on 2025 Feb 24 3:19 PM
Hello SAP Community,
We have implemented SAML2 SSO for an SAP S/4HANA On-Premise system using an external Identity Provider (IdP). The authentication process is working as expected, with Name ID Format set to PERSISTENT and user mapping configured in the standard table SAML2_PIDFED.
Due to compliance requirements, storing the IdP user ID in SAP for mapping purposes is not permitted. As a result, we are exploring an alternative approach to achieve user mapping without storing the IdP user ID directly.
The idea is to extend the SAML2.0 authentication process to call a third-party web service that provides an additional attribute (which can be legally stored) to be used for mapping instead of the IdP user ID. The high-level process would be:
Any guidance, experiences, or references to similar implementations would be greatly appreciated.
Thank you for your insights!
Request clarification before answering.
| User | Count |
|---|---|
| 17 | |
| 8 | |
| 8 | |
| 6 | |
| 4 | |
| 4 | |
| 4 | |
| 2 | |
| 2 | |
| 2 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.