Enable a Custom SAML Identity Provider
By default, SAP Cloud Identity Services are used by SAP Analytics Cloud. SAP Analytics Cloud also supports single sign-on (SSO), using your identity provider (IdP).
Prerequisites
- You must have an IdP that supports SAML 2.0 protocol.
- You must be able to configure your IdP.
- You must be assigned to the System Owner role in SAP Analytics Cloud. For more information, see Standard Application Roles.
- SAP Analytics Cloud can
be hosted either on SAP data centers or on non-SAP data centers. Determine which
environment SAP Analytics Cloud is
hosted in by inspecting your SAP Analytics Cloud URL:
- A single-digit number, for example us1 or jp1, indicates an SAP data center.
- A two-digit number, for example eu10 or us30, indicates a non-SAP data center.
- If your users are connecting from Apple devices using the SAP Analytics Cloud mobile app, the certificate used by your IdP must be compatible with Apple's App Transport Security (ATS) feature.
Context
A custom identity provider is a separate solution, like for example Azure AD, and is not part of SAP Analytics Cloud or SAP Datasphere. Therefore the change in configuration is to be applied directly in the solution, not within SAP Analytics Cloud or SAP Datasphere. Also no access to SAP Analytics Cloud or SAP Datasphere is required to make the change, only an access to the Identity Provider, eg Azure AD.
Procedure
Results
Users will be able to use SAML SSO to log onto SAP Analytics Cloud.
Next Steps
Switch to a Different Custom IdP
If SAML SSO is enabled and you would like to switch to a different SAML IdP, you can repeat the above steps using the new SAML IdP metadata.