SAP Knowledge Base Article - Public

3795637 - Enabling JWT SSO at the database level for SAP Datasphere Space Users

Symptom

When attempting to enable SSO with JWT via the SAP HANA Cockpit for this database user, the following authorization error occurs:

"You are not authorized to enable SSO. To enable SSO, log in to the SAP HANA Cockpit as a database user with the CREATE JWT PROVIDER, TRUST ADMIN, and CERTIFICATE ADMIN privileges."

"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."

Environment

SAP Datasphere

Cause

JWT provider configuration in SAP Datasphere is managed entirely by the platform at the tenant level and is not customer-configurable via SAP HANA Cockpit.

Resolution

The privileges `CREATE JWT PROVIDER`, `TRUST ADMIN`, and `CERTIFICATE ADMIN` are system-level HANA privileges that are reserved exclusively for SAP's internal service accounts in the managed Datasphere environment. These privileges cannot be granted to Space DB users. This is an intentional security boundary, not a limitation that can be worked around.

Keywords

DSP, DS, DWC, DB, database , KBA , DS-SM , Space Management , Problem

Product

SAP Datasphere all versions