The Single Sign-on feature enables SAP customers to access Emarsys accounts without the need of adding login credentials. The purpose of this article is to provide guidance on how to enable this feature in the SAP Administration Console for SAP Cloud Platform Authentication.
To enable and use SAP Single Sign-on, perform the following:
For the current limitations of the feature, see Known limitations.
Create and configure the application
As an SAP customer, first, you have to create and configure the application in the SAP Administration Console for SAP Cloud Platform Authentication. To do this, perform the following steps:
- Click + Add at the bottom of the page.

- Add application with the name “suite-sso”.

- Select the newly created "suite-sso" application and open SAML 2.0 Configuration.
- Add “suite-sso” to “Name”.
- Click Add URL.
- Add the URL for each account for which you want to enable SSO. Use the following links:
https://sso.gservice.emarsys.net/login/auth/{account_name1}
https://sso.gservice.emarsys.net/login/auth/{account_name2}
https://sso.gservice.emarsys.net/login/auth/{account_name3}
- Click Save at the bottom of the page.
- Select Assertion Attributes.
- Replace the “mail” string with “email” for the attribute named “E-mail”.
- Click + Add above the Attribute list, and select “E-mail”.
- Replace the “mail” string with “username” for the newly created attribute named “E-mail”.
There are two E-Mail user attributes in the table.
- Click Save at the bottom of the page.
- Go to the Tenant Settings in the Applications & Resources and make sure that the "IdP-Initiated SSO" is turned on.
- Under Tenant Settings, select SAML 2.0 Configuration.
- Click Download Metadata file at the bottom of the page to save the Metadata XML.

- Share the Metadata.XML with the Emarsys Customer Success Manager.
Login to Emarsys with Single Sign-on
To login to Emarsys with Single Sign-on, perform the following steps:
- Open the Emarsys login page and click on Login with SSO.

- Add the account name you want to login to and click Continue.

- Log in with your SAP credentials.

- You are redirected to the selected account.

Known limitations
Currently we do not have support for:
- Mixed setups: If a customer sets up SSO login, then all administrators must use this feature.
- Federated logout: The manual logout functionality and the session timeout is still available.
- User deprovisioning: If a user is deleted in the Identity Provider, it will not be automatically deleted from our systems but the user will not be able to log in.
There are small changes on the user management side:
- Administrators who belong to customers with the 'single_signon' feature enabled, are not disabled automatically (e.g., after long inactivity).
- Administrators can be deleted, but they will be re-created after the next login with no permissions.
- The 'administrator creation' functionality has not been disabled, however, administrators created manually in the user management will not be able to log in.
- The 'forgot password' functionality has not been disabled and a new password can be set up, however, this has no effect on the SSO login flow.
- Currently, the permissions and roles can be managed only in the Emarsys user management, the SAML2 SSO can be used only for authentication. New users are commissioned with "restricted role".