PRODUCT NEWS | XCW
With Service Pack 7, Xiting Central Workflows introduces a number of important enhancements for Identity & Access Management in the SAP ABAP environment: from a complete Business Role Management solution to a structured recertification process and expanded SOAP web services for maximum integration flexibility.
Xiting Central Workflows (XCW) is Xiting’s solution for standardized SAP workflows in Identity & Access Management. It provides best-practice processes for user administration in SAP ABAP systems – delivering greater efficiency, transparency, and security in authorization management, with fast implementation and straightforward day-to-day operations.
Service Pack 7 focuses on two key areas: expanding business role functionality and extending the SOAP web services. Additional improvements based on customer feedback have also been implemented.
Awesome. Good morning, everyone. Thank you so much for joining. We're gonna give it a few more moments here, a minute or so, and, we'll get started with the webinars we have planned for today. Alright. It is nine zero one. I wanna be respectful of everyone's time, so let's go ahead and get started. Thank you everyone for joining us today. And before we begin, just a few quick housekeeping items. Recording of today's session will be provided after the session. Participants' webcams and microphones have been turned off to ensure audio quality. If you have any questions throughout the presentation, please feel free to submit them in the chat. We will reserve time at the end of each session to review and answer as many questions as possible. Ultimately, my name is Alex Manning, and I am the managing consultant for the Americas here at Exciting, and I'll be moderating today's events. Joining me today is my colleague, Hassan Salih, who is a professional consultant at Exciting with who specializes in SAP identity and access management, and he will be leading all three of today's, sessions. Today's events have been designed as a three part webinar series focused on the XCW, the exciting central workflow workflow tool, and how organizations can modernize and simplify SAP identity and access management. The first topic we'll begin looking at is how the XCW helps organizations drive efficiency in SAP user administration through centralized workflows, automated provisioning, and self-service capabilities. Following a short five minute break, we'll continue with an overview of the XCW Service Pack seven, where Hassan will highlight the latest features, enhancements, partake before taking a deeper dive into several of the key new capabilities and practical use cases. Following another short five minute break, we'll continue and ultimately conclude with the integration of the XCW into existing external tools, demonstrating how the XCW can seamlessly integrate with external platforms while allowing organizations to maintain their existing request and approval process. We'll also explore how embedded risk analysis helps provide early visibility into potential access conflicts before provisioning takes place. So whether you're looking to improve user administration, stay current with the latest XCW functionality, or better integrate SAP identity processes into your existing technology landscape, today's sessions are designed to provide practical insights and real world examples that you can apply within your own organization. And so with that, I'll go ahead and hand it over to Hassan to begin our first session on driving efficiency and SAP user administration with the XCW. Yeah. Thank you a lot, Alex. So my name is Hassan Zali. As Alex, already told you, I'm part of the IGA team, and we are all about identity management throughout on prem to cloud services. So I would like to start and start the presentation. So we will start with a a quick presentation of XCW where we go through the agenda that, Alex already told you. So we will start with, with, point one, a few exciting facts. Just so you know who we are, then we move into point two, the XCW basics, where we explain the challenges we solve and how the solution works. In point three, we get practical with an XCW hands on, a live demo. After that, point four covers the new feature in the service. Seven pack Point five looks at third party integration. Finally, in point six, there's plenty of room for your questions answered. We will have dedicated time for the q and a at the end. And I would like to start with exciting facts. So before we dive into the topic of the day, let me quickly introduce who we are. Xighting was founded back in two thousand and eight in Zurich, Switzerland. So we are a company with Swiss roots. And as you'd expect, a strong focus on quality and security. What started in Switzerland has grown steadily into an international organization over the years. In twenty twelve, we opened our subsidiary in Germany in Schlutze. Two years later, in twenty thirteen, we expanded to the United Kingdom with our office in Bristol. In twenty sixteen, we crossed the Atlantic and established our presence in the United States in Apollo Beach, Florida. And in twenty eighteen, we added our subsidiary, Inclus Romania. So today, we operate across multiple locations, subsidiaries, sales, office, which means wherever you are, there's exciting team close by you. Now when we talk about security, trust has to be earned. And for us, that means providing it through independent certifications. Since two thousand twenty, our exciting authorization management suits the xAMS has been ZAP certified for integration with ZAP S4HANA and and SAP S4HANA Cloud. In two thousand twenty three, we went a step further. Both xAMS and xCW exciting central workflows, which is exactly what we will be looking at today, received SAP certification for integration with SAP S4HANA. And most recently, since twenty twenty six, we are certified against ISO twenty seven, yeah, twenty seven thousand one, the international recognized standard for information security. So security isn't just what we sell. It's how we run our business. So, let me give you a picture of what we actually do. First, from use case perspective, meaning which problems do we solve for our customers, we cover for, we cover, yeah, three main areas. The first is authorization management, so everything from consulting license analysis in SAP S4HANA, accelerating your SAP S4HANA migration right through the simplified SAP Fiori administration. The second is identity governance and administration, identity lifecycle management, risk and rule set management, including segregation of duty, extended access management and securing ZAP BTP and the ZAP Cloud Identity Services. The third is cybersecurity and security monitoring, vulnerable analysis, compliance monitoring, Centimeters integration, and real time ZAP security monitoring and threat detection. And we also focus on yeah. I mean, in the IGA, we also focus on the single sign on. So, essentially, we cover the full spectrum of sub security. Now the same portfolio can also be viewed from a different angle. The work stream perspective, this is really about how we work with you because every customer situation is different. If you need guidance, we offer project and sales consulting. You get coaching and advice of, for your individual requirements, whatever the scope. So if you rather have the work taken off your hand, we offer managed service consulting. You define the requirement, and we deliver the results to you. And if you prefer to do the work yourself, we give you the software solutions, powerful tools that let your own let your own team get the job done. So whether you want guidance, done for your for your service or the tools in your own hand, we can meet you exactly where you are. And, this brings it all together, in what we call the exciting security solution, our philosophy of get connected, run secure. At the center sits the identity governance administration with our XSP. Together with authorization and user management, around it, we connect your entire landscape with on prem and in the cloud. On the on prem side, that means ZAP