SAP Fiori · Authentication & Single Sign-On

In the service-provider-initiated SAML flow, the SAP Gateway never checks the user's password yet grants a session. On what basis does it decide to trust that user?

Answer locked. Get the free KnowCard app to reveal it — plus spaced-repetition review so it actually sticks.

Get it on App StoreGet it on Google Play

This is one card from the KnowCard library — thousands more across SAP, Linux, Python and more. In the app you get the answer, AI explanations, and cards that come back right before you would forget them. Free to start on iOS, Android or the web.

More in Authentication & Single Sign-On

You want an SSO mechanism that needs no issuing system reachable at logon time (e.g. for Internet-facing or occasionally-disconnected devices). Why is X.509 a fit, and what is the catch that disqualifies it for greenfield landscapes?
A landscape has users in several domains and you must map them to SAP users without a one-to-one account match. Which SSO mechanism is built for this, and what specifically lets it bridge the domains?
On the intranet, Kerberos/SPNEGO gives the smoothest Fiori SSO experience. What is the trade-off that decides whether it's actually feasible for your project?
Two near-twins for Fiori SSO: SAML 2.0 and Kerberos. For Internet-facing access, which do you choose and what single network requirement decides it?
After a user authenticates once on the ABAP front-end server, why don't subsequent Fiori requests re-authenticate from scratch — and what's still NOT skipped?
You've set up the ABAP front-end server to issue SAP logon tickets but HANA-served apps still reject SSO. What configuration step on the acceptor side was missed?

Start learning today

Free to start — download the app or use it in your browser.

Get it on App StoreGet it on Google Play