERE

This level enables logging of information about errors that might allow OracleIdentity Governance to continue running.

• WARNING

This level enables logging of information about potentially harmful situations.

• INFO

This level enables logging of messages that highlight the progress of theapplication.

• CONFIG

This level enables logging of information about fine-grained events that are usefulfor debugging.

• FINE, FINER, FINEST

These levels enable logging of information about fine-grained events, whereFINEST logs information about all events.

These message types are mapped to ODL message type and level combinations asshown in Table 4-2.

Table 4-1 Log Levels and ODL Message Type:Level Combinations

Java Level ODL Message Type:Level

SEVERE.intValue()+100 INCIDENT_ERROR:1

SEVERE ERROR:1

WARNING WARNING:1

INFO NOTIFICATION:1

CONFIG NOTIFICATION:16

FINE TRACE:1

FINER TRACE:16

Table 4-2 Log Levels and ODL Message Type:Level Combinations

Java Level ODL Message Type:Level

SEVERE.intValue()+100 INCIDENT_ERROR:1

Chapter 4Managing Logging

4-4

Page 47: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 4-2 (Cont.) Log Levels and ODL Message Type:Level Combinations

Java Level ODL Message Type:Level

SEVERE ERROR:1

WARNING WARNING:1

INFO NOTIFICATION:1

CONFIG NOTIFICATION:16

FINE TRACE:1

FINER TRACE:16

FINEST TRACE:32

The configuration file for OJDL is logging.xml, which is located at the following path:

DOMAIN_HOME/config/fmwconfig/servers/OIM_SERVER/logging.xml

Here, DOMAIN_HOME and OIM_SERVER are the domain name and server namespecified during the installation of Oracle Identity Governance.

4.3.2 Enabling LoggingTo enable logging in Oracle WebLogic Server:

1. Edit the logging.xml file as follows:

a. Add the following blocks in the file:

<log_handler name='SuccessFactors-handler' level='[LOG_LEVEL]'class='oracle.core.ojdl.logging.ODLHandlerFactory'> <property name='logreader:' value='off'/> <property name='path' value='[FILE_NAME]'/> <property name='format' value='ODL-Text'/> <property name='useThreadName' value='true'/> <property name='locale' value='en'/> <property name='maxFileSize' value='5242880'/> <property name='maxLogSize' value='52428800'/> <property name='encoding' value='UTF-8'/></log_handler>

<logger name="ORG.IDENTITYCONNECTORS.SuccessFactors" level="[LOG_LEVEL]" useParentHandlers="false"> <handler name="SuccessFactors-handler"/> <handler name="console-handler"/></logger>

b. Replace both occurrences of [LOG_LEVEL] with the ODL message type andlevel combination that you require. Table 4-2 lists the supported message typeand level combinations. Similarly, replace [FILE_NAME] with the full path and

Chapter 4Managing Logging

4-5

Page 48: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

name of the log file in which you want log messages to be recorded. Thefollowing blocks show sample values for [LOG_LEVEL] and [FILE_NAME]:

<log_handler name='SuccessFactors-handler' level='NOTIFICATION:1'class='oracle.core.ojdl.logging.ODLHandlerFactory'> <property name='logreader:' value='off'/> <property name='path' value='F:\MyMachine\middleware\user_projects\domains\base_domain1\servers\oim_server1\logs\oim_server1-diagnostic-1.log'/> <property name='format' value='ODL-Text'/> <property name='useThreadName' value='true'/> <property name='locale' value='en'/> <property name='maxFileSize' value='5242880'/> <property name='maxLogSize' value='52428800'/> <property name='encoding' value='UTF-8'/></log_handler> <logger name="ORG.IDENTITYCONNECTORS.SuccessFactors" level="NOTIFICATION:1" useParentHandlers="false"> <handler name="SuccessFactors-handler"/> <handler name="console-handler"/></logger>

With these sample values, when you use Oracle Identity Governance, allmessages generated for this connector that are of a log level equal to or higherthan the NOTIFICATION:1 level are recorded in the specified file.

2. Save and close the file.

3. Set the following environment variable to redirect the server logs to a file:

• For Microsoft Windows: set WLS_REDIRECT_LOG=FILENAME

• For UNIX: export WLS_REDIRECT_LOG=FILENAME

Replace FILENAME with the location and name of the file to which you want toredirect the output.

4. Restart the application server.

4.4 Configuring the IT Resource for the Connector ServerIf you have used the Connector Server, then you must configure values for theparameters of the Connector Server IT resource.

