Implementing AD & Azure AD-based Authentication (part 2)

 

To read part 1 please click here


Azure Active Directory Integration with SAP Fiori

Benefits of integrating Azure AD with SAP Fiori:
  • You can use Azure AD to control who has access to SAP Fiori.
  • Users can be automatically signed in to SAP Fiori with their Azure AD accounts (single sign-on).
  • You can manage your accounts in one central location, the Azure portal. 

For the configuration of Azure AD with SAP Fiori, you will need the following items:

  • An Azure AD subscription.
  • A SAP Fiori subscription with single sign-on enabled.
  • SAP Fiori 7.20 or later is required.

Add SAP Fiori to Azure portal

Firstly, you have to add SAP Fiori from the SaaS application gallery to your list of managed SaaS apps, if you want to integrate Azure AD with SAP Fiori.

Configure Azure AD single sign-on

You have to perform the following tasks to configure Azure AD single sign-on with SAP Fiori:

  • Configure Azure AD single sign-on to enable your users to use this feature.
  • Configure SAP Fiori single sign-on.
  • Assign Azure AD users to the SAP Fiori application.
  • Create SAP Fiori users linked to their Azure AD user accounts.

Azure AD integration with SAP HANA

Following are the benefits offered by integrating Azure AD with SAP HANA:
  • You can control in Azure AD who has access to SAP HANA.
  • You can enable your users to be automatically signed-in to SAP HANA (Single Sign-On) with their Azure AD accounts.
  • You can manage your accounts in one central location - the Azure portal.

You will require following items if you want to configure Azure AD integration with SAP HANA:

  • An Azure AD subscription
  • A SAP HANA subscription that's single sign-on (SSO) enabled
  • A HANA instance that's running on any public IaaS, on-premises, Azure VM, or SAP large instances in Azure 
  • The XSA administration web interface, as well as HANA studio installed on the HANA instance.

It allows you to implement SAP HANA supports IDP initiated SSO and SAP HANA supports just-in-time user provisioning.

Azure AD integration with SAP NetWeaver

You enjoy following benefits after integrating Azure AD with SAP NetWeaver:
  • You can control in Azure AD who have access to SAP NetWeaver.
  • You can enable your users to be automatically signed-in to SAP NetWeaver (Single Sign-On) with their Azure AD accounts.
  • You can manage your accounts in one central location - the Azure portal.
The following items are required to configure Azure AD integration with SAP NetWeaver:
  • An Azure AD subscription 
  •  SAP NetWeaver single sign-on enabled subscription
  • SAP NetWeaver V7.20 required at least. 
SAP NetWeaver supports SP intiated SSO.

Active Directory integration with SAP Single Sign-On (Kerberos-SPNEGO)

To integrate SAP SSO with Active Directory:

  • Configure the SAP system- You have to use the configuration wizards (transactions SNCWIZARD and SPNEGO) starting with NetWeaver ABAP version 7.31 in your SAP system to configure SSO, while for the earlier versions, or if you don't have access to the configuration wizards, you have to configure SSO manually.

  • Configure user mapping:

  1. Sign in to your SAP instance via SAPGUI and run transaction SU01.
  2. Enter your SAP user (or the user that you want to map for SSO) in the name field and select Edit.
  3. Select the SNC tab and type the SNC name you configured in the previous task in the format p:CN=USERPRINCIPALNAME@DOMAIN

  • Install secure login software on client computers

  • Configure SAP GUI for SNC communication

  1. In the Secure Network Settings Interface, type the SNC Name in the format p:CN=ServicePrincipal-Name@domain
  2. Initiate a connection and you should be signed in without being prompted to enter a password.



To read part 1 please click here







Comments

Popular posts from this blog

Query, Visualize, & Monitor Data in Azure Sentinel

Planning for Implementing SAP Solutions on Azure (Part 2 of 5)

Work with String Data Using KQL Statements