Symptom
While configuring an OpenID Connect (OIDC) trust between Microsoft Entra ID and SAP Cloud Identity Services (CIS) for Joule integration, validation of the corporate identity provider fails in SAP Cloud Identity Services. In Identity Authentication > Corporate Identity Providers > OpenID Connect Configuration, the Validate action does not complete successfully.
Network traces may show an error similar to the following:
401 Unauthorized
{
"error": "invalid_client",
"error_description": "AADSTS700212: No matching federated identity record found for presented assertion audience '[URL]'. Please check your federated identity credential Subject, Audience and Issuer against the presented assertion."
}
Read more...
Environment
- Cloud Identity Services.
- Entra ID.
Product
Identity Authentication 1.0
Keywords
AADSTS700212, invalid_client, No matching federated identity record found, Failed to receive tokens from URI, 401 Unauthorized during OIDC validation, SAP Cloud Identity Services OIDC validation failed, Microsoft Entra ID and SAP Cloud Identity Services trust configuration, OIDC trust validation failure.
, KBA , BC-IAM-OID , OIDC/OAUTH2 component in SAP Cloud Identity Services , CA-JOULE-CLT-COP , Joule MS Copilot Client , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview