This article describes how to configure SAP NetWeaver as an Service Provider for Cloud Access Service (CAS).
Configure CAS
Perform these steps to configure CAS as an IDP for SAP NetWeaver.
Procedure
- Sign in to RSA Cloud Administration Console, and navigate to Applications > Application Catalog.
- Click Create From Template and select SAML Direct.
- Choose Cloud on the Basic Information page.
- Enter the Name for the application, and click Next Step.
- On the Connection Profile page, navigate to Initiate SAML Workflow section and choose IdP-initiated.
- In the Data Import method section, enter the following values:
- ACS URL: https://SAP Netweaver domainname/sap/bc/gui/sap/its/webgui
- Service Provider Entity ID: The name must match the Issuer Entity ID as configured in the SAP NetWeaver.
- Navigate to the Identity Provider section. Make a note of the Identity Provider URL, as it will be needed for the SAP NETWEAVER configuration.
- In the Message Protection section, for SAML Response Protection:
- Choose IdP signs assertion with response.
- Scroll down to the User Identity section, and select the following information:
- Identifier Type > emailAddress
- Property > mail
- Click Next Step and select Allow All Authenticated Users
- From the dropdown list select the policy for this application.
- On the Portal Display page, select Display in Portal.
- Click Next step.
- Navigate to Fulfilment section, enter the following values:
- Click Publish Changes. After publishing, your application is now enabled for SSO.
The Configuration is complete.
SAP NetWeaver Configuration
Perform these steps to configure SAP NetWeaver Configuration.
Procedure
- Sign in to SAP NetWeaver with admin login, start the SAML 2.0 configuration application (transaction SAML2).
- Click Enable SAML 2.0 Support.
- Enter the Provider Name and click Next.
Note: The Provider Name must match the Audience (Service Provider Entity ID) as configured in the RSA ID Plus console.
- Set the Clock Skew Tolerance and click Next.
- Set the Identity Provider Discovery Selection Mode to Automatic, mark the checkbox for Assertion Consumer Service HTTP POST binding and click Finish.
Note: None of the other Assertion Consumer Service or Single Logout Service bindings are currently supported in RSA ID Plus.
- Open the Trusted Providers tab and click Add > Manually.
- Enter a Name for the new trusted identity provider and click Next.
Note: The Name must match the Issuer Entity ID as configured in the RSA ID Plus Console.
- In the Primary Signing Certificate section, click Browse and upload the Primary Signing Certificate.
- Click Next.
Note: The primary signing certificate must match the certificate uploaded to the RSA ID Plus console.
- Click Add to add a single sign-on endpoint.
- Select HTTP POST from the Binding dropdown menu, enter the Location URL and click OK.
Note: The Location URL must match the Identity Provider URL as configured in the RSA ID Plus Console.
- Click Next.
- Click Next.
- Click Next.
- Click Finish.
- Click Edit, then Add to add a NameID format.
- Choose a NameID format and click OK.
Note: The NameID format must match the Identifier Type as configured in User Identity section of the RSA ID Plus console.
- Click Save.
- Click Enable > OK.
The Configuration is complete.
Related Articles
Salesforce - SAML My Page SSO Configuration - RSA Ready Implementation Guide 66Number of Views Delinea - SAML My Page SSO Configuration - RSA Ready Implementation Guide 14Number of Views Microsoft Office 365 - SAML My Page SSO Configuration - RSA Ready Implementation Guide 121Number of Views Microsoft Entra ID - SAML My Page SSO Configuration - RSA Ready Implementation Guide 206Number of Views Citrix Cloud - SAML My Page SSO Configuration - RSA Ready Implementation Guide 21Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) Artifacts to gather in RSA Identity Governance & Lifecycle RSA Governance & Lifecycle 8.0.0 Administrators Guide RSA Governance & Lifecycle 8.0.0 Installation Guide