Custom Identity Provider for BTP
The concept name was not provided and cannot be determined from the available source snippets, which cover topics such as SAML and OpenID Connect trust migration, single sign-on login, role collections, and identity providers on SAP BTP. Without a defined concept or sufficient source material to ground a specific definition, a accurate and source-supported definition cannot be written. Please provide the concept name and relevant source snippets.
Tutorials that teach this
Docs explaining this concept
- Doc Assign User Groups to Role Collections
- Doc Display Logon Link for Custom Identity Provider for Business Users
- Doc Log On with a Custom Identity Provider to the SAP BTP Cockpit
- Doc Log in with Single Sign-On
- Doc Migration from SAML Trust to OpenID Connect Trust with SAP Cloud Identity Services
- Doc Security Recommendations for SAP Authorization and Trust Management Service
- Doc User Base Doesn't Appear in Existing Neo Subaccounts
Prerequisites
- Concept Identity Provider (IdP) Trust Configuration The concept provided is **undefined**, and the available source snippets do not contain sufficient grounded content to produce a reliable, accurate definition. All sources relate to trust configuration, SAP BTP setup tutorials, or SAP Document AI — none of which define a specific named developer concept. Without a valid concept name and supporting source material, a documentation-quality definition cannot be responsibly generated.
- Concept BTP Space Member Management A **space member** is a user who has been granted access to a specific space within SAP BTP, with one or more roles assigned to them at the space level. Developers and administrators use the [SAP BTP cockpit](https://help.sap.com/docs/btp/sap-business-technology-platform/81d0b4dcfbc84016b6b3c1465d4272f4?locale=en-US&state=PRODUCTION&version=Cloud) to [add space members and assign roles](https://help.sap.com/docs/btp/sap-business-technology-platform/81d0b4dcfbc84016b6b3c1465d4272f4?locale=en-US&state=PRODUCTION&version=Cloud), edit existing role assignments, or remove a member entirely by deleting all of their roles. Deleting all roles of a space member removes that user's access to the space.
- Concept SAP Cloud Identity Services Setup The concept provided is **undefined**, so no specific SAP developer concept has been identified to define. Based on the available sources, the closest coherent topic is **Trust and Federation with Identity Providers on SAP BTP** — a mechanism that allows developers and administrators to configure SAP Business Technology Platform (SAP BTP) subaccounts to delegate authentication to external identity providers (IdPs) using protocols such as SAML or OpenID Connect. Developers use it to enable single sign-on (SSO), manage user provisioning, and control access across SAP BTP accounts by establishing trust relationships with services such as [SAP Cloud Identity Services](https://help.sap.com/docs/btp/sap-business-technology-platform/cb1bc8f1bd5c482e891063960d7acd78?locale=en-US&state=PRODUCTION&version=Cloud). It also supports [migration from SAML-based trust to OpenID Connect trust](https://help.sap.com/docs/btp/sap-business-technology-platform/d097ce26cb2d4b8fa9a597a5381cb3cb?locale=en-US&state=PRODUCTION&version=Cloud) to align with modern authentication standards.
- Concept SAP Identity Authentication Service (IAS) Integration The concept name is not defined in the provided sources, so a precise definition cannot be grounded solely in the available snippets. Based on the sources, an **Identity Provider (IdP) user** is a user account managed by an external identity provider — such as SAP Identity Authentication Service — that developers and business users use to authenticate and access SAP BTP services and environments, including the [ABAP Environment Administration Launchpad](https://help.sap.com/docs/btp/sap-business-technology-platform/11e765e8af6d476f99ce014b3f02bd64?locale=en-US&state=PRODUCTION&version=Cloud). Developers can be [assigned to identity provider user groups](https://help.sap.com/docs/btp/sap-business-technology-platform/198c2caaa5954a58b4667bbbe4165d08?locale=en-US&state=PRODUCTION&version=Cloud) to manage access and permissions within an SAP BTP subaccount. Trust between the SAP BTP subaccount and the identity provider must be established to enable scenarios such as single sign-on across connected systems.