GRC, access control, ZAP S4HANA and many more. We in the cloud, we connect to the ZAP Ariba, ZAP S4HANA, ZAP SuccessFactors and more. But we don't stop at SAP. We provide unified connectivity to all major surrounding systems as well, to your EIM solution, your licensing tool, and your Xium landscape with connecting for platforms like ARC, ArcLight and Splunk. And we reach into your non SAP application too, such as ServiceNow and Workday. The idea is simple. So one unified secure connection across your whole environment, SAP and beyond, And, that connectivity is exactly where CyclingCentral workflow comes in, which is, what I would like to walk you through. So, that was the big picture about, the exciting, And I think we should move on to today's actual topic, and that's the XCW basics, the XCW, how it works in general, the challenges, solution functions and benefit. So let's start with the challenge, and I think many of you will recognize this from your daily work. In a lot of SAP environments role and user management still happens far too manually, roads aren't clearly designed. Instead, you hear things like give this user the same authorization as user ABC or the user just needs, to be able to post. That's vague and risky. On top of that, there are often no explicit approval procedures and no clear responsibilities for, who may assign which role. The requests themselves usually coming in by phone or mail, aren't stored in any regulated way. So there's no way to verify later why an authorization was actually granted. And even simple things like, resetting a password creates unnecessary manual effort for your team. So in short, it's manual. It's hard to trace, and it's difficult to audit. And that's exactly where XCW comes in. So the answer to all of this was the XCW. The ID is simple, but also on the other side, powerful. So we wanted to take the manual unstructured processes and turn them into central standardized and fully documented workflows for user and role management, across your entire SAP landscape. And we, should talk about, how the solution is working. So the XCW is able to be set up in three different ways. One of them is our customer defined and central system landscape. So this would mean that you will be able to import XCW on one of your systems and connect all the child systems in in the central system. This would allow you to have a a master system where you can orchestrate all your workflows from one centralized place to all the all the child systems, then you can also have the CUA in place and transport the XCW on your COA. This would also grant you some more benefits. One of the benefits would be that you're also able to generate the request from the surrounding systems, so from all the child systems. This would also enable you to use the user store from the CUA and leverage the current RFC connection to all your child systems. But as this is set up in a in a pretty short time, it's a slight benefit in the CUA. We also offer a third integration, and that's the local user administration. This is just the implementation of XCW on one of your systems, either to either to isolate that system or to either to isolate your system or to make your own systems in in certain environments, for example, your BV system that needs special care or you just want an audit trail on one of your system that's not included in your COA, and that's all possible in the local user administration. So the exciting central workflow also includes the question, do I need the CUA or a CDL? So the central so the central user administration or our, like I previously said, customer defined and central system landscape. There are some benefits and some risks that are included. One of the benefits in the CUA is the view in the SO01. So you have this user master the user store where all the information of the user is is readily available in in one view. There's a centralized maintenance where you can decide on global and local administration of user data and the possibility to control role and attribute distribution. This depends on if you set it up on global or local level in the scum, but that's more for the CUA. There are some risks involved with using the CUA that it's no longer being developed by the SAP. I mean, the use case is already pretty good defined on the CUA, but it will not be further developed. It's often set up on the Solman, and the Solman will be stopped will be stopped at around end of two thousand twenty seven or with the extended maintenance until two thousand thirty. And this would mean you have to set it up on a different system, And, it will give you the dependency on, the central system. So this will, most likely force you to to work on or decide on this one system where you have it set up. And if you try to get it in another system, that it will have to include some work. Then we have the CDL. One of the main benefits is the independence of ZAP, yeah, the ZAP CUA. It's a it also has a centralized maintenance, so you can also start all your workflows from the one system. You can build your own system landscapes, and that makes it also more flexible. What I mean, you can have different cluster sizes on XCW. This would mean, for example, all your productive systems can can be run on one central system. All your testing systems can run on one centralized system, and all your development can run on one system. This would allow you to also make different this different deployment strategies and give you more flexibility on managing your own systems. But there are still some risks involved in the CDL, and one of them would be the that there's no view of the system and the rows from others oh, I just so there's no user store information, so you don't really have one and done view where you can see all the user data and globally project all the data there, and also no direct direct view on the roads and easy to use, adding of systems and, roads. I mean, depending on how you set it up, The system assignment must be requested, but we also have and that's something that we will delve into further in the perspective, in the road map that we will also provide a user copy in the future. The XCW also excels in standardized workflows like I already said. So we set up standardized workflows for the user creation and user change. We also set up workflows for role assignments and revocation and user creation, including the role assignments. All of them also include our business role our business role concept where you can also create your own business roles across multiple systems. I would also like to talk about how the solution is functioning. So, in one site, we have different starting systems. One of them can be the HCM, the active directory, or external tools. This is something that we will, talk more about in in, in the third part of our presentation where we will talk about third party integration. And, you can also start in the exciting central workflows, and also push it to the different target systems that you can connect to in the XCW. So just short just to also say a few words of the on the benefits side of XCW, We we provide the modern ZAP Fiori UI and the modern ZAP GUI overview. This includes this includes also some of the some scrap integration, the multistage escalation procedures and and password self-service as well as a short implementation time of around three days. We are in SAP standard, so everything that we implement is in a standardized implementation way. And we also provide dashboards, the role owner concept and business roles and the integration of external tools and standardized workflows as well as segregation of duties. So we will go on the XCW hands on session. This will include the live demo where we will use make a user creation and business role assignment in the Fiori UI, and we will talk about the password self-service. So just a second. Need to check. Need to log in into the Fiori. So So, when, we are here, in the Fiori UI, we we want for the demonstration to, create a new user with, with a business role assignment and also talk about some of functionalities that you can use in in your request