Symptom
NEO subaccount is using IAS as Application Identity Provider, and configured a Corporate Identity Provider as Default Identity Provider in IAS tenant.
There are many applications in NEO subaccount. User is required to enter a user name and password when accessing one of applications for the first time. After that, when user accesses another application which is in the same NEO subaccount, login screen still pops up asking for a user name and password again. It is supposed to SSO login instead of re-entering the user name and password.
From SAML trace, we can see the parameter ForceAuthn="true" as following image:
Read more...
Environment
- SAP Business Technology Platform NEO subaccount
- Identity Authentication
Keywords
SSO, NEO subaccount, Force Authentication, ForceAuthn="true" , KBA , BC-IAM-IDS , Identity Authentication Service , BC-NEO-SEC-IAM , Authentication, Authorization(Cloud Platform Neo) , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.