After you create the application for your target system, the connector creates a defaultIT resource for the Connector Server. The name of this default IT resource isSuccessFactors Connector Server.

In Oracle Identity System Administration, search for and edit the SuccessFactorsConnector Server IT resource to specify values for the parameters of IT resource forthe Connector Server listed in Table 4-3. For more information about searching for ITresources and updating its parameters, see Managing IT Resources in Oracle FusionMiddleware Administering Oracle Identity Governance.

Chapter 4Configuring the IT Resource for the Connector Server

4-6

Page 49: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table 4-3 Parameters of the IT Resource for the SAP SuccessFactors Connector Server

Parameter Description

Host Enter the host name or IP address of the computer hosting the Connector Server.

Sample value: HostName

Key Enter the key for the Connector Server.

Port Enter the number of the port at which the Connector Server is listening.

Sample value: 8763

Timeout Enter an integer value which specifies the number of milliseconds after which theconnection between the Connector Server and Oracle Identity Governance timesout.

If the value is zero or if no value is specified, the timeout is unlimited.

Sample value: 0 (recommended value)

UseSSL Enter true to specify that you will configure SSL between Oracle IdentityGovernance and the Connector Server. Otherwise, enter false.

Default value: false

Note: It is recommended that you configure SSL to secure communication withthe connector server. To configure SSL, see Setting SSL for Connector Serverand OIM in Oracle Fusion Middleware Developing and Customizing Applicationsfor Oracle Identity Governance.

4.5 Localizing Field Labels in UI FormsYou can localize UI form field labels by using the resource bundle corresponding to thelanguage you want to use. Resource bundles are available in the connector installationmedia.

To localize field label that you add to in UI forms:

1. Log in to Oracle Enterprise Manager.

2. In the left pane, expand Application Deployments and then selectoracle.iam.console.identity.sysadmin.ear.

3. In the right pane, from the Application Deployment list, select MDS Configuration.

4. On the MDS Configuration page, click Export and save the archive(oracle.iam.console.identity.sysadmin.ear_V2.0_metadata.zip) to the localcomputer.

5. Extract the contents of the archive, and open the following file in a text editor:

SAVED_LOCATION\xliffBundles\oracle\iam\ui\runtime\BizEditorBundle.xlf

Note:

You will not be able to view the BizEditorBundle.xlf unless you completecreating the application for your target system or perform anycustomization such as creating a UDF.

Chapter 4Localizing Field Labels in UI Forms

4-7

Page 50: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

6. Edit the BizEditorBundle.xlf file in the following manner:

a. Search for the following text:

<file source-language="en" original="/xliffBundles/oracle/iam/ui/runtime/BizEditorBundle.xlf" datatype="x-oracle-adf">

b. Replace with the following text:

<file source-language="en" target-language="LANG_CODE" original="/xliffBundles/oracle/iam/ui/runtime/BizEditorBundle.xlf" datatype="x-oracle-adf">

In this text, replace LANG_CODE with the code of the language that you wantto localize the form field labels. The following is a sample value for localizingthe form field labels in Japanese:

<file source-language="en" target-language="ja" original="/xliffBundles/oracle/iam/ui/runtime/BizEditorBundle.xlf" datatype="x-oracle-adf">

c. Search for the application instance code. This procedure shows a sample editfor SuccessFactors Application instance. The original code is:

<trans-unit id="${adfBundle['oracle.adf.businesseditor.model.util.BaseRuntimeResourceBundle']['persdef.sessiondef.oracle.iam.ui.runtime.form.model.user.entity.userEO.UD_USER_NAME__c_description']}"><source>User Name</source><target/></trans-unit><trans-unit id="sessiondef.oracle.iam.ui.runtime.form.model.RSAForm.entity.SuccessFactorsFormEO.UD_USER_NAME __c_LABEL"><source>First Name</source><target/></trans-unit>

d. Open the resource file from the connector package, for exampleSuccessFactors_ja.properties, and get the value of the attribute from the file,for example,

global.udf.UD_GA_USR_ USER_NAME =\u30A2\u30AB\u30A6\u30F3 \u30C8\u540D.

e. Replace the original code shown in Step 6.c with the following:

