Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This article details integration of Azure identity and security services with an SAP RISE workload. Additionally use of some Azure monitoring services are explained for an SAP RISE landscape.
Single sign-on for SAP RISE
Single sign-On (SSO) is configured for many SAP environments. With SAP workloads running in ECS/RISE, steps to implement do not differ from a natively run SAP system. The integration steps with Microsoft Entra ID based SSO are available for typical ECS/RISE managed workloads:
- Tutorial: Microsoft Entra Single sign-on (SSO) integration with SAP NetWeaver
- Tutorial: Microsoft Entra single sign-on (SSO) integration with SAP Fiori
- Tutorial: Microsoft Entra integration with SAP HANA
SSO method | Identity Provider | Typical use case | Implementation |
---|---|---|---|
SAML/OAuth | Microsoft Entra ID | SAP Fiori, Web GUI, Portal, HANA | Configuration by customer |
SNC | Microsoft Entra ID | SAP GUI | Configuration by customer |
SPNEGO | Active Directory (AD) | Web GUI, SAP Enterprise Portal | Configuration by customer and SAP |
SSO against Active Directory (AD) of your Windows domain for ECS/RISE managed SAP environment, with SAP SSO Secure Login Client requires AD integration for end user devices. With SAP RISE, any Windows systems are not integrated with the customer's active directory domain. The domain integration isn't necessary for SSO with AD/Kerberos as the domain security token is read on the client device and exchanged securely with SAP system. Contact SAP if you require any changes to integrate AD based SSO or using third party products other than SAP SSO Secure Login Client, as some configuration on RISE managed systems might be required.
For more information about SNC, see Getting started with SAP SNC for RFC integrations - SAP blog.
Identity and Access Management for SAP RISE
Note
SAP announced retirement of SAP Identity Management (SAP IDM) by 2027. SAP recommends to customers to migrate to Microsoft Entra.
Microsoft Entra ID Governance and built-in integrations with SAP Cloud Identity Service are an ideal fit to handle SAP user lifecycle and their authorizations across both eco-systems.
Learn more from this Microsoft Learn article and our SAP scenarios hub.
Microsoft Security Copilot with SAP RISE
Security Copilot is a generative AI security product that empowers security and IT professionals respond to cyber threats, process signals, and assess risk exposure at the speed and scale of AI. It has its own portal and embedded experiences in Microsoft Defender XDR, Microsoft Sentinel, and Intune.
It can be used with any data source that Defender XDR and Sentinel support, including SAP RISE/ECS. Below shows the stand-alone experience.
In addition to that, the Security Copilot experience is embedded on the Defender XDR portal, with an out-of-the-box AI-generated summary and recommendations for SAP.
Microsoft Sentinel with SAP RISE
The SAP RISE certified Microsoft Sentinel Solution for SAP applications allows you to monitor, detect, respond, and correlate suspicious activities in SAP with your other enterprise-wide signals. Microsoft Sentinel guards your critical data against sophisticated cyberattacks for SAP systems hosted on Azure, other clouds, or on-premises infrastructure. Microsoft Sentinel Solution for SAP BTP expands that coverage to SAP Business Technology Platform (BTP).
The solution allows you to gain visibility to user activities on SAP RISE/ECS and the SAP business logic layers and apply Sentinel’s built-in content.
- Use a single console to monitor all your enterprise estate including SAP instances in SAP RISE/ECS on Azure and other clouds, SAP Azure native and on-premises estate
- Detect and automatically respond to threats: detect suspicious activity including privilege escalation, unauthorized changes, sensitive transactions, data exfiltration and more with out-of-the-box detection capabilities
- Correlate SAP activity with other signals: more accurately detect SAP threats by cross-correlating across endpoints, Microsoft Entra data and more
- Customize based on your needs - build your own detections to monitor sensitive transactions and other business risks
- Visualize the data with built-in workbooks
For SAP RISE/ECS, the Microsoft Sentinel Solution for SAP must be deployed in customer's Azure subscription. All parts of the Sentinel solution are managed by customer and not by SAP. The SAP Cloud Connector can be hosted either by SAP in the RISE subscription or by the customer in their network if virtual network connectivity is established.
Note
Alternatively, you can deploy the Microsoft Sentinel solution for SAP applications without using SAP Integration Suite and SAP Cloud Connector. This approach uses an agent-based data connector that requires you to host a container in your own environment — either in your Azure subscription or on-premises infrastructure. Learn more here.
Important
As per the RISE shared responsibility model customers using the Sentinel solution for SAP can only integrate the SAP app layer. SAP RISE infrastructure and operating system logs are only available through the optional SAP LogServ solution. It natively supports Sentinel integration. Learn more here.
Automatic response with Sentinel's SOAR capabilities
Use prebuilt playbooks for security, orchestration, automation and response capabilities (SOAR) to react to threats quickly. A popular first scenario is SAP user blocking with intervention option from Microsoft Teams. The integration pattern can be applied to any incident type and target service spanning towards SAP Business Technology Platform (BTP) or Microsoft Entra ID with regard to reducing the attack surface.
For more information on Microsoft Sentinel and SOAR for SAP, see the blog series From zero to hero security coverage with Microsoft Sentinel for your critical SAP security signals.
For more information on Microsoft Sentinel and SAP, including a deployment guide, see Sentinel product documentation.
Azure Monitoring for SAP with SAP RISE
Azure Monitor for SAP solutions is an Azure-native solution for monitoring your SAP system. It extends the Azure monitor platform monitoring capability with support to gather data about SAP NetWeaver, database, and operating system details.
SAP RISE/ECS is a fully managed service for your SAP landscape and thus Azure Monitoring for SAP is not intended to be utilized for such managed environment. SAP RISE/ECS doesn't support any integration with Azure Monitor for SAP solutions. SAP's own monitoring and reporting is used and provided to the customer as defined by your service description with SAP.
Azure Center for SAP Solutions
As with Azure Monitoring for SAP solutions, SAP RISE/ECS doesn't support any integration with Azure Center for SAP Solutions in any capability. All SAP RISE workloads are deployed by SAP and running in SAP's Azure tenant and subscription, without any access by customer to the Azure resources.
Next steps
Check out the documentation: