- Proxy Now feature is logging out the user;
- I'm being logged out when trying to use Proxy Now feature;
- After hit "ok" on Proxy Now feature, the user get logged out of the instance;
- I'm suddenly logged out when proxying as another user;
- Proxy Now feature is misbehaving;
- Kicked out of the instance when clicking "OK" after choosing Proxy target;
- When proxying I'm bring redirect to another instance.
SAP SuccessFactors HXM Suite
Reproducing the Issue
- Log in at the instance;
You must have proxy rights under someone;
- Select the "Proxy Now" feature;
- Choose proxy target user (any);
- Click "OK";
- You're logged out of the instance or being redirect to another BizX environment (such another preview, development or production environment).
- All URLs listed in the "Authorized SP Assertion Consumer Service Settings" page (Provisioning) will receive a "log out" instruction for the current user when executing a proxy.
- This is what allows that same user to be able to log back in as the proxied target user. It can be that these URLs aren't properly set or needs to have its cache refreshed.
At first, please kindly note that customers aren't able to access Provisioning, only partners or support team members.
However, as a initial hit on the issue, you can refresh the LMS Authorized URLs on your side as per the below procedure:
- Go to LMS Admin;
- Go through System administration > Configuration > System Configuration;
- Go to BizX Configuration and hit the "Apply Changes" button;
- This will enforce BizX Metadata pushing and refresh in LMS side.
- NOTE: If you experience any validation error when applying changes (like API errors), please raise a support case under the component LOD-SF-LMS-INT.
- It may be related to something else besides the behavior in discussion and perhaps requires LMS Support Team to look into it.
In case there is an extension scenario involving SAP Business Technology Platform (formerly SAP Cloud Platform), follow these steps as well:
- Log in to the SAP Cloud Platform Cockpit (https://account.hana.ondemand.com/cockpit/).
- Select the relevant Global Account and navigate to the extension subaccount.
- Go to Security > Trust > Application Identity Provider.
- Click on the entry that corresponds to the SF instance.
- In the General tab, review the following properties, make the necessary adjustments and save:
- Single Logout URL: https://<SF-data-center-domain>/sf/idp/SAML2/slo/POST
- Single Logout binding: HTTP-POST
If this procedure doesn't resolve the behavior, it may be related to another integration URL. From here, proceed as below:
# Steps for customers or partners:
- Install the HTTPWatch Tool on the affected user's browser (KBA 2089446);
- Open it by clicking in the colored umbrella icon (top right of browser page);
- Press the "Record" button and only then try to Proxy as another user;
- Once you've reproduced the behavior, you can stop the recording;
- Finally, hit the "Save" button and store the logs in "hwl" format;
- Raise a support case under the component "LOD-SF-PLT-PRX";
- Within your request, provide the following information:
- The recorded HTTPWatch logs;
- Your Instance (Company ID);
- Admin user with support access granted (KBA 2088892);
- One sample user you've tried to proxy as.
# Steps for partners or support team members:
- Open the HTTPWatch log and evaluate the flow to find the concerned URLs;
- Go through Provisioning > Authorized SP Assertion Consumer Service Settings;
- Back up this page prior to the changes;
- Perform the two above actions:
- Remove any incorrect URL placed in there;
- If the concerned URL is correct, then it's just a caching issue;
- Remove it, save, re-add it back and save again.
After these steps, the behavior shouldn't be experienced again.
Help portal guide for Proxy Access: Setting Up and Managing Proxy Access
booted out, kicked out, logged out, proxy kick out, proxy now logout, proxy now issue; suddenly logout, proxy logout, proxy not working, unable to proxy, logout, proxy now issue , KBA , LOD-SF-PLT , Platform Foundational Capabilities , LOD-SF-PLT-SSO , Single Sign-on , LOD-SF-PLT-PRX , Proxy , LOD-SF-LMS-INT , Integrations with BizX , Problem