SF PLT CommonSuperDomain
SF PLT CommonSuperDomain
2 Change History. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
SAP SuccessFactors is offering the common super domain feature to mitigate the effects caused by major browser
vendors' discontinuing support for third-party cookies on their browsers.
Vendors are discontinuing support for third-party cookies on their browsers in order to comply with new laws
created to avoid the tracking of browser behavior by advertising companies.
This deprecation impacts SAP SuccessFactors products. So, customers need to migrate all SAP SuccessFactors
HCM suite products, along with products such as Learning (LMS), Employee Central Payroll (ECP), and Onboarding
1.0 (ONB1.0).
We've identified the impact that the third-party cookie deprecation might have on SAP SuccessFactors
applications.
Note
The deprecation only impacts UI integration. API and Secure File Transfer Protocol (SFTP) integrations are not
affected.
Let’s say users are directly accessing SAP SuccessFactors applications using the SAP SuccessFactors access URL
performancemanager.successfactors.eu. Or admins could be integrating this URL in company’s native application.
Different products across the HCM suite have URLs that end up in different domains:
All these URLs are associated with different domains, and in the context of the SAP SuccessFactors application
URL, they are considered third parties. From the 2H 2023 release, SAP SuccessFactors is providing an automated
solution to help customers and partners migrate from the legacy domains to a new common super domain. The
URLs would then look like this:
Learn what you need to do before migrating to the common super domain.
• Test, analyze, and validate whether third-party cookie deprecation has any effect on your non SAP
SuccessFactors UI integration.
• Execute migration on preview and non-productive tenants and test the application thoroughly before executing
the migration on a productive tenant.
• Clean up duplicate Assertion Consumer Services (ACS) settings:
• If duplicates are not cleaned up, customers will not be able to make any changes to these ACS records in
the UI (either provisioning UI or Admin Center) because, when they try to save, they will get a message that
duplicate entries exist.
• If duplicates are not cleaned up, they won't break any of customer/partner’s tenant’s existing ACS
behavior. So, cleanup is not required, but we do recommend it.
Learn about what's in and out of scope on common super domain (CSD) migration.
In Scope
Among the impact areas specified in the Impact of Third-Party Cookie Deprecation on SAP SuccessFactors
Applications part of this document, CSD migration, an automated solution from SAP SuccessFactors, solves the
following problems:
• User authentication and single sign-on (SSO) – customer or partner tenants configured to use:
• Basic authentication, meaning username and password based on SSO.
• SAP Identity Authentication Services (IAS) as the primary and only Identity Provider (IdP).
• SAP IAS as proxy along with using third-party corporate IdP.
• Embedded iFrames where content is loaded from one of the SAP SuccessFactors products.
• SAP SuccessFactors internal integrations - that is, integration between the HCM suite and Learning, Employee
Central Payroll, Stories in People Analytics, Workforce Analytics, and Onboarding 1.0.
Out of Scope
• Customers/partners using third-party IdPs such as Microsoft Azure Active Directory, Okta for Single Sign-On
(SSO) – the SSO settings on the third-party application to allow SAML assertion and build trust on *.cloud.sap
or *.sapcloud.cn needs to be configured and established in the third-party IdP.
In such cases, customers must fix any issues with third-party cookies themselves.
• External partner UI integrations and corresponding iFrames content loading. UI embedding uses third-
party cookies to offer integrations with external partners, which provide HR services, such as background
verification, benefits administration, time management, and more. These integrations are treated as third-
1. Access to CSD migration requires the specific Common Super Domain shown here.
Here's a checklist of items to bear in mind after migration to the common super domain (CSD).
Impact of CSD migration on your tenants Analysis work Analyze the impact of CSD migration on
your tenants.
Tenant using third-party corporate iden- SSO doesn't work. After the CSD migration, you need
tify provider (IdP), such as Microsoft to identify and manually re-establish
Azure Active Directory. External UI integrations and SSO integra- SSO trust against the new domain
tions are impacted. (*.cloud.sap or *.sapcloud.cn) wherever
you have dependency on SAP Success-
Factors SSO that was earlier based on
the old domain. The identification could
be guided by the list of Assertion Con-
sumers Services settings.
Tenants configured to use IAS as Proxy Make changes to your corporate IdP to
along with the third-party corporate IdP. support IAS on the new common super
domain.
Reverse proxy settings. After CSD migration, reverse proxy Make changes to your proxy settings
doesn't work.
aligning with the common super domain
SAP SuccessFactorsis introducing and
ensure to test all the related scenarios
at your end and address any issues sur-
faced due to third-party cookies depreca-
tion.
Status of integration of SuccessFactors If a learning instance is integrated with Pull migration cannot be initiated if
Platform with Learning. SuccessFactors Platorm, sealing is a pre- the integration between SuccessFactors
requisite for initiating CSD migration. In- Platform and Learning is not sealed. To
tegration sealing is validation that the in- seal, choose System Adminstration
tegration has been correctly set up so
Configuration System Configuration
that the CSD migration of Learning URLs
completes successfully. Bizx Integration Status .