form and also talk about the password self-service. So in this case, we want to create a user and assign him a business role. Here in the formula, we set it up that you can also input a reference ID. The reference ID can also be from your third party tool or from your ticket tool or any kind of reference that you want to use to either also connect the audit trail in in in your ticket tool or any kind of reporting where you want to connect two different source systems, that is possible. You can also create a user using the search via ad app. This would allow you to to search inside of your active directory and look for a user that you want to to create in the system. So, for example, if we select this one, then, we can see that that we have, one of, the users in in our formulas. We can also change the user information, or what we can also do is we can add one user manually. This would allow us to to also put in some information as basic information. So, for example, just for orientation, you can have standardized values that you can include in your form in your request form. So, for example, your email have has to look like this, or your SNC name has to look like this, or if you have a standardized license that you want to use for all your, user creation, then you can also use this. We will make it pretty easy to follow, so we would just put in the user info the username in all the, fields. So, for example, the last name, first name, email address, and s and c just for ease to use. And we can also directly assign a system. Or if you if you search for a business role and select the business role, then you can then the system will know in which system he needs to so the XCW will know in which system the user needs to be created and will also give a reference here. So in our case, we want to use the SSG Maiment Global and the SSG Everyone. If we open up the business role, then we can see which roles are included, and we can also see which system are required for these roles. And in our case, it's, totally fine. In our use case, we also want it to be, indefinitely. And as we can see, the user will also have the, the different systems that needs to be assigned. We can also attach, different files. So, for example, if you have an email, PDF, or any kind of, any kind of, attachments that you want to include in your request form, that's, possible and, would you allow allow to further, look into the, different, requests? So in our case, that's just a new user. We can also, look if everything's totally fine and then send the request. And in our case, the workflow, was started. Just need to log into our user that needs to that needs to look at the request. So in our case, our our approver will have an item in his XCW work list. In our case, we made the user creation automatically. So currently, the user's already in your system. So if we also take a take a quick look in the s o zero one, We can see that the SH one got created here. He still does not have the roads, but he's created in the different systems. That's just an customization that we that we already set up in our XCW. So in our case, we just need to to approve the different roles. So this this is the one business role that we need to approve as this is the one that's not auto approved because the SSG everyone role, that's one of the basic roles that you can provision, without any approval. Why was it not in the user? We also have a risk check, an SOD check on on in our tool enabled. So we will watch how the requester will respond. So if something gets declined, then we will not we will not use it for the risk check as it's not needed for the user. So that's one of the reasons. So once we approve this so once we approve it in the background, we will get a risk analysis. And if there's something popping up, the risk owner would also get a notification. In our case, because I don't want to switch a lot on the different users, I made it so that this one user has to prove everything. And in this case, the SOD check was also triggered, and, we can see here the different, auth IDs that the user's breaking. We can also see, the conflict comp IDs. And, we have also different views where, we can also see the the business role that's involved in this. So you can also check which role has the problem to check. You can also click on the conflict. And if you click on the conflict, you can see on the on the left side the authorization objects and the field name that the different roads have. And on the right side, you can see which of the roads are broken in this case. And you can really go deep into the technical stuff or idea behind the craft critical authorization framework where you can see why it's breaking those rules. In our case, we just want to confirm everything so that the user gets all his, roads automatically provisioned. We can also take a take a look into into the user if it's already there. And in this case, after, like, five seconds, the user got all the different, all the different, roads assigned to. So, this was, one of the features. We would also like to talk about, the different web app, the the password self-service. So so when we, look into the password self-service. This is our, password self-service in the, CUA. So in our case, you can use your user ID and your email address. And if it's found in the s o zero one, then, the user will be prompted, to input his his token that he got per mail. And if he, if he uses the token to authenticate himself, then he will be forwarded to to to reset his password in the system that he wants to. So for example, if I put in a wrong email address in combination, I will get a error. And if I use the right one, then I will be prompted to the to the token or to the site where I need to input my token. In this case, I will input the token that I received. And here, I can see in which systems my user is created. I can see that the user is currently unlocked in this one, or I have an initial password here. And if I open up the drop down menu, I can either generate or self define my initial password. The self define definition is also pretty good if you want to use it on a technical user, but we will dive into that a little bit shorter. So I can just generate the password here. And if I generate the password, I will get an email with with the password in this system. So this is how it works. If you have a user that is also unlocked, that's not an admin locking, He will also be unlocked because if you input your password multiple times incorrectly, you will also be left out of the system and be locked in there. So you will be also automatically unlocked there. If your password's already deactivated, then we will not reset your password. And, also, if you're in an admin locked state, then you can also not unlock yourself here and reset your password. I also talked a bit about the unlocking of technical users. So, for example, if you use our other webdinpro, you as an admin can also choose specific users you want to unlock or reset the passwords. So in this case, you can also choose one of the users. So for example, this one, you can press enter, and then you can see, lock due to many incorrect lock on attempts. This one is an initial password, but it's locked with an admin lock. And here, it's not possible too many times. So, for example, here, if I use the generated one, then the email will be sent to the user. And if we refresh okay. That's, unfortunately, the refresh is not really working. But, here, we send out the the password for, the user. So you can also use it, for example, if you have a technical user, and you want to define a new initial password because, I don't know, it's like a user that where you also want to have an audit trail or any kind of protocol why he got he got unlocked. That's one of the ways to ensure that, and this would include the basic information of of the live demo. So we looked at the user creation and the business role assignments, and we looked at the password reset. I think we will have, like, a short five minute break for the next, for the XDW SP seven new features. Yeah. Perfect. Yeah. Short flow