SAP Cloud Platform · Identity · SSO
Manufacturing SAP Cloud Platform SAP Gateway
How a large building-products manufacturer enabled Single Sign-On between SAP Cloud Platform and on-premise Gateway
A Large North American Building Products Manufacturer Delivered 2019
A Mindset Principal Cloud Architect resolved a blocking Single Sign-On gap between the company's SAP Cloud Platform development environment and its on-premise SAP Gateway in under two weeks, then provided ongoing platform advisory to support the team's cloud direction.
By the numbers
-
2 weeks
To resolve SSO blocker and enable cloud connectivity
-
1
Development environment unblocked for cloud workflow progress
Before
SSO gap blocking cloud platform work
- SAP Cloud Platform development sub-account not connected to the on-premise SAP Gateway.
- Cloud workflow and identity issues stalling active Basis team work.
- No specialist on-hand for SAP Cloud Platform identity configuration.
After
SSO live, platform advisory in place
- SSO enabled between the SAP Cloud Platform development sub-account and on-premise Gateway.
- Basis team working alongside a Principal Cloud Architect with hands-on platform knowledge.
- Open advisory relationship for continued SAP Cloud Platform guidance.
Why this matters
Not every engagement is a multi-year program. Sometimes a blocking gap needs a specialist in the room for two weeks. Getting the identity layer right before building anything on top of it is the kind of foundational work that pays off quietly.
The challenge
The company is a large North American manufacturer of commercial roofing, insulation, and engineered building products. Its Basis team had active SAP Cloud Platform work underway but had hit a wall: cloud workflow and SSO issues were blocking progress, and the team needed specialist help to bridge the SAP Cloud Platform development sub-account to the on-premise SAP Gateway system.
The company wanted a cloud and identity specialist who could work alongside its own Basis team rather than around them, get SSO working, and provide advisory on SAP Cloud Platform as the work continued.
What we did
Mindset deployed a Principal Cloud Architect who worked both remotely and on-site at the company's Denver headquarters. The engagement was scoped tightly: enable SSO from the SAP Cloud Platform development sub-account to the on-premise SAP Gateway, plus general SAP Cloud Platform and digital advisory. Front-end and back-end programming were out of scope, keeping the focus on the identity and platform layer.
Delivery ran over approximately two business weeks, with the architect working closely with the company's Basis team. Any remaining hours after the SSO work was complete carried into broader SAP Cloud Platform advisory, giving the team a continued resource as follow-on questions came up.
The outcomes
SSO was enabled between the SAP Cloud Platform development sub-account and the on-premise SAP Gateway within the two-week window, removing the blocker that had stalled the team's cloud work.
The engagement was structured to leave an open door for follow-on advisory, reflecting the company's intent to continue building out its SAP Cloud Platform capability.
If we built this today
Concept · not delivered scopeSSO that explains and repairs itself.
This is a forward-looking concept, not the scope we delivered on this engagement. It is the build we would reach for now, grounded in SAP that ships today.
This team's Basis crew was stuck standing up Single Sign-On between their SAP Cloud Platform sub-account and on-premise SAP Gateway, so a 2026 build would put a platform agent on the trust chain itself.
The data product
Integration and identity health data product
A governed data product on SAP Business Data Cloud that grounds the agent in destination health, connector status, and certificate expiry across the landscape. It gives the agent real meaning behind each trust relationship instead of guessing from raw config.
Data product on SAP Business Data Cloud
The Joule agent
Identity Federation Trust Agent
Reads the SSO trust configuration across SAP BTP destinations, the SAP Cloud Connector, and the on-premise SAP Gateway identity provider, then proposes the principal-propagation and certificate fixes when a handshake breaks. It flags expiring signing certs and mismatched SAML or OAuth settings before they take the login flow down.
SAP BTP, SAP Cloud Identity Services, SAP Cloud Connector, SAP Gateway · ALERT, PROPOSE · SSO authentication success rate and time-to-resolve identity incidents
The Fiori app
SAP Cloud Identity Services admin console (BTP, not a Fiori app)
Identity federation lives in the BTP cockpit and the SAP Cloud Identity Services console with Joule guidance over destinations and trust, not in an SAP S/4HANA Fiori app. That is the honest home for this kind of work, so we point at the platform tooling rather than name an app that does not exist.
Platform tooling in the BTP cockpit, not the Fiori launchpad
We would mine the current identity and login flow in SAP Signavio, map the cloud-to-on-prem trust paths in SAP LeanIX, and let MIND accelerators carry the old SSO setup over to the new pattern.
What we built
-
Blocker resolved within a two-week window
SAP Cloud Platform SSO enablement
Single Sign-On configured from the SAP Cloud Platform development sub-account to the on-premise SAP Gateway, working alongside the company's Basis team.
-
Advisory available for the duration of the engagement
SAP Cloud Platform and digital advisory
Ongoing advisory on SAP Cloud Platform direction, architecture, and digital strategy, delivered alongside the SSO work and continuing as the team's cloud capability developed.
-
Internal team left with working configuration and platform understanding
Basis team enablement
The architect worked directly with the company's Basis team, transferring knowledge on SAP Cloud Platform sub-account configuration and identity management rather than operating as a separate workstream.