Symptom
HTTP 400 - Bad Request error after logging in to SAP Analytics Cloud (SAC) with a custom SAML Identity Provider (IdP)
Environment
SAP Analytics Cloud
Cause
The SAML assertion returned to SAC does not contain a valid Name ID required to validate the user. For example, when Custom SAML attribute is selected as the attribute method to map users:
- Value returned by the IdP:
- <saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">user@example.com</saml:NameID>
- Value in the Custom SAML attribute column:
- P000234
The values differ, and the nameid-format expects an email address, not an employee ID.
Resolution
Ensure the value returned from the custom IdP matches the value configured in SAP Analytics Cloud. See more in the KBA 2411608 - SAP Analytics Cloud SAML authentication *** Master KBA ***.
See Also
- KBA 2569847 - Where can you find SAC user assistance (help) to use, configure, and operate it more effectively?
- KBA 2487011 - What information do I need to provide when opening a case for SAP Analytics Cloud?
- KBA 2511489 - Troubleshooting performance issues in SAP Analytics Cloud
- SAP Analytics Cloud Connection Guide
- SAP Analytics Cloud Get More Help and SAP Support
- Need More Help? Contact Support
Your feedback is important to help us improve our knowledge base.
Keywords
saml, 400, error, login, logon, status, SAC, custom, SAML, IdP, nameID, email , KBA , LOD-ANA-AUT , SAC Authentication / Login , Problem
SAP Knowledge Base Article - Public