SAP Knowledge Base Article - Public

3597694 - Datasphere Support - Fundamental Information Required for Troubleshooting Single Sign-On (SSO) Issues

Symptom

If integrating IAS as a custom Identity Provider (IDP), ensure to provide relevant Identity Authentication Service (IAS) screenshots and har. file to facilitate effective troubleshooting processes.

  • Screenshots
  • har. file

"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."

Environment

  • SAP Datasphere
  • SAP Identity Authentication Service 

Resolution

Part 1: Screenshot of your IAS application configuration information.

Provides a documentation with the following screenshots in case:

  1. Self-defined Attributes:

  2. Subject Name Identifier:

  3. Default Name ID Format

  4. Conditional Authentication:

Part 2: Network trace when SSO errors occur in Datasphere.

Perform the following steps in Datasphere to record the network trace and then upload to the case:

  1. Once you get the verification URL in Datasphere, open a new InPrivate window

  2. Open the development tools (F12) -> Network tab

  3. Past the URL in InPrivate window

  4. Enter the credentials of custom IDP in InPrivate window

  5. After the error occurs, download the network trace and attach it to the case.

There is also a troubleshooting KBA, you may take a look at it as well.

0002487567 - Troubleshooting SAML assertions when configuring SAML SSO in SAP Analytics Cloud (SAC)

(Although this KBA mentions SAC, it also works for Datasphere).

See Also

How To Enable SAML SSO with IAS as Custom IdP

Keywords

Identity Authentication Service, Identity Provider, Service Provider, DS, IDP, SP, SSO, SAC , KBA , DS-SEC-AUTN , Authentication: SSO/SAML, OAuth Client , Problem

Product

SAP Datasphere all versions

Attachments

Pasted image.png
Pasted image.png