SAP Knowledge Base Article - Public

3583338 - SAP Analytics Cloud SAML NameID Policy Format Mismatch with Identity Provider (ForgeRock AM)

Symptom

  • An issue is occurring with Single Sign-On (SSO) in SAP Analytics Cloud (SAC) using SAML.
  • The Identity Provider (IdP) requires the NameID attribute to be mapped to the user's email address, but SAC is sending a SAML authentication request with a different NameID policy. 

Environment

SAP Analytics Cloud 2025.1.6

Reproducing the Issue

  1. Go to SAC > Administration >  Security > SAML Sign-On (SSO) Configuration
  2. Check the user attribute (step 3) and notice that Custom SAML User Mapping is used (as number_id) and it is working in the IDP ForgeRock, but a change to e-mail as the attribute is required.

Cause

SAC request is not the same of the IDP, however it should work with e-mail even if the SAC request is

  • "urn:oasis:names:tc:SAML:1.1:nameidformat:unspecified".

Resolution

Changing the value in the SAML request is not supported and is not on our roadmap. Even with the NameID Policy containing 'unspecified' the SAML using e-mail should work with it.

https://community.forgerock.com/t/openam-saml-http-status-500-unable-to-do-single-sign-on-or-federation/520/8

 

See Also

Keywords

SAC, IDP, SAML, NameID, e-mail, custom SAML, error, ForgeRock, request, Analytics Cloud , KBA , LOD-ANA-ADM , SAC Administration , Problem

Product

SAP Analytics Cloud 1.0