SAP BTP

Subaccount Administration & Cloud Foundry

40 flashcards · answers and spaced-repetition review in the KnowCard app

As of December 2024, SAP deprecated SAML trust configurations for user-interactive logon in customer-owned BTP accounts. What does 'deprecated' mean for an admin planning a NEW subaccount today?
Why keep at least two users managed by the DEFAULT identity provider (and two with Subaccount Admin) in a subaccount, even after the external IdP works?
A business user needs an authorization that no existing role template in the subaccount covers. Why can't the BTP admin just create the needed template, and what does that force you to do?
What are the naming rules for a subaccount's subdomain in SAP BTP?
SAP will retire the BTP Neo environment at end of 2028. What does that deadline mean for where you start NEW BTP work today?
Which hyperscaler infrastructure providers can you select in the standard SAP BTP subaccount creation dialog?
You want to add a user who is NOT yet an org member directly to a Cloud Foundry space. With only Space Manager, why does it fail, and what role fixes it in one step?
When establishing SAML trust between an external IdP and a BTP subaccount, what makes it a TWO-way exchange, and which step do people forget?
You need to confirm a BTP service exists in a specific region/provider BEFORE committing the subaccount there. Which tool answers that, and how does it differ from what the Service Marketplace shows?
SAP Build creates a new role every time a new business site is created. Why does this matter for how an admin audits or cleans up subaccount roles?
SAP now recommends OIDC over SAML for subaccount trust. Beyond 'it's newer,' what concrete property makes OIDC the better choice?
What does the 'Allow Paid Services' switch on a space quota actually control — and what does it NOT do?
A customer requires Alibaba Cloud as the BTP infrastructure provider but it's not in the subaccount creation dialog. What's the next-best step, and what does its absence from the dialog NOT mean?
What does the 'Used for Production' flag do when creating a subaccount — and what does it deliberately NOT do?
What does 'Create Shadow Users During Logon' do, and what must you still do for those users that it does NOT handle?
Which role lets you add members and assign roles at the Cloud Foundry org level in a subaccount, and who gets it without being granted it explicitly?
An admin opens a new subaccount but sees no Cloud Foundry menu (no orgs/spaces). What precondition is missing?
When provisioning subaccount users, which identity provider requires you to add users explicitly, and which does not — and why does the difference exist?
True or false: an external SAML/OIDC identity provider only matters for authentication (logon), not for what a user is authorized to do in a subaccount?
You subscribed to the SAP Audit Log Viewer service but still can't view logs. What second prerequisite is missing?
After your external IdP authenticates all users, can you delete the SAP ID default identity provider to stop logons through it — and if not, what's the supported way?
What does the Security Groups section of a Cloud Foundry space control — and what does it NOT control?
In SAP BTP, what Cloud Foundry organization-level role does the book name, and what does having it let you do when adding members?
In a Cloud Foundry space, what do Routes expose, and how is that different from Security Groups?
Space quotas in Cloud Foundry on BTP used to be mandatory but are now optional. Given that, should you still set one — and what's the risk of skipping it?
You have the Audit Log Viewer service and global-account permissions but still can't audit a specific space. What scoped permission is missing?
You're planning security, user administration, data management, and integration for two subaccounts under the same global account. Why can't you treat them as one shared environment?
Your company is in Germany but you set a subaccount's region to a US data center. Is that a mistake, and what does the region actually determine?
On a role template overview, an application shows the value 0 in both the Role Collections and Attributes columns. What can you safely conclude about who can use it?
Inside a subaccount, what's the division of labor between a Cloud Foundry org and a space?
Among the role collections SAP delivers, which one grants comprehensive subaccount management, why assign it to at least two people, and how do the Service Administrator and Viewer collections differ from it?
Before assigning authorizations, why does the book tell you to build your OWN role collections as copies rather than editing the SAP-provided ones?
Auditors want a list of every subaccount user together with their role collections. Which export gives that (versus the plain one), what's the file format, and how are multiple role collections encoded in it?
A Cloud Foundry space's configuration changed unexpectedly and you need to know who did it and when. Which section of the space answers that — and why isn't it the Security Groups or Routes section?
In the subaccount Roles overview, what's the difference between the Role Template and Role Name columns, and what can you do from that overview that you still cannot do to a template itself?
A global account already exists. How does a new subaccount come into being, and how does that differ from how the global account itself was set up?
At the subaccount level you don't hand individual roles to users one at a time. How are roles packaged, and to which kinds of assignment targets can that package go?
Right after you enable the Cloud Foundry environment in a subaccount, how many CF orgs exist, and can you add a second one later?
What exactly do subaccount-level quotas cap for orgs and spaces, and which resource types do they limit?
Two applications live in different Cloud Foundry spaces of the same subaccount. Are their data access and data visibility isolated from each other?

Start learning today

Free to start — download the app or use it in your browser.

Get it on App StoreGet it on Google Play