SAP Business Data Cloud Onboarding Guide
Prerequisites & Entitlements
Before provisioning SAP BDC, verify you have:
- S-User ID: Required to access SAP for Me provisioning portal
- Commercial entitlement to SAP Business Data Cloud product package
- Contact person designation: Your sales account executive sends initial invitation email with 7-day validity
- Multi-factor authentication (MFA): Required for system owner to create bundled identity tenants
- Cloud Foundry environment: Required for BDC tenant deployment and SAP Cloud Identity Services integration
Phase 1: Tenant Provisioning
Access SAP for Me
- Navigate to SAP for Me (https://me.sap.com)
- Sign in with your S-User ID credentials
- Go to Portfolio & Products
- Locate SAP Business Data Cloud in My Product Packages
- Access the Provisioning and Integration Dashboard
The Provisioning Dashboard
The dashboard displays:
- Overview tab: Current solutions, quota distribution, auto-provisioned SAP Business Warehouse Private Cloud Edition
- Applications tab: Where you provision solution components (SAP Datasphere, SAP Databricks, SAP Analytics Cloud)
- Solutions tab: Your existing provisioned solutions with status
- Resources tab: Resource hierarchies organized into resource groups and folders
- Customer Landscape tab: Formation configurations for system integration
Allocate Capacity Units
- Total capacity units assigned per contract are shown in the Quota Distribution card
- SAP Warehouse Private Cloud Edition receives its contractual quota automatically
- Allocate remaining units to other solutions (SAP Datasphere, Databricks, etc.) as needed during provisioning
- Note: Each solution component = 1 solution + 1 tenant within a single resource group
Phase 2: Identity Setup (SAP Cloud Identity Services)
Prerequisites for Bundled Identity
- SAP BDC tenant must be Cloud Foundry-based
- Not available for private cloud (AliCloud) or sovereign cloud (NS2)
- System owner must have MFA enabled
- System owner email must match an S-User ID (create one if needed)
Provision SAP Cloud Identity Services Tenant
- In Identity Provider Administration Tool (identity.sap.com)
- On your BDC tenant card, select + Add SAP Cloud Identity Services
- Choose:
- Provision New SCI Tenant: Auto-matches BDC tenant type (Test, Prod, etc.)
- Use Existing SCI Tenant: Link to already-provisioned tenant
- For new tenant: Enter administrator first/last name and email (auto-populated from your account)
- Confirm and start provisioning (takes up to 1 hour)
- Monitor progress bar; can close and check status later on tenant card
Configure Authentication
After SCI provisioning completes:
- Select Configure Authentication
- Choose User Attribute mapping:
- USER ID: Map IdP Subject Name Identifier to BDC User ID
- Email: Map to BDC email address
- Custom Attribute: Map to custom field (requires manual SAML User Mapping column updates for existing users)
- (Optional) Enable Dynamic User Creation: New users auto-created with default role upon first login
- Validate login in test browser (private/guest mode) using provided URL
- Confirm and finish configuration
Note: Subject Name Identifier is case-sensitive; must match exactly (user@company.com ≠ User@company.com)
Optional: Corporate IdP Federation
Configure SAP Cloud Identity Services to forward SAML authentication to your corporate IdP for centralized identity management.