five minute break. So we'll come back at, nine forty, so five minutes from now. Perfect. Well, thank you everyone for joining, the first portion of the webinar here today, and, we'll restart, with the next topic here in five minutes. Awesome. It is nine forty, so, let's go ahead and get started with the second topic we have today. Yes. We're going, pretty fast through all the points, but, I think the the most important ones or, the ones that most of us want to see are the new features of the SP seven, and, they include a variety of, new features that will definitely improve the usage of, of the, of the XCW, especially for the ones that use the business role concept. And if not, then it still has a lot of benefits, in in the third party integration and some, quality of life improvements in the XCW itself. So for example, the business role management got way better. We have more options for automatic business role changes so that they also get incremented or updated on the different users. And we also have new functionality for the business roles that include the user access review, where you can review the different business roles that are already that are already provisioned to the different users. This will make our tool way better in audit aspects. We also included some SOAP API enhancements that include the reading of users and and their assignments of in different systems. That also includes an own connector to our Kraft integration that will also allow third party tools to to make a risk analysis on how it will affect the the the user assignment. We also have some Fiori optimizations that will also make it easier for for managing users. So, for example so show that quickly. So for example, if you want, to assign somebody, roles, you can also have now more search, options available, so that you can find, the respective user faster. Those are some quality of life changes. The password self-service, like I already said, in the password self-service, it will also include now that deactivated passwords cannot be overwritten or any kind of resetting of those passwords. This will include some security improvements in that regard. And like I said, there are some small minor addition to that that will also include some performance improvements in the workflow itself as we are using a lot of data in our SOD checks, and this will make the work items lightweight for your system so they put on less strain on your SAP system. In the live demo, we will, see how is XCW handling, the changes of business roles and how it will also reflect on the assignment on different users. And we will also see some of the new changes of the XCW. And we also introduced a new a new button in our XCW. Those that already have the XAMS know that. It's the information what changed in the SP seven. It's a it's a nice feature to get an overview what changed. So, for example, we have the new reports on the update business roles, and the business role definition changed with versionizing of the different business roles. We have a business role assignment overview with reconciliation update, the new application of revision of existing business roles assignment in users. We also have the XCW web services for for business roles and updated on the workflow status that allow you to get way more information than previously. The, customizing setting to request assignments where user does not exist in specific systems will also include the user creation automatically. So for example, if you have a user that's already in your COA and maybe in the one system, for example, the in our case, the mandate two hundred two, the user would not exist. If you request a role for him in that system, he will also be automatically created. New customizing settings to decide on role assignments, maintenance in ZAP standard tools. We also have the upload from file available in business role assignment requests and a new transaction to display all collected logs of the selected workflows. Why is that important? This will also allow you to exchange different information fast on on different integrations. So you can also connect multiple informations of your XCW and give it maybe to an audit team, to check, if everything was okay. So we will focus on the business roles. In our case, we had a user where we gave him the SSG Everyone role and the Payment Global one. And as you can see, we are using the payment global for demonstration purposes as this is already the seventh version. So we make so when we change one of the business roles so for example, if we add, if we add another role to the, to the business role. So, for example, the dashboard role and save it, then we will get prompted that, we will assign a new role to the business role, and, we can use the transaction BR worse underlying inc to increment the assigned business role version after the save. So this is just some information that a user already has it, and we are now in the version eight. So now we know that it got changed slightly, and this will give us some options. So before, we could not reconciliate the roads after updating them. In in this case, we can also update them with incrementions. So, for example, if we we would just use it for our user that we just created. We can see that here, we get an information that the new role was added. You can also just use the business role instead of a user. This would make more sense, but we just want to make it as visible as possible. So instead of having, like, ten or twenty users, we just want to show it on one user specifically to see how the user will also change in the in the process. Maybe I can also show the user second. Need to change it on English. And if we look at our user here so those are the current roles the user has. And in this case, you should also get another one here. In this case, we will update the BR version. This will execute it. And if we look into the dashboard here, we can see that a new workflow got started here. For, the user, the decision is skipped as this is, just to give the user a new or correct the user in this case as we change the business role because sometimes the business needs require you to to be more flexible on your business roles as it will also include maybe a different role. And, in this case, you just showed that we got a new version. The user needs to get, the right role, and, you just want to include it, to the different users. And now if we look at the user, we can see that the dash got included here. So he received it, shortly after. And this is how if you change one of the business roles, you can just, push it forward so that all the users get the correct business roles or the different roles assigned to. And for example, there are also some use cases where you did not change the business role, but somebody went to the s o zero one. Maybe he did not receive the information that, the business role got changed. He looked at the user and said, like, okay. This was not, included in in our concept, so I want to remove, the role and save the user here. And now he got a problem because he's now inconsistent in the different systems. That's where we have the role assignment overview with reconciliation. So in this case, we can use the user again and see that in in this system, he's not he does not have the a certain role assigned to him. And in this case, you can put in, an administration, line in the ticker box, and you get some, different, extra buttons here to correct the assignment. And in this case, we want to correct the assignment because he should have this one, but somebody just went into the s o zero one and changed him. We also have a new customizing button that prohibits other users for from changing roads in the s zero one. This will prevent this issue, but as we know, different businesses need different, need have different needs. So, sometimes you just cannot block s o zero one for all the users. So, to, to to minimize the damage on on auto like, on, users changing, the assignments, we included the update. And if we correct the assignment, we can see that one of the assignments needed to be, to be assigned here. If