Single Sign-On in SAP – now in the cloud | All for One Poland

Single Sign-On in SAP – now in the cloud

SAP Secure Login Service for SAP GUI

The process of logging into ABAP-based systems in SAP GUI using Single Sign-On (SSO) has been in use for a long time. With the introduction of Secure Login Service, SAP is taking out one old element, which was a standalone application running on the customer's infrastructure, and replacing it with a small but very convenient cloud application that streamlines the whole process, but also opens it up to new possibilities.

The process of logging into ABAP-based systems in SAP GUI using Single Sign-On (SSO) has been in use for a long time. With the introduction of Secure Login Service, SAP is taking out one old element, which was a standalone application running on the customer's infrastructure, and replacing it with a small but very convenient cloud application that streamlines the whole process, but also opens it up to new possibilities.

SAP already offered the option to add an Identity Provider in the form of an enterprise or social platform, but this only applied to applications that could be connected to Cloud Identity Services, which is primarily SAP’s cloud solutions.

Users of ABAP-based on-premise systems using SAP GUI were forced to use separate software running on one of their servers to process authentication requests for users each time. SAP Secure Login Service avoids the need to install such software and takes on all the work of managing logins through SSO.

Operation of the service

The service itself as an application is not heavily developed, as it does most of the work as an intermediary processing login requests. The application in the administration console gives us its address data and allows us to set how long a user can work on a single login (1-24 hours).

Armed with this data, we can configure the client on the user’s workstation, just like a traditional SSO. Communication between the various components of this puzzle is done using X.509 certificates, but there is also the possibility of using a Kerberos token.

The SLS application is added to Cloud Identity Services (CIS), which allows us to define an identity provider for it in the same way as for any other, even the latest SAP cloud application, such as S/4HANA Cloud.

Authenticating to the Secure Login Service means authenticating to the SAP GUI.

New opportunities

Integration with CIS opens up new possibilities. The default login provider is CIS itself, however, this would require it to be the central base for user identities. To avoid creating accounts for everyone in CIS, we can change the identity provider to a third-party enterprise platform, such as Microsoft Entra ID, which is a popular choice in customer environments, since it is often the Microsoft domain that already has a long-standing base of all enterprise users.

However, if this is not a suitable solution, there is also the option of authentication through social media such as Facebook, X or Linkedin.

Not just a cloud

SAP GUI users will no longer have to use separate passwords for each system, which will certainly have a positive impact on their work comfort. Administrators, who too often had to respond to numerous requests for locked accounts and expired passwords, will also thank the implementation. Now support will be able to focus more on development and maintenance requests.

Increased security also relies on the use of modern identity delivery platforms already in place in organizations for logins, which use MFA technologies often combined with biometrics or U2F keys.

Write us Call us Send email






    Details regarding the processing of personal data are available in the Privacy Policy.


    +48 61 827 70 00

    The office is open
    Monday to Friday
    from 8am to 4pm (CET)

    General contact for the company
    office.pl@all-for-one.com

    Question about products and services
    info.pl@all-for-one.com

    Question about work and internships
    kariera@all-for-one.com

    This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.