You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
title: 'Tutorial: Azure Active Directory integration with SAP Fiori | Microsoft Docs'
2
+
title: 'Tutorial: Azure Active Directory single sign-on (SSO) integration with SAP Fiori | Microsoft Docs'
3
3
description: Learn how to configure single sign-on between Azure Active Directory and SAP Fiori.
4
4
services: active-directory
5
5
documentationCenter: na
6
6
author: jeevansd
7
-
manager: daveba
7
+
manager: mtillman
8
8
ms.reviewer: barbkess
9
9
10
10
ms.assetid: 77ad13bf-e56b-4063-97d0-c82a19da9d56
@@ -14,78 +14,65 @@ ms.workload: identity
14
14
ms.tgt_pltfrm: na
15
15
ms.devlang: na
16
16
ms.topic: tutorial
17
-
ms.date: 03/11/2019
17
+
ms.date: 09/05/2019
18
18
ms.author: jeedes
19
19
20
+
ms.collection: M365-identity-device-management
20
21
---
21
-
# Tutorial: Azure Active Directory integration with SAP Fiori
22
22
23
-
In this tutorial, you learn how to integrate SAP Fiori with Azure Active Directory (Azure AD).
23
+
# Tutorial: Azure Active Directory single sign-on (SSO) integration with SAP Fiori
24
24
25
-
Integrating SAP Fiori with Azure AD gives you the following benefits:
25
+
In this tutorial, you'll learn how to integrate SAP Fiori with Azure Active Directory (Azure AD). When you integrate SAP Fiori with Azure AD, you can:
26
26
27
-
*You can use Azure AD to control who has access to SAP Fiori.
28
-
*Users can be automatically signedin to SAP Fiori with their Azure AD accounts (single sign-on).
29
-
*You can manage your accounts in one central location, the Azure portal.
27
+
*Control in Azure AD who has access to SAP Fiori.
28
+
*Enable your users to be automatically signed-in to SAP Fiori with their Azure AD accounts.
29
+
*Manage your accounts in one central location - the Azure portal.
30
30
31
-
For more information about software as a service (SaaS) app integration with Azure AD, see [Single sign-on to applications in Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis).
31
+
To learn more about SaaS app integration with Azure AD, see [What is application access and single sign-on with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis).
32
32
33
33
## Prerequisites
34
34
35
-
To configure Azure AD integration with SAP Fiori, you need the following items:
35
+
To get started, you need the following items:
36
36
37
-
* An Azure AD subscription. If you don't have an Azure AD subscription, create a [free account](https://azure.microsoft.com/free/) before you begin.
38
-
* An SAP Fiori subscription with single sign-on enabled.
39
-
* SAP Fiori 7.20 or later is required.
37
+
* An Azure AD subscription. If you don't have a subscription, you can get a [free account](https://azure.microsoft.com/free/).
38
+
* SAP Fiori single sign-on (SSO) enabled subscription.
40
39
41
40
## Scenario description
42
41
43
-
In this tutorial, you configure and test Azure AD single sign-on in a test environment and integrate SAP Fiori with Azure AD.
42
+
In this tutorial, you configure and test Azure AD SSO in a test environment.
44
43
45
-
SAP Fiori supports the following features:
44
+
*SAP Fiori supports **SP** initiated SSO
46
45
47
-
***SP-initiated single sign-on**
46
+
> [!NOTE]
47
+
> For SAP Fiori initiated iFrame Authentication, we recommend using the **IsPassive** parameter in the SAML AuthnRequest for silent authentication. For more details of the **IsPassive** parameter refer to [Azure AD SAML single sign-on](https://docs.microsoft.com/azure/active-directory/develop/single-sign-on-saml-protocol) information
48
48
49
-
## Add SAP Fiori in the Azure portal
49
+
## Adding SAP Fiori from the gallery
50
50
51
-
To integrate SAP Fiori with Azure AD, you must add SAP Fiori to your list of managed SaaS apps.
51
+
To configure the integration of SAP Fiori into Azure AD, you need to add SAP Fiori from the gallery to your list of managed SaaS apps.
52
52
53
-
1. Sign in to the [Azure portal](https://portal.azure.com).
53
+
1. Sign in to the [Azure portal](https://portal.azure.com) using either a work or school account, or a personal Microsoft account.
54
+
1. On the left navigation pane, select the **Azure Active Directory** service.
55
+
1. Navigate to **Enterprise Applications** and then select **All Applications**.
56
+
1. To add new application, select **New application**.
57
+
1. In the **Add from the gallery** section, type **SAP Fiori** in the search box.
58
+
1. Select **SAP Fiori** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
54
59
55
-
1. In the left menu, select **Azure Active Directory**.
60
+
## Configure and test Azure AD single sign-on for SAP Fiori
56
61
57
-