<trans-unit id="${adfBundle['oracle.adf.businesseditor.model.util.BaseRuntimeResourceBu ndle']['persdef.sessiondef.oracle.iam.ui.runtime.form.model.user.entity.use rEO.UD_GA_USR_ USER_NAME __c_description']}"><source>Account Name</source> <target>u30A2\u30AB\u30A6\u30F3\u30C8\u540D</target></trans-unit> <trans-unitid="sessiondef.oracle.iam.ui.runtime.form.model.SuccessFactors.entity sEO.UD_GA_USR_ACCOUNT_NAME__c_LABEL">

Chapter 4Localizing Field Labels in UI Forms

4-8

Page 51: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

<source>Account Name</source> <target>\u30A2\u30AB\u30A6\u30F3\u30C8\u540D</target> </trans-unit>

f. Repeat Steps 6.a through 6.d for all attributes of the process form.

g. Save the file as BizEditorBundle_LANG_CODE.xlf. In this file name, replaceLANG_CODE with the code of the language to which you are localizing.Sample file name: BizEditorBundle_ja.xlf.

7. Repackage the ZIP file and import it into MDS.

8. Log out of Oracle Enterprise Manager and log in to Oracle Identity Governance.

4.6 Configuring SSLYou configure SSL to secure data communication between Oracle IdentityGovernance and the target system.

To configure SSL:

1. Obtain the SSL public key certificate of SuccessFactors.

2. Copy the public key certificate of SuccessFactors to the computer hosting OracleIdentity Governance.

3. Run the following keytool command to import the public key certificate into theidentity key store in Oracle Identity Governance:

keytool -import -alias ALIAS -trustcacerts -file CERT_FILE_NAME -keystore KEYSTORE_NAME -storepass PASSWORDIn this command:

• ALIAS is the public key certificate alias.

• CERT_FILE_NAME is the full path and name of the certificate store (thedefault is cacerts).

• KEYSTORE_NAME is the name of the keystore.

• PASSWORD is the password of the keystore.

The following is a sample value for this command:

keytool -import -alias serverwl -trustcacerts -file supportcert.pem -keystore client_store.jks -storepass example_password

Note:

• Change the parameter values passed to the keytool commandaccording to your requirements. Ensure that there is no line break inthe keytool arguments.

• Ensure that the system date for Oracle Identity Governance is insync with the validity date of the SSL certificate to avoid any errorsduring SSL communication.

Chapter 4Configuring SSL

4-9

Page 52: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

5Using the SAP SuccessFactors Connector

You can use the connector for performing reconciliation and provisioning operationsafter configuring it to meet your requirements.

The following topics are discussed in this chapter:

Note:

These sections provide both conceptual and procedural information aboutconfiguring the connector. It is recommended that you read the conceptualinformation before you perform the procedures.

• Configuring Reconciliation

• Configuring Reconciliation Jobs

• Guidelines on Performing Provisioning Operations

• Performing Provisioning Operations

• Uninstalling the Connector

5.1 Configuring ReconciliationYou can configure the connector to specify the type of reconciliation and its schedule.

The following topics related to configuring reconciliation are discussed in this section:

• Performing Full and Incremental Reconciliation for the Connector

• Performing Limited Reconciliation for the Connector

5.1.1 Performing Full and Incremental Reconciliation for the ConnectorFull reconciliation involves reconciling all existing user records from the target systeminto Oracle Identity Governance. After you create the application, you must firstperform full reconciliation.

At the end of the reconciliation run, the Latest Token parameter of the reconciliationjob for user record reconciliation is automatically updated. From the next reconciliationrun onward, only records created after this time stamp are considered forreconciliation. This is incremental reconciliation.

You can switch from incremental reconciliation to full reconciliation whenever you wantto ensure that all target system records are reconciled in Oracle Identity Governance.To perform a full reconciliation run, remove (delete) any value currently assigned tothe Latest Token and Filter parameters and run one of the reconciliation jobs listed inthe Reconciliation Jobs section.

5-1

Page 53: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

For example, consider lastModifiedDateTime as a sample Incremental ReconAttribute associated with the SAP SuccessFactors Target Resource UserReconciliation. After the first full reconciliation run, the Latest Token parameter getspopulated accordingly. In subsequent reconciliation runs, the connector fetches onlythe user records that are created or updated after the timestamp.

5.1.2 Performing Limited Reconciliation for the ConnectorLimited or filtered reconciliation is the process of limiting the number of records beingreconciled based on a set filter criteria.

By default, all target system records that are added or modified after the lastreconciliation run are reconciled during the current reconciliation run. You cancustomize this process by specifying the subset of added or modified target systemrecords that must be reconciled. You do this by creating filters for the reconciliationmodule.

