Symptom
- For monitoring SAP Analytics Cloud in SAP Datasphere, configurations steps are followed
as per Help Portal Documentation: Connecting to an SAP Analytics Cloud Tenant | SAP Help Portal.
- In step 7 "Authenticate Now" of "Connecting to an SAP Analytics Cloud Tenant",
the error Unauthorized happens when authenticating the source system user after logging on to the source tenant
and it fails with "Authenticated system user could not be found" as below:
- In step 7 "Authenticate Now" of "Connecting to an SAP Analytics Cloud Tenant",
"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."
Environment
SAP Datasphere
Reproducing the Issue
- In the side navigation area, click (Catalog) -> (Monitoring).
- In the System table, select + (Create System).
- In the System Type field, select SAP Analytics Cloud.
- In the Name field, type a name to identify the tenant.
- In the UUID field, enter the tenant identifier.
- (Optional) To automatically publish objects from the source system to the catalog every time the catalog synchronizes with the source system, select the Enable Auto Publishing to the Catalog checkbox.
- Select Authenticate Now.
A dialog with instructions on how to authenticate the user for the source system appears. Follow the instructions for authenticating the source system user.- In the Authenticate System User dialog, click (Copy) to copy the link for authenticating the system user.
- Open a private browsing window and paste the link in the address bar.
- Log on to the tenant.
- After the source system user is authenticated and you see the confirmation message, close the private browsing window.
- When you are back on the Authenticate System User dialog, select Confirm Authentication.
- Back on the Create System dialog, select Create.
Cause
Missing mandatory attribute Groups with value "sac".
Resolution
- Configure attribute Groups with value set to sac (it's case sensitive!)
- In the SAC IdP config for your SAC tenant, it is required to set the "Groups" attribute with the value "sac"
See Also
- Enabling a Custom SAML Identity Provider | SAP Help Portal
- Connecting to an SAP Analytics Cloud Tenant | SAP Help Portal
- 3330480 Error 403 Unauthorized when enabling SAML SSO in SAP Datasphere
- 3512292 SSO in Datasphere with IAS IdP fails with Unauthorized 401 error
Keywords
dwc, data warehouse cloud, sso, saml, customidp, custom, idp, ias, SAP analytics cloud, sac, Authenticated system user could not be found, catalog , KBA , DS-CAT , Unified Cataloguing solution , Problem
Product
SAP Datasphere all versions
Attachments
Pasted image.png |
Pasted image.png |