SAP Knowledge Base Article - Public

2656152 - Custom SAML User Mapping in SAP Analytics Cloud


  • You are configuring your SAP Analytics Cloud (SAC) as a Service Provider for your custom SAML Identity Provider (IdP)
  • You don't have any attribute that matches either USER ID or email for your accounts
  • Your user's emails or USER IDs have different lower/uppercase combinations in SAC than your IdP


  • SAP Analytics Cloud 2018


SAP Analytics Cloud is case sensitive and emails such as won't match a SAML assertion returning


You can use the option Custom SAML User Mapping when configuring your SAP Analytics Cloud with your IdP.

How does it work?

During configuration, you need to select as User Attribute Custom SAML User Mapping

You will need to type the Logon Credential. This is the value that is returned as a Claim by your Identity Provider


In this example, your SAML IdP will be returning the following claim:

<NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">ValueReturnedByIdP</NameID>

You can capture what is exactly returned by your Identity Provider using a Chrome extension as described in KBA 2487567

After saving the changes, SAP Analytics Cloud will convert the user accounts to your new SAML IdP. You will see a new column in Security > Users: SAML USER MAPPING


The value for the System Owner (the account of the user making the changes) will show the value you typed during the verification: ValueReturnedByIdP.

See Also

Your feedback is important to help us improve our knowledge base.
Please rate how useful you found this article by using the star rating feature at the beginning of this article.
Thank you.


saml, custom, mapping, uppercase, lowercase, match, user, credentials, SAC, SAP AC, Cloud-Analytics, CloudAnalytics, SAPCloudAnalytics , KBA , LOD-ANA , SAP Analytics Cloud , LOD-ANA-BI , SAP Analytics Cloud - Business Intelligence (BOC) , Problem


SAP Analytics Cloud 1.0