https://raw.githubusercontent.com/ajmaradiaga/feeds/main/scmt/topics/Security-blog-posts.xmlSAP Community - Security2026-07-24T20:01:44.505031+00:00python-feedgenSecurity blog posts in SAP Communityhttps://community.sap.com/t5/technology-blog-posts-by-sap/configuring-custom-grc-nwbc-launch-screens-restricted-via-pfcg-roles/ba-p/14378550Configuring custom GRC NWBC Launch Screens restricted via PFCG roles2026-04-22T06:00:00.054000+02:00akshay_j_001https://community.sap.com/t5/user/viewprofilepage/user-id/2200439<P><FONT face="verdana,geneva" size="4"><STRONG>Challenge:</STRONG> Standard SAP GRC roles for NetWeaver Business Client (NWBC) grant excessive access privileges that exceed users' actual job requirements. This over-provisioning creates security risks and poor user experience, as users encounter numerous irrelevant hyperlinks and folders they don't need for their daily tasks.</FONT></P><P><FONT face="verdana,geneva" size="4"><STRONG>Implementation Approach:</STRONG> The solution leverages transaction LPD_CUST (Configure Launchpad for Menus) to design custom NWBC landing pages. This involves copying standard Webdynpro application configuration, component configuration and UIBB component in which LPD_CUST role is linked.</FONT></P><P><FONT face="verdana,geneva" size="4">In this blog, the detailed steps for configuring LPD_CUST, Web Dynpro Configuration and PFCG mapping is highlighted.</FONT></P><P><FONT face="verdana,geneva" size="4"><STRONG>Environment:</STRONG> GRC Access Control 12.0</FONT></P><P><FONT face="verdana,geneva" size="4"><STRONG>Launchpad Flow chart:</STRONG></FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_0-1776742212948.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400602i2BE7253BE59CE40E/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_0-1776742212948.png" alt="akshay_j_001_0-1776742212948.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4"><STRONG>Section 1: LPD_CUST launchpad customisation </STRONG></FONT></P><P><FONT face="verdana,geneva" size="4">In Tcode LPD_CUST, we need to define the customization that is required for the workset, here we have considered GRACHOME (GRC Access Control Home Workset). It is recommended to take a copy of this workset to custom naming convention to preserve standard configuration.</FONT></P><P><FONT face="verdana,geneva" size="4">Select line item GRACHOME, Click on copy.</FONT></P><DIV class=""><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_1-1776742292548.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400603i36F22A4D22F440A7/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_1-1776742292548.png" alt="akshay_j_001_1-1776742292548.png" /></span></FONT><P> </P></DIV><P> </P><P><FONT face="verdana,geneva" size="4">Enter your custom values and namespace.</FONT></P><DIV class=""><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_2-1776742334089.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400606i92E4B2306910DBA9/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_2-1776742334089.png" alt="akshay_j_001_2-1776742334089.png" /></span></FONT><P> </P></DIV><P> </P><P><FONT face="verdana,geneva" size="4">In ZGRACHOME, You can make all the required customisations. Here, for simplicity, I have modified the folder name to ‘Work Inbox - CUSTOM’.</FONT></P><P><FONT face="verdana,geneva" size="4">Potential Use case 1: For Approvers users, you can keep only ‘Work Inbox’, Delete ‘Work Inbox - Simplified’ to make it more clear to users as to which one to use.</FONT></P><P><FONT face="verdana,geneva" size="4">Potential Use case 2: In Application help, You can place company’s intranet URL link that points to a guide on how to review and approve requests. For this, you can create ‘New Application’ , select application type ‘URL’ and add the required URL.</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_3-1776742490727.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400608i8EA66E869AF0898D/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_3-1776742490727.png" alt="akshay_j_001_3-1776742490727.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">You can follow the same steps to customize Setup, Access Management, Reports and Analytics Webdynpro Application</FONT></P><P> </P><P><FONT face="verdana,geneva" size="4"><STRONG>Section 2: NWBC Webdynpro customisation </STRONG></FONT></P><P><FONT face="verdana,geneva" size="4">In tcode PFCG, copy standard role SAP_GRAC_NWBC to custom role Z_TEST_NWBC,</FONT></P><P><FONT face="verdana,geneva" size="4">Tcode PFCG -> Z_TEST_NWBC</FONT></P><P><FONT face="verdana,geneva" size="4">Here, we are customizing the ‘My Home’ Webdynpro application GRFN_SERVICE_MAP.</FONT></P><P><FONT face="verdana,geneva" size="4">Right click on ‘My Home’ Webdynpro application -> Details</FONT></P><P><FONT face="verdana,geneva" size="4">We see the standard Configuration: GRAC_FPM_AC_LPD_HOME. We want to customize this Application Configuration to point our desired ‘My Home’ Layout in NWBC which we configured in LPD_CUST.</FONT></P><P><FONT face="verdana,geneva" size="4">Click on ‘Application Configuration’ button.</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_4-1776742522269.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400609iCD98D1A9A4AE7195/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_4-1776742522269.png" alt="akshay_j_001_4-1776742522269.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">This will launch a web URL which takes you to application configuration.</FONT></P><DIV class=""><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_5-1776742551696.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400610i3913BAA8193991F3/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_5-1776742551696.png" alt="akshay_j_001_5-1776742551696.png" /></span></FONT><P> </P><P> </P><FONT face="verdana,geneva" size="4">From here on, the logic is that we copy the Application Configuration, Component Configuration, UIBB Configuration and In UIBB configuration we point it to Role /instance of LPD_CUST. Refer to the flowchart.</FONT></DIV><P><FONT face="verdana,geneva" size="4">Step 1: Create Copy of Application Configuration.</FONT></P><DIV class=""><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_6-1776742619965.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400615iC95AB0B5A510095D/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_6-1776742619965.png" alt="akshay_j_001_6-1776742619965.png" /></span></FONT></DIV><DIV class=""> </DIV><DIV class=""><FONT face="verdana,geneva" size="4"><SPAN>Click on Other Functions -> New Window -> Copy</SPAN></FONT><P> </P></DIV><DIV class=""><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_7-1776742662021.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400616iD076D939B7F51A15/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_7-1776742662021.png" alt="akshay_j_001_7-1776742662021.png" /></span></FONT><P> </P></DIV><DIV class=""> </DIV><P><FONT face="verdana,geneva" size="4">Provide custom configuration ID and description</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_8-1776742703714.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400617i1F5FAD9DC12148FD/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_8-1776742703714.png" alt="akshay_j_001_8-1776742703714.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">Select the relevant package, here I chose $TMP (Non-transportable), Click OK.</FONT></P><DIV class=""><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_9-1776742744451.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400618i410119410B171B0E/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_9-1776742744451.png" alt="akshay_j_001_9-1776742744451.png" /></span></FONT><P> </P></DIV><P> </P><P><FONT face="verdana,geneva" size="4">Click Change</FONT></P><DIV class=""><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_10-1776742783331.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400619i54B128EC51042ECA/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_10-1776742783331.png" alt="akshay_j_001_10-1776742783331.png" /></span></FONT><P> </P></DIV><P><FONT face="verdana,geneva" size="4">We enter into the custom application configuration Z1GRAC_FPM_AC_LPD_HOME</FONT></P><P><FONT face="verdana,geneva" size="4">Click on hyper link GRAC_FPM_CC_LPD_HOME</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_11-1776742827879.