TrustBroker 5.1: SSO Without Microsoft Active Directory
Chapters
Share Article
Let's Talk SAP Security
Have questions about SAP Security? We’re here to help. Contact Us
TrustBroker brings SSO and context-aware, risk-based MFA into SAP protecting logins, privileged access, and sensitive transactions with authentication that adapts to the situation, not a one-size-fits-all password prompt. Version 5.1.0 is now available, and it removes a dependency that’s shaped every deployment so far: Microsoft Active Directory.
With OpenID Connect (OIDC) now built into the SNC library, TrustBroker delivers SSO and MFA into SAP without AD in the middle, connecting natively to Microsoft Entra ID, Okta, PingID, Keycloak, and SAP Cloud Identity Services (IAS) instead. No new infrastructure, no external components to patch or maintain. It’s the same principle behind everything TrustBroker does: authentication built to run inside your SAP application servers, and approved for RISE with SAP.
New Capabilities in 5.1.0
With OIDC, customers can authenticate SAP GUI users through their existing identity provider, such as Microsoft Entra ID, Okta, PingID, Keycloak, or SAP Cloud Identity Services (IAS), with no dependency on Microsoft Active Directory.
Kerberos isn’t retiring. It stays fully supported in the SNC library, so teams can move to OIDC system by system, on their own timeline.
Phishing-Resistant MFA
SAP GUI logins can now be protected with phishing-resistant MFA. Passwordless methods like Windows Hello for Business, passkeys, and FIDO2 tokens replace credentials that can be phished or intercepted.
Quantum-Safe Network Protection
Network traffic between SAP GUI and SAP systems is now protected with quantum-safe key exchange, so data captured today can’t be decrypted later once quantum computing breaks today’s encryption.
Wider Reach
TrustBroker 5.1.0 runs on Linux and Windows servers, as well as macOS and Windows workstations, with other Unix platforms like AIX coming in a later release.
Additional support in 5.1.0:
- Red Hat Enterprise Linux 10
- SUSE Linux Enterprise Server 16
- SAP GUI 8.10
- Citrix Ready certification
See It for Yourself
The demo below shows both sides of it: logging into SAP via SAP GUI with an OIDC connection and a Windows Hello passkey tied to Entra ID, then TrustBroker stepping in again with policy-based MFA the moment that same user opens a sensitive transaction.