You can perform limited reconciliation by creating filters for the reconciliation module.This connector provides a Filter Suffix attribute (a scheduled task attribute) that allowsyou to use any of the attributes of the target system to filter target system records. Youspecify a value for the Filter Suffix attribute while configuring the user reconciliationscheduled job.

Consider a filter suffix value: userId eq ‘JohnSmith’

In this example, the connector performs filter reconciliation and only reconciles theuser information whose PersonID is JohnSmith

Note:

If the target system contains more number of records than what it can returnin a single response, then use the Flat File connector to perform limitedreconciliation.

5.2 Configuring Reconciliation JobsConfigure reconciliation jobs to perform reconciliation runs that check for newinformation on your target system periodically and replicates the data in Oracle IdentityGovernance.

You can apply this procedure to configure the scheduled jobs for lookup fieldsynchronization and reconciliation.

To configure a scheduled job:

1. Log in to Oracle Identity System Administration.

2. In the left pane, under System Management, click Scheduler.

3. Search for and open the scheduled job as follows:

a. In the Search field, enter the name of the scheduled job as the searchcriterion. Alternatively, you can click Advanced Search and specify the searchcriterion.

b. In the search results table on the left pane, click the scheduled job in the JobName column.

Chapter 5Configuring Reconciliation Jobs

5-2

Page 54: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

4. On the Job Details tab, you can modify the parameters of the scheduled task:

• Retries: Enter an integer value in this field. This number represents thenumber of times the scheduler tries to start the job before assigning theStopped status to the job.

• Schedule Type: Depending on the frequency at which you want the job to run,select the appropriate schedule type.

Note:

See Creating Jobs in Oracle Fusion Middleware Administering OracleIdentity Governance for detailed information about schedule types.

In addition to modifying the job details, you can enable or disable a job.

5. On the Job Details tab, in the Parameters region, specify values for the attributesof the scheduled task.

Note:

See Reconciliation Jobs for the list of scheduled tasks and theirattributes.

6. Click Apply to save the changes.

Note:

You can use the Scheduler Status page in Identity SystemAdministration to either start, stop, or reinitialize the scheduler.

5.3 Guidelines on Performing Provisioning OperationsThese are the guidelines that you must apply while performing provisioning operations.

For a Create User Provisioning operation, you must specify a value for the User Namefield along with the domain name. For example, [email protected]. The User Nameis a mandatory field, other mandatory fields are Business Unit, Company, Hire Date,Username, Event Reason, First Name, Last Name, Supervisor and Job Classification.

5.4 Performing Provisioning OperationsYou create a new user in Identity Self Service by using the Create User page. Youprovision or request for accounts on the Accounts tab of the User Details page.

To perform provisioning operations in Oracle Identity Governance:

1. Log in to Identity Self Service.

2. Create a user as follows:

Chapter 5Guidelines on Performing Provisioning Operations

5-3

Page 55: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

a. In Identity Self Service, click Manage. The Home tab displays the differentManage option. Click Users. The Manage Users page is displayed.

b. From the Actions menu, select Create. Alternatively, you can click Create onthe toolbar. The Create User page is displayed with input fields for user profileattributes.

c. Enter details of the user in the Create User page.

3. On the Account tab, click Request Accounts.

4. In the Catalog page, search for and add to cart the application instance for theconnector that you configured earlier, and then click Checkout.

5. Specify value for fields in the application form and then click Ready to Submit.

6. Click Submit.

See Also:

Creating a User in Oracle Fusion Middleware Performing Self Service Taskswith Oracle Identity Governance for details about the fields on the CreateUser page

5.5 Uninstalling the ConnectorUninstalling the SAP SuccessFactors connector deletes all the account-related dataassociated with its resource objects.

If you want to uninstall the connector for any reason, then run the Uninstall Connectorutility. Before you run this utility, ensure that you set values for ObjectType andObjectValues properties in the ConnectorUninstall.properties file. For example, if youwant to delete resource objects, scheduled tasks, and scheduled jobs associated withthe connector, then enter "ResourceObject", "ScheduleTask","ScheduleJob" as the value of the ObjectType property and a semicolon-separatedlist of object values corresponding to your connector as the value of the ObjectValuesproperty.

For example: SuccessFactors User

Note:

If you set values for the ConnectorName and Release properties along withthe ObjectType and ObjectValue properties, then the deletion of objectslisted in the ObjectValues property is performed by the utility and theConnector information is skipped.

