Onboarding of SAP BTP Build Work Zone Service: Advanced edition

Estimated read time 11 min read

Do you know while planning to onboard the SAP BTP Build Work Zone Service, what is the checklist, onboarding steps needs to be follow?

SAP Build Work Zone is released with Standard and advanced edition.

We are planning to onboard the SAP Build Work Zone advanced edition.

Let’s discuss the high level.

Onboarding steps (disclaimer: It does depend on scenario to scenario)

S.No

Task

1

Create BTP Subaccount

2

Assign quotas & entitlements

3

Enable Build Work Zone service (Through Booster run)

4

Configure IAS & Trust

5

Setup XSUAA & Destinations

6

Create Roles and Role Collections

7

Add Business Content (Fiori, etc.)

8

Customize UI

Ā 

Create BTP Subaccount:

Enable Cloud Foundry:

Trust configuration:

Add Domain and parameter : Review and complete.

Trust configuration completed

Validate the status of Trust configuration

Once you complete S.Ā  No 1 & 2, then let’s run the Booster:

TheĀ SAP Build Work Zone, advanced editionĀ booster assists you by performing configuration steps automatically in your subaccount.

To run the booster:

In theĀ SAP BTP cockpit, use the breadcrumbs to access your global account.In the side menu, open theĀ BoostersĀ screen and click theĀ Get Started with SAP Build Work Zone, Advanced EditionĀ tile.SAP Build Work Zone, advanced editionĀ contains integration with SAP Build Process Automation service. SAP Build Process Automation is a citizen developer solution to adapt, improve, and innovate business processes with no-code workflow management and robotic process automation capabilities. If you are not planning to use SAP Build Process Automation, you can remove the service when you run the booster.

Confirm to run the Booster

Follow all the steps and complete the Build Work Zone onboarding.

Delete all, apart from Advanced edition

Onboarding setup is running

Congratulations, Booster executed successfully.

Navigate to BTP Subaccount and verify the service.

Manual execution of the Booster: If needed.

If you encounter technical issues in running the booster, here are the steps that the booster performs for you:

In theĀ SAP BTP cockpit, select a subaccount and perform the following configuration steps:

In theĀ OverviewĀ screen, enable Cloud Foundry and create an org and a space.In theĀ EntitlementsĀ screen, assign entitlements to all the services that are listed in theĀ ComponentsĀ table.In theĀ ServicesĀ Ā Instances and SubscriptionsĀ screen, subscribe and create service instances to the service plans that are listed in theĀ Service plan configurationĀ table.Create a destination to the content repository.

Run the Configurator

Launch the Configurator Wizard

After completing all previous steps, follow the configurator wizard to complete the onboarding process. You can access the configurator directly from the booster, or you can access it from the Site Manager as follows:

In theĀ SAP BTP cockpit,Ā ServicesĀ Ā Instances and Subscriptions, click theĀ SAP Build Work Zone, advanced editionĀ link in theĀ SubscriptionsĀ table to access the application.Open theĀ ConfiguratorĀ screen from the left-side menu.

Go to Site Manager: Go to Settings

Enable Identity Authentification

Now run the configurator

Select the default or custom domain as per your scenario

Ā 

Before triggering the setup, open the Destinations in SAP BTP Cockpit and download the trust

Now trigger the setup

Environment Setup completed, move to next step

Step 3: Configure the IAS, IPS to enable user authentication and user provisioning.

Switch to SAP Cloud Identity Service – Identity Authentication:

This step is only applicable to subscriptions created before March 20th, 2025. If you created a subscription after this date, your subaccount is already connected directly to Identity Authentication and you can skip this step.

Connect Your Subaccount to Identity Provisioning:

Prerequisites

The integration with the Identity Provisioning service supports only one active Identity Authentication tenant. Before you start the configuration, open the cockpit,Ā SecurityĀ Ā Trust Configuration, and verify that you have only one active Identity Authentication trust configuration in the list. The default IdP,Ā sap.default, is not relevant to the flow and can be ignored for this requirement. After the connection is formed, you can configure additional active IdPs.If you already have an active Identity Authentication tenant, you are required to reconnect it to the Identity Provisioning service after you’ve modified it.

