Skip to Content
avatar image
Former Member

SAPGUI SSO with AD authentication - different domains

Hello,

How can we achieve SSO for SAPGUI with AD authentication when SAP system resides in a separate domain and end users are logging in from a different domain? I have read that in order to accomplish this, we need to setup trust between the two domains. However if setting up trust is not an option (due to security/various reasons), then is there any other workaround/option to accomplish single sign-on for SAPGUI? Does SAP provide any product to accomplish to achieve this? Or is there a 3rd party product that can provide this feature? I am looking more along the lines where SAP system is hosted in a cloud and the SAPGUI users need to use SSO to login into the system but without setting up trust between the domains.

Any help will be greatly appreciated.

Thanks

Sid

Add comment
10|10000 characters needed characters exceeded

  • Get RSS Feed

2 Answers

  • Best Answer
    avatar image
    Former Member
    Oct 17, 2014 at 06:24 AM

    Hi Sid,

    There is no requierement to have your SAP systems in the same domain as you SAP GUI client domain to implement SAP SSO. You did not even need a trusted relation between both domains.

    Did you check the implementation videos?

    Single Sign-On with Kerberos

    KR

    Valerie

    Add comment
    10|10000 characters needed characters exceeded

    • Former Member Former Member

      Hi Sid,

      Like Christian mentions, the ABAP and your client workstations muss not be in the same domain.

      Now if you have many domains for client workstations you can either use a domain trust between the client workstation domains or configure SPN and keytabs for each domains without the trust.

      So for domain A you will need a service account Service-A, an SPN-A and a keytab-A created with the UPN or Service-A.

      For domain B you will need a service account Service-B, an SPN-B and a keytab-B created with the UPN or Service-B and so on.

      KR

      Valerie

  • Oct 17, 2014 at 06:43 AM

    Sid Q wrote:

    Or is there a 3rd party product that can provide this feature?

    Yes, there is a 3rd party product that can provide this feature.

    Thanks

    Tim

    Add comment
    10|10000 characters needed characters exceeded

    • Sid,

      Sorry, it is not possible to mention third party products on SCN forums.

      I'm sure you know, that you can click on somebodies business card to get contact details and details of who they work for. Then you can decide if you want to contact them or not.

      Take care,

      Tim