Set Up Trust Between SAP Cloud Identity Services and SAP BTP Subaccount
Set up trust between SAP Cloud Identity Services - Identity Authentication and SAP Business Technology Platform subaccount for secure communication via SAML 2.0 with SAP S/4HANA Cloud.
Be aware that in case of an integration with SAP S/4HANA Cloud the used Identity Authentication for the SAP BTP subaccount should be the very same as the one used for the SAP S/4HANA Cloud system.
Your SAP S/4HANA Cloud system you got already delivered by SAP comes with a configured trust between it and your SAP Cloud Identity Services tenant. Now you will configure the trust between that and your SAP BTP subaccount on your own.
SAP S/4HANA Cloud and SAP BTP subaccount share same Identity Provider
Step 1Get SAML metadata of SAP BTP subaccount
—
To set up the trust from Identity Authentication to the SAP BTP subaccount you need the subaccount’s SAML metadata.
Enter SAP BTP Trust Configuration and get metadata
Enter the SAP BTP subaccount’s cockpit as an administrator and expand the Security area.
Open Trust Configuration.
Click Download SAML Metadata.
The metadata will be downloaded as XML file.
Step 2Enter SAP Cloud Identity Services administration console
+
Open the SAP Cloud Identity Services administration console with its URL which follows the pattern:
The Tenant ID is an automatically generated ID by the system. The first administrator created for the tenant receives an activation e-mail with an URL in it. This URL contains the tenant ID.
SAP Cloud Identity Services administration console entry screen looks (depending on authorizations) like this
Enter SAP Cloud Identity Services administration console
Step 3Add SAP BTP subaccount as an application
+
The SAP BTP subaccount is represented in SAP Cloud Identity Services as Application.
Choose Applications & Resources (1) and go to Applications (2). Click Create (3) on the left hand panel and enter a Display Name (4) to represent your SAP BTP subaccount. Create (5) the application.
Add SAP BTP subaccount as application
Step 4Configure application's trust with SAP BTP subaccount
+
The newly created application will be shown, choose SAML 2.0 Configuration and then the option Load from File.
Configure application’ s SAML 2.0 trust with SAP BTP subaccount
Browse for the SAML metadata XML file of your SAP BTP subaccount that you downloaded before and upload it. All the needed properties will be automatically fetched from the XML file and saved in the SAML 2.0 configuration of the application.
Upload SAP BTP subaccount’ s metadata
Step 5Set application's Subject Name Identifier
+
Now you have to configure which attribute is used to identify users during SAML 2.0 authentication. SAP S/4HANA Cloud expects the Subject Name Identifier to be set to Login Name or Email. Choose a subject name identifier that is known and provided in both SAP BTP and on S/4HANA Public Cloud Side. Refer to Configure the Subject Name Identifier Sent to the Application for more information.
Still being in your application’s Trust settings select Subject Name Identifier.
Open Subject Name Identifier configuration
Under Primary Attribute use Identity Directory as Source, choose Login Name or Email as Value and save your changes.
Set Login Name as application’ s Subject Name Identifier
As most common use case the SAP Cloud Identity Services - Identity Authentication does not act as Identity Provider itself but as proxy for an already existing corporate identity provider. This has to be set now.
Still being in your application’s Trust settings scroll down and open Conditional Authentication.
Open application’ s identity provider configuration
Under Default Authenticating Identity Provider select your corporate identity provider as Default Identity Provider and click Save.
Set identity provider
Step 7Get SAML metadata of SAP Cloud Identity Services tenant
+
To set the SAP Cloud Identity Services tenant as trusted identity provider in the SAP BTP subaccount next, you need to get its SAML metadata first.
Open SAP Cloud Identity Services tenant’s settings - SAML 2.0 configuration
Choose Applications & Resources
Switch to Tenant Settings
Go to Single Sign-On section
Open SAML 2.0 Configuration
Click the Download Metadata file button
Button to start download of SAML 2.0 Metadata
In the pop-up that opens, use Default certificate and press the Download button.
Pop-up to download SAML 2.0 Metadata
Alternatively you can open the metadata XML by entering your tenant’s web address for it which follows pattern https://<YOUR_TENANTS_ID>.accounts.ondemand.com/saml2/metadata and saving that XML to a file.
Step 8Add SAP Cloud Identity Services tenant as SAP BTP subaccount's trusted identity provider
+
Switch back to your SAP BTP cockpit trust configuration.
Choose Add SAML Trust to add a trusted identity provider.
Click Add SAML Trust
Upload the metadata XML file of your SAP Cloud Identity Services tenant in the Metadata field, give a Name, as for example the tenant id. Save your changes via Add SAML Trust.
Upload identity tenant’ s metadata as trusted identity provider and save
Share feedback on this tutorial or join the conversation in SAP Community.
Submit detailed feedbackDiscuss in Community
Steps
Step 1 of 9
1. Get SAML metadata of SAP BTP subaccount2. Enter SAP Cloud Identity Services administration console3. Add SAP BTP subaccount as an application4. Configure application's trust with SAP BTP subaccount5. Set application's Subject Name Identifier6. Configure application's Default Identity Provider7. Get SAML metadata of SAP Cloud Identity Services tenant8. Add SAP Cloud Identity Services tenant as SAP BTP subaccount's trusted identity provider9. Test yourself
Joule
AI Notice
Joule is an AI assistant. Generative AI may produce inaccurate, incomplete, or biased information. Always verify important details before acting on them.
Conversations are sent to SAP-hosted large language models for processing. Do not include personal data, credentials, or confidential information in your messages.
Joule's responses are based on the SAP tutorial catalog and may not reflect the latest product changes. For authoritative guidance, consult the linked tutorials and official SAP documentation.