62
+
Configure and test Azure AD SSO with SAP Fiori using a test user called **B.Simon**. For SSO to work, you need to establish a link relationship between an Azure AD user and the related user in SAP Fiori.
1.**[Configure Azure AD SSO](#configure-azure-ad-sso)** - to enable your users to use this feature.
67
+
1.**[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
68
+
1.**[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
69
+
1.**[Configure SAP Fiori SSO](#configure-sap-fiori-sso)** - to configure the single sign-on settings on application side.
70
+
1.**[Create SAP Fiori test user](#create-sap-fiori-test-user)** - to have a counterpart of B.Simon in SAP Fiori that is linked to the Azure AD representation of user.
71
+
1.**[Test SSO](#test-sso)** - to verify whether the configuration works.
62
72
63
-
1. To add an application, select **New application**.
73
+
## Configure Azure AD SSO
64
74
65
-

66
-
67
-
1. In the search box, enter **SAP Fiori**. In the search results, select **SAP Fiori**, and then select **Add**.
68
-
69
-

70
-
71
-
## Configure and test Azure AD single sign-on
72
-
73
-
In this section, you configure and test Azure AD single sign-on with SAP Fiori based on a test user named **Britta Simon**. For single sign-on to work, you must establish a linked relationship between an Azure AD user and the related user in SAP Fiori.
74
-
75
-
To configure and test Azure AD single sign-on with SAP Fiori, you must complete the following building blocks:
76
-
77
-
| Task | Description |
78
-
| --- | --- |
79
-
|**[Configure Azure AD single sign-on](#configure-azure-ad-single-sign-on)**| Enables your users to use this feature. |
80
-
|**[Configure SAP Fiori single sign-on](#configure-sap-fiori-single-sign-on)**| Configures the single sign-on settings in the application. |
81
-
|**[Create an Azure AD test user](#create-an-azure-ad-test-user)**| Tests Azure AD single sign-on for a user named Britta Simon. |
82
-
|**[Assign the Azure AD test user](#assign-the-azure-ad-test-user)**| Enables Britta Simon to use Azure AD single sign-on. |
83
-
|**[Create an SAP Fiori test user](#create-an-sap-fiori-test-user)**| Creates a counterpart of Britta Simon in SAP Fiori that is linked to the Azure AD representation of the user. |
84
-
|**[Test single sign-on](#test-single-sign-on)**| Verifies that the configuration works. |
85
-
86
-
### Configure Azure AD single sign-on
87
-
88
-
In this section, you configure Azure AD single sign-on with SAP Fiori in the Azure portal.
75
+
Follow these steps to enable Azure AD SSO in the Azure portal.
89
76
90
77
1. Open a new web browser window and sign in to your SAP Fiori company site as an administrator.
91
78
@@ -146,31 +133,23 @@ In this section, you configure Azure AD single sign-on with SAP Fiori in the Azu
146
133
147
134

148
135
149
-
1. In the [Azure portal](https://portal.azure.com/), in the **SAP Fiori** application integration pane, select **Single sign-on**.
150
-
151
-

152
-
153
-
1. In the **Select a single sign-on method** pane, select **SAML** or **SAML/WS-Fed** mode to enable single sign-on.
1. In the [Azure portal](https://portal.azure.com/), on the **SAP Fiori** application integration page, find the **Manage** section and select **single sign-on**.
137
+
1. On the **Select a single sign-on method** page, select **SAML**.
138
+
1. On the **Set up single sign-on with SAML** page, click the edit/pen icon for **Basic SAML Configuration** to edit the settings.
156
139
157
-
1. In the **Set up Single Sign-On with SAML** pane, select **Edit** (the pencil icon) to open the **Basic SAML Configuration** pane.

170
-
171
-
1. When the metadata file is successfully uploaded, the **Identifier** and **Reply URL** values are automatically populated in the **Basic SAML Configuration** pane. In the **Sign on URL** box, enter a URL that has the following pattern: https:\//\<your company instance of SAP Fiori\>.
172
-
173
-

152
+
c. When the metadata file is successfully uploaded, the **Identifier** and **Reply URL** values are automatically populated in the **Basic SAML Configuration** pane. In the **Sign on URL** box, enter a URL that has the following pattern: `https:\//\<your company instance of SAP Fiori\>`.
174
153
175
154
> [!NOTE]
176
155
> A few customers report errors related to incorrectly configured **Reply URL** values. If you see this error, you can use the following PowerShell script to set the correct Reply URL for your instance:
@@ -198,21 +177,46 @@ In this section, you configure Azure AD single sign-on with SAP Fiori in the Azu
198
177

