In the following example Cloud Access Manager is deployed using Active Directory as the user store, and the logon ID of NetWeaver internal users matches the sAMAccountName of Cloud Access Manager users.
To configure NetWeaver (Service Provider Role)
In the SAP NetWeaver admin interface, navigate to Configuration | Security | Authentication and Single Sign-On. Select the SAML 2.0 tab.
Under Identity Provider Discovery, switch Selection Mode to Automatic.
|
NOTE: This hides the NetWeaver home realm discovery interface. It is not needed here since Cloud Access Manager is the only configured identity provider. |
Click Add in the Relay State Mappings section and insert the following entry to facilitate IDP-initiated SSO later:
RelayState = portal
Path = /irj/portal
To configure Cloud Access Manager (Identity Provider Role (IDP))
Under Federation Settings, set Recipient value to:
https://<NetWeaver_server_fqdn>:<port>/saml2/sp/acs
Where <NetWeaver_server_fqdn> is the fully-qualified domain name of your SAP NetWeaver server, and <port> is the port number used by the NetWeaver server to listen on, for example https://srvnwce73.demo.sap.corp:50001/.
Set Audience / SP Identity to NetWeaver and click Next.
Choose whether to proxy the application. Select Proxy this application if you want to expose your NetWeaver application to users on the Internet. If you choose this option, then you must:
The following sections explain how to configure NetWeaver:
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center