SAP Single Sign On (SAP SSO) offering for customer

Pratap69 80 views 10 slides Feb 29, 2024
Slide 1
Slide 1 of 10
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10

About This Presentation

SAP Single Sign On offering


Slide Content

Sap SSO Solutions – An Offering 1

What do we offer in the SSO services Identify business case and drivers for SSO that help customer protect business, reputation and trust. SSO in general offers investment protection Compliance Flexibility Lower password related costs simplicity and agility. Roadmap and implementation services based on different flavors of SSO solution and SAP Single Sign-on 2.0 product. 2

Customer SSO roadmap and implementation Services 3 Identify the most critical systems. Which systems contain most sensitive business information? How many people have access to them? Define the overall single sign-on strategy and start with these critical business systems Design the SSO solution, Run a Pilot phase Understand the different modules of SAP Single Sign-On and analyze system landscape to determine which SSO standards can be used. Deploy the SSO Solution 1 Week 2-3 Weeks 1 Week

SSO Based on Kerberos (with and without SAP NW SS0 2.0) Relies on “Integrated Windows Authentication” Kerberos Security Token created by Microsoft Active Directory (AD) No additional server required, low TCO SAP backend needs to trust the AD Kerberos/SPNEGO SSO supported by AS ABAP, AS Java 4

SSO BASED on SAML (with and without SAP NW SS0 2.0) Relies on Security Assertion Markup Language (SAML) assertions as security token. Industry standard for cloud and cross-company scenarios. Assertions created by Identity Provider, running on AS Java ( or even other IDP providers) Authentication initiated by IdP or SP Multiple ways of user credential verification (SPNEGO, LDAP,ABAP, UME,..) 5

SSO BASED on X.509 Certificates (with and without SAP NW SS0 2.0) Relies on X.509 certificate, a very mature standard security token Support for SAP backend, but also for legacy systems, 3 rd party Web applications Multiple ways of user credential verification (SPNEGO, LDAP,ABAP, UME,...) 6

SSO based on SAP Single Sign-On 2.0 Solution ( SAML, Kerberos, X.509) Single Sign-On Authenticate once and subsequently access SAP and non-SAP applications in a secure and user- friendly way. From Anywhere From mobile devices, from outside the corporate network, etc. Security Improve security measures and meet company and regulatory requirements Low Cost Leverage the benefits of quick implementation and low cost of ownership Lean solution for single sign-on on mobile devices based on SAP Authenticator. Risk-based authentication based on context. 7

SSO for mobile APPS (with NW SSO 2.0) Extend SSO solution even further and offer end users “Mobile Single Sign-On” – a straightforward authentication mechanism to favorite applications and trusted websites on mobile devices. The benefits for your employees and your company: mobile users will have only one password to remember, less typing of complicated UserIDs /Passwords and more time for actual work ! Customer will have stronger security and more simplicity for all business processes enabled for mobile access! 8

Reference Designed and implemented a comprehensive SSO solution for Ericsson, based on SAML and OAUTH for Supply mobile application for access from internet. The architecture involved Siteminder, multiple layers of reverse proxies, external and internal Active Directories, SAP Gateway and ERP. 9

Reference Simplified the authentication process for over 50,000 Ericsson users accessing SAP Enterprise Portal. The SSO solution is based on Kerberos and SPNego implementation. A similar implementation was consulted for Britannia . 10