cancel
Showing results for 
Search instead for 
Did you mean: 

SAP Cloud Foundry Platform Identity Provider for Platform Users

09-20-2019 8:24 AM
Ben Participant
2425 views 5 comments Go to solution
SAP Managed Tags
Subscribe

Dear Community

I came across following slide from this SAP CF Security presentation, where I found out that Platform Users (Admins & Developer Accounts) can be secured by 2 Factor Authentication using SAP CP IAS Service:

I was looking for some information about how to switch from SAP ID Service to Custom IdP for Platform Users, but I only found this SAP Help Page regarding the Neo Environment but not for Cloud Foundry. Does anybody know where to find more information?

Is only SAP IAS and SAP ID Service Supported for Platform User IdP or can also 3rd Party IdP's used, for example MS Azure AD?

Please note that I am not talking about "Business Users" or "Application Authentication", for this case I already implemented custom IdP Trust Configuration on Subaccount Level. What I am looking for is securing the Admin/Developer Accounts (SAP Cloud Platform Cockpit).

Best regards,

Ben

Accepted Solutions (1)

Accepted Solutions (1)

Kaempfer
Advisor
Advisor

Hi,

SAP Cloud Platform - Cloud Foundry --> Plattform Users

  • currently only possible via SAP ID Service
  • there are plans to support also SAP Cloud Identity Authentication service

Regards

Matthias

Answers (2)

Answers (2)

arnefeys
Explorer

Hi, does anyone have an update? We are in need of more advance authentication methods and MFA on our CF environment. IAS as custom Platform Identity Provider as it is possible with Neo, would be the best solution.

Thank you!

NickChecan
Explorer
0 Likes

We are also really looking forward to this feature. The current SAP documentation says that is possible, but we found few guides explaining how to perform this operation on the Cloud Foundry Feature Set B. Our current trust configuration for platform users on the global account doesn't work the same way trust configurations are set on the subaccounts and our IAS settings don't allow us to set default attributes for role collection mapping on the global account. We would appreciate any input on this.