Hello everyone,
We are using SAP IAS/IPS with Azure as Idp. We have already connected several SAP Cloud Apps to IAS, and more apps will be added.
Access to these apps is controlled by groups in Azure. For example, depending on a user’s role in SAC or Enable Now, different groups are created in Azure.
In SAC, we already have at least 10 groups, and in Enable Now even more. As more SAP Cloud Apps are connected, the number of Azure groups increases quickly.
My question is:
Is there a better or easier way to manage roles and access without creating so many groups in Azure?
How do you manage this in your environment to keep it organized and scalable?
Thanks for your help
Best regards
Request clarification before answering.
Maybe SAP IAG is a solution for this?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Please check risk based authentication in IAS which controls Azure groups fed in via Identity federation group mapping and then routes to SAC
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thank you very much for your input.
Could you please explain in a bit more detail how this would be implemented?
Does this mean that a single group should be created in Azure, and only users are provisioned to IAS and manually assigned to the appropriate groups direct in IAS (depending on the cloud application or role)?
Thank you in advance.
Best regards
| User | Count |
|---|---|
| 10 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.