Phase 3: Initial Login & Account Activation
- Owner role receives Welcome email with activation links (valid 7 days)
- Click activation link to set password; automatically logged in after
- Activation link opens via SAP for Me → BDC Resources tab → main tenant URL
- If activation expires: Use "Forgot password?" on login page with the email address from Welcome email
- If no Welcome email: Check Spam/Junk folders or contact your account executive
Phase 4: User Management & Roles
Core BDC Roles
| Role |
Permissions |
| System Owner |
Provision/configure tenant, create identity services, manage MFA |
| BD Administrator |
Create/manage users, install intelligent applications, activate data packages, manage roles & privileges |
| DW Administrator |
Manage SAP Datasphere spaces, copy preparation/application spaces, add Modeler users to scoped roles |
| DW Modeler |
Model data in SAP Datasphere, install data products, adjust view sources |
| Consumer |
Read access to published analytics and data in SAP Analytics Cloud stories |
| Standard Role |
Default role assigned to dynamically-created users; auto-created via SAML |
Create Users
Users with BD Administrator role can create accounts in:
- Security → Users menu
- Assign roles and set user attributes (User ID, Email, Custom Mapping for SAML)
- For SAML-mapped users, ensure SAML User Mapping column matches your IdP Subject Name Identifier
Create Custom Roles
BD Administrators can create custom roles with specific privileges via:
- Security → Users and Roles → Create Roles
- Define granular permissions for intelligent applications and data products
Phase 5: Install Intelligent Applications
Prerequisites
- Intelligent application entitlement must be active in your global account
- At least one SAP source system tenant (S/4HANA Cloud, BW/4HANA, etc.) exists in a BDC formation
- SAP Note 3607594: Review before installing or updating intelligent applications
Install Process
- Open SAP Business Data Cloud cockpit
- Navigate to Intelligent Applications and Data Packages → Available tab
- Select desired application; review documentation and data products
- Click Install; Install Options dialog opens
- Source System: Select SAP system providing business data (connection test runs)
- System Alias: Auto-assigned to distinguish multi-source installations
- Business Name (optional): Custom name appended to Datasphere spaces (up to 200 characters)
- Install Location: Select formation containing source system
- Click Install
Installation Details
- Status changes to Installation in progress
- Creates 3 protected SAP Datasphere spaces (import connections, replication flows, views, analytic models)
- Starts Initial & Delta load replication flows to keep data fresh
- Creates protected SAP Analytics Cloud workspace with stories
- Completion indicated by Installed status
Post-Installation Admin Steps (Datasphere)
- Add Modeler users to preparation space scoped role
- Monitor replication flows for data freshness
- Configure row-level security in preparation space permissions table (max 5,000 permissions per user)
- Run delivered task chains as scheduled
- Add Consumer users to application space scoped role for story/dashboard access
Post-Installation Admin Steps (Analytics Cloud)
- Grant story folder access to same Consumer users
- Configure appropriate workspace permissions
Warning: Install applications sequentially, not in parallel (parallel installation consumes more resources and increases timeout risk).
Phase 6: Activate Data Packages
Prerequisites
- SAP Note 3607594: Check before activation
- Authorization from BD Administrators
- SAP Datasphere space entitlement for modeling
Activation Steps
- Open SAP Business Data Cloud cockpit
- Navigate to Intelligent Applications and Data Packages → Packages tab
- Select package; click Activate
- Status moves to Active; data products now available in Catalog for consumption
Post-Activation
- Catalog admins: Share data products to consumer spaces
- Datasphere admins: Authorize spaces to install data products
- Datasphere users: Install activated products into their modeling spaces
Optional: Data Product Generator
To replicate SAP BW data into BDC:
- Configure Data Product Generator in source system
- Create data subscriptions to receive incremental updates
- Monitor refresh status in Datasphere
Phase 7: Manage Lifecycle (Updates, Deactivation, Uninstall)
Update Intelligent Applications & Packages
- SAP Note 3607594: Check for update prerequisites before each upgrade
- Status shows Update Available when new version released
- Updates include fixes, improvements, or new KPIs
- Click Update to install latest version
Deactivate Data Packages
- Used when package no longer needed or entitlement expires
- Before deactivating, check with SAP Admin whether entitlement renewal is planned
- BD Administrators perform deactivation via Packages tab
Uninstall Intelligent Applications
- Manual uninstall available when application no longer needed
- Used when entitlement has expired/terminated
- Before uninstalling, consult with SAP Administrator
- Removes all SAP Datasphere spaces and SAP Analytics Cloud content
Service Availability & Regions
Supported Regions (Controlled Release Rollout)
Current deployments across AWS, Azure, GCP hyperscalers:
- AWS: EU (Frankfurt EU10), Australia (AP10), Singapore (AP11), Tokyo (JP10), US East/Virginia (US10), Canada Montreal (CA10), Korea (AP12), Brazil (BR10), US West (US20), US East (US21), Brazil (BR20), Canada (CA20), Switzerland (CH20), Australia (AP20), Singapore (AP21)
- Azure: Europe Amsterdam (EU20), Switzerland (CH20)
- GCP: EU Frankfurt (EU30), India Mumbai (IN30), Saudi Arabia Dammam (SA30/SA31), US Iowa (US30)
Note: Solution component availability varies by region due to compliance/buildout timelines. Contact Account Executive for regional roadmap.
