Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Single Sign-On – SAP Cloud Identity Services and Microsoft Entra (previously Azure AD)

Focus mode
Single Sign-On – SAP Cloud Identity Services and Microsoft Entra (previously Azure AD) - General SAP Guides

Microsoft Entra (previously Azure AD) or other IdPs can be integrated to SAP Cloud Identity Services directly. This support a direct authentication, when you do not need AWS IAM Identity Center (i.e. no requirement to run a multi account strategy that utilizes AWS Organizations).

SAP Cloud Identity Services with Microsoft Entra

Authentication flow

  1. User accesses SAP Fiori via an Internet browser.

  2. SAP Fiori will redirect SAML request back to the internet browser.

  3. Internet Browser relays the SAML request to SAP Cloud Identity Services.

  4. SAP Cloud Identity Service delegate authentication request to IdPs.

  5. User is authenticated by IdP and SAML response is provided to the internet browser with user identity information.

  6. User can access to SAP S/4HANA in RISE with SAP VPC.

For more information on how to do this, you can refer to Enable SSO between Azure AD and SAP Cloud Platform using Identity Authentication Service.

PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.