SAP Home Learn Build Integrate Model Operate Extend with AI ConnectTutorial navigator Knowledge Graph API Devtoberfest Developer Advocates App Space

Manage my Account SAP Devs YouTube ↗ Learnings ↗ Community ↗ Provide Feedback ↗
Logout
⤢ Open full site

Set Up Trust Between SAP Cloud Identity Services and SAP BTP Subaccount

Set up trust between SAP Cloud Identity Services - Identity Authentication and SAP Business Technology Platform subaccount for secure communication via SAML 2.0 with SAP S/4HANA Cloud.

Overview

🎓 beginner 25 min. ABAP DevelopmentBeginnerABAP Extensibility

You will learn

  • How to set up SAP BTP subaccount for secure communication (with Security Assertion Markup Language = SAML 2.0)
  • How to set up SAP BTP subaccount on SAP Cloud Identity Services for secure communication
  • How to get necessary information from your SAP BTP subaccount and your SAP Cloud Identity Services tenant to set up the mutual trust between them
Peter Persiel P Peter Persiel April 30, 2026
Created by June 1, 2023
Contributors

Prerequisites

Prerequisites

  • Your user needs Administrator access to your SAP Business Technology Platform (aka SAP BTP) subaccount
  • Your user needs Administrator access to your SAP Cloud Identity Services tenant

Steps

Glossary

  • Identity: individual people, but also computers, services, computational entities like processes and threads, or any group of such things
  • Identity Provider: system entity that creates, maintains, and manages identity information for identities
  • Identity Authentication: process of authenticating an identity
  • SAP Cloud Identity Services: SAP’s solution to enable identity authentication
  • SAP Cloud Identity Services tenant: a customer’s instance of the services
  • SAP Cloud Identity Services console: Web application to configure your tenant

Additional Information

Be aware that in case of an integration with SAP S/4HANA Cloud the used Identity Authentication for the SAP BTP subaccount should be the very same as the one used for the SAP S/4HANA Cloud system.

Your SAP S/4HANA Cloud system you got already delivered by SAP comes with a configured trust between it and your SAP Cloud Identity Services tenant. Now you will configure the trust between that and your SAP BTP subaccount on your own.

SAP S/4HANA Cloud and SAP BTP subaccount share same Identity Provider
SAP S/4HANA Cloud and SAP BTP subaccount share same Identity Provider


Step 1 Get SAML metadata of SAP BTP subaccount

To set up the trust from Identity Authentication to the SAP BTP subaccount you need the subaccount’s SAML metadata.

Enter SAP BTP Trust Configuration and get metadata
Enter SAP BTP Trust Configuration and get metadata

  1. Enter the SAP BTP subaccount’s cockpit as an administrator and expand the Security area.

  2. Open Trust Configuration.

  3. Click Download SAML Metadata.

The metadata will be downloaded as XML file.

Step 2 Enter SAP Cloud Identity Services administration console
+
Step 3 Add SAP BTP subaccount as an application
+
Step 4 Configure application's trust with SAP BTP subaccount
+
Step 5 Set application's Subject Name Identifier
+
Step 6 Configure application's Default Identity Provider
+
Step 7 Get SAML metadata of SAP Cloud Identity Services tenant
+
Step 8 Add SAP Cloud Identity Services tenant as SAP BTP subaccount's trusted identity provider
+
Step 9 Test yourself
+

Resources

Discussion

Share feedback on this tutorial or join the conversation in SAP Community.

Submit detailed feedback Discuss in Community
Steps
Step 1 of 9
1. Get SAML metadata of SAP BTP subaccount 2. Enter SAP Cloud Identity Services administration console 3. Add SAP BTP subaccount as an application 4. Configure application's trust with SAP BTP subaccount 5. Set application's Subject Name Identifier 6. Configure application's Default Identity Provider 7. Get SAML metadata of SAP Cloud Identity Services tenant 8. Add SAP Cloud Identity Services tenant as SAP BTP subaccount's trusted identity provider 9. Test yourself

Learn more →