you refresh it, then, the role status gets green. And in the dashboard, we can also see that, it got already provisioned here. And if we look at the user once again, we go out and look at the roads, it got assigned again. So this is how you would correct the user if you, are not sure that somebody messed up with it or if you just look at the different documentations on the user and select, okay. Somebody just changed something, but we did not want him to to do that. We can also have, the revision, the user access review. And, in this case, if you click on the business user access review, you can make different, you can start different campaigns for different use cases. In this case, you can start with the create new revision. And here, you can call it, something like user access review. And in our case, it's the second one, and we want it completed by the end of the month. Currently, it does not have any effect, so we did not decide on on automatically, de assigning all the roads if the user is not able to finish it by that. The the reason is that sometimes it's, you set up a goal and you cannot meet it, but that does not mean that, you need to produce more chaos. Maybe in the future, we will include some different automations on that. So for example, everything gets auto approved or everything gets auto declined or some other, features, but currently, it does not have any use case except for setting up a goal and seeing if we can manage to to achieve that. So in this case, we can save it. And with a double click, we can, go inside. And here, we can have, we can download a CSV to, to up to upload that also no. To to download the information that we got here. We can also, add different, we have different ways to add users. In this case, we can say, for example, the payment global role is, how we want to select the users, or we want to, specifically call a user, in our case, the one that we, that we just created. He has two of them. One of them is a skip decision And, how that will reflect in the user, access review is that, the one, business role that has the skip decision, will not be included in the, user access review as this is just automatically approved. This will just include the one payment global role for the users so that because that's the only one that that really matters in our case. Here, we can set different approvals. For example, if we include a certain type of owner for this user access review, we can, then select, different users or, the business roles. In this case, you can just set up the business role owner. Or here, we can have it freely definable. So, for example, if we use the one user that we already used for for approving the roles, we can also reset the approval or, like I said, the business role owner. And in this case, we can start the revision. And if we start it, it's updated here, and, the the user that needs to that needs to check it can now go to the my business role revision. And here, in this case, we got the e n zero two because this one's already submitted. And here, we can see our our overview of the business roads that we need to decide on if we want to revoke it or accept it. In this case, we can either say we want to revoke it or we want to accept it as this is fine. If we accept the decision, then nothing will happen. It will just say, okay. Everything was fine. Everything's good. If you want to revoke it, then, he will lose the, the business role. And in our case, if we just revoke it here and submit it, We are done with our revision, and it's getting updated. And we let's save it. And if we go back to our dashboard, we can then see that here in this case, the business role got, deassigned as this was, this failed the revision. And if we look at the user now, we can see that he only has the common roles, the one from the auto approved one, and the other business role got revoked in this case. Yes. And this includes most of the features of the new SP seven for the business roads. In in the next chapter, we will talk about oh, no. We also have one more, and that's the road map. I wanted to to I did not want to skip it. But, except from this SP seven features, we also, will will improve the XCW further. So for example, in the road map, we have SOAP API enhancements. This will be more important when we talk about the third party integration in the next section that we have, and this will include some readout of the users or more information in that regard or some other API enhancements there. There will be access request policies. So for example, one of the more important is features is that the that you can request for certain user instead of, for all of the users. This was one of the most requested features that we had as this will give you the opportunity to, to be more specific on on who can request for different users. We will also have a copy user function. So you can decide on which copying of the user is possible depending on where the user is created. So for example, if there's a user in a certain system, you want to copy the information from that system, that's then possible. We will also include the mail framework. This will give you more leverage or possibilities to change the different mails that are getting sent out in the XCW. And we will also keep, keep the Fiori optimizations as this will be more and more important as SAP's evolving into the, into the Fiori spaces or more companies are going to the RISE cloud, and this makes it more accessible for the Fiori first companies. And, yeah, the next section will be including the XCW third party integration, and this will give you a new perspective on how to use XCW. And I'm pretty sure it's the most exciting part of our webinar as this will give you more more, flexibility on how you want to use the XCW. Awesome. Well, thank you for that information on Service Pack seven and some of the highlights associated with that. Just like the previous sessions, we'll take a quick five minute break here. So we'll resume at, one zero six, and, we'll continue with the third session, which is, integrating XCW into some of our third party integration capabilities. So thank you for joining. We'll see you in five minutes. Alright. It's ten o six. Let's go ahead and resume with our third session. Thank you, everyone for sticking on. This will be the the last session for today. And at the end of the session, as we mentioned, we will have some time for questions. So any questions that are in the chat any questions that come up during this third session, we'll take some time to get those answers. So thank you, everyone. Yeah. So, thank you, Alex. I think we also have a question, or a question for everybody on this, on the third section. Okay. Maybe you can, yeah, maybe take the pulse. Sure. Absolutely. What we want to know is, like, which ITSM tool do you use currently, and are you modeling your workflows using your ITSM tools? It's important for us to know that we can also dive further into how we currently integrate the, the XCW integration on most cases. Awesome. Yeah. So it looks like we got two polls in the chat here. So we'll we'll pause here for a moment and give people a chance to respond to those polls, and then we will take to, talk to some, the responses that we see. I think this is enough time to Awesome. To get an idea on that. So we have most of the the companies that we also know use ServiceNow, but, we also have a lot of use cases with other third party integration. And, what I would like to say is we currently have a lot of companies where we, implemented this third party integration in multiple aspects. That includes a lot of companies where we have it included in the ServiceNow and also some others. So I think currently, we are on four different ITSM tools with our integration and also our custom also some custom integrations where you can also use the third party integration. And, what I would also like to say is, before, today, so, like, two or, three years ago, we, we always used Postman on on the scenario. So in our case, we have a different UI for this case. So be be excited on that part, because this will also, give it a new light that also give you more creativity on using the XCW as a third party integration. But, let's talk about what can we do with our third party integration. So most of our cases involve the user and role assignment. This is one of the web services that we provide. We also provide one of the web services for the role assignment or the assignment. We also provide the web services where you can change your user information and also including the business role concept where you can also, provision new business roles or user sign user creation and business role assignments. We also give different reporting options. They include the reading of of the roles or authorizations of users. This also includes reading out the system that are included. And one of the new features of the SP seven is you can also have it in a you can also make a risk check on the third party integration. And this will also give you more flexibility just to make sure that everything's okay with the with the assignment of the roles and have everything on one different on one specific UI for all the users. Because a lot of times, the SAP world is divided in two. Most of the SAP users stick to the SAP UI and have to also get used to a different UI, for example, ServiceNow, where you have to make your own service requests or some other third party tools. The live demo will now include our own our own mock up of ITSM tool. So in this case, instead of always showing the integration on a on a Postman level where you can make different API calls, we can now show it on a on a on our own UI version. Some heads up before, the UI version is something we specifically designed just for the demonstration. It's not an ITSM tool. It should just mimic one so that you can get an idea on what is currently possible with our integration and what can you also include in your own your own ticket tool. And so that I don't talk and also walk the walk, I want to show the the demo in our case. And here, you can we can also look at our different, reporting possibilities. So for example, if we go to the tab for the roles, we can also load out the different roles. In our case, we have three different systems where we are reading out all the roles. This includes eighteen thousand roles from across all three systems. And, for example, if we load from the client two hundred one, this this took around, I think, three to two to four seconds. So this is how performant this is. So it's like we got six thousand rows in in a couple of seconds here. And one of the other more like, what can you use or where can you use the third party integration? We made the most common, tickets, that we know of. So how customers would like to use a third party integration, and most of them use it for the new user creation. This would also include, the role assignment, the change of users. This is one of the most basic, requests. So I just want to extend validities or change some departments on the users. Assigning of roles, de assigning of roles, so removing roles from certain users, and also some of the combinations. So for example, if you want to remove from a user, you want to read out the authorizations of the user and also de assign the specific roles, you can also get use cases where you're locking users, unlocking users, or even set up their passwords back, reactivating users, so, like, unlocking and open up the validity period of the user, extend the external validity. So for example, we found out that most of our customers also have, instead of internal users, external users. And most of the time, users are only valid for, like, one year or three months up to one year. And, they also need an option to also extend their validity so that they can still work in the company when they are still, working there. The departure. So for example, if somebody has a user exit and he leaves the company, he needs to be locked out of the system. The validity needs to be set, and the rules need to be removed. You can also copy user, and you can even set up your own recertification. So you can just set up and read out multiple users and then have them recertified. This is also possible with the third party integration. And if we look in one of the in one of the examples, so for example, if we want to see the risk analysis, we can assign a new role, type out the user that we just created, for example, and want to assign him a specific role. We can prior check the risk level, or we can send the request and have, like, the risk check before sending it out. So for example, if we just want to check, the risk, we can see that we found one of the we found one risk. This is another web service. So when we clicked on the button, we sent out a request to XCW. Please check the user and his new role if there's any kind of problem with that. So in this case, we got a reporting back that the user will have a new combination ID that will be flagged as a risk, and this will be defined with a combination security user admin and role and profile admin. This will include the two auth IDs that will be also critical for the user. This will include role and profile administration and user administration. And you we also can take out more information of the system. The authorization allows the basic or temporary adjustments of user identities and authorization roles and their assignments. So you can you can get a quick idea on how this role will impact the user and what he can do. And you can also include more information. So this is just an easy overview of what you can get with our integration. You can even get more. So for example, in the in the craft, you can also set up coloring. So you can color the different criticalities, maybe yellow or green. So, like, we know that it's a criticality. We want you to be more mindful about it, but you can also assign the role to the user. Or yellow would be more on the make sure that it's the right user that gets it as this may be a good this may be allowed, but you have to keep in touch with the supervisor and also make sure that it's okay. And the red one would more be like, this is like a real criticality for the company and for the business. So either you have a really good reason to use it or just don't use it. So you can also work with coloring schemes and give them more information and also read out the the rule sets that these rules are broken. And just to make also sure that this is not just one user. So for example, if we use another user and make a risk check, we can also see that this would become a new a new risk. And in the bottom, we can see that there's already preexisting risk. So for example, if the roads did not get mitigated, we can also see if the user currently is in a risky state. And this would also give us more idea on how we need to handle the user because if we see, okay, he already has some existing, risks, why does he have it? And do we really need to include some more? Is it not, better to to, maybe, talk with the supervisor and make sure is everything okay with the user? Those are some of the information you can, get with our risk check-in this case. And like I said, you can also make it automatically. So for example, instead of instead of checking the risk here, you can make it so that some automatic processes start with sending the request. So in ServiceNow, when you make your rhythm, you send out the request. After sending out the request, the check will come, And either the the requester needs to approve it, this is how we implemented it in our case, or in ServiceNow or any other third party integration, you can just forward it to the supervisor of the user and check if everything's okay or you have specific personal key users that needs to check this this improvement. And if we just allow this one and send out the request, then it will be forwarded to the XCW. And in this case, the sis the request was started. We can also check on the workflow status. So we made a button where we can just check on the workflow ID on what is the current status of this. You can also just check on different IDs, how you want to use it. So this is also one of the web services