Connector for User and Group Provisioning

Open the Settings screen from the left-side menu.

Go to the Identity Provisioning tab, and click the Connect button.

If your subaccount is not yet connected to the Identity Provisioning service, a new tenant will be created for your subaccount, and it will include the SAP Build Work Zone, advanced edition connector. In addition, a connection will be created between the Identity Authentication service and the Identity Provisioning service.

If your subaccount already has an Identity Provisioning tenant connected to the Identity Authentication service, clicking the connect button will expand the scope of the tenant to include the SAP Build Work Zone, advanced edition connector.

At this point, the connector is created with default values. In the next step of the onboarding, when you run the configurator, you will have to configure specific values.

SAP Build Work Zone, advanced edition is also available as a bundle connector.

Ā 

Click Assertion Attribute and add Groups form the list must start with an upper case

Add the Groups

Now add Default attributes : Add groups must start with upper case

Make sure you are selecting the correct value

Create BasicĀ  WZ Groups with reference help portal

Do the same

Create an application in IAS: Go to application & resource application and open the SAML 2.0 configuration

Create Application

In next step upload the trust file and move to configure

Now enable the permission for Administrator

Add the secret client ID

Configure the Identity Provisioning service: Source and Target systems

Let’s do for Source system

Add mandatory properties

Remember to add the URL

Now setup Build Work Zone as Target

Add mandatory properties

Copy default transformation depending on API version

Run provisioning job

Check the job status

Congratulation job was able to read and create the users.

Now go to Site manager again and run theĀ Configurator from below step.

Ā 

Congratulations you have completed the onboarding process

Access the Build Work Zone

Note* This blog has not included all the steps screenshot, only major one added.

Thank you.

Please do share your thought.

Ā 

Reference :Ā https://help.sap.com/docs/build-work-zone-advanced-edition/sap-build-work-zone-advanced-edition/what-is-sap-build-work-zone-advanced-edition

