ST-2026-140 · Authentication & identity
Microsoft Entra provisioning for SAP SuccessFactors adds workload-identity authentication
Microsoft documents federated workload identity for SAP SuccessFactors provisioning, replacing long-lived Basic credentials with short-lived OIDC tokens before SAP retires Basic authentication on 20 November 2026.
Previous state
Provisioning connectors could authenticate to SAP SuccessFactors with stored Basic credentials.
Current state
Federated workload identity uses short-lived OIDC tokens; Basic authentication remains only as a temporary rollback path until SAP retirement.
Affected users
Who needs to care
Organisations provisioning users between Microsoft Entra ID and SAP SuccessFactors.
Required response
What to do
Configure the workload identity, test token exchange and remove Basic-authentication dependencies before 20 November 2026.
Evidence boundary
What the source does not prove
The Microsoft guidance covers the named Entra provisioning connector and does not establish removal of Basic authentication from every SAP interface.
Lifecycle history
Dated event sequence
- Migration guidance updated
Microsoft documented workload-identity configuration and rollback boundaries.
- Basic authentication retires
The temporary Basic-authentication rollback route ends for the named integration.
Evidence ledger
First-party sources
- 01Microsoft Learn — Configure workload identity authentication for SAP SuccessFactors provisioning
Official integration-authentication guidance · 2026-05-27
Open official source ↗