cancel
Showing results for 
Search instead for 
Did you mean: 

IAS/IPS – Efficient Group Setup?

06-11-2025 5:17 PM
tskwin Participant
1017 views 3 comments
0 Likes
SAP Managed Tags
Subscribe

Hello everyone,

We are using SAP IAS/IPS with Azure as Idp. We have already connected several SAP Cloud Apps to IAS, and more apps will be added.

Access to these apps is controlled by groups in Azure. For example, depending on a user’s role in SAC or Enable Now, different groups are created in Azure.

In SAC, we already have at least 10 groups, and in Enable Now even more. As more SAP Cloud Apps are connected, the number of Azure groups increases quickly.

My question is:
Is there a better or easier way to manage roles and access without creating so many groups in Azure?

How do you manage this in your environment to keep it organized and scalable?

Thanks for your help

Best regards

0 Likes

Accepted Solutions (0)

Answers (2)

Answers (2)

Sgemert
Explorer
0 Likes

Maybe SAP IAG is a solution for this?

plaban_sahoo28
Participant
0 Likes

Please check risk based authentication in IAS which controls Azure groups fed in via Identity federation group mapping and then routes to SAC

tskwin
Participant
0 Likes

Hi @plaban_sahoo28 

Thank you very much for your input.

Could you please explain in a bit more detail how this would be implemented?

 Does this mean that a single group should be created in Azure, and only users are provisioned to IAS and manually assigned to the appropriate groups direct in IAS (depending on the cloud application or role)?

Thank you in advance.

Best regards