SAP Knowledge Base Article - Public

2935113 - Live HANA connection with SAML SSO enabled with Azure AD as Identity Provider (IdP) suddenly stops working with the following error in SAP Analytics Cloud (SAC)

Symptom

  • Live HANA connection with SAML SSO enabled with Azure AD as Identity Provider (IdP) suddenly stops working with the following error in SAP Analytics Cloud (SAC):
  • The SAP HANA server is also using same Identity Provider (IdP)
  • The SAP HANA server is exposed to internet users via a reverse proxy

Environment

  • SAP Analytics Cloud (Enterprise) 2020.8.9

Reproducing the Issue

  1. Log on to SAC tenant with SAML SSO enabled with Azure AD as IdP.
  2. Open one story based on Live Data connection with SAML SSO as Authentication type.
    => The SAP HANA server is also using same Identity Provider (IdP).
    => The SAP HANA server is exposed to internet users via a reverse proxy.
  3. The following error suddenly occur while it has been working for a long period.
    => "https://yourservername/sap/hana/xs/saml/login.xscfunc" cannot be reached.  yourservername’s server IP address could not be found.

Cause

  • According to help guide, if your SAP HANA server is exposed to internet users via a reverse proxy, in your SAML identity provider configuration, ensure that the Assertion Consumer Service (ACS) endpoint URL for the SAP HANA service provider is set to the SAP HANA server's reverse proxy URL. For example, https://<reverse-proxy-host>/sap/hana/xs/saml/login.xscfunc.
  • However, in Azure AD, it was changed to have two URLs for Assertion Consumer Service (ACS) endpoint: one is correct with SAP Hana URL and marked default; another url is YOURSERVERNAME. 

Resolution

  • Delete URL- YOURSERVERNAME - for Assertion Consumer Service (ACS) endpoint of SAP HANA service provider in your SAML identity provider configuration.

See Also

Your feedback is important to help us improve our knowledge base.

Keywords

SAP Cloud for Planning, sc4p, c4p, cforp, cloudforplanning, Cloud for Analytics, Cloud4Analytics, CloudforAnalytics, Cloud 4 Planning, BOC, SAPBusinessObjectsCloud, BusinessObjectsCloud, BOBJcloud, BOCloud., SAC, SAP AC, Cloud-Analytics, CloudAnalytics, SAPCloudAnalytics,Error, Issue, System, Data, User, Unable, Access, Connection, Sac, Connector, Live, Acquisition, Up, Set, setup, Model, BW, Connect, Story, Tenant, Import, Failed, Using, Working, SAML, SSO, sapanalyticscloud, sap analytical cloud, sap analytical cloud, SAC, sap analyst cloud, connected, failure, stopped,  SAML, SSO, Azure, IdP, Assertion Consumer Service, acs, endpoint , YOURSERVERNAME, reverse proxy, , KBA , LOD-ANA-AUT , SAC Authentication / Login , LOD-ANA-LDC-HAN , SAC Live Data Connection HANA , Problem

Product

SAP Analytics Cloud 1.0