Email

 

SAP Integration Suite, managed gateway for spend management and SAP Business Network (ISMG)

Migration from SAP BTP NEO to SAP BTP Cloud Foundry (CF)

What is Happening?

SAP Business Technology Platform (BTP) has announced the end-of-life for SAP BTP NEO.  As such, applications such as Integration Suite, managed gateway for spend management and SAP Business Network (ISMG) must migrate to SAP BTP Cloud Foundry (CF).

We encourage you to check-in on this site until the migration is completed to stay up-to-date!

We have organized all necessary technical details by instance of SAP Integration Suite, managed gateway for spend management and SAP Business Network:

Customer Webcast Sessions!

We are happy to offer some webcasts for you to attend and learn more about this effort. Please review and and attend a session by clicking the date/time you prefer (save the link to your personal calendar). Please note, we will add links for each date/time, so check back!

What do Customers have to do?

IMPORTANT: All necessary changes must be completed in advance of your scheduled migration date. You do not need to wait until your migration date to accommodate these changes. Please make these changes as soon as possible to avoid unnecessary disruption.

We also recommend the adoption of new domain URLs.

What is changing?

  • SAP Cloud Connector (SCC) configuration (if you are using SCC)
  • IP allowlisting / IP filtering updates (if your network policies require it)

What is not changing during this migration?

  • Integration URLs
  • Certificates or authentication mechanism
  • Functionality/UIs
  • All customer data, including transactional and configuration data

We have assembled Frequently Asked Questions and a Steps/Checklist for you as well!

Schedule

Instance Planned Migration Date Notice(s) Bundle ID Technical Details
China 10 January 2026 *COMPLETED* EVB8353324 Technical Details for China
United Arab Emirates (UAE) 06 March 2026 Postponed (future date tbd) EVB9492405 Technical Details for UAE
North America (NA) 11 April 2026 EVB8453950 Technical Details for NA
European Union (EU) 16 May 2026 EVB9492409 Technical Details for EU

 

 

ISMG Data Center - European Union (EU)

Region: cf.eu10.hana.ondemand.com

SAP Cloud Connector Subaccount Updates

If you use SAP Cloud Connector, you must add the following Subaccounts.

Environment Subaccount ID One-time Passcode URL
TEST c2cd9a88-7143-472a-a358-ac050eacdc39 https://aribaeuprodt1.authentication.eu10.hana.ondemand.com/passcode
2fdff90d-496d-4c6d-9f21-26d1bb9f37b5 https://aribaeuprodt2.authentication.eu10.hana.ondemand.com/passcode
c7845fda-254d-42ef-9069-70bde1d2b647 https://aribaeuprodt3.authentication.eu10.hana.ondemand.com/passcode
a4eca8c4-328d-492a-8ee0-cfb14a5d751c https://cig-production-eu10-outbound-test.authentication.eu10.hana.ondemand.com/passcode
PROD 38ed7fb3-5d18-4ca9-810f-751c5ce2b8ee https://aribaeuprodp1.authentication.eu10.hana.ondemand.com/passcode
0a5e6610-0c7d-4e7c-bc16-5181277b7405 https://aribaeuprodp2.authentication.eu10.hana.ondemand.com/passcode
6b368bbf-6761-427c-91bd-158a79c2ab0d https://aribaeuprodp3.authentication.eu10.hana.ondemand.com/passcode
c6938ed8-be1b-4bb3-b140-1bb8c99d76ef https://aribaeuprodp4.authentication.eu10.hana.ondemand.com/passcode
eddaa307-3566-451f-8d09-57d27dd76985 https://aribaeuprodp5.authentication.eu10.hana.ondemand.com/passcode
86efbbb1-a71b-42ca-900d-b7d24be2234e https://aribaeuprodp6.authentication.eu10.hana.ondemand.com/passcode
c4fdd25c-03cf-480d-9024-082641a58e5a https://aribaeuprodp7.authentication.eu10.hana.ondemand.com/passcode
181236c4-d33b-4948-9c14-87d3b4a3b7b5 https://cig-production-eu10-outbound-prod.authentication.eu10.hana.ondemand.com/passcode

For general instructions on Configuring SAP Cloud Connector, please see this.  While leveraging these instructions, please be sure to use the Region, Subaccount, and One-time Passcode URL details provided just above on this page.  Please remember to use the same Location ID that you are using today for the current Integration Suite, managed gateway for spend management and SAP Business Network.  Please maintain "Cloud to On-Premises" settings for the newly added sub accounts to match those of the current settings in SAP Cloud Connector.

