SAP Knowledge Base Article - Public

3667831 - AudienceRestriciton error while connecting C4C to Snapaddy

Symptom

AudienceRestriciton error while connecting C4C to Snapaddy.

Environment

SAP Cloud for Customer

Reproducing the Issue

  1. Navigate to Snapaddy.
  2. Enter details like Entity ID, OAuth Client ID, Client secret and URL

Encounter error: The provided authorization grant is invalid. Exception was> https://my****-sso.crm.ondemand.com is not defined in the element 'AudienceRestriciton'. 

Cause

The endpoint of the URL used in Snapaddy is incorrect.

Resolution

  1. Navigate to Administrator>Common task.
  2. Configure single sign on.
  3. Open the SP metadata.
  4. Copy the Entity ID and paste it in Snapaddy (URL's are case sensitive)
  5. Since customer is using OAuth2.0 via SAML bearer assertion use the endpoint URL as provided in SP metadata i.e "https://my****-sso.crm.ondemand.com/sap/saml2/sp/acs"

  

Keywords

Snapaddy,assertion,AudienceRestriciton , KBA , LOD-CRM-SEC , Security Topics , Problem

Product

SAP Cloud for Customer core applications 2508