Subject: SAP-Single-Sign-On
Category: SAP UX & Security
The SAP Fiori Launchpad is the central access point for users working with SAP S/4HANA. It provides a role-based, personalized user experience for accessing applications across the SAP landscape. To enhance usability and strengthen security, integrating Single Sign-On (SSO) with Fiori Launchpad is a best practice that enables seamless and secure access.
This article explores how to implement SAP SSO for the Fiori Launchpad in an SAP S/4HANA environment, including key configuration steps, supported authentication methods, and practical tips for success.
Implementing SSO for the Fiori Launchpad offers several advantages:
Fiori Launchpad (FLP) supports multiple authentication options for SSO:
| Method | Description | Typical Use Case |
|---|---|---|
| SAML 2.0 | Browser-based federated authentication | Cloud or hybrid IdPs (e.g., Azure AD) |
| Kerberos/SPNEGO | Windows-integrated authentication | On-premise Active Directory setups |
| X.509 Certificates | Certificate-based login using Secure Login Client | High-security environments |
| SAP Logon Tickets | Traditional NetWeaver-based SSO | Legacy SAP systems |
Among these, SAML 2.0 is the most popular method for web-based Fiori Launchpad deployments, especially in hybrid and cloud-ready setups.
To enable SSO for Fiori Launchpad, the following components are typically involved:
Enable SAML 2.0 in SAP:
SAML2Set Assertion Consumer Service (ACS) URL:
https://<hostname>/sap/saml2/sp/acsMap User Attributes:
NameID) matching SAP usernames (e.g., User ID or Email)Trust Configuration:
Ensure the following Internet Communication Framework (ICF) services are active:
/sap/bc/ui5_ui5/ (UI5 runtime)/sap/bc/ui2/flp (Fiori Launchpad)/sap/public/bc/icf/logoff (for logout handling)Use transaction SICF to check and activate these services.
Use transaction SICF to set logon procedures for relevant services to “SAML Logon” or “SPNEGO” based on the SSO method used.
https://<hostname>/sap/bc/ui2/flp)To enable HTTPS access and support reverse proxy functionality, you can place SAP Web Dispatcher in front of your S/4HANA system:
| Issue | Possible Cause | Solution |
|---|---|---|
| SAML error during login | Incorrect SP configuration or metadata | Re-import metadata, verify URLs |
| User not found in SAP | Attribute mismatch (e.g., NameID) | Adjust SAML attribute mapping |
| Infinite login loop | Cookie issues or misconfigured trust | Check Web Dispatcher settings |
| Logout does not work | ICF logoff service not configured | Enable /sap/public/bc/icf/logoff |
Integrating SAP SSO with the Fiori Launchpad in S/4HANA environments significantly improves user experience and enhances enterprise security. Whether using SAML 2.0 for federated cloud access or SPNEGO for internal users, SSO simplifies authentication and supports modern access governance.
By carefully planning the SSO setup and aligning it with corporate identity strategies, organizations can deliver a secure, scalable, and user-friendly SAP Fiori environment for their workforce.