cancel
Showing results for 
Search instead for 
Did you mean: 

SAP IAS - Password Synchronisation with Active Directory

RP_25
Product and Topic Expert
Product and Topic Expert
0 Kudos

Hello all,
Is it possible to sync passwords between IAS and Active Directory? 
I have a scenario under which users can authenticate using the SPNEGO mechanism: however, in case the kerberos token is not available, they should be able to log-in via Username and Password, using the same password that they use to authenticate via AD.

I was not able to find anything in the documentation that reflects a similar scenario.

Any hint?
Best,
Roberto.

Accepted Solutions (1)

Accepted Solutions (1)

MSo
Product and Topic Expert
Product and Topic Expert
0 Kudos

Hi Roberto,

IAS - rather IdDS, the Identity Directory Service - cannot export the user's password.
IdDS only keeps the psw hash but does not persist the user's psw.

Importing the user's password from another IdP or IDM system is possible via the SCIM API. 
See https://api.sap.com/api/IdDS_SCIM/resource/Users for details.

If users shall be authenticated with their password in AD you might have a look at the Corporate User Store scenario: https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/corporate-user-store 
With such a configuration AD can be leveraged as authenticating authority and thus psw synch will not be required.

Best, Marko - Product Management Identity Authentication Service

RP_25
Product and Topic Expert
Product and Topic Expert
0 Kudos
Thank you Marko, super useful! We’re going to give it a shot!

Answers (0)