Ā 

​ Do you know while planning to onboard the SAP BTP Build Work Zone Service, what is the checklist, onboarding steps needs to be follow?SAP Build Work Zone is released with Standard and advanced edition.We are planning to onboard the SAP Build Work Zone advanced edition.Let’s discuss the high level.Onboarding steps (disclaimer: It does depend on scenario to scenario)S.NoTask1Create BTP Subaccount2Assign quotas & entitlements3Enable Build Work Zone service (Through Booster run)4Configure IAS & Trust5Setup XSUAA & Destinations6Create Roles and Role Collections7Add Business Content (Fiori, etc.)8Customize UIĀ Create BTP Subaccount:Enable Cloud Foundry:Trust configuration:Add Domain and parameter : Review and complete.Trust configuration completedValidate the status of Trust configurationOnce you complete S.Ā  No 1 & 2, then let’s run the Booster:TheĀ SAP Build Work Zone, advanced editionĀ booster assists you by performing configuration steps automatically in your subaccount.To run the booster:In theĀ SAP BTP cockpit, use the breadcrumbs to access your global account.In the side menu, open theĀ BoostersĀ screen and click theĀ Get Started with SAP Build Work Zone, Advanced EditionĀ tile.SAP Build Work Zone, advanced editionĀ contains integration with SAP Build Process Automation service. SAP Build Process Automation is a citizen developer solution to adapt, improve, and innovate business processes with no-code workflow management and robotic process automation capabilities. If you are not planning to use SAP Build Process Automation, you can remove the service when you run the booster.Confirm to run the BoosterFollow all the steps and complete the Build Work Zone onboarding.Delete all, apart from Advanced editionOnboarding setup is runningCongratulations, Booster executed successfully.Navigate to BTP Subaccount and verify the service.Manual execution of the Booster: If needed.If you encounter technical issues in running the booster, here are the steps that the booster performs for you:In theĀ SAP BTP cockpit, select a subaccount and perform the following configuration steps:In theĀ OverviewĀ screen, enable Cloud Foundry and create an org and a space.In theĀ EntitlementsĀ screen, assign entitlements to all the services that are listed in theĀ ComponentsĀ table.In theĀ ServicesĀ Ā Instances and SubscriptionsĀ screen, subscribe and create service instances to the service plans that are listed in theĀ Service plan configurationĀ table.Create a destination to the content repository.Run the ConfiguratorLaunch the Configurator WizardAfter completing all previous steps, follow the configurator wizard to complete the onboarding process. You can access the configurator directly from the booster, or you can access it from the Site Manager as follows:In theĀ SAP BTP cockpit,Ā ServicesĀ Ā Instances and Subscriptions, click theĀ SAP Build Work Zone, advanced editionĀ link in theĀ SubscriptionsĀ table to access the application.Open theĀ ConfiguratorĀ screen from the left-side menu.Go to Site Manager: Go to SettingsEnable Identity Authentification Now run the configurator Select the default or custom domain as per your scenarioĀ Before triggering the setup, open the Destinations in SAP BTP Cockpit and download the trustNow trigger the setupEnvironment Setup completed, move to next stepStep 3: Configure the IAS, IPS to enable user authentication and user provisioning.Switch to SAP Cloud Identity Service – Identity Authentication:This step is only applicable to subscriptions created before March 20th, 2025. If you created a subscription after this date, your subaccount is already connected directly to Identity Authentication and you can skip this step.Connect Your Subaccount to Identity Provisioning:PrerequisitesThe integration with the Identity Provisioning service supports only one active Identity Authentication tenant. Before you start the configuration, open the cockpit,Ā SecurityĀ Ā Trust Configuration, and verify that you have only one active Identity Authentication trust configuration in the list. The default IdP,Ā sap.default, is not relevant to the flow and can be ignored for this requirement. After the connection is formed, you can configure additional active IdPs.If you already have an active Identity Authentication tenant, you are required to reconnect it to the Identity Provisioning service after you’ve modified it.Connector for User and Group ProvisioningOpen the Settings screen from the left-side menu.Go to the Identity Provisioning tab, and click the Connect button.If your subaccount is not yet connected to the Identity Provisioning service, a new tenant will be created for your subaccount, and it will include the SAP Build Work Zone, advanced edition connector. In addition, a connection will be created between the Identity Authentication service and the Identity Provisioning service.If your subaccount already has an Identity Provisioning tenant connected to the Identity Authentication service, clicking the connect button will expand the scope of the tenant to include the SAP Build Work Zone, advanced edition connector.At this point, the connector is created with default values. In the next step of the onboarding, when you run the configurator, you will have to configure specific values.SAP Build Work Zone, advanced edition is also available as a bundle connector.Ā Click Assertion Attribute and add Groups form the list must start with an upper caseAdd the GroupsNow add Default attributes : Add groups must start with upper case Make sure you are selecting the correct valueCreate BasicĀ  WZ Groups with reference help portalDo the same Create an application in IAS: Go to application & resource application and open the SAML 2.0 configurationCreate ApplicationIn next step upload the trust file and move to configure Now enable the permission for AdministratorAdd the secret client IDConfigure the Identity Provisioning service: Source and Target systemsLet’s do for Source system Add mandatory properties Remember to add the URLNow setup Build Work Zone as TargetAdd mandatory propertiesCopy default transformation depending on API versionRun provisioning jobCheck the job statusCongratulation job was able to read and create the users.Now go to Site manager again and run theĀ Configurator from below step.Ā Congratulations you have completed the onboarding processAccess the Build Work Zone Note* This blog has not included all the steps screenshot, only major one added.Thank you.Please do share your thought.Ā Reference :Ā https://help.sap.com/docs/build-work-zone-advanced-edition/sap-build-work-zone-advanced-edition/what-is-sap-build-work-zone-advanced-editionĀ Ā Ā Read MoreĀ Technology Blog Posts by Members articlesĀ 

#SAP

#SAPTechnologyblog

You May Also Like

More From Author