User Management

This section describes how to configure user management for SAP Solution Sales Configuration, cloud edition.

Figure: Overview of User Management

There are mainly three parts for user management:

  1. Identity provider (IdP)

    SAP Cloud Platform supports SAML 2.0 identity providers, and you've the option to use SAP Cloud Platform Identity Authentication Service (SCI) or any SAML 2.0 identity provider. You must configure your own custom SAML 2.0 identity provider and establish trust between your SAP Cloud Platform subaccount and the identity provider. The <email> field in IdP is mandatory in SAP Solution Sales Configuration, cloud edition.

    The trust configuration consists of the following parts:

    Trust Configuration

    Configuration

    Procedure

    Configuring trust in a subaccount

    Establish Trust with an SAML 2.0 Identity Provider in a Subaccount

    Configuring trust in an SAML 2.0 identity provider

    Register SAP Cloud Platform Subaccount in the SAML 2.0 Identity Provider

    Trust and Federation with SAML 2.0 Identity Providers

  2. XSA UAA

    The User Account and Authentication (UAA) component provides a programming model for business applications. It is the central infrastructure component of the runtime platform for business user authentication and authorization management. The users are stored in identity providers.

  3. Security Programming Model of SAP Solution Sales Configuration, cloud edition.

    This is defined and provided by the application internally.