SAP Knowledge Base Article - Public

3355751 - Authentication Error when trying to activate Extended Integration with Microsoft 365

Symptom

  • Extended  functionality to integrate SF with Teams is not working.
  • When trying to enable the "Enabling Extended Integration with Microsoft 365"  the error "Authentication Error. Please contact your administrator for help" occurs.

Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental. 

Environment

SAP SuccessFactors HCM Suite

Reproducing the Issue

  1. Login to SF -> Admin Centre->  Go to  “Work Tech Configuration” page.
  2. Click Connect in the section Connection and Authentication
  3. After clicking on Connect and adding the credentials for Microsoft to accept the permissions, the Authentication Error appears:

           

Cause

  • An attempt is made to connect two different SAP SuccessFactors instances of the same customer to the same Microsoft Azure tenant while both instances are on the same Production or Preview stack/environment.
  • The Microsoft account used after clicking “Connect” does not have Microsoft 365 Global Administrator privileges, which are required to authorize the integration.
  • The Azure Active Directory tenant has “Admin consent required” enabled, and the application has not been authorized using the correct admin consent process.

Resolution

Two SuccessFactors instances to be connected to the same Azure

By design, a single Microsoft Azure tenant cannot be connected to more than one SAP SuccessFactors company on the same data center. If this design constraint is violated, an authentication error will occur during the connection process.

Resolution options:

  • Option 1: Disconnect the other SuccessFactors instance from the Azure tenant under Work Tech Configuration, then connect the required instance.
  • Option 2: Use a different or new Azure tenant to connect the required instance.

Note: When switching to a different or new Azure tenant, Microsoft Teams users may be different. Ensure that all required users exist in the new tenant and are assigned the appropriate permissions before proceeding.

Missing 365 Global admin permission

The authorization process must be completed by a user with Microsoft 365 Global Administrator privileges.

Verify that the user performing the authorization has the Global Administrator role. If the user does not have this role:

  1. Click “Copy Link” in SuccessFactors.
  2. Share the copied authorization link with a Microsoft 365 Global Administrator.
  3. The Global Administrator must complete the authorization using that link.

Important: The authorization link expires after 30 minutes. Ensure the Global Administrator completes the consent process within this timeframe.

    SAP SUPPORT ENGINEERS, see Internal Memo

                 

    See Also

    Keywords

    Authentication Error, Microsoft Azure, Microsoft 365 Integration with Teams, Teams, oauthCallback, INC24571522 , KBA , LOD-SF-EAS-WRK , Collaboration and Work Tech , Problem

    Product

    SAP SuccessFactors HCM Core all versions

    Attachments

    Pasted image.png
    Pasted image.jpg
    Pasted image.png
    Pasted image.png
    Pasted image.png
    Pasted image.png
    Pasted image.png
    Pasted image.png
    Pasted image.png
    Pasted image.png
    Pasted image.png
    Pasted image.png
    Pasted image.png