199
178
200
179

180
+
181
+
1. On the **Set up single sign-on with SAML** page, in the **SAML Signing Certificate** section, find **Federation Metadata XML** and select **Download** to download the certificate and save it on your computer.
1.In the **Set up Single Sign-On with SAML**pane, in the **SAML Signing Certificate** section, select **Download** next to **Federation Metadata XML**. Select a download option based on your requirements. Save the certificate on your computer.
185
+
1.On the **Set up SAP Fiori**section, copy the appropriate URL(s) based on your requirement.
1. Select the **Show password** check box, and then write down the value that's displayed in the **Password** box.
199
+
1. Click **Create**.
200
+
201
+
### Assign the Azure AD test user
202
+
203
+
In this section, you'll enable B.Simon to use Azure single sign-on by granting access to SAP Fiori.
204
+
205
+
1. In the Azure portal, select **Enterprise Applications**, and then select **All applications**.
206
+
1. In the applications list, select **SAP Fiori**.
207
+
1. In the app's overview page, find the **Manage** section and select **Users and groups**.
214
208
215
-
### Configure SAP Fiori single sign-on
209
+

210
+
211
+
1. Select **Add user**, then select **Users and groups** in the **Add Assignment** dialog.
212
+
213
+

214
+
215
+
1. In the **Users and groups** dialog, select **B.Simon** from the Users list, then click the **Select** button at the bottom of the screen.
216
+
1. If you're expecting any role value in the SAML assertion, in the **Select Role** dialog, select the appropriate role for the user from the list and then click the **Select** button at the bottom of the screen.
217
+
1. In the **Add Assignment** dialog, click the **Assign** button.
218
+
219
+
## Configure SAP Fiori SSO
216
220
217
221
1. Sign in to the SAP system and go to transaction code **SAML2**. A new browser window opens with the SAML configuration page.
218
222
@@ -294,61 +298,11 @@ In this section, you configure Azure AD single sign-on with SAP Fiori in the Azu
294
298
295
299

296
300
297
-
### Create an Azure AD test user
298
-
299
-
In this section, you create a test user named Britta Simon in the Azure portal.
300
-
301
-
1. In the Azure portal, select **Azure Active Directory** > **Users** > **All users**.
302
-
303
-

304
-
305
-
1. Select **New user**.
306
-
307
-

308
-
309
-
1. In the **User** pane, complete the following steps:
310
-
311
-
1. In the **Name** box, enter **BrittaSimon**.
312
-
313
-
1. In the **User name** box, enter **brittasimon\@\<your-company-domain>.\<extension>**. For example, **brittasimon\@contoso.com**.
314
-
315
-
1. Select the **Show password** check box. Write down the value that's displayed in the **Password** box.
316
-
317
-
1. Select **Create**.
318
-
319
-

320
-
321
-
### Assign the Azure AD test user
322
-
323
-
In this section, you grant Britta Simon access to SAP Fiori so she can use Azure single sign-on.
324
-
325
-
1. In the Azure portal, select **Enterprise applications** > **All applications** > **SAP Fiori**.
1. In the **Users and groups** pane, select **Britta Simon** in the list of users. Choose **Select**.
342
-
343
-
1. If you are expecting a role value in the SAML assertion, in the **Select role** pane, select the relevant role for the user from the list. Choose **Select**.
344
-
345
-
1. In the **Add Assignment** pane, select **Assign**.
346
-
347
-
### Create an SAP Fiori test user
301
+
### Create SAP Fiori test user
348
302
349
303
In this section, you create a user named Britta Simon in SAP Fiori. Work with your in-house SAP team of experts or your organization SAP partner to add the user in the SAP Fiori platform.
350
304
351
-
###Test single sign-on
305
+
## Test SSO
352
306
353
307
1. After the identity provider Azure AD is activated in SAP Fiori, try to access one of the following URLs to test single sign-on (you shouldn't be prompted for a username and password):
354
308
@@ -364,10 +318,12 @@ In this section, you create a user named Britta Simon in SAP Fiori. Work with yo
364
318
365
319
1. If you are prompted for a username and password, enable trace to help diagnose the issue. Use the following URL for the trace: https:\//\<sapurl\>/sap/bc/webdynpro/sap/sec_diag_tool?sap-client=122&sap-language=EN#.
366
320
367
-
## Next steps
321
+
## Additional resources
322
+
323
+
-[ List of Tutorials on How to Integrate SaaS Apps with Azure Active Directory ](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
324
+
325
+
-[What is application access and single sign-on with Azure Active Directory? ](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis)
368
326
369
-
To learn more, review these articles:
327
+
-[What is conditional access in Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/conditional-access/overview)
370
328
371
-
-[List of tutorials for integrating SaaS apps with Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-saas-tutorial-list)
372
-
-[Single sign-on to applications in Azure Active Directory](https://docs.microsoft.com/azure/active-directory/active-directory-appssoaccess-whatis)
373
-
-[What is Conditional Access in Azure Active Directory?](https://docs.microsoft.com/azure/active-directory/conditional-access/overview)
329
+
-[Try SAP Fiori with Azure AD](https://aad.portal.azure.com/)
0 commit comments