Skip to Content

Using the SCP NEO Console Client with SAP Identity Authentication/ADFS Platform IdP?

Hi,

We are using SAP Identity Authentication as our SCP SubAccount platform identity provider. That is then configured to use ADFS to our Active Directory user store. All of that works fine. We are using the NEO SCP platform.

My problem is... Since switching the platform identity provider on our SCP SubAccounts from accounts.sap.com to SAP Identity Authentication with ADFS I can no longer authenticate to the SubAccounts using the NEO Console Client. It will not accept either my SAP ID (which works fine if the platform IdP is accounts.sap.com) nor my AD ID (I guess it cannot do ADFS via the command line as that isn't really possible).

Does anyone know if there is a workaround for this? i.e. a way that I can still use the NEO Console Client, but with my SAP ID, although our platform IdP isn't accounts.sap.com? Or any other workaround?

I really need to continue to use the Console Client, but we also must keep our corporate ADFS as our platform IdP.

Thanks,

Brendan

Add comment
10|10000 characters needed characters exceeded

  • Get RSS Feed

1 Answer

  • Feb 19 at 01:19 PM

    Hi Brendan,

    How are your trying to login using the console client? What is the error message? Maybe you could post a screenshot of the error.

    When you configure the authentication to a different IdP, it may be required to add additional roles to AD users to be able to access all of the cockpit features as well as the console client. So you may need to add the role "Administrator" to your AD email account via "Members". Once this is done you should use the IDs from ADFS (which is supposed to be an email address) to login via console client.

    If this doesn't work at all and there is no fallback authentication, then I would suggest you to open an incident on SAP support system.

    Regards,
    Ivan

    Add comment
    10|10000 characters needed characters exceeded