Symptom
- After a successful authentication to the Identity Provider (IDP), user is redirected back to SAP but gets an "401 Not authorized" error screen, a logon screen, or a logon popup.
and - In the SAML trace via Security Diagnostic Tool, the error "Federation error: Can't map user name. Assertion attribute with name '<attribute_name>' was not found." can be found.
"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."
Read more...
Environment
- SAP NetWeaver
- ABAP platform
- SAP S/4HANA
Product
ABAP platform all versions ; SAP NetWeaver all versions ; SAP S/4HANA all versions
Keywords
SAML, SAML2, Federation error, Can't map user name, Assertion attribute with name was not found, Assertion attribute with name, was not found , KBA , BC-SEC-LGN-SML , SAML 2.0 for ABAP , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview