cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

Select which Identity Provider is used for an application in Cloud Identity Service

RouvenGob
Explorer
0 Kudos
221

Hey everyone,

we are using EntraID as an Corporate Identity Provider (SSO). I want my users to be able to use EntaID to log onto BTP applications, but i also want some users from the CIS to directly log on to the same applications.

Here is what I want:

  • user enters username and pw -> EntraID is used
  • user enters email and pw -> CIS Tenant is used

There is the option to use conditional authentication but u can´t define a rule for a username. Only Domains

RouvenGob_0-1740140522355.png

Greetings
Rouven 

Accepted Solutions (0)

Answers (1)

Answers (1)

dyaryura
Contributor
0 Kudos

Hi Rouven

I'm not sure what you want to achieve as part of this. I'd say that if you want users to login via EntraID and provide access to some PWD users the "natural" way to do it would be to configure EntraID in the app as default and set the option "allow users stored in Identity Authentication to log on". You need to provide the link to your PWD login users and make sure they have a PWD set in IAS

dyaryura_0-1740401932376.png

As an alternative, in the SAP guides you'll find complex scenarios solved via granting users to different groups in IAS. As long as your PWD users are static or you find a way to automate the group assignment in IAS (i.e via IPS) might be a valid option.

Thanks

Diego