<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Reconfigure the Okta SAP Analytics Cloud Integration by September 3, 2026

Single Sign-On
Okta Classic Engine
Okta Identity Engine

Overview

Okta is upgrading its SAP Analytics Cloud OIN integration to SCIM 2.0 to improve group sync performance and add support for group description attributes. As part of this enhancement, authentication shifts to OAuth 2.0 Client Credentials to eliminate interactive session dependencies. Administrators must reconfigure the application settings in both SAP Analytics Cloud and Okta to maintain continuous provisioning and SSO functionality before September 3, 2026.

Applies To

  • Okta Integration Network (OIN)
  • SAP Analytics Cloud
  • Okta Identity Engine (OIE)
  • Okta Classic Engine

Solution

To prevent operational disruption, administrators must execute the following actions prior to September 3, 2026.

How is the SAP Analytics Cloud integration reconfigured?

Create a new OAuth client in SAP Analytics Cloud, update the provisioning settings in the Okta Admin Console, and configure the Security Assertion Markup Language (SAML) user mapping to maintain continuous functionality.

 

What are the steps to create a new OAuth client in SAP Analytics Cloud?

Generate a new OAuth 2.0 Client Credentials token in the SAP Analytics Cloud administration console to prepare for the Okta configuration.

 Create a new OAuth Client (Client Credentials)

  1.   Go to System > Administration > App Integration
  2.   Click Add a New OAuth Client
  3.   Set Purpose to API Access only
  4.   Set Grant Type to Client Credentials
  5.   Save and copy the Client ID and Secret — you only see the secret once

 

 

What Steps are required in the Okta Admin Console to update provisioning and SSO settings?

  1.  Go to the SAP Analytics Cloud app in the Okta Admin Console
  2.  Provisioning tab → Integration
    1.   Click Edit
    2.   Add/Update the Tenant link check it from tenant links tab in administration
    3.   Enter the Client ID and Client Secret from SAP
    4.   Enter the Token URL from SAP (Get it from App integration tab in administration)
    5. Locate the SAML User Mapping setting and select either userid or email (depending on how your users are matched in SAP), then save your changes.
    6.  Test the connection and Save


How to update the SAML user mapping configuration in Okta?

Customers must update their SAML user mapping configuration in Okta to match what is configured in their SAP Analytics Cloud tenant. Failure to do so may result in SSO authentication failures.

Steps:

  1.   In Okta, navigate to your SAP Analytics Cloud application settings.
  2.   Locate the SAML User Mapping  field in user management (provisioning tab).
  3.   Set the value based on your SAP tenant configuration:
    1. If your SAP tenant is configured to use User ID → select User ID in Okta
    2. If your SAP tenant is configured to use Email → select Email in Okta
    3. or allow both
  4.   Save and validate SSO login after making the change.

 

Note: Customers are advised to verify their current SAP tenant configuration before making changes in Okta to ensure the values align. Misconfiguration will prevent users from logging in via SSO.

 

Loading
Okta Support - Reconfigure the Okta SAP Analytics Cloud Integration by September 3, 2026