Introduction
When we introduced SCIM (System for Cross-domain Identity Management) API support for SAP Sales & Service Cloud Version 2, ESM, the initial release focused on provisioning users of type Employee — enabling organizations to automate the full identity lifecycle of their internal workforce through SAP Cloud Identity Services.
With the latest enhancement, SAP now extends this capability to support External users. Organizations can provision and manage non-employee users — such as partners, contractors, or external collaborators — through the same SCIM-based identity lifecycle processes. As a result, these users are created and managed as External Business Users in SAP Sales Cloud Version 2, SAP Service Cloud Version 2, SAP Enterprise Service Management (ESM), and Utilities solutions built on SAP Service Cloud Version 2.
What Is New?
The SCIM API for User Management has been enhanced to support replication of userType = External.
When a user is maintained as an external user in the source identity provider — such as SAP Cloud Identity Services – Identity Authentication (IAS) — the user type information can now be propagated to downstream SAP CX applications through SCIM-based provisioning via SAP Identity Provisioning Service (IPS). The user is then created and managed as an External Business User in the target solution.
This enhancement is supported for:
- SAP Sales Cloud Version 2
- SAP Service Cloud Version 2
- SAP Enterprise Service Management (ESM)
- Utilities solutions built on SAP Service Cloud Version 2
No additional configuration is required beyond what was already established for Employee user provisioning. The userType attribute in the SCIM payload drives the classification at the target.
How It Works
The provisioning flow follows the same architecture established for the Employee user type:
- Source: A user is created or updated in SAP Cloud Identity Services – Identity Authentication (IAS), or a connected identity directory, with
userTypeset toExternal. - Propagation: SAP Identity Provisioning Service (IPS) reads the user record and transmits it to the target system using the SCIM 2.0-based connector (connector version 4).
- Target: SAP Sales Cloud Version 2, SAP Service Cloud Version 2, ESM, or a Utilities solution receives the SCIM payload and provisions the user as an External Business User.
As with the Employee flow, this enhanced connector does not require SAP Cloud Integration, supports PATCH operations for incremental updates, and handles conflict resolution automatically.
Availability
The Replicate External User Type in SCIM API feature is generally available as an informational enhancement and is activated by default. The availability date is 18 August 2026
Key Benefits
Automated User Lifecycle Management
Organizations can automate onboarding, updates, and deprovisioning of external users through a centralized identity management platform.
Improved Governance
External users are clearly distinguished from employees, helping organizations maintain accurate user records and comply with security policies.
Reduced Administration Effort
Manual user maintenance across multiple systems is minimized, reducing operational overhead and human error.
Consistent Identity Across Systems
The external user classification remains consistent from IAS to SAP Sales Cloud, SAP Service Cloud, ESM, and Utilities applications.
Better Scalability
As partner ecosystems grow, organizations can onboard large numbers of external users through standard SCIM provisioning mechanisms.
Final Thoughts
The introduction of External User Type replication through the SCIM API is a valuable enhancement for organizations using SAP Sales Cloud, SAP Service Cloud, SAP Enterprise Service Management, and Utilities solutions. By enabling seamless provisioning of contractors, partners, consultants, and other non-employee users from IAS, SAP simplifies identity management while improving governance and operational efficiency.
Source link