When can we make these changes?

The Cloud Connector Subaccount Updates can be made ASAP, but must be done by your scheduled change date.

What happens if we fail to make these changes by the date above?

Your transactions will fail to be received by your ERP.

IP AllowList Updating

If you are leveraging IP AllowLists, you must update your AllowList to include the new regional endpoints for your region (cf-eu10, cf-eu10-002, cf-eu10-003, cf-eu10-004, cf-eu10-005).  The necessary IP details are published in the Regions and API Endpoints for SAP Cloud Foundry Environment resource.

When can we make these changes?

You can add the new/future IPs to your AllowList effective immediately, but do not remove the current IPs until the migration is completed for your scheduled change date.

What happens if we fail to make these changes by the date above?

Your transactions will fail to be sent to SAP by your ERP.

(back to top)

 

ISMG Data Center - North America (NA)

Region: cf.us10.hana.ondemand.com

SAP Cloud Connector Subaccount Updates

If you use SAP Cloud Connector, you must add the following Subaccounts.

Environment Subaccount ID One-time Passcode URL
TEST 865860f6-c079-4e00-bfb1-da6d4c202bda https://aribausprodt1.authentication.us10.hana.ondemand.com/passcode
ca9e875f-3213-4277-89c7-48c0721fe1a8 https://aribausprodt2.authentication.us10.hana.ondemand.com/passcode
9f78d636-ced8-441a-8543-23870a6c5353 https://cig-production-us10-outbound-test.authentication.us10.hana.ondemand.com/passcode
PROD bd12b724-5a80-46dd-9834-c748486de411 https://aribausprodp1.authentication.us10.hana.ondemand.com/passcode
fa099043-3ff3-465a-90a5-808b3f324aac https://aribausprodp2.authentication.us10.hana.ondemand.com/passcode
4d527499-b34f-4f67-b046-7c5b561eebbb https://aribausprodp3.authentication.us10.hana.ondemand.com/passcode
bc3debb0-9dea-468c-ab1d-010ca7f67158 https://aribausprodp4.authentication.us10.hana.ondemand.com/passcode
c1c8acd4-1921-4c81-a6a6-d04023fde368 https://aribausprodp5.authentication.us10.hana.ondemand.com/passcode
80ec591d-5211-44c6-873d-c67456799567 https://aribausprodp6.authentication.us10.hana.ondemand.com/passcode
4869e1a2-f119-4a1d-acd8-5211df9aa417 https://cig-production-us10-outbound-prod.authentication.us10.hana.ondemand.com/passcode

For general instructions on Configuring SAP Cloud Connector, please see this.  While leveraging these instructions, please be sure to use the Region, Subaccount, and One-time Passcode URL details provided just above on this page.  Please remember to use the same Location ID that you are using today for the current Integration Suite, managed gateway for spend management and SAP Business Network.  Please maintain "Cloud to On-Premises" settings for the newly added sub accounts to match those of the current settings in SAP Cloud Connector.

When can we make these changes?

The Cloud Connector Subaccount Updates can be made ASAP, but must be done by your scheduled change date.

What happens if we fail to make these changes by the date above?

Your transactions will fail to be received by your ERP.

IP AllowList Updating

If you are leveraging IP AllowLists, you must update your AllowList to include the new regional endpoints for your region (cf-us10, cf-us10-001, cf-us10-002).  The necessary IP details are published in the Regions and API Endpoints for SAP Cloud Foundry Environment resource.

When can we make these changes?

You can add the new/future IPs to your AllowList effective immediately, but do not remove the current IPs until the migration is completed for your scheduled change date.

What happens if we fail to make these changes by the date above?

Your transactions will fail to be sent to SAP by your ERP.

(back to top)

 

ISMG Data Center - United Arab Emirates (UAE) 

Region: mtls.ae01-l-c.uc-live.shoot.live.k8s-hana.ondemand.com

SAP Cloud Connector Subaccount Updates

If you use SAP Cloud Connector, you must add the following Subaccounts.

Environment Subaccount ID One-time Passcode URL
TEST  887c372f-2be8-4f80-86da-240e50453dbf  https://aribaaeprodt1.authentication.ae01.hana.ondemand.com/passcode
 ebbde14e-2eb7-4d94-9f8b-c326845f2d14  https://aribaaeprodt2.authentication.ae01.hana.ondemand.com/passcode
 2c02a921-2922-47f3-a08c-f392d37e2656  https://cig-production-ae01-outbound-test.authentication.ae01.hana.ondemand.com/passcode
PROD  88f4f4b6-7e16-4492-8365-1222d9b712c3  https://aribaaeprodp1.authentication.ae01.hana.ondemand.com/passcode
 f29eabd2-7d73-48ec-8464-80708ac9e25f  https://aribaaeprodp2.authentication.ae01.hana.ondemand.com/passcode
 3d277c25-9444-4a26-943f-59037be3bd72  https://cig-production-ae01-outbound-prod.authentication.ae01.hana.ondemand.com/passcode

For general instructions on Configuring SAP Cloud Connector, please see this.  While leveraging these instructions, please be sure to use the Region, Subaccount, and One-time Passcode URL details provided just above on this page.  Please remember to use the same Location ID that you are using today for the current Integration Suite, managed gateway for spend management and SAP Business Network.  Please maintain "Cloud to On-Premises" settings for the newly added sub accounts to match those of the current settings in SAP Cloud Connector.

When can we make these changes?

The Cloud Connector Subaccount Updates can be made ASAP, but must be done by your scheduled change date.

What happens if we fail to make these changes by the date above?

Your transactions will fail to be received by your ERP.

Server Name Indication (SNI) Support

The new Data Centers will only support SNI.  If applicable, please ensure that your systems are updated to support SNI to maintain proper connectivity.  The following resource may be of help: How to confirm and test if the SNI (Server Name Indication) extension is active in my ERP?

When can we make these changes?

We encourage you to confirm that your systems support SNI effective immediately, but they must be by your scheduled change date.

What happens if we fail to make these changes by the date above?

Your transactions will fail to be sent to SAP by your ERP.

IP AllowList Updating

If you are leveraging IP AllowLists, you must update your AllowList to include the new regional endpoints for your region (ae01).  The necessary IP details are published in the Regions and API Endpoints for SAP Cloud Foundry Environment resource.

When can we make these changes?

You can add the new/future IPs to your AllowList effective immediately, but do not remove the current IPs until the migration is completed for your scheduled change date.

What happens if we fail to make these changes by the date above?

Your transactions will fail to be sent to SAP by your ERP.

(back to top)

 

ISMG Data Center - China

Region: cf.cn40.platform.sapcloud.cn

SAP Cloud Connector Subaccount Updates

If you use SAP Cloud Connector, you must add the following Subaccounts.

Environment Subaccount ID One-time Passcode URL
TEST a84e1de1-9875-48da-9be8-5917098092b4 https://aribaprodcnt1.authentication.cn40.platform.sapcloud.cn/passcode
6794ea15-de6a-4a2a-9d91-a84ed3efb212 https://aribaprodcnt2.authentication.cn40.platform.sapcloud.cn/passcode
8dced308-6076-4cd3-bdf2-f488a2366090 https://cig-production-china-outbound-test.authentication.cn40.platform.sapcloud.cn/passcode
PROD edf0094a-6e4c-4c57-be5f-dac4a9c4e7a6 https://aribaprodcnp1.authentication.cn40.platform.sapcloud.cn/passcode
22054ed9-9109-4b0f-9fce-8835c4146322 https://aribaprodcnp2.authentication.cn40.platform.sapcloud.cn/passcode
ced366bb-7581-4f6e-ac14-8cd367ed9a9e https://cig-production-china-outbound-prod.authentication.cn40.platform.sapcloud.cn/passcode

For general instructions on Configuring SAP Cloud Connector, please see this.  While leveraging these instructions, please be sure to use the Region, Subaccount, and One-time Passcode URL details provided just above on this page.  Please remember to use the same Location ID that you are using today for the current Integration Suite, managed gateway for spend management and SAP Business Network.   Please maintain "Cloud to On-Premises" settings for the newly added sub accounts to match those of the current settings in SAP Cloud Connector.

When can we make these changes?

The Cloud Connector Subaccount Updates can be made ASAP, but must be done by your scheduled change date.

What happens if we fail to make these changes by the date above?

Your transactions will fail to be received by your ERP.

