SAP Knowledge Base Article - Public

2932099 - Some SAML users in SAP Analytics Cloud (SAC) do not have the correct SAML mapping


The following behavior occurs in SAP Analytics Cloud (SAC):

  • Some users do not see their Groups mapped in SAC Teams
  • This causes log in and permissions or rights issues 


  • SAP Analytics Cloud (Enterprise)
  • Custom IdP (Azure AD)


-Azure Active Directory limits the number of groups it will emit in a token to 150 for SAML assertions

-Under certain circumstances, even other custom IdP's have similar limitations

-There is a known physical limit of characters that can be received in the HTTP group headers


This issue is currently under investigation by development.

- From the Azure side, you can use group Filtering to map only the most significant groups to SAC Teams and roles.

See Also

Your feedback is important to help us improve our knowledge base.


SAP Cloud for Planning, sc4p, c4p, cforp, cloudforplanning, Cloud for Analytics, Cloud4Analytics, CloudforAnalytics, Cloud 4 Planning, BOC, SAPBusinessObjectsCloud, BusinessObjectsCloud, BOBJcloud, BOCloud., SAC, SAP AC, Cloud-Analytics, CloudAnalytics, SAPCloudAnalytics,Error, Issue, System, Data, User, Unable, Access, Connection, Sac, Connector, Live, Acquisition, Up, Set, setup, Model, BW, Connect, Story, Tenant, Import, Failed, Using, Working, SAML, SSO, sapanalyticscloud, sap analytical cloud, sap analytical cloud, SAC , KBA , LOD-ANA-DES , Story Design & Visualizations , Problem


SAP Analytics Cloud 1.0