User Management
This section describes how to configure user management for SAP Solution Sales Configuration, cloud edition.
Figure: Overview of User Management

There are mainly three parts for user management:
-
Identity provider (IdP)
SAP Cloud Platform supports SAML 2.0 identity providers, and you've the option to use SAP Cloud Platform Identity Authentication Service (SCI) or any SAML 2.0 identity provider. You must configure your own custom SAML 2.0 identity provider and establish trust between your SAP Cloud Platform subaccount and the identity provider. The <email> field in IdP is mandatory in SAP Solution Sales Configuration, cloud edition.
The trust configuration consists of the following parts:
Trust Configuration Configuration
Procedure
Configuring trust in a subaccount
Establish Trust with an SAML 2.0 Identity Provider in a Subaccount
Configuring trust in an SAML 2.0 identity provider
Register SAP Cloud Platform Subaccount in the SAML 2.0 Identity Provider
-
XSA UAA
The User Account and Authentication (UAA) component provides a programming model for business applications. It is the central infrastructure component of the runtime platform for business user authentication and authorization management. The users are stored in identity providers.
-
Security Programming Model of SAP Solution Sales Configuration, cloud edition.
This is defined and provided by the application internally.