Browser Support
- Google Chrome: Latest version (continuous updates)
- Microsoft Edge: Chromium-based, latest version
- Exceptional instances may limit support; see browser documentation for full requirements
Compliance & Security
- BDC itself is not certified; component certifications apply to SAP Datasphere, SAP Analytics Cloud, BTP
- Data protection: Follows SAP global guidelines; see Personal Data Processing for SAP Cloud Services
- SLA: Refer to Service Level Agreement for SAP Cloud Services (covers uptime, credits, update windows)
- Maintenance windows: Check SAP Help Portal Maintenance Windows for SAP Cloud Services (search for your service)
Common First-Day Pitfalls
- Activation link expiration: Set password within 7 days of Welcome email
- SAML identity mismatch: Subject Name Identifier must match BDC user attribute case-sensitively
- Missing entitlements: Verify intelligent application & data package entitlements before installation
- Parallel installations: Install applications sequentially to avoid timeouts
- Permissions not configured: Row-level security requires explicit permission table setup in Datasphere
- User attribute mapping mismatch: Dynamic user creation requires matching IdP attributes with BDC User ID/Email
- MFA not enabled: System owner requires MFA for bundled identity services setup
- Region limitations: Not all features available in all regions; check availability table for limitations
Support & References
- SAP Note 3607594: Prerequisites for installing/updating intelligent applications
- SAP Note 3568017: Providing support user access for troubleshooting
- SAP Note 3619907: Bundled SAP Cloud Identity Services controlled release status
- Contact: Sales Account Executive or Customer Interaction Center (CIC) for provisioning assistance
- Help Portal: https://help.sap.com/docs/SAP_BUSINESS_DATA_CLOUD
References
references/onboarding.pdf — Complete SAP BDC onboarding guide (35 pages)
references/availability.pdf — Regions, SLAs, compliance, and browser support (4 pages)
1---2name: bdc-onboarding3description: Use when the user is setting up SAP BDC for the first time, provisioning the tenant, onboarding admins/users, asking about BDC availability/regions/SLAs, or needs a getting-started walkthrough. Trigger phrases include "set up BDC", "onboard BDC", "BDC tenant", "BDC availability", "BDC regions", "BDC getting started", "first time BDC", "provision BDC".4---56# SAP Business Data Cloud Onboarding Guide78## Prerequisites & Entitlements910Before provisioning SAP BDC, verify you have:11- **S-User ID**: Required to access SAP for Me provisioning portal12- **Commercial entitlement** to SAP Business Data Cloud product package13- **Contact person designation**: Your sales account executive sends initial invitation email with 7-day validity14- **Multi-factor authentication (MFA)**: Required for system owner to create bundled identity tenants15- **Cloud Foundry environment**: Required for BDC tenant deployment and SAP Cloud Identity Services integration1617## Phase 1: Tenant Provisioning1819### Access SAP for Me201. Navigate to SAP for Me (https://me.sap.com)212. Sign in with your S-User ID credentials223. Go to **Portfolio & Products**234. Locate **SAP Business Data Cloud** in My Product Packages245. Access the **Provisioning and Integration Dashboard**2526### The Provisioning Dashboard27The dashboard displays:28- **Overview tab**: Current solutions, quota distribution, auto-provisioned SAP Business Warehouse Private Cloud Edition29- **Applications tab**: Where you provision solution components (SAP Datasphere, SAP Databricks, SAP Analytics Cloud)30- **Solutions tab**: Your existing provisioned solutions with status31- **Resources tab**: Resource hierarchies organized into resource groups and folders32- **Customer Landscape tab**: Formation configurations for system integration3334### Allocate Capacity Units35- Total capacity units assigned per contract are shown in the Quota Distribution card36- SAP Warehouse Private Cloud Edition receives its contractual quota automatically37- Allocate remaining units to other solutions (SAP Datasphere, Databricks, etc.) as needed during provisioning38- Note: Each solution component = 1 solution + 1 tenant within a single resource group3940## Phase 2: Identity Setup (SAP Cloud Identity Services)4142### Prerequisites for Bundled Identity43- SAP BDC tenant must be Cloud Foundry-based44- Not available for private cloud (AliCloud) or sovereign cloud (NS2)45- System owner must have MFA enabled46- System owner email must match an S-User ID (create one if needed)4748### Provision SAP Cloud Identity Services Tenant491. In **Identity Provider Administration Tool** (identity.sap.com)502. On your BDC tenant card, select **+ Add SAP Cloud Identity Services**513. Choose:52 - **Provision New SCI Tenant**: Auto-matches BDC tenant type (Test, Prod, etc.)53 - **Use Existing