Subject Name Identifier Mapping
User provisioning is the automated process of creating users who are later granted access to applications and services on SAP Business Technology Platform. Developers and administrators use it to manage user lifecycles — including the creation, updating, and deactivation of user accounts — across connected systems such as SAP Cloud Identity Services and SAP BTP subaccounts. It works in conjunction with trust configurations, such as establishing trust of type OpenID Connect, to ensure that authenticated users are available and correctly provisioned in the target environment.
Tutorials that teach this
Docs explaining this concept
Prerequisites
- Concept Identity Provider Custom User Attributes The concept name was not provided (marked as "undefined"), and the supplied sources cover the **User API Service** and **Specify Attributes in a New Role** — neither of which can be confidently mapped to an unnamed concept. Based on the available sources, the closest supportable definition is: The [User API Service](https://help.sap.com/docs/btp/sap-business-technology-platform/b80abb01ef084bc098636348b1d618af?locale=en-US&state=PRODUCTION&version=Cloud) is an endpoint exposed by the application router that returns details of the users who are logged into an application. Developers use it to retrieve authenticated user information at runtime within SAP BTP applications. Administrators can complement user identity with [role attributes](https://help.sap.com/docs/btp/sap-business-technology-platform/ab089a9bb3c541e798dd4c9111417246?locale=en-US&state=PRODUCTION&version=Cloud) to control access based on user-specific properties defined in roles.
- Concept SAML Identity Provider Trust Configuration The provided sources do not contain enough grounded information to define a concept labeled "undefined." Based on the available sources, they collectively describe **SAML trust configuration** on SAP BTP — a mechanism that allows developers to establish federated trust between SAP BTP subaccounts and identity providers (such as [SAP Cloud Identity Services](https://help.sap.com/docs/btp/sap-business-technology-platform/7c6aa87459764b179aeccadccd4f91f3?locale=en-US&state=PRODUCTION&version=Cloud) or SAP SuccessFactors) using the SAML 2.0 protocol. Developers use it to enable single sign-on, map identity provider groups to platform roles, and configure OAuth 2.0 SAML Bearer Assertion grants for secure service-to-service communication. It can also be [restored after replacement](https://help.sap.com/docs/btp/sap-business-technology-platform/21d86cf36ce94da7b2f2db8271e0b539?locale=en-US&state=PRODUCTION&version=Cloud) to recover a previous trust setup in a subaccount.
- Concept Identity Authentication (IAS) Tenant Configuration The provided sources do not contain sufficient information to define a specific SAP developer concept — the concept name is listed as "undefined" and the source snippets consist primarily of tutorial titles and troubleshooting symptom headers without substantive explanatory content. A accurate, source-grounded definition cannot be produced from these materials.