SAP HANA Academy, 2021

Azure AD as IdP and SAP Identity Authentication Service as SAML Federation Proxy

video

Authors

SAP HANA Academy

Year

2021

Abstract

In this video tutorial we show how to configure Microsoft Azure AD as identity provider for business applications on the SAP Business Technology Platoform (SAP Cloud Platform) Cloud Foundry environment.

For more information, sample code, and additional references visit
https://blogs.sap.com/2021/02/10/sap-...

0:00 - Introduction
2:20 - Create new Enterprise application in Azure AD
3:00 - Configure User Attributes & Claims
3:30 - Download federation metadata XML (IdP)
4:00 - Create new Corporate IdP in SAP Identity Authentication Service and upload IdP metadata
4:25 - Update Identiy Provider Type
4:30 - Download IAS metadata (IdP Proxy)
4:55 - Upload IAS metadata in Azure Ad
5:15 - Create net Trust Configuration in SAP Cloud Platform and upload IAS metadata (IdP Proxy)
5:40 - Download service provider (SP) metadata
5:55 - Create new application in SAP Identity Authentication Service and upload SP metadata
6:15 - Configure Default Name ID Format, SAML Assertion Attributes, and Conditional Authentication
6:50 - Assign user to application in Azure AD
7:15 - First test (fails with SAML error)
7:55 - Download federation metadata XML from Azure AD and upload for the IdP in SAP Identity Authentication Service
8:15 - Second test succeeds on authentication
8:25 - Shadow users
8:50 - Third test with myappsec sample appliation: Forbidden
9:20 - Option 1: Assign shadow user to role collection
10:15 - User authorization concepts
11:05 - Map role collection to Azure AD group

This video is part of the SAP Cloud Platform | Cloud Foundry | Security playlist: http://sap.to/6054Hg1l8

Code samples are available on Github: http://sap.to/6055Hg1lD

Find the latest SAP HANA Academy video tutorials here:

Thank you for watching. Video by the SAP HANA Academy

(, accessed 28 Aug 2021)

Citation

SAP HANA Academy, n.d. Azure AD as IdP and SAP Identity Authentication Service as SAML Federation Proxy. URL:


Follow us on LinkedIn | Discuss on Slack | Support us with Patreon | Sign-up for a free membership.


This wiki is owned by Open Measure, a non-profit association. The original content we publish is licensed under a Creative Commons Attribution 4.0 International License.