
SAP CUA Deprovisioning Workflow: Complete Guide
Date Posted:
Category:
Security
Author:
Malarvanan

SAP CUA Deprovisioning Workflow: Complete Guide
Date Posted:
Category:
Security
Author:
Malarvanan

SAP CUA Deprovisioning Workflow: Complete Guide
Date Posted:
Category:
Security
Author:
Malarvanan
Get your Tailored Quote for your Organisation
Get your Tailored Quote for your Organisation
Get your Tailored Quote for your Organisation
SAP-CUA Deprovisioning Workflow
1. Purpose
This workflow is to update SAP attributes whenever an account gets locked.
2. Systems Involved
System | Purpose |
|---|---|
SailPoint ISC | Workflow |
SAP CUA | Account/HTTP operations |
Workday | Enddate / cloudlifecycle state |
ServiceNow | Termination requests |
3. Termination Trigger
The workflow can start from two systems.
Workday Trigger
Workday automatically marks the employee as terminated. When SailPoint detects the following change:
cloudLifecycleState = terminated |
The deprovisioning workflow starts. In this scenario, there is no ServiceNow ticket number.
ServiceNow Trigger
A termination request can also come from ServiceNow. ServiceNow sends the request to SailPoint through an API call with the following information:
Identity ID
Ticket Number (e.g. INC0012345)
Termination Date
The ticket number is stored in SAP for audit tracking.
4. Day 0 – Immediate Actions
When termination is detected, SailPoint immediately performs the following actions in SAP.
Lock SAP Account
SailPoint performs: Manage Accounts → Disable
Result:
SAP user account becomes locked.
User cannot log in.

Disable will lock the account in SAP : https://documentation.sailpoint.com/connectors/identityiq/sap_ibp_for_supply_chain/help/sap_framework/integrating_sap_ibp_for_supply_chain/enable_disable_operations.html
Update SAP Attributes
After the account is locked, several SAP attributes are updated.
SAP Field | Value |
|---|---|
User Group | FLAG4DELETE |
End Date | Termination Date |
Removed | |
Account No | ServiceNow Ticket |
Method: Direct HTTP operation to SAP (OR) Before Provisioning Rule when Disable operation occurs, plan sets these values to the attributes. Because we can't directly update the account/identity attribute via workflow or API. |
5. Manager Notification
After the account is locked, SailPoint sends an email to the user's manager.
The email informs the manager that the user has been terminated and provides an option to reactivate the account if necessary.
Example message |
|---|
User has been terminated. If the termination was incorrect, please reactivate the account within 7 days. If no action is taken, the account access will be permanently removed. |
A form is included in the email - the manager can choose: Reactivate or Do Not Reactivate |
6. Grace Period (7 Days)
The system provides a 7-day grace period.
During this time:
The account remains locked.
Roles and profiles are still assigned.
The manager can request reactivation.
This allows recovery if termination was incorrect.
7. Reactivation Scenario
If the manager requests reactivation within 7 days (from the form), SailPoint performs:
Manage Accounts → Enable
Result:
SAP account becomes unlocked.
User can log in again.
8. No Reactivation After 7 Days
If the manager does not respond or chooses not to reactivate, SailPoint performs final cleanup.
The following actions occur:
Remove SAP Roles.
Remove SAP Profiles.
9. Overall Workflow

Stay tuned to our blog to see more posts about
Sailpoint products implementation and its related updates.
Stay tuned to our blog to see more posts about SailPoint products implementation and its related updates.
Category:
Category:
Security
Security
SAP-CUA Deprovisioning Workflow
1. Purpose
This workflow is to update SAP attributes whenever an account gets locked.
2. Systems Involved
System | Purpose |
|---|---|
SailPoint ISC | Workflow |
SAP CUA | Account/HTTP operations |
Workday | Enddate / cloudlifecycle state |
ServiceNow | Termination requests |
3. Termination Trigger
The workflow can start from two systems.
Workday Trigger
Workday automatically marks the employee as terminated. When SailPoint detects the following change:
cloudLifecycleState = terminated |
The deprovisioning workflow starts. In this scenario, there is no ServiceNow ticket number.
ServiceNow Trigger
A termination request can also come from ServiceNow. ServiceNow sends the request to SailPoint through an API call with the following information:
Identity ID
Ticket Number (e.g. INC0012345)
Termination Date
The ticket number is stored in SAP for audit tracking.
4. Day 0 – Immediate Actions
When termination is detected, SailPoint immediately performs the following actions in SAP.
Lock SAP Account
SailPoint performs: Manage Accounts → Disable
Result:
SAP user account becomes locked.
User cannot log in.

Disable will lock the account in SAP : https://documentation.sailpoint.com/connectors/identityiq/sap_ibp_for_supply_chain/help/sap_framework/integrating_sap_ibp_for_supply_chain/enable_disable_operations.html
Update SAP Attributes
After the account is locked, several SAP attributes are updated.
SAP Field | Value |
|---|---|
User Group | FLAG4DELETE |
End Date | Termination Date |
Removed | |
Account No | ServiceNow Ticket |
Method: Direct HTTP operation to SAP (OR) Before Provisioning Rule when Disable operation occurs, plan sets these values to the attributes. Because we can't directly update the account/identity attribute via workflow or API. |
5. Manager Notification
After the account is locked, SailPoint sends an email to the user's manager.
The email informs the manager that the user has been terminated and provides an option to reactivate the account if necessary.
Example message |
|---|
User has been terminated. If the termination was incorrect, please reactivate the account within 7 days. If no action is taken, the account access will be permanently removed. |
A form is included in the email - the manager can choose: Reactivate or Do Not Reactivate |
6. Grace Period (7 Days)
The system provides a 7-day grace period.
During this time:
The account remains locked.
Roles and profiles are still assigned.
The manager can request reactivation.
This allows recovery if termination was incorrect.
7. Reactivation Scenario
If the manager requests reactivation within 7 days (from the form), SailPoint performs:
Manage Accounts → Enable
Result:
SAP account becomes unlocked.
User can log in again.
8. No Reactivation After 7 Days
If the manager does not respond or chooses not to reactivate, SailPoint performs final cleanup.
The following actions occur:
Remove SAP Roles.
Remove SAP Profiles.
9. Overall Workflow

Stay tuned to our blog to see more posts about
Sailpoint products implementation and its related updates.
Category:
Security

