SAP Knowledge Base Article - Preview

3355156 - User has no role collection assigned in BTP when using Azure AD and IAS


You are using Azure AD as IdP and SAP IAS as SAML Federation Proxy and the User Attributes have been mapped in BTP's trust configuration. However, when checking the user's role collection in BTP, they have none.



  • Azure Active Directory.
  • SAP Identity Authentication Service.
  • SAP Business Technology Platform.


SAP BTP, Neo environment 1.0 ; SAP Cloud Identity Services all versions


Azure AD, IAS, BTP, role mappings, trust configuration, SAML, user attributes. , KBA , BC-CP-CF-SEC-IAM , UAA, Authentication, Authorization, Trust Mgmnt , BC-IAM-IPS , Identity Provisioning Service (IPS) , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.