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400620i2A0BC322AAFA7B4D/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_11-1776742827879.png" alt="akshay_j_001_11-1776742827879.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">You will reach Component Configuration screen as below</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_12-1776742858727.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400621i3AE99DA67441670D/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_12-1776742858727.png" alt="akshay_j_001_12-1776742858727.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">Step 2: Create copy of component configuration</FONT></P><P><FONT face="verdana,geneva" size="4">Click on Other Functions -> New Window -> Copy</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_13-1776742906635.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400622i3BC014503FF16043/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_13-1776742906635.png" alt="akshay_j_001_13-1776742906635.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">Provide the custom configuration ID and description</FONT></P><DIV class=""><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_14-1776742938516.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400623iFB874620942F4F21/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_14-1776742938516.png" alt="akshay_j_001_14-1776742938516.png" /></span></FONT><P> </P></DIV><P><FONT face="verdana,geneva" size="4">Enter the desired package</FONT></P><DIV class=""><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_15-1776742961791.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400624iA8CB3C4417E69229/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_15-1776742961791.png" alt="akshay_j_001_15-1776742961791.png" /></span></FONT><P> </P></DIV><P><FONT face="verdana,geneva" size="4">Click Change</FONT></P><DIV class=""><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_16-1776742997893.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400625i877A5697B8C8CD15/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_16-1776742997893.png" alt="akshay_j_001_16-1776742997893.png" /></span></FONT><P> </P></DIV><P><FONT face="verdana,geneva" size="4">Click on Edit -> Cancel to get in Display mode, Click on hyperlink ‘GRAC_FPM_UIBB_LPD_HOME’</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_17-1776743055560.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400626i2C7B59883A104B5C/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_17-1776743055560.png" alt="akshay_j_001_17-1776743055560.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">Step 3: Create copy of UIBB configuration</FONT></P><P><FONT face="verdana,geneva" size="4">In this window, Click on Other Functions -> New Window</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_18-1776743090388.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400627iE76E871A6C656CCF/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_18-1776743090388.png" alt="akshay_j_001_18-1776743090388.png" /></span></FONT></P><P><FONT face="verdana,geneva" size="4">Click Copy</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_19-1776743274411.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400628i284FDA62B70502CA/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_19-1776743274411.png" alt="akshay_j_001_19-1776743274411.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">Provide the custom configuration ID and description</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_20-1776743357557.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400629i1C44B3B8C49BECBD/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_20-1776743357557.png" alt="akshay_j_001_20-1776743357557.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">Click Change.</FONT></P><P><FONT face="verdana,geneva" size="4">In this window, we need to map ZGRACHOME in Role field (earlier created in LPD_CUST).</FONT></P><P><FONT face="verdana,geneva" size="4">Change it to ZGRACHOME. All the customizations done in ZGRACHOME can be previewed. Notice that we had changed folder ‘Work Inbox – CUSTOM’ in this scenario.</FONT></P><P><FONT face="verdana,geneva" size="4">Click Save.</FONT></P><P><FONT face="verdana,geneva" size="4">Select the TR and Click OK</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_21-1776743402433.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400630i988ABBDE883E1635/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_21-1776743402433.png" alt="akshay_j_001_21-1776743402433.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4"><STRONG>Section 3: PFCG Role Configuration mapping</STRONG></FONT></P><P><FONT face="verdana,geneva" size="4">Step 1: In tcode PFCG, Role Z_TEST_NWBC</FONT></P><P><FONT face="verdana,geneva" size="4">Right click on ‘My Home’ -> Details -> Change configuration to Z1GRAC_FPM_AC_LPD_HOME</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_22-1776743455256.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400631i5947D7917FB25A88/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_22-1776743455256.png" alt="akshay_j_001_22-1776743455256.png" /></span></FONT></P><P><FONT face="verdana,geneva" size="4">Click Save</FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">Step 2: Again, Right click on ‘My Home’ -> Details -> Click Application Configuration.</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_23-1776743501703.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400632iD767AEC0F3C7B154/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_23-1776743501703.png" alt="akshay_j_001_23-1776743501703.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">This will open up URL in web browser, we see that we are in custom application configuration Z1GRAC_FPM_AC_LPD_HOME, we see standard component configuration is mapped, we will need to change to custom component configuration Z1GRAC_FPM_CC_LPD_HOME</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_24-1776743540572.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400633iB6245CD0D0B4E310/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_24-1776743540572.png" alt="akshay_j_001_24-1776743540572.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">Click on Edit -> Assign Configuration Name</FONT></P><P><FONT face="verdana,geneva" size="4">Assign the custom component configuration ID Z1GRAC_FPM_CC_LPD_HOME</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_25-1776743582417.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400634i2163E327C05E7A73/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_25-1776743582417.png" alt="akshay_j_001_25-1776743582417.png" /></span></FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_26-1776743631085.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400635i0E45528B47A0A7E4/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_26-1776743631085.png" alt="akshay_j_001_26-1776743631085.png" /></span></FONT></P><P><FONT face="verdana,geneva" size="4">Click Save.</FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">Step 3: Click the hyperlink Z1GRAC_FPM_CC_LPD_HOME</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_27-1776743747022.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400636iF1C3A945B9C7F27B/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_27-1776743747022.png" alt="akshay_j_001_27-1776743747022.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">This will open up Custom component configuration, we see that standard UIBB is mapped, but we need to change to custom UIBB Z1GRAC_FPM_UIBB_LPD_HOME</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_28-1776743777678.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400637iE3685DA9006BF8E5/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_28-1776743777678.png" alt="akshay_j_001_28-1776743777678.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">Click on F4 button on GRAC_FPM_UIBB_LPD_HOME, change it to Z1GRAC_FPM_UIBB_LPD_HOME</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_29-1776743811437.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400638iE1A947DCDB833DF6/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_29-1776743811437.png" alt="akshay_j_001_29-1776743811437.png" /></span></FONT></P><P><FONT face="verdana,geneva" size="4">Click Save</FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">Step 4: Click on Edit -> Cancel. We are in display mode. Click on hyperlink Z1GRAC_FPM_UIBB_LPD_HOME</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_30-1776743846544.