SAP Fiori · Authentication & Single Sign-On

Two near-twins for Fiori SSO: SAML 2.0 and Kerberos. For Internet-facing access, which do you choose and what single network requirement decides it?

Answer locked. Get the free KnowCard app to reveal it — plus spaced-repetition review so it actually sticks.

Get it on App StoreGet it on Google Play

This is one card from the KnowCard library — thousands more across SAP, Linux, Python and more. In the app you get the answer, AI explanations, and cards that come back right before you would forget them. Free to start on iOS, Android or the web.

More in Authentication & Single Sign-On

You want an SSO mechanism that needs no issuing system reachable at logon time (e.g. for Internet-facing or occasionally-disconnected devices). Why is X.509 a fit, and what is the catch that disqualifies it for greenfield landscapes?
A landscape has users in several domains and you must map them to SAP users without a one-to-one account match. Which SSO mechanism is built for this, and what specifically lets it bridge the domains?
On the intranet, Kerberos/SPNEGO gives the smoothest Fiori SSO experience. What is the trade-off that decides whether it's actually feasible for your project?
After a user authenticates once on the ABAP front-end server, why don't subsequent Fiori requests re-authenticate from scratch — and what's still NOT skipped?
You've set up the ABAP front-end server to issue SAP logon tickets but HANA-served apps still reject SSO. What configuration step on the acceptor side was missed?
Why must you NOT choose Kerberos/SPNEGO as the SSO mechanism for users who connect from outside the corporate network, and what is the only workaround?

Start learning today

Free to start — download the app or use it in your browser.

Get it on App StoreGet it on Google Play