The authentication response sent by the Identity Authentication Service to the Application contains the message in the subject, which can be seen in the SAML trace (see SAP KBA 2461862):
<Response ...>
<StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Responder">
<StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:AuthnFailed"/>
<StatusMessage>The user [PXXXXXX] is not provisioned for Service Provider [...]</StatusMessage>
In the Troubleshooting log, the following error is displayed:
Identity Provider could not process the authentication request received due to error on its own side.The user [Pxxxxxx] is not provisioned for Service Provider [<sp_URL>] Caused by: The user [Pxxxxxx] is not provisioned for Service Provider [<sp_URL>] Caused by: The user [Pxxxxxx] is not provisioned for Service Provider [<sp_URL>]
Identity Authentication Service
sci, cloud identity, access, not provisioned, ias , KBA , BC-IAM-IDS , Identity Authentication Service , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.