SAP Cloud Identity Services
SAP Cloud Identity Services — comprising Identity Authentication (IAS), Identity Provisioning (IPS), and the Identity Directory (IdDS) — form the mandatory identity foundation for every SAP cloud landscape. We design, configure, and harden IAS/IPS implementations that integrate cleanly with your corporate IdP, automate user lifecycle management, and enforce consistent security policy across all SAP applications.
Architecture
The Three Components of SAP Cloud Identity Services
SAP Cloud Identity Services is not a single product — it is a suite of three tightly integrated services, each with a distinct responsibility in the identity architecture.
- Central SSO hub for all SAP cloud applications
- Federates with corporate IdPs (SAML / OIDC proxy)
- Terminates auth flows and issues new application tokens
- Enforces MFA, conditional access, and login policies
- Pre-configured trust with all SAP SaaS applications
- Stores user identities, groups, and role assignments
- Merges corporate IdP attributes into IAS-issued tokens
- Enables cross-application identity correlation (Task Center, Joule)
- Required when “Use Identity Authentication user store” is enabled
- Source of truth for user attributes in hybrid scenarios
- Automates user and group sync across connected systems
- 200+ pre-built source and target connectors
- Attribute transformation and filtering via proxy rules
- Handles provisioning, deprovisioning, and updates
- Supports real-time and scheduled job execution
Trust Architecture
SAP Cloud Identity Services sits between your corporate identity provider and every SAP application in your landscape — each application trusts only IAS, while IAS handles federation with your existing enterprise IdP (Entra ID, Okta, Ping, ADFS, or any SAML/OIDC provider).
Every SAP SaaS application ships with a pre-configured trust to IAS — reducing SSO setup from days to hours. A single IAS configuration change (e.g. adding an MFA policy) propagates to every connected application instantly. New BTP trust configurations use OIDC (SAP Note 3521979 documents SAML’s deprecation for user-interactive BTP authentication) — we reference SAP’s standard federation and token-issuance mechanism here rather than reproducing it.
Authentication Flow
IAS supports both application-initiated and IAS-initiated SSO, and separately brokers SAP GUI sign-on via short-lived X.509 certificates issued through SAP Secure Login Service. In every case, IAS terminates the inbound flow from the corporate IdP and issues a fresh, application-specific token enriched with IdDS attributes — the standard SAP authentication-broker pattern, not a CNBS-specific mechanism.
Identity Directory (IdDS) — Central User Store
The Identity Directory is the persistent user store that powers cross-application identity correlation in modern SAP SaaS scenarios. Without users in IdDS, features like SAP Task Center (cross-application task aggregation) and Joule (SAP’s AI assistant) cannot function — they require a stable, cross-application user identity.
User Provisioning with IPS
SAP Identity Provisioning automates the full user lifecycle — provisioning, attribute updates, and deprovisioning — across connected SAP and non-SAP systems via SCIM 2.0. We configure the source-to-target flows (Entra ID, SuccessFactors, on-premise HR systems, Active Directory) and transformation rules for your landscape; every provisioning run is logged in the IPS audit journal with user-level granularity.
What We Deliver
IAS Tenant Configuration & Trust Setup
IAS tenant activation, custom domain configuration, and certificate setup. Application registration for every SAP cloud product in your landscape. Trust configuration with your corporate IdP (Entra ID, Okta, Ping, ADFS) via SAML 2.0 or OIDC. OIDC trust between IAS and SAP BTP (aligned to SAP Note 3521979).
Corporate IdP Proxy Architecture
IAS configured as a SAML/OIDC proxy in front of your existing corporate identity provider. Conditional forwarding rules per application — some apps authenticate directly via IAS, others proxy through Entra ID or Okta. Token enrichment configuration to merge IdDS attributes into the outgoing assertion.
IPS Provisioning Flows
Source-to-target provisioning job design, SCIM connector configuration, and attribute transformation rule authoring. User and group synchronisation from your HR system or corporate directory into IdDS, BTP, S/4HANA, and SuccessFactors. Deprovisioning automation aligned to your joiner-mover-leaver process.
MFA, Risk-Based Auth & Login Policies
Multi-factor authentication configuration — TOTP authenticator apps, email OTP, FIDO2/WebAuthn (passkeys), and SMS. Risk-based authentication policies that escalate to MFA based on IP range, location, or user risk score. Application-specific login policies: password rules, session timeouts, self-registration controls.
IdDS User Store & Cross-App Readiness
IdDS population strategy, group hierarchy design, and attribute schema extension for application-specific requirements. “Use Identity Authentication user store” enablement and validation. Cross-application user correlation setup for SAP Task Center and Joule — including the IPS job chain that keeps IdDS in sync with the authoritative HR source.
Audit, Monitoring & Security Hardening
IAS audit log activation and export to your SIEM. Login attempt monitoring, failed authentication alerting, and suspicious activity detection. Security hardening: token expiry tuning, CORS policy, allowed redirect URIs lockdown, and administrator access governance. Compliance alignment for GDPR and ISO 27001.
How Customers Benefit
How We Work
Identity Landscape Assessment
We audit your current identity setup: existing corporate IdPs, connected SAP systems, user stores, provisioning gaps, MFA coverage, and compliance requirements. Output: an identity architecture gap report with risk-ranked findings and a recommended target topology.
Architecture Design
Trust topology design (direct trust vs proxy), protocol selection (SAML / OIDC per application), IdDS population strategy, IPS source-to-target provisioning model, attribute mapping design, MFA policy framework, and group-to-role assignment model — all documented before any configuration begins.
IAS & IdDS Foundation
IAS tenant setup, custom domain and certificate configuration, corporate IdP federation (SAML/OIDC), application registrations for all SAP products, login policy baseline, and IdDS group hierarchy. OIDC trust with SAP BTP configured per SAP Note 3521979.
IPS Provisioning Implementation
Source and target connector setup, provisioning job design, attribute transformation rule authoring (JSONata), group membership sync, and deprovisioning flow validation. End-to-end testing of the full joiner-mover-leaver lifecycle across all target systems.
MFA, Hardening & Compliance
MFA method rollout (TOTP, FIDO2, email OTP), risk-based authentication policy tuning, audit log activation and SIEM export, token security hardening, and compliance documentation for GDPR and ISO 27001 evidence packages.
Governance & Knowledge Transfer
Operational runbooks for IAS administration, IPS job monitoring, and incident response for authentication failures. Live workshops with your IAM and security teams, architecture documentation, and a validated testing checklist for future application onboarding.
Ready to secure your SAP landscape?
Let’s build your identity foundation.
Tell us about your current identity setup, SAP cloud footprint, and compliance requirements — we’ll design a secure, scalable IAS/IPS architecture that works for your entire enterprise.
Get in touch →