2.4 Admin Alerts, Check Tool, and System Access Settings
Key Takeaways
- Admin Alerts show pending action items such as stalled workflows, integration issues, and HR data issues.
- Check Tool checks are grouped into System Health, Migration, and Validation tabs.
- If the Check Tool is not opened for 90 days, its periodic check runs become inactive until it is opened again.
- Check Tool permissions are Access Check Tool, Allow Configuration Export, and Allow Check Tool Quick Fix.
- Welcome and reset password links can expire after 1 to 30 days, set in Password & Login Policy Settings.
2.4 Admin Alerts, Check Tool, and System Access Settings
Quick Answer: Admin Alerts list pending problems, such as stalled workflows or failed follow-up processes, that an administrator must act on. The Check Tool finds configuration and data conflicts, proposes solutions, and for some checks applies Quick Fixes. Password & Login Policy Settings and Reset User Account control how users regain access.
Admin Alerts
Admin Alerts inform administrators of pending action items such as stalled workflows, integration issues, and HR data issues. To configure alert types you need Administrator Permissions > Admin Alerts > Configure Alert Types. In the tool you can:
- choose an Admin Alert Type, read its description (Information), and Subscribe to Emails, for example daily
- configure auto-acknowledgment for specific alert types. Each application sets a maximum, and you choose a number of days up to it. Examples are Time Valuation, Periodic Time Account Update, Termination End Handling Alert, and Time Collector.
- use Retract Acknowledgment to undo an auto-acknowledgment. The alert table shows an Auto-Acknowledged column.
Employee Central and Position Management use admin alerts heavily. For example, if a Position Management follow-up process fails after a termination, the initiator gets an e-mail and an admin alert is created. Retriggering the alert reruns the failed process and all later ones (Section 12.4).
The Check Tool
When an application behaves unexpectedly, the cause is often inconsistent data or a configuration error. The Check Tool finds these problems quickly so you can avoid support tickets. If you still need a ticket, you can export the check results and your configuration so support can diagnose faster.
Check Types
| Tab | Purpose |
|---|---|
| System Health | Checks that run periodically and need no input parameters |
| Migration | Checks that migrate features, for example moving Basic business rules to application-specific rule scenarios |
| Validation | Checks that need parameters such as a template, user, or time frame |
- The history of check runs is kept, and a help option lists all available checks, even ones you have no access to.
- New checks in a release get an initial run, then checks run regularly (at least monthly). SAP recommends opening the Check Tool after each release upgrade.
- If the Check Tool is not opened for 90 days, periodic runs become inactive until someone opens it again. Automatic initial runs at the start of a release are not affected.
Permissions and Quick Fixes
| Permission | Allows |
|---|---|
| Access Check Tool | Opening the tool |
| Allow Configuration Export | Attaching configuration information to a support ticket |
| Allow Check Tool Quick Fix | Fixing configuration and data issues from the tool |
Quick Fixes are offered for certain checks with parameters on the Validation tab. The button appears under Proposed Solution on the Result tab and starts a three-step wizard. Results show a yellow warning (not serious, with a proposed solution) or a red alarm (serious; act, possibly by opening a ticket).
Employee Central Uses of the Check Tool
- Picklists: find invalid picklist references in personal and employment elements.
- Data models: SAP recommends running the checks after uploading the Succession and country-specific Succession Data Models. A check also validates existing or missing field criteria.
- Business rules: Migration > Business Rules Application mass-migrates Basic rules to application-specific scenarios.
- Position Management: checks such as mandatory PM settings, matrix picklist consistency, the position code rule, sync rules, and the Pending Data flag (Section 11.5).
Password & Login Policy Settings
In Company Settings > Password & Login Policy Settings, administrators customize the login and help experience:
- Forgot password: users reset their password through an e-mail link, through security questions followed by an e-mail link, or through security questions alone
- Welcome Password and Reset Password link expiration: 1 to 30 days. Changes affect links that have not expired yet.
- Password Expiration for Long-Time Unused Passwords: expire passwords unused for a selected number of years (N/A disables it)
- CAPTCHA for the Forgot Password page: after a chosen number of reset attempts within one minute
- Manage security questions: how many answers must be correct, system questions, and custom questions
- Forgot username: users retrieve their username by e-mail
Resetting Passwords and Locked Accounts
There are three password reset types: reset an individual password with a supplied password, reset an individual password to a system-generated one, and reset passwords for a group of users. Users receive an e-mail and must change the password at next login. For SSO users, a reset affects only Basic Authentication and token-based SSO.
When a company limits unsuccessful login attempts, the system locks the account after too many failures. In Reset User Account, filter by division, department, group, location, name, or job code. Locked users show a red X. Select them and choose Reset Selected Users. The reset only reactivates the login; nothing else changes.
Automatic periodic checks have stopped running in a customer's Check Tool. What is the most likely cause?
Which permission lets an administrator correct a configuration or data issue directly from the Check Tool?
A customer wants new-hire welcome links to stay valid for two weeks. Where and within which range is this configured?