For more information, see Uninstalling Connectors in Oracle Fusion MiddlewareAdministering Oracle Identity Governance.

Chapter 5Uninstalling the Connector

5-4

Page 56: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

6Extending the Functionality of the SAPSuccessFactors Connector

You can extend the functionality of the connector to address your specific businessrequirements.

The following topics are discussed in this section:

• Configuring Transformation and Validation of Data

• Configuring Action Scripts

• Configuring the Connector for Multiple Installations of the Target System

• Understanding OData API Dictionary

6.1 Configuring Transformation and Validation of DataConfigure transformation and validation of user account data by writing Groovy scriptlogic while creating your application.

You can configure transformation of reconciled single-valued user data according toyour requirements. For example, you can use First Name and Last Name values tocreate a value for the Full Name field in Oracle Identity Governance.

Similarly, you can configure validation of reconciled and provisioned single-valueddata according to your requirements. For example, you can validate data fetched fromthe First Name attribute to ensure that it does not contain the number sign (#). Inaddition, you can validate data entered in the First Name field on the process form sothat the number sign (#) is not sent to the target system during provisioningoperations.

To configure transformation or validation of user account data, you must write Groovyscripts while creating your application. For more information about writing Groovyscript-based validation and transformation logic, see Validation and Transformation ofProvisioning and Reconciliation Attributes of Oracle Fusion Middleware PerformingSelf Service Tasks with Oracle Identity Governance.

Following is a sample transformation script for reference:

def getBeneficiaryAttrFromContext(attrName) { if (context.beneficiary != null) { return context.beneficiary.getAttribute(attrName); }

return null; }

def getBeneficiaryPwdFromContext() { return context.beneficiaryPassword;

6-1

Page 57: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

}

if (binding.variables != null) { if (binding.variables.containsKey("context")) { if (context.operationType != null) { if(context.operationType.equalsIgnoreCase("create")) { if (context.provisionMechanism != null) { if(context.provisionMechanism.equalsIgnoreCase("POLICY")) { Username = getBeneficiaryAttrFromContext("User Login"); First_Name = getBeneficiaryAttrFromContext("First Name"); Last_Name = getBeneficiaryAttrFromContext("Last Name"); Password = getBeneficiaryPwdFromContext(); Company = "ACE_USA"; Job_Classification = "ADMIN-1"; Event_Reason = "HIRNEW"; Business_Unit = "ACE_IND"; Supervisor = "JDOE"; Hire_Date = (new java.util.Date()-1); } //if else if (context.provisionMechanism.equalsIgnoreCase("REQUEST") || context.provisionMechanism.equalsIgnoreCase("ADMIN")) {

if (Username == null || Username == "") { Username = getBeneficiaryAttrFromContext("User Login"); } if (First_Name == null || First_Name == "") { First_Name = getBeneficiaryAttrFromContext("First Name"); } if (Last_Name == null || Last_Name == "") { Last_Name = getBeneficiaryAttrFromContext("Last Name"); } if (Password == null || Password == "") { Password = getBeneficiaryPwdFromContext(); } if (Company == null || Company == "") {

Chapter 6Configuring Transformation and Validation of Data

6-2

Page 58: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Company = "ACE_USA"; } if (Job_Classification== null || Job_Classification == "") { Job_Classification = "ADMIN-1"; } if (Event_Reason== null || Event_Reason == "") { Event_Reason = "HIRNEW"; } if (Business_Unit== null || Business_Unit == "") { Business_Unit = "ACE_IND"; } if (Supervisor== null || Supervisor == "") { Supervisor = "JDOE"; } Hire_Date = (new java.util.Date()-1); }//else if } }

} } }

6.2 Configuring Action ScriptsYou can configure Action Scripts by writing your own Groovy scripts while creatingyour application.

These scripts can be configured to run before or after the create, update, or delete anaccount provisioning operations. For example, you can configure a script to run beforeevery user creation operation.

For information on adding or editing action scripts, see Updating the ProvisioningConfiguration in Oracle Fusion Middleware Performing Self Service Tasks with OracleIdentity Governance.

6.3 Configuring the Connector for Multiple Installations ofthe Target System

You must create copies of configurations of your base application to configure it formultiple installations of the target system.

The following example illustrates this requirement:The London and New York offices of Example Multinational Inc. have their owninstallations of the target system, including independent schema for each. Thecompany has recently installed Oracle Identity Governance, and they want toconfigure it to link all the installations of the target system.

