SAP Knowledge Base Article - Public

3800988 - SAP Analytics Cloud – SSO Configuration Using OIDC Bundling with SAP Cloud Identity Services

Symptom

  • When configuring Single Sign-On (SSO) for SAP Analytics Cloud (SAC) using the new SSO process, the previous SAML 2.0-based configuration procedure may no longer be applicable.
  • The legacy procedure may include manual configuration of parameters such as SAML attributes, Name ID, and metadata.

Environment

SAP Analytics Cloud 2026.15.6 

Reproducing the Issue

  1. Sign in to the tenant with an administrator account.
  2. Navigate to System > Administration > Security.
  3. Observe that the Authentication Method selection is not available and SAML 2.0 option cannot be selected under IAS.

Cause

  • SAP Analytics Cloud uses a new SSO configuration process based on OpenID Connect (OIDC) bundling with SAP Cloud Identity Services – Identity Authentication (IAS).
  • The previous SAML 2.0 configuration method belongs to the legacy SSO setup and is not applicable to the new OIDC bundling process.
  • Therefore, the legacy SAML 2.0 configuration procedure should not be followed when setting up SSO through the new process.

Resolution

  • Use the OIDC bundling process through the Identity Provider Administration Tool (IdP-admin)  to establish the SSO integration between SAP Analytics Cloud and SAP Cloud Identity Services – Identity Authentication.
  • The bundling process simplifies and automates the configuration between the SAP application and IAS, reducing the number of manual configuration steps.
    • Refer to the following KBA for additional guidance: KBA 3576392 - *MASTER KBA* Cloud Identity Services (IAS/IPS) Bundling with BDC, DSP, and SAC using Identity Provider Administration Tool - SAP for Me

Advantages of OIDC Bundling

    • Automated integration: The SSO configuration between SAC and IAS is established through the bundling process, reducing manual configuration.
    • Reduced configuration errors: Configuration parameters that previously required manual setup are handled automatically as part of the integration.
    • Simplified user identification: The process helps ensure that the required user identification attributes are correctly configured between the SAP application and IAS, avoiding manual configuration issues related to parameters such as Name ID.
    • Metadata maintenance: The relevant metadata and configuration information on the SAP application and IAS sides can be updated when required, reducing the need for manual maintenance.
    • Standardized configuration: The bundling approach provides a consistent SSO configuration between the SAP application and IAS.
    • Reduced maintenance effort: Fewer manual configuration steps are required when changes to the SSO integration are introduced.
    • Improved integration with IAS: The bundling process provides a more integrated approach between SAP Analytics Cloud and SAP Cloud Identity Services.

See Also

  • KBA 3719332  - Options to enable a custom SAML Identity Provider are missing in SAP Analytics Cloud (SAC) - SAP for Me
  • KBA  3576392  - *MASTER KBA* Cloud Identity Services (IAS/IPS) Bundling with BDC, DSP, and SAC using Identity Provider Administration Tool - SAP for Me
  • KBA 2859509 - How to change the System Owner Email Address in SAP Analytics Cloud (SAC) - SAP for Me

Keywords

SAP Analytics Cloud, SAC, SAP Datasphere, DSP, SSO, Single Sign-On, OIDC, OpenID Connect, OIDC Bundling, IAS, Identity Authentication, SAML 2.0, Name ID, metadata, authentication , KBA , LOD-ANA-AUT , SAC Authentication / Login , Problem

Product

SAP Analytics Cloud all versions ; SAP Datasphere all versions