that we provide. This will allow you to get an overview on how the the workflow is running. So in our case, the workflow is running. There are some information on the assignment to of the role to the user, who is responsible, also, like, who's the approver of this, and those are some of the information. And in this case maybe I need I need to log in again. So in this case, this is also one of the approval roles. Just to make sure, you can also set up XCW so that it automatically so that it automatically assigns roles or remove roles. It's not necessary that you need an you need an approval step in the XCW. This is just how we set it up for our demo purposes so that you know there's also a hybrid case. Why why am I talking about a hybrid case? You can either offload everything on your third party integration, the workflows, the approvals, the requesters, and manage everything on your third party ITSM. So you can manage the requester sends out the request. Then there's a risk check. You you give it to maybe to some of the risk owners to check if everything's okay, or you just give it right to the key users that needs to approve it. Or the supervisor needs it. This is something that you can decide on, in your case, how you want to proceed there. Or you can just say, okay. We want that the requester is sending out the request from our third party tool. But then again, all the approval steps need to be done in XCW. This is also possible. So for example, once I send out the request from the third party integration, I can also use it here in XCW. And as you can see, this is now where the risk check identified the problem. And here, we can see that it's the same risk, the combination security, user admin and role profile administration. Those are the same risks that we also analyzed for the user, and this will give us some different opportunities here. We can also make it so that the risk is only done in XCW, but the approval of the roads is automatically done after the third party integration. And what I also want to highlight in this case, it also allows you to work on mass changes outside of XCW. So if you have an idea about how you want to use XCW or maybe you don't even have an ITSM tool or anything like that, and you just want to make a repeatable mass change of multiple users, and maybe XCW does not provide you with the functionality in this case. You can just do it on your own. So if maybe you get a list each week from your HCM or your SuccessFactors or your workdays, and they include all the department changes. And after department change, all the users also needs need new roles. You can just use the list that you receive from there and just make your own mass change automation to the XCW. This is also possible now with our third party integration. So the third party integration just means we are opening up XCW for your own vision and your own flexible use cases. So if you want automation, for example, you get a report from SuccessFactors about all the users that are getting that are leaving the company after each month instead of going manually through all the different all the different users and and out manually remove them or exit them from from the system. So for example, remove all the roles in three multiple systems and lock the users in the different systems. I mean, you can use the XCW to request it, or you can just make an automation out of that where you just upload the tool in your own version. So for example, you upload the Excel in ServiceNow. They identify the username. They identify when they need to leave the company, and they can automatically trigger the locking or unlocking of users. This is also one of the benefits where you can also see the use case of our third party integration. Or, for example, if after the assignment of roles, maybe we can even take a look how the user looks now. So in this case, he received the XCW crit role. So this is the latency that we can expect. So we sent out the request. It was directly in the system, and it was done. So for example, if we want to remove the roles, we can also first use one of our web services to to read out the roles of the user in the specific systems. And this is how we got the information from our third party integration. And if we look at the s o zero one and look at the roles, we can see the SSG crit and both of the SSG roles. And if I just go and add the removal of the crit role, I I don't really need to put in anything there. I want to remove it. I mean, in our case, we still have the the approval. So we just send it out. Now we got the approval here. We want to unassign this role. We approve it here. And we can also check the status. The workflow is still running. Proved we're done. It's done. So once we look at our s o zero one, we can see that the role was removed. So this is how how fast you can expect XCW to run. If you even if you only use it for for provisioning or deprovisioning, like our own XCW provisioning engine in this case, It's just a call to the XCW, and it's directly running in the system. So there should be no no big delays there. If, for example, we want to lock the user, we can also just go and send out a request send out a request to a specific user. As we know, this is a CUA. We can just globally lock him by by checking the the CUA master system, the central system. And because we don't have any approval in the user change requests for example, it got it just sent out the the call, and the user's globally globally locked. And if we go and just unlock the user, for example, We can also unlock and reset the password. So you can even make your own password self-service in this case where you have more flexibility on that. So once we go with with the unlocking, we can save this, send out the request. And once we send out the request, the user's not unlocked. That was in a split second. So there's close to a small amount of delay in this case, and this makes it really strong on this part. So once the workflow engine of the SAP system is running, you can expect a short time of delay until this is happening. And you can also interwine the different web services, like I said, with the remove roads. Here, we are reading out here, we are reading out the users. So, for example, if I click on this, we get a call from one of our web services. He's waiting for the response. And after respond after the response gets sent out, we can here then select the different roles. So this is one aspect of the web services. And if we edit, we can also see on the right side how the technical view is showing us what is really happening beneath this. So this is how the how the request would look like in in or how XCW will receive it. And because we have a lot of ServiceNow systems, we also included the written number. And this will also allow us to also make some special cases. So, for example, when we download the audit file, and we also export the workflows for today, for example. This may take a take a second. You could also just use a service request and upload the files and then see where is the written number matching. And you can also include more in the protocol of of your ServiceNow or any kind of third party integration. You can just see which one of them has the workflow ID and then just connect all of the all of the information in all of the systems. So you have one system where you can just get all the information about what happened. And instead of also exporting on XCW all the time when there's an audit, you can just periodically include that in your information in your third party tool. Yeah. I think this is most of the idea behind this. This is like I said, this is just the UI. This is not your third party integration. This is not ServiceNow. This is not any kind of other ITSM. This is what we built as a demonstration. So this should show you the possibilities with our integration. So you can just create your own version. And when you see that XCW is lacking in some aspects, you can just say, okay, I want to change it. I want to make my own automation or my own custom processes. You can just use our XDW third party integration and