SAP Knowledge Base Article - Public

3472807 - "Creation of NameID is not allowed per AuthnRequest" error message while implementing Single Sign On in SAP Analytics Cloud (SAC)

Symptom

  • While implementing Single Sign On with SAML the following error occurs: "Response has invalid status code urn:oasis:names:tc:SAML:2.0:status:InvalidNameIDPolicy, status message is Creation of NameID is not allowed per AuthnRequest."
  • The configuration is correct and matches the SAP Attribute names
  • NameID is a correct match

Environment

  • SAP Analytics Cloud (Enterprise)
  • Custom Identity Provider (IdP)

Reproducing the Issue

  1. Configure the SAML IDP according to SAP help pages
  2. Try to log in to SAC
  3. Observe the error message

Cause

While SAC sends request for NameID in the AuthnRequest, the IdP will not return it in the desired format by SAC, resulting in the error message when trying to establish SAML SSO for the tenant.

Resolution

Enable the "Disable NameID persistence" option during the configuration of the SAML.

See Also

Keywords

SSO, Single Sign On, SAML, IDP, error, issue, problem, error message, NameID, SAC, SAP Analytics Cloud , KBA , LOD-ANA-AUT , SAC Authentication / Login , LOD-ANA-ADM , SAC Administration , Problem

Product

SAP Analytics Cloud 1.0