Chapter 6Configuring Action Scripts

6-3

Page 59: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

To meet the requirement posed by such a scenario, you must clone your applicationwhich copies all configurations of the base application into the cloned application. Formore information about cloning applications, see Cloning Applications in Oracle FusionMiddleware Performing Self Service Tasks with Oracle Identity Governance.

6.4 Understanding OData API DictionaryThe OData API Dictionary component stores a bundle of object entities. EachSuccessFactors instance contains ready-to-use object entities. The object entities inthe OData API Dictionary can also be customized as per requirement.

The following topics are discussed in this appendix:

• About OData API Dictionary

• Viewing OData API Dictionary in the SAP SuccessFactors Connector

• Adding Custom Attributes and Object Entities in Oracle Identity Governance

• Providing Values in Static Lookups

6.4.1 About OData API DictionaryEvery SuccessFactors instance has several object entities. The OData API Dictionarybundles these object entities and presents them in a tabular format. TheSuccessFactors object entities contain information such as allowed operations,attributes (also referred to as property name) and labels.

6.4.2 Viewing OData API Dictionary in the SAP SuccessFactorsConnector

SAP SuccessFactors provides an option to view existing object entities listed underthe OData API Dictionary link.

To view an existing OData API Dictionary:

1. Log in to your SuccessFactors instance.

2. Search for OData API Dictionary in the Tool Search text field on the Admin Centerpage. The OData API Dictionary link listed under My Favorites link category.

3. Click OData API Dictionary link. The OData API Entities list appears.

The displayed list includes both ready-to-use object entities along with yourcustomized object entities.Figure 6-1 shows a list of OData API Entities.

Chapter 6Understanding OData API Dictionary

6-4

Page 60: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Figure 6-1 OData API Entities

Note:

• In the current release, User Interface for the OData API DataDictionary is enhanced. The OData API Data Dictionary link isavailable in the Admin Center console. If this link is not visible, verifyyour access grant permissions.

• In the OData API Data Dictionary, you can use the Search Allfunctionality. However for a filtered search, you can either usespecific search terms such as Entity, Complex Type, or FunctionImport, or you can use objects such as PerPersonal,EmpEmployment and Attributes. associated with them.

6.4.3 Adding Custom Attributes and Object Entities in Oracle IdentityGovernance

SAP SuccessFactors provides a ready-to-use OData API Dictionary. Apart from theready-to-use object entities present in the OData API Dictionary, if you require a newattribute and a new object entity, then you need to customize the OData APIDictionary. Using the OData API Dictionary component, all customized object entitiesare mapped to their corresponding attributes in the target system.

Adding custom attributes and object entities to Oracle Identity Governance is a two-step operation as follows:

• Firstly in your SuccessFactors instance, you need to search for the customattribute that is present in the OData API Dictionary. Make a note of the customattribute and the entity object below which this custom attribute is listed. For moreinformation about customizing the OData API Dictionary, contact SAPSuccessFactors support.

Chapter 6Understanding OData API Dictionary

6-5

Page 61: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

• After obtaining the required information about custom attribute and object entity,you need to add this new attribute to Oracle Identity Governance. This newattribute provides a mapping between the custom attribute and the target system.

To associate the attribute with an object entity:

1. Log in to Identity Self Service by using the System Administration account.

2. Go to the Manage tab and click the Applications box. The Applications pageappears.

3. From the Applications page, from the Actions menu, click Create, and thenselect Target. The Application Template page appears.

4. From the Application Template page, navigate to Schema Attribute page.

5. From the Schema Attribute, click Add Attribute to add a new row to the table.Provide the following Application Attribute details:

a. Display Name: Enter the display name for the attribute in Oracle IdentityGovernance.

b. Target Attribute: Enter the target attribute name. For SuccessFactors, enterPerPersonal.formalName.

c. Data Type: Select the String data type from the list.

d. Mandatory: Select if the attribute is mandatory for target provisioning.

e. Provision Field: Select Yes from the list.

f. Recon Field: Select Yes from the list.

g. Key Field: Select No from the list.

h. Case Insensitive: Do not make any modifications to this attribute.

6. Click Save to save your changes.

6.4.4 Providing Values in Static LookupsSuccessFactors provides an option to add values to the static lookup definition. Addingvalues is a requirement to associate code and the meaning values in the targetsystem. To add values in the static lookups for SuccessFactors, first you need tocheck if any code value is present for the attribute under consideration. If a code valueis present, then the same needs to be added to the corresponding lookup definition inOracle Identity Governance.

