Symptom
- When configuring Single Sign-On (SSO) for SAP Analytics Cloud (SAC) using the new SSO process, the previous SAML 2.0-based configuration procedure may no longer be applicable.
- The legacy procedure may include manual configuration of parameters such as SAML attributes, Name ID, and metadata.
Environment
SAP Analytics Cloud 2026.15.6
Reproducing the Issue
- Sign in to the tenant with an administrator account.
- Navigate to System > Administration > Security.
- Observe that the Authentication Method selection is not available and SAML 2.0 option cannot be selected under IAS.
Cause
- SAP Analytics Cloud uses a new SSO configuration process based on OpenID Connect (OIDC) bundling with SAP Cloud Identity Services – Identity Authentication (IAS).
- The previous SAML 2.0 configuration method belongs to the legacy SSO setup and is not applicable to the new OIDC bundling process.
- Therefore, the legacy SAML 2.0 configuration procedure should not be followed when setting up SSO through the new process.
Resolution
- Use the OIDC bundling process through the Identity Provider Administration Tool (IdP-admin) to establish the SSO integration between SAP Analytics Cloud and SAP Cloud Identity Services – Identity Authentication.
- The bundling process simplifies and automates the configuration between the SAP application and IAS, reducing the number of manual configuration steps.
- Refer to the following KBA for additional guidance: KBA 3576392 - *MASTER KBA* Cloud Identity Services (IAS/IPS) Bundling with BDC, DSP, and SAC using Identity Provider Administration Tool - SAP for Me
Advantages of OIDC Bundling
-
- Automated integration: The SSO configuration between SAC and IAS is established through the bundling process, reducing manual configuration.
- Reduced configuration errors: Configuration parameters that previously required manual setup are handled automatically as part of the integration.
- Simplified user identification: The process helps ensure that the required user identification attributes are correctly configured between the SAP application and IAS, avoiding manual configuration issues related to parameters such as Name ID.
- Metadata maintenance: The relevant metadata and configuration information on the SAP application and IAS sides can be updated when required, reducing the need for manual maintenance.
- Standardized configuration: The bundling approach provides a consistent SSO configuration between the SAP application and IAS.
- Reduced maintenance effort: Fewer manual configuration steps are required when changes to the SSO integration are introduced.
- Improved integration with IAS: The bundling process provides a more integrated approach between SAP Analytics Cloud and SAP Cloud Identity Services.
See Also
- KBA 3719332 - Options to enable a custom SAML Identity Provider are missing in SAP Analytics Cloud (SAC) - SAP for Me
- KBA 3576392 - *MASTER KBA* Cloud Identity Services (IAS/IPS) Bundling with BDC, DSP, and SAC using Identity Provider Administration Tool - SAP for Me
- KBA 2859509 - How to change the System Owner Email Address in SAP Analytics Cloud (SAC) - SAP for Me
Keywords
SAP Analytics Cloud, SAC, SAP Datasphere, DSP, SSO, Single Sign-On, OIDC, OpenID Connect, OIDC Bundling, IAS, Identity Authentication, SAML 2.0, Name ID, metadata, authentication , KBA , LOD-ANA-AUT , SAC Authentication / Login , Problem
Product
SAP Analytics Cloud all versions ; SAP Datasphere all versions
SAP Knowledge Base Article - Public