Learning tenants using custom content N/A If the Learning instance includes content
server. launched from a content server hosted
outside of SAP SuccessFactors, the new
Learning instance URL that includes the
common super domain will need to be
added to the allowlist for the cross-do-
main portlet.
Learning tenants using Open Content N/A If Open Content Network (OCN) is ena-
Network, such as LinkedIn. bled in the Learning instance for one or
more vendors, the configuration in the
vendor application might need to be up-
dated. If the OCN vendor application in-
cludes any references to the legacy do-
main in the Learning instance's URL, it
will need to be updated to reference the
common super domain.
External (Partner) UI integrations includ- Embedded iFrames with partner content Review Assertion Consumer Services
ing SolEx partners and any SSO dependency on SAP IAS will (ACS) Settings. This will provide a list of
be impacted. integrations built into your tenant. Ana-
lyze the impact for each integration and
work with partners to get it fixed.
New CSD adoption in the company’s eco- N/A The new domain (*.cloud.sap) should be
system/landscape – Allow requests from added to the company’s IT landscape if
*.cloud.sap or *.sapcloud.cn. (Firewalls this kind of allowed listing exists before
should consider requests coming from CSD migration is triggered.
these sources as authentic requests)
Customers can choose to purchase and add additional preview test tenants or production dev/test tenants in their
existing landscape.
Every new tenant (greenfield) assigned to a customer will be provisioned on a common super domain (CSD) by
default. There is no need to migrate these tenants to CSD.
Next: Additional Enhancements Outside Common Super Domain Migration [page 12]
Not every impact on SAP SuccessFactors applications arising from third-party cookie deprecation can be
addressed by updating the product access or integration domains to a common super domain (CSD).
There are some special scenarios that need specific handling and solutioning outside CSD migration. An example is
Learning Integration with Work Zone.
The display of Work Zone within the Course Home page requires the use of third-party cookies and action
is needed to ensure that the Work Zone integration continues to function when third party cookies are not
supported in a browser. In System Administration Configuration System Configuration BizX , set
openJaminNewBrowserWindow to true.
Next: Other Things You Need to Know About Migration [page 12]
There are some more things you need to know about common secure domain (CSD) migration.
• SAP SuccessFactors HCM suite-wide products will be migrated through the automated solution for CSD
migration, to avoid production integration issues.
Changes in the external integrations, such as third-party corporate identity provider (IdP), should be
synchronized with the CSD migration.
• The CSD migration can take up 30 minutes. There could be 30 minutes of UI downtime during migration.
However, backend API executions and jobs are not impacted.
• If any errors occur during CSD migration or there are issues afterwards, please log an incident under LOD-SF-
CSD.
Previous: Additional Enhancements Outside Common Super Domain Migration [page 12]
Joule customers need to make some updates after migrating to the common super domain (CSD).
Procedure
Previous: Other Things You Need to Know About Migration [page 12]
1.3.9 Troubleshooting
You might encounter problems with migration to the common super domain. Here's some help on how to resolve
them.
If you see this message It's this type of message: This needs to happen:
An enabled reverse proxy has been de- Warning • Reverse proxy configuration needs
tected.
to be adopted to the new domain-
that is, hr.cloud.sap.com.
• Disable reverse proxy and proceed
with migration.
• If customer does not really use re-
verse proxy then request SAP/Part-
ner to remove the configuration in
HCM provisioning.
Open Content Network (OCN) is enabled Warning You need to update the OCN vendor ap-
in this Learning instance for one or more plication URL reference to the common
vendors. If the OCN vendor application super domain.
includes any references to the legacy do-
main in the Learning instances, you need
to update it to reference the common su-
per domain.
This Learning instance includes content Warning You need to add the new Learning in-
launched from a content server hosted stance URL that includes the common
outside of SuccessFactors. You need to super domain to the allowlist for the
add the new Learning instance URL that cross-domain proxlet.
includes the common super domain to
the allowlist for the cross-domain proxlet.
A Learning instance is integrated with Error You need to seal LMS application with
your SAP SuccessFactors Platform in- BizX company ID.
stance; however, the integration is not
sealed.
The IAS tenant is integrated with a cor- Warning Customers need to configure corporate
porate IDP, thus further configurations IDP to accommodate IAS on cloud.sap
are needed on corporate IDP to ensure domain
connection to IAS on the new common
super domain. Please make appropri-
ate changes on the corporate IDP, then
come back acknowledge that necessary
changes are made before proceeding
with this automated common super do-
main migration.
Caution
Customers need to configure corpo-
rate IDP.
Customer IDP has been detected. Please Warning We recommend that you migrate to IAS
check the SAML2 configuration and, if as proxy to the IDP before running the
required, adapt it when migration is com- migration.Customers can run migration,
plete. but needs to manually update SAML con-
figurations in IDP.
Customer IDP has been detected. Push Error Customer, not SAP, should run the migra-
Scenario stopped. tion.
An SSO configuration for a Solution Ex- Warning After the migration, the embedding of
tension such as OpenText, Workforce your SolEx or BTP application might not
Software, Benefit Focus or a Business work anymore. The changes required to
Technology Platform extension has been make the embedding work again are ex-
detected in "Provisioning - Authorized SP plained in the KBA. This includes chang-
Assertion Consumer Setting". ing or adding the new URLs to the config-
uration of the third-party or BTP applica-
tion.
