Configure workload identity-based authentication for SAP SuccessFactors provisioning

Configure workload identity-based authentication for SAP SuccessFactors provisioning

| Chetan Desai |

SFSF EntraID


Episode #306

Introduction

In episode 306 of our SAP on Azure video podcast we talk about workload identity based authentication.

A lot of companies have SAP SuccessFactors for their HR related processes. At the same time they are using Microsoft Entra ID for their Windows, Microsoft 365 and a lot of other authentications. For quite some time we have worked with SAP to use Microsoft Entra to orchestrate the identities for your employees and their access accross your SAP applications.

SAP plans to deprecated basic authentication for SAP SuccessFactors APIs, so we have been working to offer workload identity-based authentication for the Microsoft Entra <-> SAP SuccessFactors provisioning integrations. To tell us more about this new functionality, I am happy to have Chetan Desai back with us.

Find all the links mentioned here: https://www.saponazurepodcast.de/episode306

Reach out to us for any feedback / questions:

#Microsoft #SAP #Azure #SAPonAzure #SAPSuccessFactors #OIDC #SAPIAS

Summary created by AI

  • Chetan Desai explains how Microsoft Entra ID Governance is modernizing SAP SuccessFactors provisioning by replacing basic authentication with workload identity federation using OIDC and short-lived tokens.

  • Authentication Modernization (Basic Auth → Workload Identity)

  • SAP SuccessFactors APIs are moving away from basic authentication toward workload identity federation due to security improvements and SAP deprecation timeline. 5:13

  • Basic auth is replaced by short-lived OIDC/JWT-based tokens instead of static credentials. 5:55

  • Deprecation of basic authentication is planned by SAP for late 2027, driving migration urgency. 5:29

  • How the New Trust Model Works

  • Entra issues a short-lived JWT containing issuer, subject, and audience claims for the provisioning service. 7:10

  • SAP Cloud Identity Services (IAS) acts as the trust broker between Entra and SuccessFactors. 7:30

  • IAS exchanges the Entra token for a SuccessFactors access token used for API calls. 7:51

  • Trust relationships exist between Entra ↔ IAS and IAS ↔ SuccessFactors to enable secure delegation. 8:16

  • Configuration Steps (High-Level Flow)

  • Create an OIDC application in SAP Cloud Identity Services for Entra integration. 15:24

  • Add SuccessFactors as a dependent application within the IAS OIDC app configuration. 16:10

  • Register the OIDC client in SuccessFactors Admin Center and map it to a technical user. 16:44

  • Configure trust in IAS using issuer, audience, and metadata from Entra workload identity. 20:35

  • Complete setup by saving, activating, and validating via test connection and provisioning checks. 22:57

  • Validation & Operation

  • Test connection confirms correct configuration before activation. 22:51

  • Provision-on-demand verifies end-to-end user data synchronization from SuccessFactors to Entra. 25:57

  • A new service principal (“Sync Fabric workload identity”) is created automatically in Entra during setup. 27:08

  • Key Benefits Highlighted

  • Eliminates static credentials and manual secret rotation. 5:55

  • Provides secure, short-lived token-based authentication using industry standards (OIDC). 5:57

  • Enables “set-and-forget” integration after initial trust configuration. 6:06