cancel
Showing results for 
Search instead for 
Did you mean: 

SAP Identity Authentication Service as Proxy IdP for SAP BTP

michael_sharrar
Participant

After reading a blog from denys.kempen, I'm curious if the SAP Identity Authentication Service configuration (as a proxy) is "re-usable" within multiple SAP BTP subaccounts.

Meaning, can I set this up once and then use the same SAML configuration for all of my BTP subaccounts?

Link to blog:

SAP Business Technology Platform Security | Hands-on Video Tutorials | SAP Blogs

Martin-Pankraz
Active Contributor

Hi ua08520,

the SAP IAS proxy concept refers to using another IdP such as Azure AD as your Identity truth. Nevertheless you can also configure multiple BTP subaccounts (XSUAA) as apps in your IAS tenant like juergen.adolf described. I wouldn't call that "proxy" anymore even though from XSUAA perspective it would be. Just to avoid confusion with the terminology on the docs and the community.

Have a look here at our best practices configuration for the SAP IAS proxy scenario with Azure AD.

Let the community know what you implemented in the end 🙂

KR

Martin

Accepted Solutions (0)

Answers (1)

Answers (1)

JürgenAdolf
Product and Topic Expert
Product and Topic Expert

After you have configured in your Identity Authentication tenant a corporate identity provider you may choose a Default Identity Provider for an Application in the admin cockpit of IAS. Each application has an own representation in IAS. In Identity Authentication you can have three types of applications. Bundled and charged applications (SAML 2.0 or OpenID Connect), and system applications. Bundled applications are recognized by Identity Authentication as SAP applications, while charged applications are third party application. Identity Authentication identifies the type of the application by the URI or SAML 2.0 endpoints. Meaning: For end-user Applications running on BTP you can decide for each application how to authenticate.

For the BTP cockpit and the subaccounts there will be one application. In this application you may set conditional authentication rules. You may Select the identity provider to delegate authentication to when all conditions specified are met.