SAP Knowledge Base Article - Public

3160352 - Why do you need the employee id as a result for SAML request for SPM authentication?

Symptom


Why do you need the employee id as a result for SAML request? ITS are suggesting to use userprinipalname instead of employeeid.


User Attributes & Claims
User Identifier (Name ID)user.employeeid <-> user.userprinipalname
last_nameuser.surname
first_nameuser.givenname
emailuser.mail



Resolution


We require a 'unique ID' that never changes for the User Identifier, as email addresses and names do change.

For example, if you used the userprinipalname as the 'unique ID' to create a new account and at some point in the future you changed a users name, that would mean the userprintpalname would change. Then you will end up with two accounts in our system and consume multiple licenses.



Keywords

KBA , BPI-SIG-CA-SEC-SAM , SAML 2.0 for SAP Signavio , How To

Product

SAP Signavio Process Manager all versions ; Signavio Process Manager all versions