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400639i174AF3BCB8EEA68E/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_30-1776743846544.png" alt="akshay_j_001_30-1776743846544.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">You will find all the elements mapped as per the flowchart</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_31-1776743875220.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400640i0E86B521CAF0A434/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_31-1776743875220.png" alt="akshay_j_001_31-1776743875220.png" /></span></FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_32-1776743892260.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400641i381A6E663FCBCDC7/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_32-1776743892260.png" alt="akshay_j_001_32-1776743892260.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">Assign the PFCG role Z_TEST_NWBC to user and test the changes. Or you can Right click on ‘My Home’ -> Execute.</FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_33-1776743932459.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400642i85AE5E5CA2AF199B/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_33-1776743932459.png" alt="akshay_j_001_33-1776743932459.png" /></span></FONT></P><P> </P><P><FONT face="verdana,geneva" size="4">The customisation done in LPD_CUST reflects. </FONT></P><P><FONT face="verdana,geneva" size="4"><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akshay_j_001_34-1776743977408.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/400643iEFEA6B65A6D32B2E/image-size/large?v=v2&px=999" role="button" title="akshay_j_001_34-1776743977408.png" alt="akshay_j_001_34-1776743977408.png" /></span></FONT></P><P><FONT face="verdana,geneva" size="4">NOTE: If you assign standard role SAP_GRAC_NWBC and custom role Z_TEST_NWBC together to a user, this won’t work as intended since the system is confused whether to pick up the standard application configuration or the custom application configuration defined in the Webdynpro application GRFN_SERVICE_MAP. The intent of creating the custom role is to assign that specific custom role Z_TEST_NWBC to satisfy all NWBC access requirements for the user.</FONT></P><P><FONT face="verdana,geneva" size="4">You can follow the same steps to customize Setup, Access Management, Reports and Analytics Webdynpro Application.</FONT></P><P> </P><P><STRONG><FONT face="verdana,geneva" size="4">Conclusion:</FONT></STRONG></P><P><FONT face="verdana,geneva" size="4">You have now successfully created a custom PFCG role with Web Dynpro application configuration pointing to Custom NWBC screen. </FONT></P><P> </P>2026-04-22T06:00:00.054000+02:00https://community.sap.com/t5/technology-blog-posts-by-sap/advancements-in-cloud-alm-and-configuration-amp-security-analysis/ba-p/14380396Advancements in Cloud ALM and Configuration & Security Analysis application2026-04-22T12:10:46.912000+02:00AnisaTuscanohttps://community.sap.com/t5/user/viewprofilepage/user-id/2003264<P><SPAN><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Advancements in Cloud ALM Blog banner.jpg" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401386iDCB1A2787EB59151/image-size/large?v=v2&px=999" role="button" title="Advancements in Cloud ALM Blog banner.jpg" alt="Advancements in Cloud ALM Blog banner.jpg" /></span></SPAN></P><P><SPAN>As SAP landscapes grow and become more hybrid, maintaining </SPAN><SPAN>a </SPAN><SPAN>secure and compliant system configuration</SPAN><SPAN> is no longer a one-time task - it’s</SPAN><SPAN> an ongoing responsibility. </SPAN><SPAN> </SPAN></P><P><SPAN>The Configuration & Security Analysis (CSA) application in SAP Cloud ALM Operations is designed to support exactly this. This blog walks you through the new </SPAN><SPAN>a</SPAN><SPAN>dvancements in the </SPAN><SPAN>SAP </SPAN><SPAN>Cloud ALM and Configuration Analysis </SPAN><SPAN>a</SPAN><SPAN>pplication.</SPAN><SPAN> </SPAN></P><P><SPAN>The </SPAN><SPAN>g</SPAN><SPAN>oal is to make sure that all </SPAN><SPAN>c</SPAN><SPAN>loud </SPAN><SPAN>s</SPAN><SPAN>ervices are operat</SPAN><SPAN>ing</SPAN><SPAN> </SPAN><SPAN>and </SPAN><SPAN>compliant to applicable audit standards and with an acceptable security posture.</SPAN><SPAN> </SPAN></P><H3 id="toc-hId-1924087655"><SPAN><span class="lia-unicode-emoji" title=":glowing_star:">🌟</span>What’s New?</SPAN><SPAN> </SPAN></H3><P><SPAN>You can now:</SPAN><SPAN> </SPAN></P><P><STRONG><SPAN><span class="lia-unicode-emoji" title=":heavy_check_mark:">✔️</span> Validate</SPAN></STRONG><SPAN> your systems and services against </SPAN><SPAN> </SPAN><STRONG><SPAN>SAP </SPAN></STRONG><SPAN><STRONG>s</STRONG></SPAN><STRONG><SPAN>ecurity </SPAN></STRONG><SPAN><STRONG>b</STRONG></SPAN><STRONG><SPAN>aseline - </SPAN></STRONG><A href="https://support.sap.com/en/offerings-programs/support-services/security-optimization-services-portfolio.html?anchorId=section" target="_blank" rel="noopener noreferrer">SAP Security Optimization Services</A> </P><P><SPAN><span class="lia-unicode-emoji" title=":heavy_check_mark:">✔️</span>Display the </SPAN><STRONG><SPAN>compliance status</SPAN></STRONG><SPAN> for your favourite systems in the </SPAN><STRONG><SPAN>CSA Home screen.</SPAN></STRONG><SPAN> </SPAN></P><P><STRONG><SPAN><span class="lia-unicode-emoji" title=":heavy_check_mark:">✔️</span>Restrict access </SPAN></STRONG><SPAN>of users to specific services and systems.</SPAN><SPAN> </SPAN></P><P><SPAN><span class="lia-unicode-emoji" title=":heavy_check_mark:">✔️</span>Create <STRONG>notifications</STRONG></SPAN><STRONG><SPAN>, </SPAN></STRONG><SPAN><STRONG>a</STRONG></SPAN><STRONG><SPAN>lerts and </SPAN></STRONG><SPAN><STRONG>t</STRONG></SPAN><STRONG><SPAN>ickets.</SPAN></STRONG><SPAN> </SPAN><SPAN> </SPAN></P><P><SPAN>For more information kindly visit : <A href="https://help.sap.com/docs/cloud-alm/applicationhelp/configuration-security-analysis" target="_blank" rel="noopener noreferrer">Configuration & Security Analysis</A> </SPAN></P><H3 id="toc-hId-1727574150"><STRONG><SPAN><span class="lia-unicode-emoji" title=":link:">🔗</span>Stay connected</SPAN></STRONG><SPAN> </SPAN></H3><P><SPAN>Want to stay up to date on our services? Join our <A href="https://community.sap.com/t5/sap-cloud-alm-cross-solution-topics-value-map/gh-p/alm-cross-vm" target="_blank">SAP Cloud ALM & Cross-Solution Topics</A> </SPAN><SPAN>community!</SPAN><SPAN> </SPAN></P>2026-04-22T12:10:46.912000+02:00https://community.sap.com/t5/technology-blog-posts-by-sap/high-availability-setup-for-sap-secure-login-service-with-aws-route-53/ba-p/14380911High-Availability Setup for SAP Secure Login Service with AWS Route 532026-04-23T00:01:25.054000+02:00Jayesh_Kothari87https://community.sap.com/t5/user/viewprofilepage/user-id/1579923<H2 id="toc-hId-1734053448" id="toc-hId-1795010449"><SPAN>Introduction</SPAN></H2><P>Inspired by the initial blog by our Product team members</P><P><A href="https://community.sap.com/t5/technology-blog-posts-by-sap/high-availability-setup-for-sap-secure-login-service-with-microsoft-azure/ba-p/14140475" target="_blank">https://community.sap.com/t5/technology-blog-posts-by-sap/high-availability-setup-for-sap-secure-login-service-with-microsoft-azure/ba-p/14140475</A></P><P>SAP Secure Login Service for SAP GUI enables secure authentication and single sign-on (SSO) for SAP GUI using SAP BTP, leveraging its built-in <SPAN><A href="https://help.sap.com/docs/btp/sap-business-technology-platform/resilience-high-availability-and-disaster-recovery?version=Cloud" target="_self" rel="noopener noreferrer">platform capabilities for high availability</A> </SPAN></P><P>In most cases, this is sufficient, as the service is only used during the user’s initial login. Once authenticated, an X.509 certificate provides SSO for the rest of the session.</P><P>However, some organizations require higher resilience and opt for a multi-region failover setup. In this blog, I’ll walk through how to implement this using <STRONG>SAP Secure Login Service, SAP BTP Custom Domain Service, and AWS Route 53.</STRONG></P><P><FONT size="5"><STRONG>Architecture </STRONG></FONT></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_0-1776893513558.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401592i3552FF26BF5BEAB4/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_0-1776893513558.png" alt="Jayesh8887_0-1776893513558.png" /></span></P><H2 id="toc-hId-1598496944">Prerequisites</H2><H3 id="toc-hId-1531066158">SAP BTP</H3><UL><LI>Two subaccounts in different regions (e.g. US10, US21, EU10 etc). For this blog i have used US10 and EU10.