Technology Blog Posts by SAP
cancel
Showing results for 
Search instead for 
Did you mean: 
Mohammed_Ghemraoui
Associate
Associate
2,493

See as well: 

Table of Contents:

  • SAP Fieldglass SAML Metadata Retrieval
  • SAP IAS SAML Authentication Configuration
  • SAP IAS SAML Metadata Retrieval
  • SAP Fieldglass SAML Authentication Self-service Configuration
  • SAP IAS User Setup
  • SAP Fieldglass SSO Verification
    • Validate the SAP Fieldglass SSO via Configuration Manager
    • Validate the SAP Fieldglass SSO by accessing the SAP Fieldglass URL in the browser
      • SAP Fieldglass without SSO
      • SAP Fieldglass with SSO to SAP IAS
      • SAP Fieldglass with SSO to External Identity Provider

SAP Fieldglass SAML Metadata Retrieval

Prerequisites:

  • SAP Fieldglass user with Configuration Manager access

To download the SAP Fieldglass SAML Metadata for use with SAP IAS as the Identity Provider:

  • enter the SAP Fieldglass tenant as a Configuration Manager User
  • navigate to the user menu -> Linked Accounts and click on the linked Configuration Manager user

Mohammed_Ghemraoui_0-1719813120213.png

 

  • Click on the Single Sign On tile -> Actions -> Download SP Metadata

Mohammed_Ghemraoui_0-1719967937158.png

 SAP IAS SAML Authentication Configuration

Prerequisites:

  • SAP Fieldglass Metadata File
  • SAP IAS user added as Administrator to SAP IAS (Users & Authorizations -> Administrators -> [Add])

To configure SAP IAS SAML Authentication with SAP Fieldglass:

  • enter the SAP IAS Administration Console via https://<SAP IAS tenant  id>.accounts.ondemand.com/admin
  • navigate to Application & Resources -> Application -> [Create] to create Application for SAP Fieldglass as Service Provider (SP)
    • Enter the Display Name, choose SAP Fieldglass solution as TypeSAML 2.0 as Protocol Type and hit [Create]

Mohammed_Ghemraoui_2-1719813120223.png

  • load the SAP Fieldglass Metadata File you retrieved from SAP Fieldglass in the SAML 2.0 Configuration section within the Application

Mohammed_Ghemraoui_1-1719968048619.png

SAP IAS SAML Metadata Retrieval

To retrieve SAML Metadata from SAP IAS directly:

  • enter the below SAP IAS URL into browser:
    https://<SAP IAS tenant  id>.accounts.ondemand.com/saml2/metadata?action=download
  •  store the downloaded SAP IAS Metadata File

To retrieve SAML Metadata manually from SAP IAS application:

  • go to Applications & Resources -> Tenant Settings -> Authentication -> SAML 2.0 Configuration
  •  click Download Metadata File

Mohammed_Ghemraoui_8-1719969615454.png

SAP Fieldglass SAML Authentication Self-service Configuration

Prerequisites:

  • SAP Fieldglass user with Configuration Manager access
  • SAP IAS Metadata File

To configure SAP Fieldglass SAML Authentication with SAP IAS as the Identity Provider:

  • Upload the IAS metadata file from the previous step into SAP Fieldglass by clicking on the Single Sign On tile -> Actions -> Edit -> Identity Provider Details -> Upload

Mohammed_Ghemraoui_1-1720502490798.png

  • OPTIONAL CONFIGURATION: SAML Identity Location
    • The default configuration is to use the NameID in the SAML Response to authenticate the user against the Username field in SAP Fieldglass using SAML Identity Location as Subject.Mohammed_Ghemraoui_3-1720502563284.png
    • We can use a different attribute in the SAML Response for this purpose instead of the NameID by selecting Attribute as the SAML Identity Location and entering the value of that attribute.Mohammed_Ghemraoui_7-1720502688917.png
    • Sample SAML response below, where we will use the value in the custom FGUserID attribute instead of the NameID

Mohammed_Ghemraoui_0-1720502291112.png

  • Complete the wizard by clicking Next through the remaining steps

Mohammed_Ghemraoui_6-1719813120248.png

  • Under Applications & Resources -> Applications, select the application, then Subject Name Identifier. Select the attribute from the drop down list to use for authentication in SAP Fieldglass (Login Name in this example).

