SAP Concur’s self-activated SSO is a self-service configuration that allows customers to fast-track the SSO onboarding process and provides:
- Easy and secure, long-term SSO management. As the designated SSO admin for your company, you can manage your own SSO configuration by using the Manage Single Sign-On page.
- Full SAML 2.0 (Security Assertion Markup Language) compliance. SAML SSO involves two parties: an IdP and an SP. SAP Concur is the SP.
Caution
The SAP Concur SSO service supports various IdPs such as: SAP IAS, Microsoft Azure AD, Okta, Ping Identity, OneLogin, JumpCloud, Idaptive, Google G Suite, ADFS, Shibboleth, VMWare Workspace One, Siteminder, and more. For a list of the supported IdPs, refer to the SSO Management Setup Guide
How Does the SSO service Work?
Note
The SSO self-service tool is used ONLY for the second part of the process - uploading your IdP metadata to SAP Concur.This part of the process is accomplished in the following high-level steps:
- As your company's SSO admin, access the Manage Single Sign-On page and then retrieve the SAP Concur SP metadata.
- Configure the SSO settings at the IdP based on information from the SP metadata.
- Retrieve IdP metadata from the IdP and upload it to the Manage Single Sign-On page.
- Add a few test users, test the new SSO connection, and then your company rolls out SSO to their SAP Concur users.
How to Obtain the Required Permissions?