SAP Home Learn Build Integrate Model Operate Extend with AI ConnectTutorial navigator Knowledge Graph API Devtoberfest Developer Advocates App Space

Manage my Account SAP Devs YouTube ↗ Learnings ↗ Community ↗ Provide Feedback ↗
Logout
⤢ Open full site

Set Up Trust Between Identity Authentication and SAP Business Technology Platform Neo Environment

Set up trust between SAP Cloud Identity Services - Identity Authentication and SAP Business Technology Platform for secure communication via SAML 2.0.

Overview

🎓 beginner 25 min. ABAP DevelopmentBeginnerABAP Extensibility

You will learn

  • How to set up SAP Business Technology Platform Subaccount for secure communication (with Security Assertion Markup Language = SAML 2.0)
  • How to set up SAP Business Technology Platform Subaccount on SAP Cloud Identity Services - Identity Authentication for secure communication
  • How to get necessary information from your SAP Business Technology Platform Subaccount and your SAP Cloud Identity Services - Identity Authentication tenant to set up the mutual trust between them
Raz Korn R Raz Korn November 27, 2024
Created by March 21, 2023
Contributors

Prerequisites

Prerequisites

Authorizations: Your user needs

  • Administrator access to your SAP Business Technology Platform (aka SAP BTP) Neo subaccount
  • Administrator access to your SAP Cloud Identity Services tenant

Glossary

Identity: individual people, but also computers, services, computational entities like processes and threads, or any group of such things

Identity Provider: system entity that creates, maintains, and manages identity information for identities

Identity Authentication: process of authenticating an identity

SAP Cloud Identity Services: SAP’s solution to enable identity authentication

SAP Cloud Identity Services tenant: a customer’s instance of the services

SAP Cloud Identity Services console: Web application to configure your tenant

Steps

Intro

Be aware that in case of an integration with SAP S/4HANA Cloud the used Identity Authentication for the SAP BTP subaccount should be the very same as the one used for the SAP S/4HANA Cloud system.

Your SAP S/4HANA Cloud system you got already delivered by SAP with a configured trust between it and your SAP Cloud Identity Services tenant. Now you will configure the trust between that and your SAP BTP subaccount on your own.

SAP S/4HANA Cloud and SAP BTP subaccount share same Identity Provider
SAP S/4HANA Cloud and SAP BTP subaccount share same Identity Provider

Additional Information


Step 1 Enter trust management of subaccount

Enter the SAP Business Technology Platform subaccount as an administrator and expand the Security area to open Trust Management by clicking the Trust section.

Enter SAP Business Technology Platform Subaccount
Enter SAP Business Technology Platform Subaccount

Step 2 Set subaccount as service provider
+
Step 3 Get metadata of subaccount
+
Step 4 Enter Identity Authentication Administration Console
+
Step 5 Add SAP BTP subaccount as an application
+
Step 6 Configure application's trust with SAP BTP subaccount
+
Step 7 Set application's Subject Name Identifier
+
Step 8 Configure application's Default Identity Provider
+
Step 9 Get SAML metadata of SAP Cloud Identity Services tenant
+
Step 10 Add SAP Cloud Identity Services tenant as SAP BTP subaccount's trusted identity provider
+
Step 11 Test yourself
+

Resources

Discussion

Share feedback on this tutorial or join the conversation in SAP Community.

Submit detailed feedback Discuss in Community
Steps
Step 1 of 11
1. Enter trust management of subaccount 2. Set subaccount as service provider 3. Get metadata of subaccount 4. Enter Identity Authentication Administration Console 5. Add SAP BTP subaccount as an application 6. Configure application's trust with SAP BTP subaccount 7. Set application's Subject Name Identifier 8. Configure application's Default Identity Provider 9. Get SAML metadata of SAP Cloud Identity Services tenant 10. Add SAP Cloud Identity Services tenant as SAP BTP subaccount's trusted identity provider 11. Test yourself

Learn more →