Before connecting EmpowerID to an external directory, please review the Getting Started with Directory Systems topic. The topic walks you through the prerequisites you need to complete before connecting to an external directory for the first time. These prerequisites include: Configuring the appropriate server roles for your EmpowerID servers Reviewing the Join and Provision Rules for your environment Reviewing the Join and Provision Filters for your environment If you have already connected EmpowerID to another external directory, you can skip the above prerequisites. EmpowerID provides connectors for a wide range of user directories and resource systems. As an administrator, you can use these connectors to quickly connect EmpowerID to your organization's identity-aware systems and applications. When you do so, you create an account store for that application in the EmpowerID Identity Warehouse and use that account store to configure how you want EmpowerID to manage the identity information in that system.
The EmpowerID SAP HANA DB connector lets you create, synchronize, and manage SAP HANA DB user, role and role assignment information in EmpowerID. Imported user information can be managed and synchronized with data in any connected back-end user directories. When EmpowerID inventories SAP HANA DB, it creates an account in the EmpowerID Identity Warehouse for each SAP HANA DB user, a group for each SAP HANA DB role, and assigns group membership to users based on their database roles in SAP HANA DB.
Once connected, you can manage this data from EmpowerID in the following ways:
Account Management
Inventory user accounts
Create, Update and Delete user accounts
Enable and Disable user accounts
Role Management
Inventory roles
Inventory role memberships
Create and Delete roles
Add and Remove members to and from roles
Attribute Flow
Users in SAP HANA DB are inventoried as accounts in EmpowerID. The below table shows the attribute mappings of SAP HANA DB user attributes to EmpowerID account attributes.
SAP HANA DB Attribute | EmpowerID Attribute | Description |
---|---|---|
UserName | ||
FriendlyName | FriendlyName | Friendly or Display Name of a user |
Email address of a user | ||
ValidFrom | ValidFrom | The date and time a user was created in the system |
PreferredLanguage | PreferredLanguage | Preferred language of a user |
TimeZone | ExtensionAttribute10 | Time Zone of a user |
IsKerberosEnabled | ExtensionAttribute11 | Kerberos authentication enabled |