SAP Knowledge Base Article - Preview

3443847 - MFA is required when Corporate-IdP is authenticating users and IAS is acting as proxy

Symptom

  • There is a need to turn on Multi-Factor Authentication (MFA) or Two-Factor Authentication (2FA) for an application that uses corporate identity provider (IdP) to authenticate users and SAP Cloud Identity Services (IAS) acts as the proxy.

  • Following is an example scenario of how the authentication flow looks like. Microsoft Azure (Entra ID) is used as an example of a corporate IdP.
    • SAP BTP (Service Provider) --> SAP IAS ( proxy ) --> Entra ID (Corporate IdP) --> SAP IAS ( proxy ) --> SAP BTP  (Service Provider) 




Read more...

Environment

SAP Cloud Identity Services

Product

Identity Authentication 1.0

Keywords

Azure
Entra
Microsoft
Corporate IdP 
Identity provider
Multi Factor Authentication
Two Factor Authentication
Identity Authentication
IAS 

, KBA , BC-IAM-IDS , Identity Authentication Service , How To

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.