SAML Identity Provider Trust Configuration
The provided sources do not contain enough grounded information to define a concept labeled "undefined." Based on the available sources, they collectively describe SAML trust configuration on SAP BTP — a mechanism that allows developers to establish federated trust between SAP BTP subaccounts and identity providers (such as SAP Cloud Identity Services or SAP SuccessFactors) using the SAML 2.0 protocol. Developers use it to enable single sign-on, map identity provider groups to platform roles, and configure OAuth 2.0 SAML Bearer Assertion grants for secure service-to-service communication. It can also be restored after replacement to recover a previous trust setup in a subaccount.
Tutorials that teach this
- Tutorial Set Up Trust Between SAP Cloud Identity Services and SAP BTP Subaccount
- Tutorial Establish Trust Configuration between SAP S/4HANA On-premise and SAP BTP
- Tutorial Set Up SAP Build Apps (with Booster) on SAP BTP Trial Account
- Tutorial Reconfigure Trust Relationships on SAP HANA XS Systems
- Tutorial Enable Multi-User Mode for MDK Application
- Tutorial Set Up SAP Build Apps on SAP BTP Trial Account
- Tutorial Establish Trust Configuration between SAP S/4HANA Cloud, public edition and SAP BTP Subaccount
- Tutorial Connect Azure Active Directory to Identity Authentication Service
- Tutorial Configure Outbound SAML OAuth between SAP S/4HANA Cloud, public edition and SAP BTP
- Tutorial Extend SAP SuccessFactors on SAP BTP, Cloud Foundry Environment
- Tutorial Access Protected SAP Analytics Cloud Resources with OAuth Two-Legged Flow
- Tutorial Set Up SAP Build Work Zone, standard edition Using a Trial Account
- Tutorial Set Up Trust Between Identity Authentication and SAP Business Technology Platform Neo Environment
Docs explaining this concept
- Doc Configure OAuth 2.0 SAML Bearer Assertion Grant
- Doc Configure SAP SuccessFactors as a Trusted Identity Provider in SAP BTP
- Doc Manually Establish Trust and Federation Between SAP Authorization and Trust Management Service and SAP Cloud Identity Services
- Doc Mapping the Identity Provider Group Developers to the Neo Group
- Doc Restore SAML Trust Configuration
Prerequisites
- Concept SAML 2.0 and OpenID Connect Protocols SAML 2.0 and OpenID Connect are industry-standard protocols used to enable [identity federation](https://help.sap.com/docs/btp/sap-business-technology-platform/2abdc1d4373648799a8b1275084b7975?locale=en-US&state=PRODUCTION&version=Cloud) on SAP Business Technology Platform — the process of sharing identity information between two parties. Developers use these protocols to establish trust between an identity provider and SAP BTP, allowing users to authenticate through a central identity provider rather than managing separate credentials for each service.
- Concept SAML Metadata Exchange The concept name was not provided (marked as "undefined"), and the available source snippets do not contain enough substantive content to identify or define a specific SAP developer concept. Sources [S1] and [S2] reference SAP BTP trust configuration and SAML token signing key rotation, while [S3]–[S7] are tutorial titles only, providing no body text to draw from. Without a named concept and with insufficient grounded source material, a compliant definition cannot be produced.
- Concept Identity Authentication (IAS) Tenant Configuration The provided sources do not contain sufficient information to define a specific SAP developer concept — the concept name is listed as "undefined" and the source snippets consist primarily of tutorial titles and troubleshooting symptom headers without substantive explanatory content. A accurate, source-grounded definition cannot be produced from these materials.
- Concept Identity Authentication Tenant Configuration The concept name is not defined in the provided sources, and the sources do not contain sufficient grounded content to produce an accurate, fully supported definition. A reliable definition cannot be written without source material that clearly explains what the concept is and how developers use it.
- Concept SAP BTP Cockpit The concept name was not provided and the supplied source snippets do not define or describe a single, identifiable SAP developer concept — they cover a range of unrelated SAP BTP topics such as Kyma environment setup, Cloud Foundry org deletion, subaccount management, and service instances. A focused definition cannot be grounded solely in these sources without a clearly stated concept to define.
- Concept Single Sign-On (SSO) and SAML Authentication The concept name is not defined in the provided sources, so a grounded definition cannot be written. Based on the available sources, which cover topics such as identity providers, trust and federation, single sign-on, and live data connections on SAP BTP, the specific concept intended here is unclear. Please provide a valid concept name so that an accurate, source-grounded definition can be produced.
- Concept Identity Provider (IdP) Trust Configuration The concept provided is **undefined**, and the available source snippets do not contain sufficient grounded content to produce a reliable, accurate definition. All sources relate to trust configuration, SAP BTP setup tutorials, or SAP Document AI — none of which define a specific named developer concept. Without a valid concept name and supporting source material, a documentation-quality definition cannot be responsibly generated.
- Concept SAP Cloud Identity Services Setup The concept provided is **undefined**, so no specific SAP developer concept has been identified to define. Based on the available sources, the closest coherent topic is **Trust and Federation with Identity Providers on SAP BTP** — a mechanism that allows developers and administrators to configure SAP Business Technology Platform (SAP BTP) subaccounts to delegate authentication to external identity providers (IdPs) using protocols such as SAML or OpenID Connect. Developers use it to enable single sign-on (SSO), manage user provisioning, and control access across SAP BTP accounts by establishing trust relationships with services such as [SAP Cloud Identity Services](https://help.sap.com/docs/btp/sap-business-technology-platform/cb1bc8f1bd5c482e891063960d7acd78?locale=en-US&state=PRODUCTION&version=Cloud). It also supports [migration from SAML-based trust to OpenID Connect trust](https://help.sap.com/docs/btp/sap-business-technology-platform/d097ce26cb2d4b8fa9a597a5381cb3cb?locale=en-US&state=PRODUCTION&version=Cloud) to align with modern authentication standards.
- Concept Communication Arrangement for Cloud Connector A **Communication Arrangement** is a configuration object in the ABAP environment of SAP Business Technology Platform that defines how an external system connects to and communicates with your system. Developers use it to set up integration scenarios by specifying a [communication scenario, system, and user](https://help.sap.com/docs/btp/sap-business-technology-platform/04488354490349f989871c5d555a2926?locale=en-US&state=PRODUCTION&version=Cloud), enabling both inbound and outbound connections. The [communication management apps](https://help.sap.com/docs/btp/sap-business-technology-platform/2e84a10c430645a88bdbfaaa23ac9ff7?locale=en-US&state=PRODUCTION&version=Cloud) allow developers to integrate their system with other systems, such as SAP Analytics Cloud, SAP Datasphere, or on-premise systems via Cloud Connector, as well as services like outbound email via SMTP.
- Concept SAP HANA Certificate and PSE (Certificate Collection) Management The concept name provided is "undefined," and the available sources do not contain sufficient information to define a specific, identifiable SAP developer concept. The sources reference topics such as [downloading certificates](https://help.sap.com/docs/btp/sap-business-technology-platform/3645813291be47839e72ab08d8a31ac9?locale=en-US&state=PRODUCTION&version=Cloud), X.509 authentication, SAP HANA Cloud data virtualization, and SAP Analytics Cloud connections, but without a concrete concept name, no accurate and grounded definition can be produced.
- Concept SAP BTP Subaccount and Entitlement Setup The provided sources do not contain sufficient information to define this concept. The concept name is "undefined" and none of the source snippets supply grounded content that could be used to write an accurate, sourced definition.
- Concept Communication Systems Configuration The provided sources do not contain sufficient information to define the concept **"undefined"** — no concept name or relevant explanatory content was supplied. A meaningful definition cannot be grounded solely in the available source snippets, which cover unrelated topics such as certificate renewal, communication systems, and SMTP integration. Please provide a valid concept name and supporting sources so an accurate, grounded definition can be written.
Concepts that build on this
- Concept SAP Build Work Zone configuration
- Concept Bearer Assertion Flow
- Concept OAuth 2.0 SAML Bearer Assertion Grant
- Concept Corporate Identity Provider for SAP BTP Platform Users
- Concept SAML Bearer Assertion Provider Configuration
- Concept Assertion Consumer Service (ACS)
- Concept Principal Propagation
- Concept SAML Assertion Authentication
- Concept Role and Role Collection Management
- Concept OAuth 2.0 Authentication
- Concept OAuth2 SAML Bearer Assertion Authentication Setup
- Concept Single Sign-On Between SAP BTP and SAP SuccessFactors
- Concept Subject Name Identifier Mapping
- Concept MDK Multi-User Mode Configuration
- Concept SAML-Based SSO Integration
- Concept Corporate Identity Provider Delegation
- Concept Role Collection Mapping
- Concept SAML Identity Provider Integration for Business Users
- Concept SAML Trust Relationship Reconfiguration on SAP HANA XS
- Concept Google Workspace Admin Console User Management
- Concept Identity Authentication (IAS) Tenant Configuration