SAP Concur - SAML Relying Party Configuration - RSA Ready Implementation Guide
2 years ago
This article describes how to integrate RSA SecurID Access with SAP Concur using SAML Relying Party.

Configure the RSA Cloud Authentication Service

Perform these steps to configure the RSA Cloud Authentication Service as a Relying Party to SAP Concur.

Procedure
  1. Sign in to the RSA Cloud Administration Console with Administrator credentials.
  2. Click Authentication Clients > Relying Parties on the menu at the top of the screen.image.png
  3. Click Add a Relying Party.  
  4. In the Relying Party Catalog, click Add corresponding to Service Provider SAMLimage.png
  5. On the Basic Information page, enter the name for the application in the Name field and click Next Step.image.png
  6. On the Authentication page, choose SecurID manages all authentication.
  7. Select a Primary Authentication Method and Access Policy as required and click Next Step.image.png
  8. To provide the Service Provider details, select Import Metadata and click Choose File.
  9. Select the file downloaded from the service provider.
    Refer to the SAP Concur configuration section below for instructions on how to download the metadata file.image.png
  10. In the Service Provider section, the values for ACS URL and Service Provider Entity ID should be automatically filled.image.png
  11. In the SAML Response Protection section, choose IdP signs entire SAML response.
  12. Click Download Certificate to download the certificate.image.png
  13. Click Show Advanced Configuration and configure Identifier Type and Property under the User Identity section as "Auto Detect" as shown in the following screenshot.image.png
  14. Click Save and Finish.
  15. Go to the My Relying Parties page and choose Metadata from the Edit dropdown menu to download the metadata.
  16. Click Publish Changes. After publishing, your application is now enabled for SSO.image.pngimage.png

Configure SAP Concur

Perform these steps to configure SAP Concur.

Procedure
  1. Log in to SAP Concur with administrator credentials.
  2. Navigate to Home > Expense Settings.image.png
  3. Navigate to Company > Authentication Admin.image.png
  4. Click Manage Single Sign-On.image.png
  5. Click Download to download SAP Concur metadata.image.png
  6. On the IdP metadata section, click Addimage.png
  7. Provide the Custom IdP Name and click Upload XML File to upload the metadata file downloaded from RSA.
  8. Click Add Metadata.image.png

The configuration is complete.
Return to SAP Concur - RSA Ready Implementation Guide.