</LI><LI>SLS subscribed in both subaccounts</LI><LI>Custom Domain Service entitlement assigned and activated in both subaccounts</LI></UL><H3 id="toc-hId-1334552653">AWS</H3><UL><LI>Route 53 hosted zone for your domain</LI></UL><H3 id="toc-hId-1138039148">Identity</H3><UL><LI>IAS tenants configured with SLS</LI></UL><H3 id="toc-hId-941525643">Certificates</H3><UL><LI>TLS certificate for sls.yourdomain.com (from a public CA)</LI></UL><H2 id="toc-hId-615929419">Step 1: Configure Custom Domain Service — US10 (Primary)</H2><P>In the US10 subaccount, open Custom Domain Manager and complete the following:</P><P>Reserve domain: yourdomain.com</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_1-1776893590670.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401594i05EC711C7B92D097/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_1-1776893590670.png" alt="Jayesh8887_1-1776893590670.png" /></span></P><P>Create custom domain: sls.yourdomain.com</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_2-1776893590674.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401593i4DE008332D046C26/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_2-1776893590674.png" alt="Jayesh8887_2-1776893590674.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_3-1776893590679.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401595iB3A512EA7DAC5114/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_3-1776893590679.png" alt="Jayesh8887_3-1776893590679.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_4-1776893590690.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401598iA07403D8B52FAD49/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_4-1776893590690.png" alt="Jayesh8887_4-1776893590690.png" /></span> </P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_5-1776893590694.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401596i90AA20DB41CB1549/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_5-1776893590694.png" alt="Jayesh8887_5-1776893590694.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_6-1776893590700.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401597iF363392478DB2A0D/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_6-1776893590700.png" alt="Jayesh8887_6-1776893590700.png" /></span></P><P><STRONG>Create a SaaS route: map sls.yourdomain.com to the SLS subscription</STRONG></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_7-1776893590702.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401599i9693A6816A005EEB/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_7-1776893590702.png" alt="Jayesh8887_7-1776893590702.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_2-1776895858102.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401630iA8EF283D9FF63A0B/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_2-1776895858102.png" alt="Jayesh8887_2-1776895858102.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_3-1776895891100.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401631i2597041E5D128FDD/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_3-1776895891100.png" alt="Jayesh8887_3-1776895891100.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_10-1776893590726.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401603i0D5225A10A4C50C6/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_10-1776893590726.png" alt="Jayesh8887_10-1776893590726.png" /></span> </P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_4-1776895938427.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401632i208D8996590511D4/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_4-1776895938427.png" alt="Jayesh8887_4-1776895938427.png" /></span></P><P><STRONG>Perform TLS configurations</STRONG></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_12-1776893590736.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401602i15F8546D6559A774/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_12-1776893590736.png" alt="Jayesh8887_12-1776893590736.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_13-1776893590739.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401606iE5F8BADDD129C0AC/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_13-1776893590739.png" alt="Jayesh8887_13-1776893590739.png" /></span></P><P><STRONG>Create a Server Identity and generate a CSR (Certificate Signing Request)</STRONG></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_14-1776893590742.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401607i144414A7DBAA9B7B/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_14-1776893590742.png" alt="Jayesh8887_14-1776893590742.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_15-1776893590746.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401605i1F4FA5BECED6947E/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_15-1776893590746.png" alt="Jayesh8887_15-1776893590746.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_16-1776893590752.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401608iD14420AF513A12E4/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_16-1776893590752.png" alt="Jayesh8887_16-1776893590752.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_17-1776893590757.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401609iDC8A60F837FFF4A0/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_17-1776893590757.png" alt="Jayesh8887_17-1776893590757.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_18-1776893590762.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401610iBF8AB26969AD99E8/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_18-1776893590762.png" alt="Jayesh8887_18-1776893590762.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_19-1776893590767.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401611i2FD496033B3BE840/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_19-1776893590767.png" alt="Jayesh8887_19-1776893590767.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_20-1776893590773.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401613i0A1321D5866E79D8/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_20-1776893590773.png" alt="Jayesh8887_20-1776893590773.png" /></span></P><P><STRONG>Obtain a TLS certificate from a public CA using the CSR and Upload the full certificate chain and activate it</STRONG></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_21-1776893590791.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401612iABD9D97E5DBF94BF/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_21-1776893590791.png" alt="Jayesh8887_21-1776893590791.png" /></span></P><P><STRONG>Activate it</STRONG></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_22-1776893590796.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401614iE6F0490C1C43C901/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_22-1776893590796.png" alt="Jayesh8887_22-1776893590796.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_23-1776893590801.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401616i5F2DD9B8A8D9F421/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_23-1776893590801.png" alt="Jayesh8887_23-1776893590801.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_24-1776893590805.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401615iB648F14AC8FEF6C0/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_24-1776893590805.png" alt="Jayesh8887_24-1776893590805.png" /></span></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_25-1776893590810.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401618i59DCDAEE64E54403/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_25-1776893590810.png" alt="Jayesh8887_25-1776893590810.png" /></span></P><P>Note the <STRONG>CNAME target</STRONG> shown under "DNS CNAME Recommendation" — you will need this exact value for Route 53</P><P><STRONG>About the CNAME target</STRONG><BR />The CNAME target provided by Custom Domain Manager is SAP's ingress hostname for SaaS routes in the US10 region. Use exactly what Custom Domain Manager shows. Do not substitute or guess any hostname.</P><H2 id="toc-hId-419415914">Step 2: Configure Custom Domain Service — EU10 (Secondary)</H2><P>Repeat exactly the same steps in the EU10 subaccount. Use the <STRONG>same custom domain</STRONG>: sls.yourdomain.com.</P><P>Note the CNAME target for EU10 as well.