SAP Knowledge Base Article - Preview

2574530 - SAML2.0: Format <format_name> is not supported for user assignment

Symptom

The following error occurs when authenticating to the SAP NetWeaver ABAP using SAML2.0:

SAML20 SP (client 010):  Exception raised:
SAML20  SAML20 CX_SAML20_FEDERATION: Format 'transient' is not supported (or this can also be 'emailaddress' or 'unspecified' rather than 'transient') for user assignment. Long text: Format 'transient' is not supported for user assignment. 
SAML20     at CL_SAML20_ENTITY->IS_NAMEID_FORMAT_SUPPORTED

The same can be checked in traces collected with Security Diagnostic tool:

SAML_transient.png

or :

Format 'emailAddress' is not supported for user assignment. Details: Format 'emailAddress' is not supported for user

or

Format 'WindowsDomainQualifiedName' is not supported for user assignment.


Read more...

Environment

  • SAP enhancement package 2 for SAP NetWeaver 7.0
  • SAP NetWeaver 7.3
  • SAP enhancement package 1 for SAP NetWeaver 7.3
  • SAP NetWeaver 7.4
  • SAP NetWeaver 7.5 and higher

Product

SAP NetWeaver 7.3 ; SAP NetWeaver 7.4 ; SAP NetWeaver 7.5 ; SAP NetWeaver Application Server for ABAP innovation package all versions ; SAP enhancement package 1 for SAP NetWeaver 7.3 ; SAP enhancement package 2 for SAP NetWeaver 7.0

Keywords

Can't map username, username, map, login error, Identity Provider (IdP), saml2, SSO,Security Diagnostic Tool, is not supported for user assignment, emailAddress, WindowsDomainQualifiedName, Format 'unspecified' is not supported. , KBA , BC-SEC-LGN-SML , SAML 2.0 for ABAP , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.