Consider the below illustration shown in Figure 6-2. In the illustration, observe that thevalue in the location field is San Mateo (US_SFO). The US_SFO is the value whichneeds to be provided as the Code and the value San Mateo (US_SFO) or just the nameof the location San Mateo as the Meaning value for the static Lookup Location. Thesetwo values need to be present under Lookup.Location in Oracle Identity ManagerProcess Form page.

Chapter 6Understanding OData API Dictionary

6-6

Page 62: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Figure 6-2 Providing Values in a Static Lookup

To provide values for the Lookup.SuccessFactors.Location static lookup:

1. Log in to Oracle Identity System Administration.

2. Click Lookups from the left navigation pane. The Search and Select LookupType window appears.

3. From the Search and Select Lookup Type window, search and open the lookupfor which the new static value needs to be added, and click Search.

4. From the search results, select the Lookup for which the new static value needs tobe added and click the edit icon. The Edit Lookup Type window appears.

5. In the Edit Lookup Type window, click the create Lookup icon and enter valuesfor Code and Meaning attributes. For the Code attribute, provide the targetattribute name and for the meaning attribute, provide the process form name.

6. Click Save to save your changes.

Chapter 6Understanding OData API Dictionary

6-7

Page 63: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

7Upgrading the SAP SuccessFactorsConnector

If you have already deployed the 11.1.1.5.0 version of the SAP SuccessFactorsconnector, then you can upgrade the connector to version 12.2.1.3.0 by uploading thenew connector JAR files to the Oracle Identity Manager database.

Note:

• Before you perform the upgrade procedure:

– It is strongly recommended that you create a backup of the OracleIdentity Manager database. Refer to the database documentation forinformation about creating a backup.

– As a best practice, perform the upgrade procedure in a testenvironment initially.

The following sections discuss the procedure to upgrade the connector:

• Upgrade Steps

• Postupgrade Steps

See Also:

About Upgrading Connectors in Oracle Fusion Middleware AdministeringOracle Identity Manager for detailed information on these steps

7.1 Upgrade StepsThis is a summary of the procedure to upgrade the connector for both staging andproduction environments.

Depending on the environment in which you are upgrading the connector, perform oneof the following steps:

• Staging Environment

Perform the upgrade procedure by using the wizard mode.

7-1

Page 64: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Note:

Do not upgrade IT resource type definition. In order to retain the defaultsetting, you must map the IT resource definition to "None".

• Production Environment

Perform the upgrade procedure by using the silent mode.

7.2 Postupgrade StepsUpgrade steps involve uploading new connector JAR to the Oracle Identity Managerdatabase.

Perform the following procedure:

1. If the connector is deployed on a Connector Server, then:

a. Stop the connector server.

b. Replace the existing jarorg.identityconnectors.successfactors-1.0.11150.jar withorg.identityconnectors.successfactors-12.3.0.jar.

Note:

Replace the existing bundle with new bundle in the ConnectorServer and also in the database bundle folder of Oracle IdentityManager.

c. Start the connector server.

2. If the connector is not deployed on a Connector Server, then:

a. Run the Oracle Identity Manager Delete JARs utility to delete the existing ICFbundle org.identityconnectors.successfactors-1.0.11150.jarfrom the Oracle Identity Manager database.

When you run the Delete JARs utility, you are prompted to enter the logincredentials of the Oracle Identity Manager administrator, URL of the OracleIdentity Manager host computer, context factory value, type of JAR file beingdeleted, and the name of the JAR file to be removed. Specify 4 as the value ofthe JAR type.

b. Run the Oracle Identity Manager Upload JARs utility to post the ICF bundleorg.identityconnectors.successfactors-12.3.0.jar. file to theOracle Identity Manager database.

When you run the Upload JARs utility, you are prompted to enter the logincredentials of the Oracle Identity Manager administrator, URL of the OracleIdentity Manager host computer, context factory value, type of JAR file beinguploaded, and the location from which the JAR file is to be uploaded. Specify4 as the value of the JAR type.

Chapter 7Postupgrade Steps

7-2

Page 65: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Note:

After completing the connector upgrade steps, ensure to delete thefollowing Code Key and Decode entries inLookup.SuccessFactors.Configuration andLookup.SuccessFactors.Configuration.Trusted lookup definitions:

• Code Key: Bundle Version

• Decode: 1.0.1115

Additionally, after completing the artifact level upgrade steps, ensure thatyou delete any attribute which reflects previous version of the connectorfrom both target and trusted lookup configuration tables.

