SAP Knowledge Base Article - Preview

2615705 - Identity Authentication Service as proxy to ADFS or Azure fails because of the Scoping tag

Symptom

Microsoft ADFS or Azure AD/Entra ID is set as a Corporate Identity Provider to delegate authentication from an Identity Authentication tenant.

Authentication is not working on the ADFS or Azure AD/Entra ID side and either of the following messages is seen:

The SAML authentication request element 'Scoping' is not supported.

The SAML authentication request property 'Scoping/ProxyCount' is not supported.

Encountered error during federation passive request. 
System.Xml.XmlException: MSIS0018: The SAML protocol message cannot be read because it contains data that is not valid. ---> System.UriFormatException: Invalid URI: The format of the URI could not be determined.

Es ist ein Fehler aufgetreten. Wenden Sie sich an Ihren Administrator, um weitere Informationen zu erhalten.


Read more...

Environment

Identity Authentication

Product

SAP Cloud Identity Services all versions

Keywords

sci cloud identity ias AADSTS900236 , KBA , BC-IAM-IDS , Identity Authentication Service , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.