</P><P><STRONG>Why the same hostname in both subaccounts?</STRONG><BR />Each subaccount independently maps sls.yourdomain.com to its local SLS SaaS instance. This is fully supported by Custom Domain Service. Both instances respond to the same hostname, which is what makes Route 53 failover work transparently. Route 53 resolves sls.yourdomain.com to the CNAME target of whichever region is active — and that region's SLS instance is already configured to serve requests for that hostname.</P><H2 id="toc-hId-222902409">Step 3: Configure IAS Redirect URI</H2><P>In your IAS tenants, add the following as an allowed redirect URI for the SLS application:</P><P><A href="https://sls.yourdomain.com/login/callback" target="_blank" rel="noopener nofollow noreferrer">https://sls.yourdomain.com/login/callback</A></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_6-1776896196693.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401634iA1A4EB8D7D00E0D6/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_6-1776896196693.png" alt="Jayesh8887_6-1776896196693.png" /></span></P><P> </P><P>Keep all existing redirect URIs — just add this one. Because both SLS instances share the same hostname, this single redirect URI covers both regions regardless of which instance handles the authentication request.</P><P><FONT color="#FF0000"> <STRONG>Each SLS instance uses a separate IAS tenant, add this redirect URI in both tenants ( US10 and EU10)</STRONG></FONT></P><H2 id="toc-hId-26388904">Step 4: Configure Route 53 Failover Routing</H2><H3 id="toc-hId--116273251">Health Checks</H3><P>Create two Route 53 health checks — one per SLS instance — targeting each SLS instance hostname directly:</P><P><STRONG>Health Check 1 (Primary — US10):</STRONG></P><UL><LI>Protocol: HTTPS</LI><LI>Endpoint: <your-us10-sls-hostname> (the actual SLS instance hostname in US10, e.g. yourinstance.us10.sls.cloud.sap)</LI><LI>Path: /health</LI><LI>Port: 443</LI><LI>Purpose: Monitors US10 SLS instance directly</LI></UL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_5-1776896022387.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401633i5ED71EF3E6537FBA/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_5-1776896022387.png" alt="Jayesh8887_5-1776896022387.png" /></span></P><P><STRONG>Health Check 2 (Secondary — EU10):</STRONG></P><UL><LI>Protocol: HTTPS</LI><LI>Endpoint: <your-eu10-sls-hostname> (the actual SLS instance hostname in EU10, e.g. yourinstance.eu10.sls.cloud.sap)</LI><LI>Path: /health</LI><LI>Port: 443</LI><LI>Purpose: Monitors EU10 SLS instance directly</LI></UL><P>(like primary US10 setup)</P><P><STRONG>Why target the SLS instance hostname directly?</STRONG><BR />The health checks must target each SLS instance hostname directly — not sls.yourdomain.com. At any point in time, sls.yourdomain.com only resolves to the currently active region. A health check on sls.yourdomain.com would only monitor whichever instance Route 53 is currently routing to, and would never detect that the primary is down (because Route 53 would have already switched). By monitoring each SLS instance hostname independently, Route 53 can detect failures in either region at any time.</P><H3 id="toc-hId--312786756">CNAME records for failover</H3><H3 id="toc-hId--509300261">Primary Record</H3><P><FONT size="3">Name: sls.yourdomain.com</FONT></P><P><FONT size="3">Type: CNAME</FONT></P><P><FONT size="3">Value: api.cf.us10.hana.ondemand.com</FONT></P><P><FONT size="3">Routing policy: Failover — PRIMARY</FONT></P><P><FONT size="3">Health check: Yes (associate Health Check 1 — US10)</FONT></P><H3 id="toc-hId--705813766"> </H3><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_28-1776893590824.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401620i31B9678AC180B6D3/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_28-1776893590824.png" alt="Jayesh8887_28-1776893590824.png" /></span></P><P> </P><H3 id="toc-hId--902327271">Secondary Record</H3><P>Similarly for Secondary</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_29-1776893590826.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401621i0E809C16546F20E6/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_29-1776893590826.png" alt="Jayesh8887_29-1776893590826.png" /></span></P><P> </P><P><STRONG>TTL recommendation</STRONG><BR />Could set TTL to 60 seconds. A lower TTL means faster DNS propagation during failover events.</P><H2 id="toc-hId--805437769">Step 5: Configure SAP Secure Login Client</H2><P>Configure SAP Secure Login Client (SLC) with the SLS URL pointing to your custom domain:</P><P><A href="https://sls.yourdomain.com/slc/v1/login" target="_blank" rel="noopener nofollow noreferrer">https://sls.yourdomain.com/slc/v1/login</A></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jayesh8887_30-1776893590835.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401622i75206A21C6FE41D1/image-size/large?v=v2&px=999" role="button" title="Jayesh8887_30-1776893590835.png" alt="Jayesh8887_30-1776893590835.png" /></span></P><P> </P><P> </P><P>Distribute this configuration via:</P><UL><LI>GPO (Group Policy Object)</LI><LI>Intune</LI><LI>SCCM</LI></UL><P>Because the URL always points to sls.yourdomain.com, no SLC reconfiguration is needed when a failover occurs. Route 53 changes the DNS resolution transparently.</P><H2 id="toc-hId--1001951274">Failover Behavior</H2><TABLE width="100%"><TBODY><TR><TD><P><STRONG>Scenario</STRONG></P></TD><TD><P><STRONG>Result</STRONG></P></TD></TR><TR><TD><P>Primary healthy</P></TD><TD><P>Traffic → US10 SLS SaaS instance</P></TD></TR><TR><TD><P>Primary fails health check</P></TD><TD><P>Route 53 switches DNS to EU10 CNAME target</P></TD></TR><TR><TD><P>Primary recovers</P></TD><TD><P>Route 53 switches traffic back to US10</P></TD></TR></TBODY></TABLE><H3 id="toc-hId--1491867786">Failover Timing</H3><UL><LI>Health check detection: ~30–90 seconds</LI><LI>DNS TTL propagation: ~60 seconds</LI><LI>Total worst-case failover time: approximately 2 minutes</LI></UL><DIV class=""> </DIV><P> </P><H2 id="toc-hId--1394978284">Important Considerations</H2><OL><LI><STRONG>Failover Is NOT Session-Aware</STRONG><BR />Active login flows that are in progress during a failover event may fail. Users may need to retry authentication. Design user communications accordingly and set expectations with support teams.</LI><LI><STRONG>SLS Instances Are Independent</STRONG><BR />Both SLS instances must be kept in sync manually. This includes IAS configuration, authentication policies, certificate trust configuration, and version levels. Drift between instances can cause inconsistent behavior depending on which region is active.</LI><LI><STRONG>Certificate Strategy</STRONG><BR />You can use the same TLS certificate (same Subject Alternative Name) across both regions for simplicity, since both Custom Domain Manager instances are serving the same hostname. Alternatively, use separate certificates per region for better security isolation. Either approach is valid.</LI><LI><STRONG>Health Checks on Both Records</STRONG><BR />It is recommended to add health checks on both primary and secondary records. Without a health check on the secondary, Route 53 may route traffic to a failed secondary during a primary failover, resulting in an outage even though the primary was available.</LI></OL><H2 id="toc-hId--1591491789">Testing</H2><H3 id="toc-hId--1913224610">1. DNS Verification</H3><P>nslookup sls.yourdomain.com</P><P>Confirm it resolves to the US10 CNAME target under normal conditions.</P><H3 id="toc-hId--2109738115">2. End-to-End Login</H3><P>Open SAP GUI Secure Login Client and authenticate end-to-end. Confirm the full OIDC flow completes, including the redirect back to sls.yourdomain.com/login/callback.</P><H3 id="toc-hId-1988715676">3. Failover Simulation</H3><P>Disable the primary health check in Route 53. Wait approximately 2 minutes, then run:</P><P>nslookup sls.yourdomain.com</P><P>Confirm it now resolves to the EU10 CNAME target.</P><H3 id="toc-hId-1792202171">4. Secondary Authentication</H3><P>Verify that authentication still works end-to-end when Route 53 is routing to the EU10 instance.</P><H3 id="toc-hId-1595688666">5. Failback</H3><P>Re-enable the primary health check. After the TTL expires, confirm DNS resolves back to the US10 CNAME target and authentication continues to work.</P><P><STRONG><FONT size="4">SAP Backend user mapping</FONT></STRONG></P><P>There are<SPAN> </SPAN><STRONG>two options to ensure that the SNC mapping remains intact</STRONG>:</P><UL><LI>Use parameters of the SAP Cryptographic Library to<SPAN> </SPAN><STRONG>strip the region names from the certificate subject</STRONG><SPAN> </SPAN>before the mapping takes place. That way, certificates from different regions will match the same SNC name. See note <A href="https://me.sap.com/notes/2338952" target="_self" rel="noopener noreferrer">2338952</A><SPAN> </SPAN>for details.</LI><LI>Change the SAP Secure Login Service configuration to<SPAN> </SPAN><STRONG>use a customer-managed certificate authority</STRONG>. This gives you the option to customize the subject name of the certificate so that it does not include the BTP region.</LI></UL><H2 id="toc-hId-1692578168">Conclusion</H2><P>By combining SAP BTP Custom Domain Service and AWS Route 53 failover routing, you eliminate the single point of failure in SAP GUI authentication. The key enabler is the shared custom domain: both SLS SaaS instances respond to sls.yourdomain.com, making the OIDC redirect_uri consistent across regions regardless of which instance is currently active.</P><P>Route 53 health checks detect failures automatically and update DNS within approximately two minutes. End users and SAP Secure Login Client configurations require no changes when a failover or failback occurs.</P><P><STRONG>Final Takeaway</STRONG><BR />This setup provides:</P><UL><LI>High availability for SAP GUI authentication via a managed SaaS architecture</LI><LI>Transparent DNS-level failover with no client reconfiguration</LI><LI>A consistent OIDC redirect URI across both regions</LI></UL><P> </P><P><a href="https://community.sap.com/t5/c-khhcw49343/SAP+Secure+Login+Service+for+SAP+GUI/pd-p/8fe6cadb-1b5a-4898-b255-8afdc7236971" class="lia-product-mention" data-product="1201-1">SAP Secure Login Service for SAP GUI</a> <a href="https://community.sap.com/t5/user/viewprofilepage/user-id/181868">@Christian_Cohrs1</a> </P>2026-04-23T00:01:25.054000+02:00https://community.sap.com/t5/technology-blog-posts-by-members/key-figure-column-based-security-in-datasphere/ba-p/14380611Key figure / column based security in Datasphere2026-04-23T09:52:00.093000+02:00appel_solar_dkhttps://community.sap.com/t5/user/viewprofilepage/user-id/581632<H2 id="toc-hId-1795007566">Intro</H2><P>Datasphere do not directly support Key figure / column based security. SAP suggests creating separate models or separate tables for key figures and use DAC or separate spaces to protect the key figures which is a lot of extra work and a lot of extra maintenance. We will give an idea to how to solve the problem a bit more dynamic.</P><H2 id="toc-hId-1598494061"><STRONG>Challenge</STRONG></H2><P>We have in principle 3 levels of information about product cost. All can see level A, fewer can see level B and even fever level C. The method we will show use some of the ideas from the general Data Access Control (DAC) to hide secrets, but with our own implementation.</P><H2 id="toc-hId-1401980556"><STRONG>In short:</STRONG></H2><UL><LI>Create a Column DAC table in your permissions / DAC space that contains information about what a user is allowed to see.</LI><LI>The information from the Column DAC table is joined into relevant fact views.</LI><LI>Create calculated measures that will be blank (or zero) if the user is not allowed to see them.</LI><LI>Remove the original "secret" measures from the model.</LI></UL><H2 id="toc-hId-1205467051"><STRONG>The details:</STRONG></H2><P>Like for standard DAC create a table in a separate space where only trusted people can maintain the data.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="appel_solar_dk_0-1776883212485.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401555i77CE28EACDEB8BC7/image-size/medium?v=v2&px=400" role="button" title="appel_solar_dk_0-1776883212485.png" alt="appel_solar_dk_0-1776883212485.png" /></span></P><P>Highest_Cost_Type_Permitted can have default value A. Fill the table with user IDs and their highest cost type permitted.</P><P>Create a helper table CostFactors.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="appel_solar_dk_1-1776883275593.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401556i2D8FD1CCF381CF4E/image-size/medium?v=v2&px=400" role="button" title="appel_solar_dk_1-1776883275593.png" alt="appel_solar_dk_1-1776883275593.png" /></span></P><P>Fill the table with values 1 for visible and 0 / null for not visible</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="appel_solar_dk_3-1776883453656.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401558i66E3ABB359AD03E7/image-size/medium?v=v2&px=400" role="button" title="appel_solar_dk_3-1776883453656.png" alt="appel_solar_dk_3-1776883453656.png" /></span></P><P>The factor fields can be used to multiply like C_COST = C_Factor * <original cost field> which can give a null value. The priority factors can be used to create a measure like Authorized cost = “A_Priority_Factor” * < original A_cost_value> + “BA_Priority_Factor” * < original B_cost_value> + “C_Priority_Factor” * < original C_cost_value> which will give a not null value.</P><P>Now create a view VR_User_Cost_DAC something like</P><pre class="lia-code-sample language-sql"><code>SELECT
1 AS "join_column",
"FilterUser_0"."UserID" AS "UserID",
"TR_CostFactors_1"."Highest_Cost_Type_Permitted" AS "Highest_Cost_Type_Permitted",
"TR_CostFactors_1"."A_Factor" AS "A_Factor",
"TR_CostFactors_1"."B_Factor" AS "B_Factor",
"TR_CostFactors_1"."C_Factor" AS "C_Factor",
"TR_CostFactors_1"."A_Priority_Factor" AS "A_Priority_Factor",
"TR_CostFactors_1"."B_Priority_Factor" AS "B_Priority_Factor",
"TR_CostFactors_1"."C_Priority_Factor" AS "C_Priority_Factor"
FROM ((SELECT "TR_CostPermission_2"."UserID",
"TR_CostPermission_2"."Highest_Cost_Type_Permitted"
FROM "TR_CostPermission" AS "TR_CostPermission_2"
WHERE upper("TR_CostPermission_2"."UserID") = session_context('APPLICATIONUSER')) AS "FilterUser_0"
INNER JOIN
"TR_CostFactors_ZZ" AS "TR_CostFactors_1" ON "FilterUser_0"."Highest_Cost_Type_Permitted" = "TR_CostFactors_1"."Highest_Cost_Type_Permitted");</code></pre><P>in words find the record for the current user and join to the factor table to get the relevant factors (the SQL was generated from a graphical view...). The only special feature here is the use of session_context('APPLICATIONUSER') to get the current user.</P><H2 id="toc-hId-1008953546"><STRONG>In use</STRONG></H2><P>A fact view containing B or C types of measures must be modified. The example here has a driving table "TR_Salesorder_items":</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="appel_solar_dk_4-1776883512453.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401559i3123854FDF9F9B4A/image-size/medium?v=v2&px=400" role="button" title="appel_solar_dk_4-1776883512453.png" alt="appel_solar_dk_4-1776883512453.png" /></span></P><P><STRONG>Step 1</STRONG> (fx), create artificial “join_column” type integer value 1</P><P><STRONG>Step 2</STRONG> <STRONG>/ 3, Left Join</STRONG> to VR_User_Cost_DAC shared from the permission space</P><P>Join on “join_column” which is just an artificial column with the value 1</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="appel_solar_dk_5-1776883620988.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/401560i3EF1CA60320AE47E/image-size/medium?v=v2&px=400" role="button" title="appel_solar_dk_5-1776883620988.png" alt="appel_solar_dk_5-1776883620988.png" /></span></P><P><STRONG>Step 4)</STRONG> (fx) Create calculated measures like:</P><P>C_Cost = C_Factor * <original C_cost_value></P><P>Authorized_cost = “A_Priority_Factor” * < original A_cost_value> + “BA_Priority_Factor” * < original B_cost_value> + “C_Priority_Factor” * < original C_cost_value></P><P><STRONG>Step 5)</STRONG> Hide original cost measures.</P><P><STRONG>Step 6)</STRONG> Maintain Semantic type on the newly created measures.</P><P>Now B_Cost, C_cost and Authorized_cost will be safe to use.</P><P> </P><P> </P>2026-04-23T09:52:00.093000+02:00https://community.sap.com/t5/technology-platform-learning-group-blog-posts/become-an-sap-certified-security-administrator/ba-p/14384240Become an SAP Certified Security Administrator!2026-04-27T18:16:38.460000+02:00JLG1https://community.sap.com/t5/user/viewprofilepage/user-id/1664023<P>The new hands-on practical examination for becoming an SAP Certified Security Administrator was released earlier this month and has been well received! This certification verifies that the candidate has a general understanding of the core knowledge required of a Security Administrator in SAP system security. It proves that the candidate has a basic understanding about SAP authorization and security concepts in SAP S/4HANA Public and Private Edition and can put this knowledge into practice as a member of a project or security team.