IP AllowList Updating

If you are leveraging IP AllowLists, you must update your AllowList to include the new regional endpoints for your region (cn40).  The necessary IP details are published in the Regions and API Endpoints for SAP Cloud Foundry Environment resource.

When can we make these changes?

You can add the new/future IPs to your AllowList effective immediately, but do not remove the current IPs until the migration is completed for your scheduled change date.

What happens if we fail to make these changes by the date above?

Your transactions will fail to be sent to SAP by your ERP.

(back to top)

 

Steps to follow (Checklist)

  • Determine your ISMG Data Center
  • Confirm if you use SAP Cloud Connector
  • Add new SAP BTP Cloud Foundry Subaccounts
    • Use correct Region (E.g. eu10, us10, ae01)
    • Use provided Subaccount ID and One-time Passcode (OTP)
    • Maintain same Location ID
    • Maintain Cloud-to-On-Premise settings
    • Configure for both TEST and PROD
    • Note: Do not remove existing/current IP addresses or subaccounts until the scheduled migration is fully completed.
  • Confirm if you leverage IP Allow Listing and update accordingly

(back to top)

 

Region Codes for SAP BTP Neo and SAP BTP Cloud Foundry

To identify what Data Center applies to your organization, please log in to SAP Business Network or your SAP Ariba Procurement/Sourcing system (prior to accessing ISMG). You will find the applicable Data Center information displayed accordingly:

SAP Business Network SAP Ariba Solutions
A screenshot of a computerAI-generated content may be incorrect. A screenshot of a computerAI-generated content may be incorrect.

 

ISMG Data Center SAP BTP Neo Region SAP BTP Cloud Foundry Region
United Arab Emirates (UAE) ae1 ae01
North America (NA) us4 us10
European Union (EU) eu1 eu10

(back to top)

 

Frequently Asked Questions

I see the identifier $SAP-CP-SSO-PASSCODES in the "Initiated By" field when using SAP Cloud Connector. Is this expected?

Yes. This is expected behavior in older Cloud Connector versions where the technical SSO passcode identifier cannot be replaced with a P-user.

What should customers do to resolve this?

Customers are strongly advised to upgrade to the latest SAP Cloud Connector version. The upgrade provides:

  • Accurate representation of initiating users (where supported)
  • Improved transparency in audit and monitoring logs
  • Alignment with SAP's latest security and compliance standards
  • Enhanced logging, auditing, and user identification capabilities

After upgrading, customers may still need to configure users again, but the Cloud Connector will no longer reflect the passcode instead of the P-user.

How can we check if we're using SAP Cloud Connector? / How can I tell if I'm applicable to make changes?

In ISMG, go to the My Configuration > Connection tab. If Transport has ADDON or CLOUDCONNECTOR, that means you are using SAP Cloud Connector:

What if I don't use SAP Cloud Connector (SCC)? 

If you do not see “Cloud Connector” /"AddOn" in your ISMG portal, that indicates you are not using SCC, so there is no SCC-related action required. You should still confirm with your IT team whether you use IP filtering / allowlisting and update it if needed.

What if I use CPI instead of a direct Cloud Connector connection?

This migration is specific to ISMG. Standalone CPI is not impacted. Where CPI is part of the integration landscape, customers should still review IP allowlisting from their side if applicable.

I used my P-user and P-user password to configure the subaccount. Is that OK?

No. You must use the One-Time Passcode (OTP) instead of the P-user password.

What should I do if I configured the subaccount using a P-user instead of the One-Time Passcode?

Delete the subaccount configuration and recreate it from scratch using the One-Time Passcode (OTP).

Why can't the P-user be used? Why must the One-Time Passcode be used? What's the difference?

  • The OTP is part of SAP’s security design for onboarding Cloud Foundry subaccounts to the Cloud Connector.
  • It is short‑livedsingle‑use, and designed to minimize credential exposure during the trust setup.
  • While it may sometimes be possible to onboard using a P‑user password, it is unsupported, increases security risks, and does not comply with SAP’s recommended security practices.
    SAP officially recommends using the OTP method only.

How do I get a One-Time Passcode (OTP)?

Follow the Steps to add cloud foundry subaccounts of Managed Gateway for Spend & Network

Is there a way to test whether the subaccount configuration is correct before the migration?

No. A successful Cloud Connector connection to the new ISMG subaccounts is sufficient for migration preparation.