use the SOAP calls to make your own creativity happen. So maybe we are pretty fast on the time. I'm also a bit anxious on on on if I can get all my points across, but I think I I sped up a bit. I hope we got some of the questions, and maybe we can also answer some of them. And Absolutely. And, thank you for, walking us through that. And as you mentioned, we do have a lot of time left, which is great. We'll try and take that time to get to any questions that we have in the chat. So let me just go ahead and take a look and see what we have. Someone did ask if they could have a copy of the recording. Yes. Everyone who does sign up for the webinar, whether they are attending the full session or, whether they have to walk away and are unable to attend, as long as you sign up and register for the webinar, you will receive a copy of the recording then as well. Yep. Absolutely. Some XCW related questions. I do see a couple in the chat here. I have one relating to business roles. Someone's asking if a business role has changed, is the assignment updated automatically within the XCW? It's not automatically updated, but we have the new functionalities where you can also just click on it. And because it's a mindful it's a mindful change on the business roles, you can just you can also just update them directly afterwards. So Okay. So it's happening automatically, but you also need to start the updating process. Because sometimes you also need to make sure that nobody made a problem on that or, made an error on this, so it's better to to not automatically push out any kind of changes. Sure. Yeah. Good. Great call out there. Let me see if we have some other XEW related questions in the chat. It looks like we have another one relating to SOAP interfaces. Can assignments also be queried via the SOAP interface, someone asks? Can you repeat the question? Oh, yeah. Sure. Of course. Yeah. Can assignments also be queried via the SOAP interface? Oh, yes. They can. Yep. They can. Yeah. And how are they query? Is there is it, is there a web service available, or how is that? So in this case, so for example, when we go for the assignment of roles, it will look like just to get a practical view on that, it will look like this. So if we add in the different, roles, for example, if we also include another system, this is how it would be curied here. This is how it should look like. And once you also have, like, different validities on that part, they should also change up here, and you get a different, validity period. Okay. Awesome. Thank you for for showing that as well. For a for a technical view. It's more on the technical side, but, yes. Okay. Great. Other questions. I have one here relating to, server system landscape. So it looks like they're asking, do you need a dedicated server slash system landscape for the XCW? It's not needed. In in this case, you can just, transport XCW on any of your SAP systems. You can also make your own client or mandate, how how you want to call it, and have a dedicated space for XDW, but it's all running on your SAP system. So it's in this regard, it's the same as the XAMS, and you don't need any kind of specific or individual or pay any money for any kind of server that you need to set up prior. Okay. And so, as we talk about connectivity associated with the XCW, we talked about some of its integration capabilities with external ticketing tools like ServiceNow. But as it relates to workflow assignment capabilities, do we have any integration with, like, SuccessFactors, Ariba, some of these cloud applications? I think, then, we would need to go a bit, back to this. So this is our x c XSP, and this will also be, there to connect to the cloud world. So everything involving the SuccessFactors, Ariba, and so on, it's better to, also jump onto the XSP and have all the cloud connections there as this is also native for cloud application, and this will also improve, the usability in this regard. Okay. Awesome. And I think this next question is kinda similar to the one I asked two ago. But someone's asking, where is the XCW hosted? I think you kinda said, you know, hosted from a Yeah. Exactly. It's it's hosted from an SAP system. Yep. It does not involve any kind of extra costs. It does not involve any kind of extra server maintenance. Most of the time, the SAP servers are already monitored in any kind of system, so you already have everything in place to to to see if the server's running and going. And I will also say one thing. Because it's running on your SAP, if your SAP is not running, you don't need any kind of user user maintenance. Okay. So Awesome. Also has that benefit on that part. Great. Well, I don't see anything else, in the chat at this time, so, I think we'll go ahead and and wrap out, and that kinda concludes today's webinar events. And on behalf of everyone at Xciting, I'd like to extend a sincere thank you for everyone joining us today, and a special thank you to Hassan for leading us through all of these sessions and sharing your experience as it relates to the XCW. We hope today's sessions have provided some form of practical insights and ideas that you can take back to your own organization as you continue to optimize and modernize your SAP IAM landscape. As a reminder, a a recording of the webinar along with the presentation materials will be shared following the events. If you have any additional questions that come to mind after today's session, you know, please don't hesitate to reach out to us. We're more than happy to continue the conversation and discuss how these capabilities may apply to your specific, you know, use cases that you have at your organization. And thank you again for spending your time with us today. We truly appreciate it. We appreciate your participation, and we hope to see you again on some future upcoming exciting webinars. Thank you, everyone, and have a wonderful rest of your day. Thank you all. Have a nice day. Thank you.
Service Pack 7 delivers the complete business role management feature set. At its core is the ability to version and reconcile roles, along with simplified logging tables that ensure background stability. Data consistency is maintained as XCW automatically compares existing assignments against live data in the target system.
If inconsistencies are detected, they can be resolved without requiring additional approvals. Changes to existing business roles are also handled automatically – assignments can be added or removed without triggering an approval workflow.
The figure below shows a reconciliation report for a user. The “Correct assignments via WF” button initiates the corresponding assignments:
The dashboard provides a full overview of all activities performed: changes to business roles and the resulting user adjustments, triggered reconciliation actions, and additional activities such as business role reviews or requests submitted via Fiori.
Regular reviews of authorization assignments are mandatory in many organizations – whether driven by compliance requirements or internal security policies. XCW Service Pack 7 introduces a structured recertification process to address this need:
The screenshots below illustrate the process from both the administrator’s and the approver’s perspective:
The SOAP web services offer maximum flexibility in designing IAM workflows – whether approval has already been completed in an external tool, an ITSM system serves as the entry point, or risk checks are needed early in the process.
Service Pack 7 expands the existing web services with the following capabilities:
Based on customer feedback, numerous smaller enhancements have been implemented:
Julia Sterr
Marketing Manager
Phone: +49 151 125 710 12
You are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from YouTube. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from hCaptcha to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from Turnstile to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Hubspot Embedded Content. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Hubspot Meetings. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information