Mohammed_Ghemraoui_2-1719968118714.png

  • Test the connection using the SSO URL (https://<environment>/SSOLogin?TARGET=company%3D<BuyerCode>)
    NOTE: Notice the URL differs to the standard SAP Fieldglass URL. This is required to indicate to the SAP Fieldglass application that we are using SSO. Using the standard SAP Fieldglass URL (i.e. https://www.fieldglass.net as opposed to https://www.fieldglass.net/SSOLogin?TARGET=company%3D<BuyerCode>), will route the user to the standard SAP Fieldglass login page.

 

SAP IAS User Setup

  • After the SSO is enabled, SAP Fieldglass will authenticate the users credentials (passwords) stored in SAP IAS and not credentials (passwords) stored in SAP Fieldglass. Therefore SAP Fieldglass business users will need to be created in SAP IAS.
  • The below configuration considers the default setting of SAML Identity Location set to Subject
  • Set the value for the attribute to use for authentication. In the example below, we are using Login Name, which will need to match the users username in SAP Fieldglass. NOTE: the attribute to use for authentication from SAP IAS can be configured as described above, if required.
  •  ensure the users setup in SAP IAS have the Login Name set and matching to the SAP Fieldglass Username
    • navigate to Users & Authorizations -> User Management -> and specific user SAP IAS Login Name needs to match user SAP Fieldglass Username

 SAP IAS User Profile:

Mohammed_Ghemraoui_4-1719968287548.png

 

 SAP Fieldglass User Profile:

Mohammed_Ghemraoui_10-1719969732252.png

 In case you are reading this line, you have successfully configured the Single Sign-On (SSO) between SAP Fieldglass as Service Provider (SP) and SAP IAS as Identity Provider (IdP)!

  • To verify the status of the SAP Fieldglass SSO Setup follow one of the options below:
  • Validate the SAP Fieldglass SSO via Configuration Manager
  • Validate the SAP Fieldglass SSO by accessing the SAP Fieldglass URL in the browser

Validate the SAP Fieldglass SSO via Configuration Manager

Prerequisites:

  • SAP Fieldglass user with Configuration Manager access

To review existing SAP Fieldglass SSO setup:

  • enter the SAP Fieldglass tenant
  • sign in with a user with Configuration Manager
  • click on the Single Sign On tile
  • check the SAP Fieldglass SSO configuration for Test or Production

Mohammed_Ghemraoui_5-1719968361719.png

Validate the SAP Fieldglass SSO by accessing the SAP Fieldglass URL in the browser

Validate the SAP Fieldglass SSO setup by accessing the SAP Fieldglass URL via browser - accessing the business user access URL (https://<environment>/SSOLogin?TARGET=company%3D<BuyerCode>)

SAP Fieldglass without SSO

Reaching below SAP Fieldglass Login screen means, SAP Fieldglass SSO is not setup for the user and SAP Fieldglass requires the user credentials to be entered as stored in SAP Fieldglass

Mohammed_Ghemraoui_13-1719813120312.png

 SAP Fieldglass with SSO to SAP IAS

Reaching below SAP IAS Login screen means, SAP Fieldglass SSO is setup with SAP IAS (directly, without further identity federation) and SAP Fieldglass site requires the user credentials to be entered as stored in SAP IAS

Mohammed_Ghemraoui_14-1719813120313.png

SAP Fieldglass with SSO to External Identity Provider (Example Microsoft Entra ID below)

Reaching below Microsoft Entra ID Login screen means, SAP Fieldglass SSO is setup with Microsoft Entra ID and SAP Fieldglass site requires the user credentials to be entered as stored in SAP Microsoft Entra ID

Note: You can achieve the usage of Microsoft Entra ID for SAP Fieldglass SSO via direct configuration to Microsoft Entra ID or via Identity Federation setup of SAP IAS, in case of Identity FederationSAP Fieldglass SSO is setup to SAP IAS and SAP IAS delegates all the authentication requests to Microsoft Entra ID. Because of this we might not be able to recognize whether the SAP Fieldglass SSO is setup directly with Microsoft Entra ID or via SAP IAS Identity Federation.

Mohammed_Ghemraoui_15-1719813120316.png

See as well: