SAP BTP
Federation & Advanced Authentication
47 flashcards · answers and spaced-repetition review in the KnowCard app
A user hits an app for the first time after you enabled TOTP two-factor authentication for their group. What must they do on that first login, and how do you later confirm MFA is actually active on the account?
You run Identity Authentication as a proxy to Microsoft Entra ID and want two-factor authentication. Does the second factor have to be enforced inside Identity Authentication itself?
An admin wants 2FA enforced for one sensitive app but not for casual sign-ins to a low-risk app in the same tenant. Where in Identity Authentication does 2FA actually get configured, and what does that scoping imply?
In a risk-based authentication policy, when does the default action (Allow / Deny / Two-Factor Authentication) actually fire, and what does setting it to Deny mean for a login that matches no rule?
What are the three dot-separated parts of a JSON Web Token (JWT), and what does each hold?
When you federate Microsoft Entra ID into Identity Authentication via SAML, which system is the identity provider and which is the service provider — and what is the practical tell for getting the metadata exchange right?
A team proposes 'stronger 2FA' by adding a mandatory security question on top of the password. Why does this not count as two-factor authentication?
A conditional authentication rule decides which IdP a user is routed to BEFORE they type a password. Given that timing, what kinds of conditions can such a rule match on — and what can it NOT use?
In SAML, people often mix up identity provider and service provider. Which one authenticates the user, which one is the app being accessed, and what's the reliable way to tell them apart?
How does risk-based authentication differ from simply turning 2FA on for all users, and what does it use to make that distinction?
Of the second-factor methods you can enforce, which one does SAP advise AGAINST, what should you pick instead, and why is the convenient choice the weak one?
In the Cloud Foundry environment, which protocol connects Identity Authentication as the PLATFORM and application identity provider — and what's the exception that still allows SAML?
What are the four grant types defined by OAuth 2.0?
Two risk-based rules both match a given login. Which one is applied, and what does that imply about how you order a 'deny risky countries' rule against an 'allow internal IPs' rule?
After the IdP authenticates the user in a SAML flow, what does it send back, and what must the service provider do with it before granting access?
A developer says 'we'll use OAuth 2.0 to log users in.' Why is that framing wrong, and what does OAuth 2.0 actually grant?
In conditional authentication, what is the Default Authenticating Identity Provider, and what changes operationally if you point it at a corporate IdP instead of leaving it as IAS?
What distinguishes SP-initiated from IdP-initiated SSO in SAML, and which one matches a user who clicks a deep link straight into an application?
Which attack scenarios does 2FA defend against, and what's the common thread in how it stops each?
Why did SAP BTP's Neo environment rely exclusively on SAML 2.0 rather than OIDC — and why is that no longer the default in newer environments?
OAuth 2.0 and OpenID Connect look similar and are often conflated. What does each actually do, and what's the relationship between them?
What is the operational advantage of using Identity Authentication as a proxy to a third-party IdP instead of connecting that IdP to each subaccount directly, and what's the trade-off you accept?
Who maintains SAML, what is the current published version, and why does 'current' here look frozen compared with OAuth/OIDC?
Risk-based authentication assigns a risk to a login. Which signals does it actually use, and why are these specifically the ones available at decision time?
OIDC lets users authenticate via a third-party IdP. What is it built on, and what does that dependency mean if your environment can't support that underlying framework?
Microsoft Entra ID can be integrated into Identity Authentication using two protocols. Which two, and what should drive the choice between them?
Conditional authentication and risk-based authentication both branch on user attributes. What is conditional authentication specifically FOR, and how does its purpose differ from risk-based auth?
SAML 2.0 is frequently described loosely as a 'security protocol.' More precisely, what does it exchange and what is its primary corporate use — and what does it NOT do?
With conditional authentication active, the login screen asks only for email/username first and withholds the password field. Why is that ordering necessary?
What are the four roles defined by OAuth 2.0, and what does each do?
In the multicloud SAP BTP environment, name the places OIDC is used to connect Identity Authentication — including the level people most often forget.
To make Identity Authentication a SAML proxy in front of Microsoft Entra ID, metadata has to travel in both directions. Which direction carries which side's metadata, and where does each file get imported?
Which two-factor methods can a risk-based authentication rule in Identity Authentication enforce, and which commonly-assumed method is NOT among them?
A colleague says single sign-on 'just saves users from retyping passwords.' Beyond user convenience, what does SSO change for the administration team?
In service provider–initiated SAML SSO, two signed messages cross the wire. What are they, who signs each, and why does identity provider–initiated SSO have only one?
An app doesn't get an OAuth 2.0 access token by asking the authorization server directly. What intermediate step must happen first, and what is it called?
Given that OAuth 2.0 is an authorization framework, what are its typical real-world use cases — and why does 'social login' belong on that list?
Everyone says 'OIDC is OAuth 2.0 plus authentication.' Concretely, what three features does OIDC add on top of OAuth 2.0?
When you set up Identity Authentication as a proxy to a third-party IdP like Microsoft Entra ID, which two integration protocols can you choose between, and what access must you already hold before you start?
After configuring a corporate IdP as a proxy, some users hit an identity-provider selection screen at login while others don't. What causes this dialog, and how do you avoid it?
A user proxied through Microsoft Entra ID logs in successfully but then lands on an authorization error in the target app (e.g. Feature Flags Service). What actually happened, and what's the fix?
During OIDC proxy setup you add the email claim in Entra ID's Token Configuration, yet the email never arrives in the token Identity Authentication receives. What is an OIDC claim, and what step did the configuration miss?
After creating a new client secret in Entra ID for the OIDC proxy, a colleague copies the Secret ID into Identity Authentication and validation fails. Which field is actually the secret, and how do you complete the wiring on the IAS side?
Identity Authentication's 'subject name identifier' is described differently for SAML than for OIDC. What is the difference, and where do you set which attribute fills it?
When you register the Microsoft Entra ID application for an OIDC proxy to Identity Authentication, what exactly must the Redirect URI point to, and where do you then read off the client ID?
In the OIDC proxy's Identity Federation settings you pick among Use Identity Authentication User Store, Allow Identity Authentication Users Only, and Apply Application Configurations. What does each control, and which one actually pulls risk-based authentication into the flow?
SAP Single Sign-On (the on-premise, AS Java-based SSO product) is going out of maintenance. What is SAP's cloud-based successor for SSO to SAP GUI, and what does moving to it remove from your landscape?
Start learning today
Free to start — download the app or use it in your browser.
