SAP Knowledge Base Article - Preview

3704643 - What is the effect of the option "Force Re-authentication" set in a SAML2 Authentication Policy?

Symptom

In an SAP S/4HANA or ABAP-based system configured with SAML 2.0 Authentication, administrators configured a Web Application Policy with the Authentication Policy set to “Force Re-authentication”.

What is the effect of this configuration ?


Read more...

Environment

  • SAP S/4HANA or SAP NetWeaver ABAP
  • External Identity Provider (for example, Microsoft Azure AD, Entra ID, Okta, etc..)

Product

SAP NetWeaver Application Server all versions

Keywords

SAML2, authentication, Force Re-authentication, Conditional Access policies, ForceAuthn, Force Re-authentication, SAML, SAML authentication request, Identity Provider, IdP, SAP SSO, Single Sign-On, Azure AD, Entra ID, IdP session, silent authentication, Conditional Access, sign-in frequency, IdP policy, privileged access, security compliance, re-authentication enforcement, SSO bypass, SAML attribute  , KBA , BC-SEC-LGN-SML , SAML 2.0 for ABAP , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.