</P><P>We are pleased to announce today that we will be offering <STRONG><EM>“Get Certified” Live Sessions</EM></STRONG> to help prepare candidates for this examination starting May 27, 2026. In these live sessions, expert trainers will support you via a number of live sessions related to the <A href="https://learning.sap.com/certifications/sap-certified-associate-security-administrator" target="_blank" rel="noopener noreferrer">C_SEC</A> certification: SAP Certified - Security Administrator.</P><P>The series consists of the following:</P><UL><LI>Kick-off session - Outlining the live session series, introducing the certification, explaining the certification format and exam interface, providing tips for preparation, explaining the learning journey self-study content, practice systems, and corresponding content review sessions - 1 hour</LI><LI>8 content review sessions - Covering important certification-relevant topics from the courses that are part of the corresponding learning journey. These sessions complement your self-study, providing you with the opportunity to get explanations and demonstrations from an expert, who can answer questions you have about the content, helping you to be better prepared for the certification.</LI></UL><P> </P><UL><UL><LI><A href="https://learning.sap.com/live-sessions/how-to-set-up-and-maintain-users-in-sap-s-4hana" target="_blank" rel="noopener noreferrer">How to set up and maintain users in SAP S/4HANA</A></LI><LI><A href="https://learning.sap.com/live-sessions/working-with-abap-role-maintenance" target="_blank" rel="noopener noreferrer">Working with ABAP Role Maintenance</A></LI><LI><A href="https://learning.sap.com/live-sessions/understanding-authorization-default-values-in-su24" target="_blank" rel="noopener noreferrer">Understanding Authorization Default Values in SU24</A></LI><LI><A href="https://learning.sap.com/live-sessions/managing-sap-fiori-catalogs" target="_blank" rel="noopener noreferrer">Managing SAP Fiori Catalogs</A></LI><LI><A href="https://learning.sap.com/live-sessions/managing-sap-fiori-business-roles" target="_blank" rel="noopener noreferrer">Managing SAP Fiori Business Roles</A></LI><LI><A href="https://learning.sap.com/live-sessions/sap-fiori-spaces-and-pages" target="_blank" rel="noopener noreferrer">SAP Fiori Spaces and Pages</A></LI><LI><A href="https://learning.sap.com/live-sessions/sap-authorizations-traces" target="_blank" rel="noopener noreferrer">SAP Authorizations - Traces</A></LI><LI><A href="https://learning.sap.com/live-sessions/sap-authorizations-sap-user-information-system-reports" target="_blank" rel="noopener noreferrer">SAP Authorizations - SAP User Information System Reports</A></LI></UL></UL><P> </P><P>Sessions can be taken in any order, as your busy schedule permits.</P><P>Sessions are offered in multiple time zones, so if you are interested in becoming an SAP Certified Security Administrator, check out the link below to sign up for the sessions you’re interested in:</P><P><A href="https://learning.sap.com/live-sessions/get-certified-sap-certified-security-administrator?searchId=51f47223-b967-47f6-85d9-f14d46cce51e&listPosition=1" target="_blank" rel="noopener noreferrer">https://learning.sap.com/live-sessions/get-certified-sap-certified-security-administrator?searchId=51f47223-b967-47f6-85d9-f14d46cce51e&listPosition=1</A></P><P>The complete SAP Learning Journey for this certification is found at:</P><P><A href="https://learning.sap.com/learning-journeys/managing-user-access-and-security-of-sap-s-4-hana-and-sap-s-4hana-cloud-public-edition" target="_blank" rel="noopener noreferrer">Managing User Access and Security of SAP S/4 Hana and SAP S/4HANA</A></P><P> </P>2026-04-27T18:16:38.460000+02:00https://community.sap.com/t5/technology-blog-posts-by-sap/cap-developers-call-to-action-to-mitigate-and-apply-solution-provided-in/ba-p/14387683CAP Developers - Call to Action to mitigate and Apply Solution provided in SAP Note 37477872026-05-01T21:27:54.994000+02:00Yoganandahttps://community.sap.com/t5/user/viewprofilepage/user-id/75<P>On April 29, 2026, four malicious open-source package versions were distributed into the NPM ecosystem. These malicious versions appear to exfiltrate information, such as credentials, and attempt to propagate into downstream software packages as well as adjacent software repositories when installed on a system.</P><P>If you are uncertain whether your systems have been affected, it is crucial to act promptly. Begin by following the mitigation steps outlined to maintain your environment’s security. Promptly taking these actions will help protect your systems and data from potential risks.</P><H3 id="Other Terms" id="toc-hId-1924299041">Other Terms</H3><UL><LI>MBT</LI><LI>NPM</LI><LI>CAP</LI><LI>SAP Cloud Application Programming Model</LI><LI>MTA Build Tool</LI></UL><P>List of compromised NPM package versions:</P><UL><LI>· @cap-js/sqlite - v2.2.2</LI><LI>· @cap-js/postgres - v2.2.2</LI><LI>· @cap-js/db-service - v2.10.1</LI><LI>· <A href="mailto:mbt@1.2.48" target="_blank" rel="noopener nofollow noreferrer">mbt@1.2.48</A></LI></UL><H3 id="toc-hId-1727785536"><FONT color="#008000">Solution</FONT></H3><P>If you have identified that you may be affected, perform the following measures via provided SAP Note below:</P><P><A href="https://me.sap.com/notes/0003747787" target="_blank" rel="noopener noreferrer">https://me.sap.com/notes/0003747787</A></P><P><STRONG><FONT color="#993300">SAP Support Ticket Component</FONT></STRONG> : <SPAN class=""><SPAN class="">BC-XS-CDX-NJS</SPAN></SPAN></P><P><STRONG>Potential references:</STRONG></P><UL><LI><A href="https://www.aikido.dev/blog/mini-shai-hulud-has-appeared" target="_blank" rel="noopener nofollow noreferrer">https://www.aikido.dev/blog/mini-shai-hulud-has-appeared</A></LI></UL><UL><LI><A href="https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared" target="_blank" rel="noopener nofollow noreferrer">https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared</A></LI></UL><UL><LI><A href="https://"/" target="_blank" rel="noopener nofollow noreferrer">https://www.mend.io/blog/shai-hulud-sap-cap-supply-chain-attack-claude-code/</A></LI></UL><UL><LI><A href="https://"/" target="_blank" rel="noopener nofollow noreferrer">https://onapsis.com/blog/sap-cap-mini-shai-hulud-supply-chain-attack/</A></LI></UL><UL><LI><A href="https://snyk.io/de/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/" target="_blank" rel="noopener nofollow noreferrer">https://snyk.io/de/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/</A></LI></UL>2026-05-01T21:27:54.994000+02:00https://community.sap.com/t5/technology-blog-posts-by-sap/sapphire-orlando-2026-responsible-innovation-joule-architecture-for/ba-p/14391237Sapphire Orlando 2026: Responsible innovation - Joule architecture for security and governance2026-05-07T12:05:19.098000+02:00sudhakarsinghhttps://community.sap.com/t5/user/viewprofilepage/user-id/464411<P>Hello everyone!</P><P>SAP Sapphire & ASUG Annual Conference Orlando 2026 is where SAP will showcase its latest AI advancements, including the next evolution of Joule. Today, I want to share insights about my session on Responsible AI —and why it matters now more than ever.</P><P><STRONG>About Me</STRONG><BR />I’m part of the SAP Business AI team, where I lead work on Responsible AI. In simple terms, Responsible AI is about asking (and answering) the uncomfortable questions: What can go wrong with AI? How might it be misused? Where do we need stronger safeguards —across ethics, cybersecurity, and compliance? How to verify safety and security of AI applications? That includes topics like AI security, guidance on ethical usage, and navigating regulatory expectations—whether they’re country-specific or industry-specific. My role is to bring together experts across ethics, security, and compliance so we can build Business AI that earns trust by design.