SAP Knowledge Base Article - Public

3597694 - Datasphere Support - Fundamental Information Required for Troubleshooting Single Sign-On (SSO) Issues

Symptom

If integrating IAS as a custom Identity Provider (IDP), ensure to provide relevant Identity Authentication Service (IAS) screenshots and har. file to facilitate effective troubleshooting processes.

  • Screenshots
  • har. file

"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."

Environment

  • SAP Datasphere
  • SAP Identity Authentication Service 

Resolution

Part 1: Screenshot of your IAS application configuration information.

Provides a documentation with the following screenshots in case:

  1. Self-defined Attributes:

  2. Subject Name Identifier:

  3. Default Name ID Format

  4. Conditional Authentication:

Part 2: Network trace when SSO errors occur.

Perform the following steps to record the network trace and then upload to the case:

  1. Once you get the verification URL, open an InPrivate window

  2. Open the development tools (F12) -> Network tab

  3. Past the URL in InPrivate window

  4. Continue checking

  5. Download the network trace and attach it to this incident.

There is also a troubleshooting KBA, you may take a look at it as well.

0002487567 - Troubleshooting SAML assertions when configuring SAML SSO in SAP Analytics Cloud (SAC)

(Although this KBA mentions SAC, it also works for Datasphere).

Keywords

Identity Authentication Service, Identity Provider, Service Provider, DS, IDP, SP, SSO , KBA , DS-AUT , Authorizations (Locks, etc.) , Problem

Product

SAP Datasphere all versions

Attachments

Pasted image.png