Symptom
You enable a custom SAML Identity Provider in your SAP Analytics Cloud (SAC)
Environment
- SAP Analytics Cloud
- Any valid SAML 2 Identity Provider (IdP)
Cause
The SAML assertion returned to SAC doesn't contain a valid Name ID required to validate the user.
For example, you selected Custom SAML attribute as the attribute method to map users.
Value returned by the IdP:
<saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">user@example.com</saml:NameID>
Value in the column Custom SAML attribute:
P000234
Not only the values are different, also the nameid-format is expecting an email address.
Resolution
Make sure that the value returned from your custom IdP matches the value selected in SAP Analytics Cloud.
See more in the KBA 2411608 - SAP Analytics Cloud SAML authentication *** Master KBA ***
See Also
- How to find User Assistance for SAP Analytics Cloud?
- Ask a question on the SAP Community!
- 2487011 - What information do I need to provide when opening incidents with SAP Analytics Cloud (Hint: Use component LOD-ANA*)
Your feedback is important to help us improve our knowledge base.
Please rate how useful you found this article by using the star rating feature at the beginning of this article.
Thank you.
Keywords
saml, 400, error, login, logon, status, SAC, SAP AC, Cloud-Analytics, CloudAnalytics, SAPCloudAnalytics , KBA , LOD-ANA , SAP Analytics Cloud (SAC) , LOD-ANA-BI , Business Intelligence Functionality, Analytic Models , LOD-ANA-PL , Planning , LOD-ANA-BR , SAC Boardroom , LOD-ANA-PR , SAC Predictive , Problem