🔐

SAP Identity Authentication Service (IAS)

Jul 12, 2024

SAP Identity Authentication Service (IAS)

Introduction

  • Presenter: Anit
  • Focus: SAP IAS, a part of BTP security domain within Business Technology Platform.
  • Also mentioned: Other videos on various BTP services available on the channel.

Other BTP Services Covered in Videos

  • BTP Audit Log Management Service
  • Alert Notification Service
  • Transport Management Service
  • Continuous Integration & Delivery Service
  • BTP Application Logging Service
  • BTP DevOps
  • BTP Application Autoscaler Service
  • BTP Identity Provisioning Service (IPS)
  • BTP Cloud Identity Services
  • Identity Access Governance
  • BTP Connectivity Service
  • BTP Destination Service
  • BTP Build Work Zone

Main Topic: SAP Identity Authentication Service (IAS)

  • Definition: IAS is an identity provider by SAP, part of BTP.
  • Other Identity Providers:
    • Azure AD (by Microsoft)
    • Google Identity (by Google)
    • AWS IAM (by Amazon Web Services)
    • Okta, Ping Federate, SailPoint, etc.
  • Purpose: Store ID data (user/system details) for application authentication.
  • Functionality:
    • Authenticate users when they attempt to log in to applications.
    • Offers features like Single Sign-On, Multi-Factor Authentication, Federated authentication, concurrent access management, risk-based and conditional authentication, etc.

Key Use Cases

  1. Main Identity Provider
    • All user data is stored in IAS.
    • Directly authenticate users via IAS.
  2. Proxy Identity Provider
    • Uses an existing corporate identity provider (e.g., Azure AD) with IAS as a proxy.
    • Delegates authentication to corporate identity provider.
    • Reduces redundancy and supports seamless SAP application integration.

Cloud Identity Services

  • IAS and IPS have been merged into one system known as Cloud Identity Services.
  • Categories:
    • IAS Tabs
    • IPS Tabs
    • Monitoring common to both.
  • Capabilities:
    • Store Identity Data
    • Import/Export Users
    • Real-time Provisioning
    • Onboard Corporate Identity Providers (Okta, Ping Federate, Azure AD, Google Identity, AWS IAM, etc.)

Training and Courses Offered

  • BTP Administration
  • BTP Security (including Identity and Access Management)
  • BTP Build Process and Development
  • RAP Development
  • CAP Development
  • No Code/Low Code Application Development
  • BTP Extension Suite
  • BTP Identity and Access Governance
  • BTP DevOps
  • BTP AI
  • Other Cloud and On-premise Trainings