3. Restart Oracle Identity Manager.

See Also:

If you have configured the connector for multiple versions of targetsystem, then refer to Configuring the Connector for Multiple Installationsof the Target System for more information

Chapter 7Postupgrade Steps

7-3

Page 66: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

8Known Issues and Workarounds for theSAP SuccessFactors Connector

These are the known issues and workarounds associated with this release of theconnector.

The following are issues associated with the target system:

• Support for Delete User Operation

• Support for Removing Child Attributes

• Support for Translation of Termination Date

8.1 Support for Delete User OperationThis connector does not support delete user operation. When you initiate a delete useroperation in Oracle Identity Governance, since the delete operation is not supported,the target system disables the user.

Workaround:

There is no workaround available for this issue.

8.2 Support for Removing Child AttributesIn this release, removing child attributes are not supported.

As an example consider phone number to be a multivalued attribute. As a multivaluedattribute, phone number includes child attributes such as mobile number, work phone,and alternate mobile number. In this connector release, you cannot remove childattribute such as mobile number from the phone number parent attribute.

Workaround:

There is no workaround available for this issue.

8.3 Support for Translation of Termination DateThe SuccessFactors connector bundle supports 28 different languages. In thisrelease, the translation for the attribute Termination Date is not supported acrossdifferent languages.

Workaround:

There is no workaround available for this issue.

8-1

Page 67: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

AFiles and Directories on the SAPSuccessFactors Connector InstallationPackage

This appendix provides the list of files and directories in the connector installationpackage and their descriptions.

Table A-1 Files and Directories in the Connector Installation Package

File in the Installation Media Directory Description

org.identityconnectors.successfactors-12.3.0.jar This JAR is the ICF connector bundle.

configuration/SuccessFactors-CI.xml This file is used for installing a CI-based connector. ThisXML file contains configuration information that is usedby the Connector Installer during connector installation.

Files in the resources directory Each of these resource bundles contains language-specific information that is used by the connector.During connector deployment, this file is copied to theOracle Identity Governance database.

Note: A resource bundle is a file containing localizedversions of the text strings that include GUI elementlabels and messages.

xml/SuccessFactors-ConnectorConfig.xml This XML file contains definitions for the followingconnector objects

• IT resource definition• Process forms• Process tasks and adapters• Lookup definitions• Resource objects• Process definition• Scheduled tasks• Reconciliation rules

Note: This file is applicable only for a CI-basedconnector.

xml/SuccessFactors-auth-template.xml This file contains definitions for the connector objectsrequired for creating an Authoritative application. Itincludes certain details required to connect OracleIdentity Governance with the target system . It alsoincludes configuration details specific to your targetsystem, attribute mappings, correlation rules, andreconciliation jobs.

xml/SuccessFactors-pre-config.xml This XML file contains definitions for the connectorobjects associated with any non-User objects such asRoles.

A-1

Page 68: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Table A-1 (Cont.) Files and Directories in the Connector Installation Package

File in the Installation Media Directory Description

xml/SuccessFactors-target-template.xml This file contains definitions for the connector objectsrequired for creating a Target application. It includescertain details required to connect Oracle IdentityGovernance with the target system. It also includesconfiguration details specific to your target system,attribute mappings, correlation rules, and reconciliationjobs.

Appendix A

A-2

Page 69: Configuring the SAP SuccessFactors Application › cd › F10043_01 › cgsfo › ... · Oracle® Identity Governance Configuring the SAP SuccessFactors Application Release 12c (12.2.1.3.0)

Index

Symbols(target) resource of Oracle Identity Governance,

3-1

Aauthoritative resource reconciliation, 1-4

Cconfigure scheduled jobs, 5-2connector architecture, 1-4connector features, 1-6connector files and directories, A-1connector installation media, A-1

Eenable logging, 4-5

Ffeatures of connector, 1-6filtered reconciliation, 5-2full reconciliation, 1-7, 5-1

Iidentity aware, 3-1

Llimited reconciliation, 5-2localizing, 4-7logging, 4-3, 4-5

Rreconciliation

full, 5-1limited, 5-2

Sstages of connector deployment

preinstallation, 4-1

Ttarget resource reconciliation, 1-4trusted source reconciliation, 1-7

Uuse cases example, 1-5

Index-1