Activating the ClickJacking-Framing-Protection service

Published by Tobias Hofmann on

1 min read

When you start the transaction SAML2 in your SAP NetWeaver ABAP system, you might geht the error message:

ERROR: ICF-Service für ClickJacking-Framing-Protection ist inaktiv (termination: ERROR_MESSAGE_STATE)


The solution can be found in SAP Note 2389051. Activate the ICF node UICS and its child whitelist: /sap/public/bc/uics

Activate the node with sub nodes.

This will activate both services.

Go back to your browser with the HTTP 500 error and reload the page. Now the SAML 2.0 configuration wizard will launch.

Alternative activation option

You may also activate this ICF node using an alternative approach. Instead of activating it in the SICF transaction, you can use a transaction for activating special ICF services. More information at SAP Help.

Transaction SICF_INST
Technical name: UICS_BASIC

When you run this transaction with the technical name UICS_BASIC, the ICF node will be activated.


Let the world know
Categories: BasisSAP

Tobias Hofmann

Doing stuff with SAP since 1998. Open, web, UX, cloud. I am not a Basis guy, but very knowledgeable about Basis stuff, as it's the foundation of everything I do (DevOps). Performance is king, and unit tests is something I actually do. Developing HTML5 apps when HTML5 wasn't around. HCP/SCP user since 2012, NetWeaver since 2002, ABAP since 1998.

1 Comment

Emre · November 25, 2021 at 13:02

Dear Sir,

I confronted “Clickjacking Vulnerable”. When i try to solve this, i read your article. In first OSS Note is about S4 HANA Systems (So I passed this)
In second way (Alternative Solution) When I run SICF_INST and Technical name: UICS_BASIC, i got Error “Application is not in table ICFINSTACT ”

Is is about SAP Application version?

Leave a Reply

Avatar placeholder

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.