Skip to content

TrustBroker 5.1: SSO Without Microsoft Active Directory

author icon
SecurityBridge
September 3, 2026
2 min read

Chapters

Share Article

Let's Talk SAP Security

Have questions about SAP Security? We’re here to help. Contact Us

TrustBroker brings SSO and context-aware, risk-based MFA into SAP protecting logins, privileged access, and sensitive transactions with authentication that adapts to the situation, not a one-size-fits-all password prompt. Version 5.1.0 is now available, and it removes a dependency that’s shaped every deployment so far: Microsoft Active Directory.

With OpenID Connect (OIDC) now built into the SNC library, TrustBroker delivers SSO and MFA into SAP without AD in the middle, connecting natively to Microsoft Entra ID, Okta, PingID, Keycloak, and SAP Cloud Identity Services (IAS) instead. No new infrastructure, no external components to patch or maintain. It’s the same principle behind everything TrustBroker does: authentication built to run inside your SAP application servers, and approved for RISE with SAP.

New Capabilities in 5.1.0

With OIDC, customers can authenticate SAP GUI users through their existing identity provider, such as Microsoft Entra ID, Okta, PingID, Keycloak, or SAP Cloud Identity Services (IAS), with no dependency on Microsoft Active Directory.

Kerberos isn’t retiring. It stays fully supported in the SNC library, so teams can move to OIDC system by system, on their own timeline.

Phishing-Resistant MFA

SAP GUI logins can now be protected with phishing-resistant MFA. Passwordless methods like Windows Hello for Business, passkeys, and FIDO2 tokens replace credentials that can be phished or intercepted.

Quantum-Safe Network Protection

Network traffic between SAP GUI and SAP systems is now protected with quantum-safe key exchange, so data captured today can’t be decrypted later once quantum computing breaks today’s encryption.

Wider Reach

TrustBroker 5.1.0 runs on Linux and Windows servers, as well as macOS and Windows workstations, with other Unix platforms like AIX coming in a later release.

Additional support in 5.1.0:

  • Red Hat Enterprise Linux 10
  • SUSE Linux Enterprise Server 16
  • SAP GUI 8.10
  • Citrix Ready certification

See It for Yourself

The demo below shows both sides of it: logging into SAP via SAP GUI with an OIDC connection and a Windows Hello passkey tied to Entra ID, then TrustBroker stepping in again with policy-based MFA the moment that same user opens a sensitive transaction.

More on TrustBroker’s SSO and step-up MFA for SAP: securitybridge.com/solutions/trustbroker