SAP BTP · Federation & Advanced Authentication

Given that OAuth 2.0 is an authorization framework, what are its typical real-world use cases — and why does 'social login' belong on that list?

Answer locked. Get the free KnowCard app to reveal it — plus spaced-repetition review so it actually sticks.

Get it on App StoreGet it on Google Play

This is one card from the KnowCard library — thousands more across SAP, Linux, Python and more. In the app you get the answer, AI explanations, and cards that come back right before you would forget them. Free to start on iOS, Android or the web.

More in Federation & Advanced Authentication

A user hits an app for the first time after you enabled TOTP two-factor authentication for their group. What must they do on that first login, and how do you later confirm MFA is actually active on the account?
You run Identity Authentication as a proxy to Microsoft Entra ID and want two-factor authentication. Does the second factor have to be enforced inside Identity Authentication itself?
An admin wants 2FA enforced for one sensitive app but not for casual sign-ins to a low-risk app in the same tenant. Where in Identity Authentication does 2FA actually get configured, and what does that scoping imply?
In a risk-based authentication policy, when does the default action (Allow / Deny / Two-Factor Authentication) actually fire, and what does setting it to Deny mean for a login that matches no rule?
What are the three dot-separated parts of a JSON Web Token (JWT), and what does each hold?
When you federate Microsoft Entra ID into Identity Authentication via SAML, which system is the identity provider and which is the service provider — and what is the practical tell for getting the metadata exchange right?

Start learning today

Free to start — download the app or use it in your browser.

Get it on App StoreGet it on Google Play