SAP Knowledge Base Article - Public

2656152 - How to use "Custom SAML User Mapping" option in SAP Analytics Cloud when enabling Single Sign On (SSO)

Symptom

  • SAP Analytics Cloud (SAC) is being configured as a Service Provider for your custom SAML Identity Provider (IdP).
  • There aren't any attribute that matches either the user ID or the e-mail for the user accounts.
  • The users' emails or user IDs have different lower/uppercase combinations in SAC than your IdP.

"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."

Environment

SAP Analytics Cloud (Enterprise)

Cause

SAP Analytics Cloud is case sensitive and emails such as User1@example.com do not match a SAML assertion returning user1@example.com.

Resolution

The option Custom SAML User Mapping can be used when configuring your SAP Analytics Cloud with your IdP.

  • How does this work?

During configuration, select User Attribute Custom SAML User Mapping.

Type the Logon Credential. This is the value returned as a Claim by your Identity Provider (IdP).

Mapping_Custom_Attribute.png

In this example, the SAML IdP returns the following claim:

<NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">ValueReturnedByIdP</NameID>

You can capture what is exactly returned by your Identity Provider using a Chrome extension as described in KBA 2487567 - Troubleshooting SAML assertions when configuring SAML SSO in SAP Analytics Cloud (SAC) .

After saving the changes, SAP Analytics Cloud will convert the user accounts to your new SAML IdP. A new column will appear in the Security section > User view: SAML USER MAPPING.

NewColumn_Custom_SAML_User.png

The value for the System Owner (the account of the user making the changes) will show the value you typed during the verification: ValueReturnedByIdP.

See Also

    Your feedback is important to help us improve our knowledge base.

    Keywords

    saml, custom, mapping, uppercase, lowercase, match, user, credentials, SAC, SAP AC, Cloud-Analytics, CloudAnalytics, SAPCloudAnalytics, email, SAP Cloud for Planning, sc4p, c4p, cforp, cloudforplanning, Cloud for Analytics, Cloud4Analytics, CloudforAnalytics, Cloud 4 Planning, BOC, SAPBusinessObjectsCloud, BusinessObjectsCloud, BOBJcloud, BOCloud., SAC, SAP AC, Cloud-Analytics, CloudAnalytics, SAPCloudAnalytics,Error, Issue, System, Data, User, Unable, Access, Connection, Sac, Connector, Live, Acquisition, Up, Set, setup, Model, BW, Connect, Story, Tenant, Import, Failed, Using, Working, SAML, SSO, sapanalyticscloud, sap analytical cloud, sap analytical cloud, SAC , KBA , LOD-ANA-AUT , SAC Authentication / Login , How To

    Product

    SAP Analytics Cloud 1.0