SCI Tenant**: Link to already-provisioned tenant544. For new tenant: Enter administrator first/last name and email (auto-populated from your account)555. Confirm and start provisioning (takes up to 1 hour)566. Monitor progress bar; can close and check status later on tenant card5758### Configure Authentication59After SCI provisioning completes:601. Select **Configure Authentication**612. Choose **User Attribute mapping**:62 - **USER ID**: Map IdP Subject Name Identifier to BDC User ID63 - **Email**: Map to BDC email address64 - **Custom Attribute**: Map to custom field (requires manual SAML User Mapping column updates for existing users)653. **(Optional) Enable Dynamic User Creation**: New users auto-created with default role upon first login664. Validate login in test browser (private/guest mode) using provided URL675. Confirm and finish configuration6869**Note**: Subject Name Identifier is case-sensitive; must match exactly (user@company.com ≠ User@company.com)7071### Optional: Corporate IdP Federation72Configure SAP Cloud Identity Services to forward SAML authentication to your corporate IdP for centralized identity management.7374## Phase 3: Initial Login & Account Activation7576- **Owner role** receives Welcome email with activation links (valid 7 days)77- Click activation link to set password; automatically logged in after78- Activation link opens via SAP for Me → BDC Resources tab → main tenant URL79- **If activation expires**: Use "Forgot password?" on login page with the email address from Welcome email80- **If no Welcome email**: Check Spam/Junk folders or contact your account executive8182## Phase 4: User Management & Roles8384### Core BDC Roles8586| Role | Permissions |87|------|-----------|88| **System Owner** | Provision/configure tenant, create identity services, manage MFA |89| **BD Administrator** | Create/manage users, install intelligent applications, activate data packages, manage roles & privileges |90| **DW Administrator** | Manage SAP Datasphere spaces, copy preparation/application spaces, add Modeler users to scoped roles |91| **DW Modeler** | Model data in SAP Datasphere, install data products, adjust view sources |92| **Consumer** | Read access to published analytics and data in SAP Analytics Cloud stories |93| **Standard Role** | Default role assigned to dynamically-created users; auto-created via SAML |9495### Create Users96Users with **BD Administrator** role can create accounts in:97- **Security** → **Users** menu98- Assign roles and set user attributes (User ID, Email, Custom Mapping for SAML)99- For SAML-mapped users, ensure **SAML User Mapping** column matches your IdP Subject Name Identifier100101### Create Custom Roles102BD Administrators can create custom roles with specific privileges via:103- **Security** → **Users and Roles** → **Create Roles**104- Define granular permissions for intelligent applications and data products105106## Phase 5: Install Intelligent Applications107108### Prerequisites109- Intelligent application entitlement must be active in your global account110- At least one SAP source system tenant (S/4HANA Cloud, BW/4HANA, etc.) exists in a BDC formation111- **SAP Note 3607594**: Review before installing or updating intelligent applications112113### Install Process1141. Open SAP Business Data Cloud cockpit1152. Navigate to **Intelligent Applications and Data Packages** → **Available** tab1163. Select desired application; review documentation and data products1174. Click **Install**; Install Options dialog opens1185. **Source System**: Select SAP system providing business data (connection test runs)1196. **System Alias**: Auto-assigned to distinguish multi-source installations1207. **Business Name** (optional): Custom name appended to Datasphere spaces (up to 200 characters)1218. **Install Location**: Select formation containing source system1229. Click **Install**123124### Installation Details125- Status changes to **Installation in progress**126- Creates 3 protected SAP Datasphere spaces (import connections, replication flows, views, analytic models)127- Starts Initial & Delta load replication flows to keep data fresh128- Creates protected SAP Analytics Cloud workspace with stories129- Completion indicated by **Installed** status130131### Post-Installation Admin Steps (Datasphere)1321. **Add Modeler users** to preparation space scoped role1332. **Monitor replication flows** for data freshness1343. **Configure row-level security** in preparation space permissions table (max 5,000 permissions per user)1354. **Run delivered task chains** as scheduled1365. **Add Consumer users** to application space scoped role for story/dashboard access137138### Post-Installation Admin Steps (Analytics Cloud)139- Grant story folder access to same Consumer users140- Configure appropriate workspace permissions141142**Warning**: Install applications sequentially, not in parallel (parallel installation consumes more resources and increases timeout risk).143144## Phase 6: Activate Data Packages145146### Prerequisites147- **SAP Note 3607594**: Check before activation148- Authorization from BD Administrators149- SAP Datasphere space entitlement for modeling150151### Activation Steps1521. Open SAP Business Data Cloud cockpit1532. Navigate to **Intelligent Applications and Data Packages** → **Packages** tab1543. Select package; click **Activate**1554. Status moves to **Active**; data products now available in Catalog for consumption156157### Post-Activation158- **Catalog admins**: Share data products to consumer spaces159- **Datasphere admins**: Authorize spaces to install data products160- **Datasphere users**: Install activated products into their modeling spaces161162### Optional: Data Product Generator163To replicate SAP BW data into BDC:1641. Configure **Data Product Generator** in source system1652. Create **data subscriptions** to receive incremental updates1663. Monitor refresh status in Datasphere167168## Phase 7: Manage Lifecycle (Updates, Deactivation, Uninstall)169170### Update Intelligent Applications & Packages171- **SAP Note 3607594**: Check for update prerequisites before each upgrade172- Status shows **Update Available** when new version released173- Updates include fixes, improvements, or new KPIs174- Click **Update** to install latest version175176### Deactivate Data Packages177- Used when package no longer needed or entitlement expires178- Before deactivating, check with SAP Admin whether entitlement renewal is planned179- BD Administrators perform deactivation via **Packages** tab180181### Uninstall Intelligent Applications182- Manual uninstall available when application no longer needed183- Used when entitlement has expired/terminated184- Before uninstalling, consult with SAP Administrator185- Removes all SAP Datasphere spaces and SAP Analytics Cloud content186187## Service Availability & Regions188189### Supported Regions (Controlled Release Rollout)190Current deployments across AWS, Azure, GCP hyperscalers:191- **AWS**: EU (Frankfurt EU10), Australia (AP10), Singapore (AP11), Tokyo (JP10), US East/Virginia (US10), Canada Montreal (CA10), Korea (AP12), Brazil (BR10), US West (US20), US East (US21), Brazil (BR20), Canada (CA20), Switzerland (CH20), Australia (AP20), Singapore (AP21)192- **Azure**: Europe Amsterdam (EU20), Switzerland (CH20)193- **GCP**: EU Frankfurt (EU30), India Mumbai (IN30), Saudi Arabia Dammam (SA30/SA31), US Iowa (US30)194195Note: Solution component availability varies by region due to compliance/buildout timelines. Contact Account Executive for regional roadmap.196197### Browser Support198- **Google Chrome**: Latest version (continuous updates)199- **Microsoft Edge**: Chromium-based, latest version200- Exceptional instances may limit support; see browser documentation for full requirements201202### Compliance & Security203- **BDC itself** is not certified; component certifications apply to SAP Datasphere, SAP Analytics Cloud, BTP204- **Data protection**: Follows SAP global guidelines; see Personal Data Processing for SAP Cloud Services205- **SLA**: Refer to Service Level Agreement for SAP Cloud Services (covers uptime, credits, update windows)206- **Maintenance windows**: Check SAP Help Portal Maintenance Windows for SAP Cloud Services (search for your service)207208## Common First-Day Pitfalls2092101. **Activation link expiration**: Set password within 7 days of Welcome email2112. **SAML identity mismatch**: Subject Name Identifier must match BDC user attribute case-sensitively2123. **Missing entitlements**: Verify intelligent application & data package entitlements before installation2134. **Parallel installations**: Install applications sequentially to avoid timeouts2145. **Permissions not configured**: Row-level security requires explicit permission table setup in Datasphere2156. **User attribute mapping mismatch**: Dynamic user creation requires matching IdP attributes with BDC User ID/Email2167. **MFA not enabled**: System owner requires MFA for bundled identity services setup2178. **Region limitations**: Not all features available in all regions; check availability table for limitations218219## Support & References220221- **SAP Note 3607594**: Prerequisites for installing/updating intelligent applications222- **SAP Note 3568017**: Providing support user access for troubleshooting223- **SAP Note 3619907**: Bundled SAP Cloud Identity Services controlled release status224- **Contact**: Sales Account Executive or Customer Interaction Center (CIC) for provisioning assistance225- **Help Portal**: https://help.sap.com/docs/SAP_BUSINESS_DATA_CLOUD226227---228229## References230- `references/onboarding.pdf` — Complete SAP BDC onboarding guide (35 pages)231- `references/availability.pdf` — Regions, SLAs, compliance, and browser support (4 pages)