QuestionQ304

Design and implement an infrastructure to support SAP workloads on Azure

You have an Azure Active Directory (Azure AD) tenant and an SAP Cloud Platform Identity Authentication Service tenant.

You need to ensure that users can use their Azure AD credentials to authenticate to SAP applications and services that trust the SAP Cloud Platform Identity Authentication Service tenant.

In which order should you perform the actions?

Drag & Drop
Download the SAP Cloud Platform Identity Authentication Service tenant metadata
Download the single sign-on (SSO) metadata from the Azure AD tenant
Create and configure an enterprise application in the Azure AD tenant
Create and configure a corporate identity provider in the SAP Cloud Platform Identity Authentication Service tenant
Upload the SAP Cloud Platform Identity Authentication Service tenant metadata to Azure AD tenant
Explanation

Azure AD must first have an enterprise application so that it can generate SAML SSO metadata. IAS then uses that Azure AD metadata when configuring Azure AD as a corporate identity provider. IAS metadata is subsequently downloaded and uploaded to the Azure AD enterprise application so Azure AD has the IAS service-provider configuration needed for the SAML trust.

Community Discussion

No comments yet. Be the first to start the discussion!