Microsoft Entra Workload ID
Authentication

Configure workload identity-based authentication for SAP SuccessFactors provisioning

In brief

The guide removes the Preview label and documents that workload identities are reusable only when their Application API host matches the provisioning app’s SAP SuccessFactors API host. It also adds the Application ID URI format and compatibility details for the September 15, 2026 update.

What Entra admins need to know

Ensure the workload identity and provisioning app use the same SAP SuccessFactors API host; otherwise the identity cannot be selected.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure workload identity-based authentication for SAP SuccessFactors provisioning (Preview)

This article is for administrators who configure Microsoft Entra provisioning integrations with SAP SuccessFactors. It explains how to replace the provisioning service's long-lived basic authentication credential with short-lived OpenID Connect (OIDC) tokens issued by your Microsoft Entra tenant. SAP Cloud Identity Services (SAP IAS) validates these tokens and exchanges them for access tokens used to call SAP SuccessFactors APIs. Before you begin, make sure you have a configured SAP SuccessFactors provisioning app and access to Microsoft Entra, SAP IAS, and SAP SuccessFactors administration.

Workload identity-based authentication provides a more secure authentication model in preparation for SAP's plan to deprecate basic authentication for SuccessFactors APIs.

This article applies to the following provisioning integrations: - Register to let the guided experience create a fresh workload identity app registration. You can optionally rename the default App registration name. - Select existing if you already configured a workload identity application that talks to SAP Cloud Identity Services (for example, if you have multiple SAP SuccessFactors provisioning apps and you want to reuse an existing workload identity app). :::image type="content" source="./media/configure-workload-identity-sap-successfactors-provisioning/select-or-register-workload-identity-app.png" alt-text="Screenshot showing the register and select options." lightbox="./media/configure-workload-identity-sap-successfactors-provisioning/select-or-register-workload-identity-app.png":::

  1. When you select Register, the guided experience creates the workload identity app registration in your tenant.
  1. When you select Register, the guided experience creates the workload identity app registration in your tenant.
  1. After you select the workload identity application, Microsoft Entra displays the values that SAP Cloud Identity Services needs to trust tokens issued by your tenant. Keep this panel open and switch to the SAP Cloud Identity Services admin console.
Symptom Likely cause Action
An existing workload identity is unavailable or displays This app is configured for a different Application API host and cannot be selected The workload identity uses a different SAP SuccessFactors Application API host. If the hosts match, the provisioning enterprise app might have been created before September 15, 2026, and the workload identity after that date. Workload identities are forward compatible, not backward compatible, across this implementation update. Compare the Application API URL configured for both apps. If the hosts match, use a workload identity that's available to the provisioning app. If no compatible workload identity is available, register a new workload identity for the app.
invalid_client_assertion from SAP IAS AT1 subject or audience doesn't match the SAP IAS Trust-by-Issuer rule. Compare the Subject and Audience values provided by Microsoft Entra with the corresponding values in the SAP IAS trust rule.
unauthorized_client from SAP IAS JWKS URI is unreachable or signature validation failed. Confirm the Microsoft Entra OIDC discovery endpoint is reachable from SAP IAS and that the tenant ID in the issuer claim matches.
OData call returns 403 SAP IAS client ID is not mapped to the right API User ID, or the API user lacks appropriate role-based permissions. Re-verify the OIDC OAuth client mapping in SAP SuccessFactors and the permission group on the API user.
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…