✔How to set up SAP Business Technology Platform Subaccount for secure communication (with Security Assertion Markup Language = SAML 2.0)
✔How to set up SAP Business Technology Platform Subaccount on SAP Cloud Identity Services - Identity Authentication for secure communication
✔How to get necessary information from your SAP Business Technology Platform Subaccount and your SAP Cloud Identity Services - Identity Authentication tenant to set up the mutual trust between them
Be aware that in case of an integration with SAP S/4HANA Cloud the used Identity Authentication for the SAP BTP subaccount should be the very same as the one used for the SAP S/4HANA Cloud system.
Your SAP S/4HANA Cloud system you got already delivered by SAP with a configured trust between it and your SAP Cloud Identity Services tenant. Now you will configure the trust between that and your SAP BTP subaccount on your own.
SAP S/4HANA Cloud and SAP BTP subaccount share same Identity Provider
Enter the SAP Business Technology Platform subaccount as an administrator and expand the Security area to open Trust Management by clicking the Trust section.
Enter SAP Business Technology Platform Subaccount
Step 2Set subaccount as service provider
+
To enable secure (Security Assertion Markup Language = SAML 2.0) communication the SAP Business Technology Platform Subaccount has to be set up as Service Provider.
Being in the trust management, click Edit to change the default Local Service Provider.
Edit local service provider
Change and add following information to your local provider:
| ——————————————- | ——————————————- |
| Configuration Type | Custom |
| Local Provider Name | <platform region s URL>/<subaccount name> (set automatically) |
| Principal Propagation | Enabled |
| Force Authentication | Disabled |
Click Generate Key Pair
Generate Key Pair for and save Local Service Provider
Save your changes.
Confirm the “Now you can proceed to configuring the trusted identity provider settings on the next tab.” pop up.
Step 3Get metadata of subaccount
+
To set up the trust from Identity Authentication to the Subaccount soon you need the subaccount’s metadata.
Download the metadata by clicking Get Metadata.
Tenant ID is an automatically generated ID by the system. The first administrator created for the tenant receives an activation e-mail with a URL in it. This URL contains the tenant ID.
SAP Cloud Identity Services - Identity Authentication Administration Console entry screen looks (depending on authorizations) like that
Enter SAP Cloud Identity Services administration console
Step 5Add SAP BTP subaccount as an application
+
The SAP BTP subaccount is represented in SAP Cloud Identity Services as Application.
Choose Applications & Resources (1) and go to Applications (2). Click Create (3) on the left hand panel and enter a Display Name (4) to represent your SAP BTP subaccount. Create (5) the application.
Add SAP BTP subaccount as application
Step 6Configure application's trust with SAP BTP subaccount
+
The newly created application will be shown, choose SAML 2.0 Configuration.
Configure application’ s SAML 2.0 trust with SAP BTP subaccount
Browse (1) for the SAML metadata XML file of your SAP BTP subaccount that you downloaded before and upload it.
Upload SAP BTP subaccount’ s metadata
All the needed properties will be automatically fetched from the XML file.
Save (2) the SAML 2.0 configuration.
Step 7Set application's Subject Name Identifier
+
Now you have to configure which attribute is used to identify users during SAML2.0 secure communication. By default this is User ID, but as SAP S/4HANA Cloud by default works with Login Name it shall be switched to that.
Still being in your application’s Trust settings select Subject Name Identifier.
Open Subject Name Identifier configuration
Under Primary Attribute use Identity Directory as Source, choose Login Name as Value and save your changes.
Set Login Name as application’ s Subject Name Identifier
As most common use case the SAP Cloud Identity Services - Identity Authentication does not act as Identity Provider itself but as proxy for an already existing corporate identity provider. This has to be set now.
Still being in your application’s Trust settings scroll down and open Conditional Authentication.
Open application’ s identity provider configuration
Under Default Authenticating Identity Provider select your corporate identity provider as Default Identity Provider and click Save.
Set identity provider
Save that XML to a file.
Step 9Get SAML metadata of SAP Cloud Identity Services tenant
+
To set the SAP Cloud Identity Services tenant as trusted identity provider in the SAP BTP subaccount next, you need to get its SAML metadata first.
Open SAP Cloud Identity Services tenant’s settings - SAML 2.0 configuration
Choose Applications & Resources
Switch to Tenant Settings
Go to Single Sign-On section
Open SAML 2.0 Configuration
Click the Download Metadata file button
Button to start download of SAML 2.0 Metadata
In the pop-up that opens, use Default certificate and press the Download button.
Pop-up to download SAML 2.0 Metadata
Alternatively you can open the metadata XML by entering your tenant’s web address for it which follows pattern https://<YOUR_TENANTS_ID>.accounts.ondemand.com/saml2/metadata and saving that XML to a file.
Step 10Add SAP Cloud Identity Services tenant as SAP BTP subaccount's trusted identity provider
+
Switch back to your SAP BTP cockpit and the Neo subaccount’s trust management.
Choose Application Identity Provider to add a trusted identity provider.
Add subaccount’ s trusted identity provider
Upload metadata XML file of your SAP Cloud Identity Services tenant in the Metadata File field. Add it as identity provider.
Upload identity tenant’ s metadata as trusted identity provider
Share feedback on this tutorial or join the conversation in SAP Community.
Submit detailed feedbackDiscuss in Community
Steps
Step 1 of 11
1. Enter trust management of subaccount2. Set subaccount as service provider3. Get metadata of subaccount4. Enter Identity Authentication Administration Console5. Add SAP BTP subaccount as an application6. Configure application's trust with SAP BTP subaccount7. Set application's Subject Name Identifier8. Configure application's Default Identity Provider9. Get SAML metadata of SAP Cloud Identity Services tenant10. Add SAP Cloud Identity Services tenant as SAP BTP subaccount's trusted identity provider11. Test yourself
Joule
AI Notice
Joule is an AI assistant. Generative AI may produce inaccurate, incomplete, or biased information. Always verify important details before acting on them.
Conversations are sent to SAP-hosted large language models for processing. Do not include personal data, credentials, or confidential information in your messages.
Joule's responses are based on the SAP tutorial catalog and may not reflect the latest product changes. For authoritative guidance, consult the linked tutorials and official SAP documentation.