Symptom
AudienceRestriciton error while connecting C4C to Snapaddy.
Environment
SAP Cloud for Customer
Reproducing the Issue
- Navigate to Snapaddy.
- Enter details like Entity ID, OAuth Client ID, Client secret and URL
Encounter error: The provided authorization grant is invalid. Exception was> https://my****-sso.crm.ondemand.com is not defined in the element 'AudienceRestriciton'.
Cause
The endpoint of the URL used in Snapaddy is incorrect.
Resolution
- Navigate to Administrator>Common task.
- Configure single sign on.
- Open the SP metadata.
- Copy the Entity ID and paste it in Snapaddy (URL's are case sensitive)
- Since customer is using OAuth2.0 via SAML bearer assertion use the endpoint URL as provided in SP metadata i.e "https://my****-sso.crm.ondemand.com/sap/saml2/sp/acs"
Keywords
Snapaddy,assertion,AudienceRestriciton , KBA , LOD-CRM-SEC , Security Topics , Problem
Product
SAP Cloud for Customer core applications 2508
SAP Knowledge Base Article - Public