Identity Authentication
Identity Authentication (IAS) is SAP BTP's cloud identity provider used to authenticate users, federate corporate identity providers, manage trust relationships with subaccounts and applications, and enforce authentication policies across SAP BTP services, Integration Suite, and SAP/non-SAP cloud applications. This topic covers its purpose, core configuration, trust and federation architecture, runtime authentication flow, and production troubleshooting.
Overview
Identity Authentication (IAS) is SAP BTP's cloud identity provider used to authenticate users, federate corporate identity providers, manage trust relationships with subaccounts and applications, and enforce authentication policies across SAP BTP services, Integration Suite, and SAP/non-SAP cloud applications. This topic covers its purpose, core configuration, trust and federation architecture, runtime authentication flow, and production troubleshooting.
Lessons in this topic
- What Identity Authentication Is and Why It Matters on BTPIntroduces SAP Cloud Identity Services - Identity Authentication (IAS), its role as the default identity provider for BTP subaccounts, and why centralized authentication matters for security and consultant work.
- Federating Corporate Identity Providers and Enforcing Conditional Authentication in IASLearn how to federate a corporate identity provider into SAP Cloud Identity Services and enforce conditional authentication policies such as risk-based access, group-based routing, and step-up multi-factor authentication for sensitive applications.
- Configuring Trust and Corporate IdP Federation with Identity AuthenticationWalks through establishing trust between a BTP subaccount and an Identity Authentication tenant, and federating IAS with a corporate identity provider using SAML/OIDC, including runtime login flow and verification steps.