<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: TFA causing break in saml Registration/login acoount link flow in CRM and CX Q&amp;A</title>
    <link>https://community.sap.com/t5/crm-and-cx-q-a/tfa-causing-break-in-saml-registration-login-acoount-link-flow/qaa-p/12544354#M438424</link>
    <description>&lt;P&gt;Hi Rohit, &lt;/P&gt;&lt;P&gt;My suggestion is:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create a separate apikey (within the same site group) to handle SAML logins. &lt;/LI&gt;&lt;LI&gt;In RBA, Exclude this apikey from the TFA rule. &lt;/LI&gt;&lt;LI&gt;point SAML logins to a page that runs under this apikey.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;With this setup in place:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;User logs in via SAML&lt;/LI&gt;&lt;LI&gt;They are prompted with account linking.&lt;/LI&gt;&lt;LI&gt;They perform account linking successfully (No TFA required as it's excluded from this apikey)&lt;/LI&gt;&lt;LI&gt;They SSO to the main application (original apikey)&lt;/LI&gt;&lt;LI&gt;As part of the SSO, the platform will prompt for TFA&lt;/LI&gt;&lt;LI&gt;They pass TFA process and successfully log it to the application.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Hope this makes sense.&lt;/P&gt;&lt;P&gt;Igal&lt;/P&gt;</description>
    <pubDate>Thu, 17 Mar 2022 08:43:44 GMT</pubDate>
    <dc:creator>igal_mi</dc:creator>
    <dc:date>2022-03-17T08:43:44Z</dc:date>
    <item>
      <title>TFA causing break in saml Registration/login acoount link flow</title>
      <link>https://community.sap.com/t5/crm-and-cx-q-a/tfa-causing-break-in-saml-registration-login-acoount-link-flow/qaq-p/12544353</link>
      <description>&lt;P&gt;Hello experts,&lt;/P&gt;
  &lt;P&gt;We have TFA configured for every login from different device/country. now we are implementing sso with external idp using SAML. where we are facing issue with account linking for saml user.&lt;/P&gt;
  &lt;P&gt;case is, if user is already have site identity at CDC, when user tries to use saml sign in option from different device there will be identity conflict &amp;amp; cdc triggers account link flow. &lt;/P&gt;
  &lt;P&gt;now because of TFA required for the account which is trying to link saml user is not supported, this is also mentioned in cdc documentation.&lt;/P&gt;
  &lt;P&gt;1. To make the linking happen, we have to disable the TFA which is not serving purpose of configuring it at first.&lt;/P&gt;
  &lt;P&gt;2. If we chose option by not linking two identities, CDC is asking for TFA two time within one device for same user.&lt;/P&gt;
  &lt;P&gt;Is there any alternative in option 1 apart from option 2?&lt;/P&gt;
  &lt;P&gt;Thanks.&lt;/P&gt;
  &lt;P&gt;Rohit&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 11:05:36 GMT</pubDate>
      <guid>https://community.sap.com/t5/crm-and-cx-q-a/tfa-causing-break-in-saml-registration-login-acoount-link-flow/qaq-p/12544353</guid>
      <dc:creator>grohitg238</dc:creator>
      <dc:date>2022-03-16T11:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: TFA causing break in saml Registration/login acoount link flow</title>
      <link>https://community.sap.com/t5/crm-and-cx-q-a/tfa-causing-break-in-saml-registration-login-acoount-link-flow/qaa-p/12544354#M438424</link>
      <description>&lt;P&gt;Hi Rohit, &lt;/P&gt;&lt;P&gt;My suggestion is:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create a separate apikey (within the same site group) to handle SAML logins. &lt;/LI&gt;&lt;LI&gt;In RBA, Exclude this apikey from the TFA rule. &lt;/LI&gt;&lt;LI&gt;point SAML logins to a page that runs under this apikey.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;With this setup in place:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;User logs in via SAML&lt;/LI&gt;&lt;LI&gt;They are prompted with account linking.&lt;/LI&gt;&lt;LI&gt;They perform account linking successfully (No TFA required as it's excluded from this apikey)&lt;/LI&gt;&lt;LI&gt;They SSO to the main application (original apikey)&lt;/LI&gt;&lt;LI&gt;As part of the SSO, the platform will prompt for TFA&lt;/LI&gt;&lt;LI&gt;They pass TFA process and successfully log it to the application.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Hope this makes sense.&lt;/P&gt;&lt;P&gt;Igal&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 08:43:44 GMT</pubDate>
      <guid>https://community.sap.com/t5/crm-and-cx-q-a/tfa-causing-break-in-saml-registration-login-acoount-link-flow/qaa-p/12544354#M438424</guid>
      <dc:creator>igal_mi</dc:creator>
      <dc:date>2022-03-17T08:43:44Z</dc:date>
    </item>
  </channel>
</rss>