KBA 3448820
A legacy IdP-initiated SSO URL has been Warning After the migration, the IdP-initiated SSO
detected for External Benefits Adminis- won't work until you change the domain
tration in Provisioning. of the URL to the new one, as described
in the KBA.
KBA 3448820
A legacy IdP-initiated SSO URL has been Warning After the migration, the IdP-initiated SSO
detected for External Time Management won't work until you change the domain
in Provisioning. of the URL to the new one, as described
in the KBA.
KBA 3448820
A legacy IdP-initiated SSO URL has been Warning After the migration, the IdP-initiated SSO
detected for External Time Management won't work until you change the domain
in Provisioning. of the URL to the new one, as described
in the KBA.
KBA 3448820
Assumptions and options for migrations are different, depending on whether you use SAP Identity Authentication
Services (IAS) as your identity provider (IdP) or you use a third-party IdP.
Learn about the assumptions and options governing common super domain (CSD) migration if you are using SAP
Identity Authentication Services (IAS) as your sole identity provider (IdP).
After Migration
SAP IAS can support both ondemand.com and cloud.sap accesses at the same time, and these are available now.
IAS tenant ID will remain the same – that is, the Name under Tenant Settings page in the IAS Admin Console will
NOT change.
If this tenant name is changed, then ALL applications connected to this IAS need to update the Security Assertion
Markup Language (SAML) issuer name in each application affected. Since there could be many applications
connected to one single IAS, such a change could significantly impact the connected applications operation. If you
can migrate all the applications authenticating using SAP IAS to the same common super domain, then you can
change the IAS’s name to CSD as well.
Once done with the configuration changes described above, you can test the login and logout process on both the
SP initiate and the IAS initiate.
• End users are able to log in with the new domain. They are redirected to IAS on CSD to enter their User ID and
password.
• End users can successfully log out and are redirected to the logout page under CSD.
• End users are redirected to IAS (on CSD) for login and then redirected back to the SAP SuccessFactors HCM
suite on CSD.
• End users can successfully log out and are then redirected to the logout URL specified in the Manage SAML
SSO page.
Learn about the assumptions and options governing common secure domain (CSD) migration if you are not using
SAP Identity Authentication Services (IAS) as your identity provider (IdP).
If you are using SAP SuccessFactors products such as Learning, Employee Central Payroll, or Onboarding, or are
using partner applications, these will be migrated to CSD to avoid product integration discrepancies or issues.
Execution Options
• Migrate to IAS as the corporate IdP, then use SAP's automated solution for migrating to CSD.
1. Identify, configure, test, and deploy other necessary changes for the specific third-party corporate IdP
deployed. For specific changes outside of the ones listed below, please check the official documentation of
your IdP vendors to reconfigure URLs aligning with CSD embedded URLs.
2. On the third-party corporate IdP side, at minimum, change the parameters equivalent to these parameters in
SAP IAS:
• Assertion Consumer Service Endpoint
• Single Logout Endpoint
In SAP SuccessFactors, review and change the redirect URLs for the third-party corporate IdP, if applicable.
The URLs for the relevant sales demo systems are changing.
Learn about changes to the documentation for the common super domain in recent releases.
1H 2024
New We've added information on some up- Actions Following Migration [page 13]
dates Joule customers need to make af-
ter migrating to the common super do-
main.
2H 2023
March 2024
Added We added information on changes to sales Sales Demo System URL Changes [page
demo system urls. 21]
December 2023
Hyperlinks
Some links are classified by an icon and/or a mouseover text. These links provide additional information.
About the icons:
• Links with the icon : You are entering a Web site that is not hosted by SAP. By using such links, you agree (unless expressly stated otherwise in your agreements
with SAP) to this:
• The content of the linked-to site is not SAP documentation. You may not infer any product claims against SAP based on this information.
• SAP does not agree or disagree with the content on the linked-to site, nor does SAP warrant the availability and correctness. SAP shall not be liable for any
damages caused by the use of such content unless damages have been caused by SAP's gross negligence or willful misconduct.
• Links with the icon : You are leaving the documentation for that particular SAP product or service and are entering an SAP-hosted Web site. By using such links,
you agree that (unless expressly stated otherwise in your agreements with SAP) you may not infer any product claims against SAP based on this information.
Example Code
Any software coding and/or code snippets are examples. They are not for productive use. The example code is only intended to better explain and visualize the syntax and
phrasing rules. SAP does not warrant the correctness and completeness of the example code. SAP shall not be liable for errors or damages caused by the use of example
code unless damages have been caused by SAP's gross negligence or willful misconduct.
Bias-Free Language
SAP supports a culture of diversity and inclusion. Whenever possible, we use unbiased language in our documentation to refer to people of all cultures, ethnicities, genders,
and abilities.
SAP and other SAP products and services mentioned herein as well as
their respective logos are trademarks or registered trademarks of SAP
SE (or an SAP affiliate company) in Germany and other countries. All
other product and service names mentioned are the trademarks of their
respective companies.