SAP Knowledge Base Article - Public

2932099 - Some SAML users in SAP Analytics Cloud (SAC) do not have the correct SAML mapping

Symptom

The following behavior occurs in SAP Analytics Cloud (SAC):

  • Some users do not see their Groups mapped in SAC Teams
  • This causes log in and permissions or rights issues 

Environment

  • SAP Analytics Cloud (Enterprise) 2020.xxx
  • Custom IdP (Azure AD)

Cause

-Azure Active Directory limits the number of groups it will emit in a token to 150 for SAML assertions

-Under certain circumstances, even other custom IdP's have similar limitations

-There is a known physical limit of characters that can be received in the HTTP group headers

Resolution

This issue is currently under investigation by development.

- From the Azure side, you can use group Filtering to map only the most significant groups to SAC Teams and roles.

See Also

Your feedback is important to help us improve our knowledge base.

Keywords

SAP Cloud for Planning, sc4p, c4p, cforp, cloudforplanning, Cloud for Analytics, Cloud4Analytics, CloudforAnalytics, Cloud 4 Planning, BOC, SAPBusinessObjectsCloud, BusinessObjectsCloud, BOBJcloud, BOCloud., SAC, SAP AC, Cloud-Analytics, CloudAnalytics, SAPCloudAnalytics,Error, Issue, System, Data, User, Unable, Access, Connection, Sac, Connector, Live, Acquisition, Up, Set, setup, Model, BW, Connect, Story, Tenant, Import, Failed, Using, Working, SAML, SSO, sapanalyticscloud, sap analytical cloud, sap analytical cloud, SAC , KBA , LOD-ANA-DES , Model, Story Design & Visualizations , Problem

Product

SAP Analytics Cloud 1.0