cancel
Showing results for 
Search instead for 
Did you mean: 

Cloud Identity Services - Restrict Logon to Corporate Identity Provider groups without IAS sync

Marçal_Oliveras
Active Contributor
0 Kudos

Hi,

I configured Entra ID (Azure AD) as Corporate Identity Provider. Then I setup one of my apps to use Azure AD as the default IdP. Everything works fine, and I can also map role collections in the BTP subaccount from groups in Azure AD.

The problem is that absolutely all AAD users can login now if they know the link, no matter to what groups or apps they belong. They don't get any role assigned if they don't belong to a group, so they can't do anything after logging in, but they get created as shadow users in the subaccount.

I would like to prevent the logon based on groups and I found the documentation on how to do that by configuring the "Corporate IdP Identity Federation".

However, this setup assumes that users exist in the IAS tenant and they belong to IAS groups. What I want is to just use IAS as a proxy and to not even create the users in the IAS tenant as I have now.

Is it possible to do that? Or is it mandatory to sync the corporate IdP users in IAS?

View Entire Topic
Amin_Omidy
Active Participant

Hi Marcal,

You can choose not use IAS as user store and just have your user in your Azure IdP and target systems with the right permissions.

In IAS go to your Corporate Identity Provider >Identity Federation

Then turn off User store for IAS by choosing option one:

For more detail please check the link:

https://help.sap.com/docs/identity-authentication/identity-authentication/corp-idp-configure-identit...

Thanks,

Amin

Marçal_Oliveras
Active Contributor
0 Kudos

Thanks amin_omidy, I already knew that but it's not exactly what I was looking. I think I might have to ask a new question to clarify that I want to limit at app level.