SAP Concur - SSO Configuration

SAP Concur - SSO Configuration

Alert
This application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk.
QuoteThis documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for SAP Concur using Multi-Pass. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization.
WarningTo set up Multi-Pass with SAP Concur, ensure you meet the following requirements:
- SAP Concur admin rights
- MPAS Admin rights
- Make sure that all users intended to use SSO in SAP Concur are registered in your IdP and have the necessary permissions to access SAP Concur.
Important: Custom elements in URLs (like realm names) are case sensitive. Make sure to match the exact casing from your environment.





SAP Concur - SSO Configuration






Step 1 - Obtain Tenant XML Metadata from Multi-Pass (IdP)

  • Open Multi-Pass Dashboard
  • Select the correct tenant and go to Integrations, click on Applications
  • Select SAML in the custom integration section

  • Select Download under Tenant XML data and save the file locally



Step 2 - Configure SAP Concur as the Service Provider (SP)

  • Log into SAP Concur as an Administrator
  • Navigate to Home > Administration > Company > Authentication Admin
  • Select SSO Required beside SSO Setting
  • Select Download SAP Concur Metadata and save the file locally
  • Beside SSO Configurations select Add
  • Under Custom IdP Name enter Multi-Pass
  • Select Upload XML File and upload the Tenant XML Metadata file from Step 1
  • Select Add Metadata

Step 3 - Configure Multi-Pass as the Identity Provider (IdP)

  • Open Multi-Pass Dashboard
  • Select the correct tenant and go to Integrations, click on Applications
  • Select SAML in the custom integration section

  • Select Upload File and upload your SAP Concur Metadata

  1. Confirm/Complete the remaining fields based on the table below:
FieldValue
Client ID (=SP Entity ID)https://us.api.concursolutions.com/saml2
Namesapconcur
DescriptionSAP Concur SSO integration
Assertion Consumer Service URLhttps://www-us.api.concursolutions.com/sso/saml2/V1/acs/
NameID Policy FormatEmail


  1. Go to the Advanced Console by clicking on the right side of your screen

  1. Complete the fields based on the tables below:
General settings (Multi-Pass)
FieldValue
Client IDhttps://us.api.concursolutions.com/saml2
Namesapconcur
DescriptionSAP Concur SSO Integration
Always display in UION
Access settings (Multi-Pass)
FieldValue
Home URL (IdP-initiated)https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/clients/<APP_NAME>
Valid Redirect URIs (ACS)https://www-us.api.concursolutions.com/sso/saml2/V1/acs/
IDP-Initiated SSO URL Name<APP_NAME>
SAML Capabilities
SettingValue
Name ID Formatemail
Force Name ID FormatOFF
Force POST BindingON
Include AuthnStatementON
Signature & Encryption
SettingValue
Sign DocumentsOFF
Sign AssertionsON
  • Move to the tab Keys and ensure that both parameters are set to OFF.

    • Related Articles

    • SAP SuccessFactors - SSO Configuration

      This application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a step-by-step guide to ...
    • D2L Brightspace - SSO Integration

      This application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a step-by-step guide to ...
    • Mulesoft - SSO Integration

      This application has been formally tested by Kelvin Zero Inc. This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Mulesoft using Multi-Pass. SSO simplifies user authentication by allowing access to multiple ...
    • SAML SSO Integration Guide

      This guide provides an overview of how to configure SAML Single Sign-On (SSO) between Multi-Pass and a third-party Service Provider (SP). Multi-Pass acts as the Identity Provider (IdP) in this federation model. Multi-Pass is working on SCIM support ...
    • Miro - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Miro using MPAS. SSO simplifies user authentication by allowing access to multiple ...