Configure workload identity-based authentication for SAP SuccessFactors provisioning
| Chetan Desai |
Episode #306
Introduction
In episode 306 of our SAP on Azure video podcast we talk about workload identity based authentication.
A lot of companies have SAP SuccessFactors for their HR related processes. At the same time they are using Microsoft Entra ID for their Windows, Microsoft 365 and a lot of other authentications. For quite some time we have worked with SAP to use Microsoft Entra to orchestrate the identities for your employees and their access accross your SAP applications.
SAP plans to deprecated basic authentication for SAP SuccessFactors APIs, so we have been working to offer workload identity-based authentication for the Microsoft Entra <-> SAP SuccessFactors provisioning integrations. To tell us more about this new functionality, I am happy to have Chetan Desai back with us.
Find all the links mentioned here: https://www.saponazurepodcast.de/episode306
Reach out to us for any feedback / questions:
- Goran Condric: https://www.linkedin.com/in/gorancondric/
- Holger Bruchelt: https://www.linkedin.com/in/holger-bruchelt/
#Microsoft #SAP #Azure #SAPonAzure #SAPSuccessFactors #OIDC #SAPIAS
Summary created by AI
Chetan Desai explains how Microsoft Entra ID Governance is modernizing SAP SuccessFactors provisioning by replacing basic authentication with workload identity federation using OIDC and short-lived tokens.
Authentication Modernization (Basic Auth → Workload Identity)
SAP SuccessFactors APIs are moving away from basic authentication toward workload identity federation due to security improvements and SAP deprecation timeline. 5:13
Basic auth is replaced by short-lived OIDC/JWT-based tokens instead of static credentials. 5:55
Deprecation of basic authentication is planned by SAP for late 2027, driving migration urgency. 5:29
How the New Trust Model Works
Entra issues a short-lived JWT containing issuer, subject, and audience claims for the provisioning service. 7:10
SAP Cloud Identity Services (IAS) acts as the trust broker between Entra and SuccessFactors. 7:30
IAS exchanges the Entra token for a SuccessFactors access token used for API calls. 7:51
Trust relationships exist between Entra ↔ IAS and IAS ↔ SuccessFactors to enable secure delegation. 8:16
Configuration Steps (High-Level Flow)
Create an OIDC application in SAP Cloud Identity Services for Entra integration. 15:24
Add SuccessFactors as a dependent application within the IAS OIDC app configuration. 16:10
Register the OIDC client in SuccessFactors Admin Center and map it to a technical user. 16:44
Configure trust in IAS using issuer, audience, and metadata from Entra workload identity. 20:35
Complete setup by saving, activating, and validating via test connection and provisioning checks. 22:57
Validation & Operation
Test connection confirms correct configuration before activation. 22:51
Provision-on-demand verifies end-to-end user data synchronization from SuccessFactors to Entra. 25:57
A new service principal (“Sync Fabric workload identity”) is created automatically in Entra during setup. 27:08
Key Benefits Highlighted
Eliminates static credentials and manual secret rotation. 5:55
Provides secure, short-lived token-based authentication using industry standards (OIDC). 5:57
Enables “set-and-forget” integration after initial trust configuration. 6:06
- 0:00 Intro
- 1:12 Meet Chetan Desai
- 4:24 Why workload identity-based authentication
- 6:13 Moving away from static secrets
- 8:34 Trust between Microsoft Entra and SAP Cloud Identity Services
- 12:05 Switching from basic authentication to OIDC
- 14:42 Prerequisites and configuration flow
- 16:17 Setting up SAP Cloud Identity Services
- 22:58 Testing the connection
- 25:57 Provision on demand and what happens under the hood
