Trust configuration between SAP Cloud Identity Services and SAP BTP
The provided sources do not contain enough information to define a specific, named SAP developer concept, as the concept supplied is "undefined." The sources relate to custom identity providers on SAP BTP, but without a concrete concept name or sufficient descriptive snippets, a grounded definition cannot be accurately composed.
Docs explaining this concept
Discovery missions teaching this
Prerequisites
- Concept SAP Identity Authentication Service (IAS) Integration The concept name is not defined in the provided sources, so a precise definition cannot be grounded solely in the available snippets. Based on the sources, an **Identity Provider (IdP) user** is a user account managed by an external identity provider — such as SAP Identity Authentication Service — that developers and business users use to authenticate and access SAP BTP services and environments, including the [ABAP Environment Administration Launchpad](https://help.sap.com/docs/btp/sap-business-technology-platform/11e765e8af6d476f99ce014b3f02bd64?locale=en-US&state=PRODUCTION&version=Cloud). Developers can be [assigned to identity provider user groups](https://help.sap.com/docs/btp/sap-business-technology-platform/198c2caaa5954a58b4667bbbe4165d08?locale=en-US&state=PRODUCTION&version=Cloud) to manage access and permissions within an SAP BTP subaccount. Trust between the SAP BTP subaccount and the identity provider must be established to enable scenarios such as single sign-on across connected systems.
- Concept SAP Cloud Identity Services Setup The concept provided is **undefined**, so no specific SAP developer concept has been identified to define. Based on the available sources, the closest coherent topic is **Trust and Federation with Identity Providers on SAP BTP** — a mechanism that allows developers and administrators to configure SAP Business Technology Platform (SAP BTP) subaccounts to delegate authentication to external identity providers (IdPs) using protocols such as SAML or OpenID Connect. Developers use it to enable single sign-on (SSO), manage user provisioning, and control access across SAP BTP accounts by establishing trust relationships with services such as [SAP Cloud Identity Services](https://help.sap.com/docs/btp/sap-business-technology-platform/cb1bc8f1bd5c482e891063960d7acd78?locale=en-US&state=PRODUCTION&version=Cloud). It also supports [migration from SAML-based trust to OpenID Connect trust](https://help.sap.com/docs/btp/sap-business-technology-platform/d097ce26cb2d4b8fa9a597a5381cb3cb?locale=en-US&state=PRODUCTION&version=Cloud) to align with modern authentication standards.
- Concept Identity Provider Configuration The concept name was not provided, and the supplied sources cover a range of SAP BTP Identity and Access Management topics — including backup configuration for SAP Authorization and Trust Management Service, trust setup, identity provider switching, role collection assignment, and auditing — without a single, clearly isolated concept to define. A precise, source-grounded definition cannot be produced without knowing which specific concept is intended.
- Concept SAP BTP Cockpit The concept name was not provided and the supplied source snippets do not define or describe a single, identifiable SAP developer concept — they cover a range of unrelated SAP BTP topics such as Kyma environment setup, Cloud Foundry org deletion, subaccount management, and service instances. A focused definition cannot be grounded solely in these sources without a clearly stated concept to define.
- Concept SAML/OIDC Federation The concept name was not provided (received "undefined"), and the available source snippet does not contain enough detail to ground a complete, accurate definition. A valid concept name and sufficient source material are required to produce a reliable reference definition.
- Concept SAP BTP Subaccount and Entitlement Setup The provided sources do not contain sufficient information to define this concept. The concept name is "undefined" and none of the source snippets supply grounded content that could be used to write an accurate, sourced definition.
- Concept Single Sign-On (SSO) and SAML Authentication The concept name is not defined in the provided sources, so a grounded definition cannot be written. Based on the available sources, which cover topics such as identity providers, trust and federation, single sign-on, and live data connections on SAP BTP, the specific concept intended here is unclear. Please provide a valid concept name so that an accurate, source-grounded definition can be produced.
- Concept BTP Destination Configuration for API Testing A **destination** in SAP Business Technology Platform (SAP BTP) is a configuration object that defines the connection parameters needed to enable communication between an application and a remote service or system. Developers create and manage destinations in the [SAP BTP cockpit](https://help.sap.com/docs/btp/sap-business-technology-platform/eb1d0a34b7c1411ba18401c07203020a?locale=en-US&state=PRODUCTION&version=Cloud) to connect to external resources such as on-premise systems, OData services, or other subaccounts. Destinations can be configured to support various authentication methods — such as SAML assertion authentication — and connectivity scenarios, including [on-premise connectivity via HTTP or RFC](https://help.sap.com/docs/btp/sap-business-technology-platform/9b6510edf4d844a28f022b3db41f3202?locale=en-US&state=PRODUCTION&version=Cloud).
- Concept Cloud Identity Services Integration SAP Document AI is a service that enables developers to extract structured data from business documents automatically. Developers use it to process documents such as invoices or receipts by subscribing to the service through SAP BTP Trial and accessing its capabilities via the [SAP Document AI Basic UI](https://developers.sap.com).
- Concept SAP Mobile Services Account Setup and Configuration No concept was provided, and the supplied sources do not converge on a single, identifiable SAP developer concept that can be defined. A meaningful definition cannot be written without a specified concept to define.
Concepts that build on this
- Concept Application Frontend Service Deployment for HTML5 Apps
- Concept SAP Build Work Zone configuration
- Concept Role Collection Mapping
- Concept Role Collection Assignment
- Concept OAuth2 SAML Bearer Assertion Authentication Setup
- Concept Role Collections and Access Management
- Concept SAP Cloud Identity Services – Authorization Management