When can I delete my old subaccounts?

After connecting to the new subaccounts, customers should keep the old ones until after the migration date and until they have confirmed that the transactions are flowing as expected via the new subaccounts.

How do I confirm success before go-live? 

A successful Cloud Connector connection to the new ISMG subaccounts is sufficient for migration preparation. Customers should also ensure that the same Location ID is retained and that Cloud to On-Premises settings are maintained.

Is there any practical check I can do?

If you keep the same LOCATION ID and can perform a ping test from Cloud Connector to your backend system, the configuration is considered done and good to go.

How can I check if I need to update IP Allow Lists? If I use SAP S/4HANA Public Cloud. do I need to do anything regarding IP Allow Listing?

If you previously maintained an IP allowlist, ensure that the new subaccount IP ranges are included. SAP will update the KBA section on IP Allowlist Updating to help identify correct IPs per region.

Is it mandatory to switch to the new BTP Cloud Foundry domains during this migration?

It is recommended, but not mandatory to adopt the new domain URLs.

If I use SAP S/4HANA Private Cloud hosted by SAP, do I need SAP to update IP Allow Listing?

Private Cloud Edition customers can restrict IPs. SAP recommends raising a PCO-OPS support ticket to confirm whether additional IPs need to be allow listed.

When configuring firewall rules, is the NAT IP used for inbound (ISMG to S/4) and load balancer IP for outbound (S/4 to ISMG)?

Yes. Details are available in the BTP help guide.

Should we Allow List all IPs for our region?

Yes. All entries should be included as ISMG may use additional domains in the future.

Where can customers go to update their P-user password and when do they need to do it?

Customers can update their P‑user password by navigating to My Configurations → Authorization tab and clicking Change Password. They should only perform this action when they no longer remember their current P‑user password or must reset it for security reasons.

Important note: Changing the P‑user password in the portal should be considered a last resort. This action can disrupt production and test transactions originating from SAP ERP or SAP S/4HANA systems. To avoid integration failures or account lockouts, ensure that the new password is updated simultaneously across all connected interfaces and end systems where the P‑user is used. Alternatively, temporarily pause message transmission during the password update window.

For related configuration steps, customers can also refer to Steps to add cloud foundry subaccounts of Managed Gateway for Spend & Network

How can customers determine their Data Center? 

Please note that Region might be different from your company location. When you access ISMG, you can user the URL showing up in your browser to determine your Data Center:

  • UAE: integration-uae.ariba.com
  • NA: integration-us.ariba.com
  • EU: integration.ariba.com

Downtime Expectation 

Plan for an announced downtime window of up to two hours, while the actual switch is typically completed in minutes.

Support (How to get help) 

Where to open a case

Open a support case under component BNS-ARI-CI-PLT-CON.

When to use high priority / P1 ticket

If an issue occurs after the migration, log a P1 case under BNS-ARI-CI-PLT-CON so Support can engage quickly.

If you want SAP to confirm your situation

To confirm whether action is required for your specific setup, open a case under BNS-ARI-CI-PLT-CON and request confirmation. When setup verification is needed, provide ANID, realm, or project details in the support case.

Trouble-shooting 

“SCC handshake failed: 401 — Unauthorized” 

Create a support case under BNS-ARI-CI-PLT-CON and include the error details. This error can be associated with authorization issues when setting up or activating required subaccounts.

I used my P-user / P-account password when adding the new subaccounts. Is that OK? 

No. If you used the P-user / P-account credentials directly instead of the required one-time passcode, the setup must be redone using the one-time passcode. The P-user credentials are used to obtain the one-time passcode, which is then used to configure the subaccounts.

Do I need to install a new certificate as part of the migration? 

No. No certificate changes are required as part of this BTP Neo to Cloud Foundry migration.

We already allow traffic from *.ariba.com. Is that sufficient?

Not necessarily. Hostnames and IPs for the ISMG subaccounts are based on BTP and are different from ariba.com, so customers should review the exact IP details in the referenced migration article and validate them with their infrastructure team where needed.

(back to top)

 

Additional Information

Questions?

  • For assistance, contact SAP Support using the Support Hotline. We recommend opening a support ticket with the component BNS-ARI-CI-PLT-CON.

Additional Resources:

© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.

 

Terms of Use  |  Copyright  |  Security Disclosure  |  Privacy