</P><P><STRONG>My Session at SAP Sapphire Orlando 2026</STRONG><BR />Session title: Responsible innovation: Joule architecture for security and governance<BR />Session <A title="Responsible AI" href="https://www.sap.com/events/sapphire/orlando/flow/sap/so26/catalog/page/catalog/session/1774484072840001m3w5 " target="_self" rel="noopener noreferrer">link</A></P><P>AI is a core part of SAP’s strategy, and Sapphire is where you’ll see new innovations and experiences in Joule. Alongside that innovation, we will also talk about responsibility: how we design Joule and agentic applications so they can be used safely, governed appropriately, and protected against misuse.<BR />Specifically, I’ll address:<BR />- The architectural building blocks of Joule<BR />- How they reduce common risk patterns<BR />- How governance controls apply when AI agents are involved behind the scenes</P><P>Agent governance in business systems is not a nice-to-have feature—it is a mandatory requirement to ensure the safety of businesses and their users. We will discuss how we solve this challenge in Joule, and I look forward to learning from your experiences and ideas.</P><P>Thanks,<BR />Sudhakar</P>2026-05-07T12:05:19.098000+02:00https://community.sap.com/t5/technology-blog-posts-by-members/acing-the-sap-roles-and-authorization-design-review-what-sap-checks-and-how/ba-p/14392797Acing the SAP Roles and Authorization Design Review — What SAP Checks and How to Prepare2026-05-10T20:09:03.699000+02:00SahilTanejahttps://community.sap.com/t5/user/viewprofilepage/user-id/606691<P><FONT color="#99CC00"><U><STRONG>Treat your Non-Prod systems like production. Because, SAP certainly will.</STRONG></U></FONT></P><P><FONT face="georgia,palatino">We recently had a security design review done by SAP itself, and we came out with positive feedback on almost all parameters. To be honest, I was a little anxious before the report, but we had been doing everything right, so it went well. I tried to find what SAP checks before the review, but couldn't find much; hence writing this blog. This information will come in handy while prepping for a Design Review. <STRONG>Fair warning — if you follow all of this outside of review season too, your system will be embarrassingly clean. People will start asking what your secret is. Just smile and point them here.</STRONG></FONT></P><P><FONT face="georgia,palatino">Start taking care of all these things from the QA system onwards. Whatever system, SAP performs review on, they treat it as Prod system and test all parameters, and sometimes it becomes really hard to make the client understand that couple profile assignments to service users/systems users is fine <span class="lia-unicode-emoji" title=":slightly_smiling_face:">🙂</span> particularly the clients who are new to SAP and traditionally had one environment for their ERPs (trust me, I have seen those).</FONT></P><P class="">I'll go one by one, divided into 7 sections:</P><OL class=""><LI>Governance</LI><LI>User Administration</LI><LI>Role Administration</LI><LI>Fiori Launchpad Administration</LI><LI>Custom Transactions</LI><LI>Authorization-based SAP S/4HANA Enterprise Management</LI><LI>Miscellaneous</LI></OL><P class=""><STRONG>1. Governance</STRONG></P><OL class="lia-list-style-type-lower-greek"><LI><STRONG>Authorization Concept Documentation - </STRONG>No matter what phase you are in, always have the documentation updated. Like your user management policy, role design documents -> design and the role naming principles etc. It can be as simple as couple slides, but having that is a must. A good role design document should cover the full picture: what roles exist and what access they give, your naming convention, your list of critical accesses and controls. Make sure you maintain version history, segregated sections for Master, Derived and Composite Roles. <U>My advice</U>: don't create this document for the review. Create it as soon as you start the design, update it as your design evolves, and make sure it's accessible to key stakeholders. That's what SAP wants to see.</LI><LI><STRONG>Naming Convention - </STRONG>I am not going to say that, you should use ZD or Z_D for derived roles. Use anything, but it has to be consistent. If you've been disciplined about this (e.g., prefixes that distinguish security roles, display roles, composite roles, etc.), you're fine. This one is easy to get right if you define the convention early and enforce it. Don't let people create ad-hoc role names mid-project.</LI></OL><P><STRONG>2. User Administration</STRONG></P><OL class="lia-list-style-type-lower-greek"><LI><STRONG>Master Roles Assigned to Users - </STRONG>Master roles are templates — they should never be directly assigned to users. Only derived roles go on users. SAP checks this explicitly. If your project has been following a proper derivation concept, you'll have no findings here.</LI><LI><STRONG>Direct Profile Assignments — Especially SAP_ALL and SAP_NEW</STRONG> - SAP looks for users who have profiles assigned directly (outside of PFCG roles), and specifically calls out SAP_ALL and SAP_NEW. In QA environments, teams often give these to BASIS team members while roles are still being built. I would suggest a better one, until you have the matured roles for basis, create one role from SAP_ALL template, deactivate Sec related objects. May be call this Y*SAP_ALL*MINUS_SECURITY, but use it until you have enough inputs to create one support/FF role. A word of caution on interface users; these are often the ones that get forgotten. SAP_ALL on a system or service user is actually more dangerous than on a dialog user, because it opens the door for RFC-based attacks. Ideally you should have minimum privileged roles for them, but in the initial phases, when you don't have enough inputs, use the same role (SAP_ALL minus security). You can use STUSERTRACE for building interface user roles. Refer - <A href="https://community.sap.com/t5/application-development-and-automation-blog-posts/stusertrace-new-tracing-option-authorization-trace-for-user/ba-p/13501490" target="_self">STUSERTRACE users</A> </LI><LI><P class=""><STRONG>Expired / Terminated Users with Role Assignments - </STRONG>SAP checks for user IDs that are expired or terminated but still have active role assignments. Locking a user is not enough, remove the role assignments too. It demonstrates that your offboarding process is complete, not just half-done. Have an admin process documented for this and make sure it's actually running even in non-prod systems.</P></LI><LI><STRONG>Reference User Type - </STRONG>SAP checks if you are using Reference users assigned to anyone without proper reason and documentation. I am sure, noone uses it, but if you still have any use case, document it or rather use General roles assigned to all composites.</LI></OL><P><STRONG>3. Role Administration - </STRONG>This section typically has the most findings in any review. Most are avoidable if you build good habits from the start.</P><OL class="lia-list-style-type-lower-greek"><LI><P class=""><STRONG>Transaction Ranges in Roles </STRONG></P>Never use transaction ranges (like MM* or FI*) in PFCG role menus. The reason is simple —> if a new transaction gets created within that range later, users automatically get access to it without any approval or awareness. Always add individual t-codes.</LI><LI><P class=""><STRONG>Transactions Not Maintained via Menu </STRONG></P><P class="">Every t-code in a role should be added through the Menu tab in PFCG, not manually inserted into the authorization data. This maintains the relationship between the t-code and its authorization objects. If you remove a t-code from the menu later, the corresponding objects get cleaned up properly. If you bypass the menu, that cleanup doesn't happen — you're left with orphaned objects giving access nobody asked for.</P></LI><LI><P class=""><STRONG>Non-Existing Transactions in Roles</STRONG></P><P class="">SAP checks for t-codes in roles that don't actually exist in the system. These are usually leftovers from ECC role copies where certain transactions don't exist in S/4HANA, or from template roles that were never cleaned up. Remove the ghost tcodes once and for all (even in the non production system roles).</P></LI><LI><P class=""><STRONG>Manual Objects in Roles</STRONG></P><P class=""><U>This is a big one</U>. Every authorization object in a role should come from SU24 proposals; triggered by adding a t-code via the menu. If you manually add objects directly in the authorization data tab, SAP loses the ability to trace the relationship between that object and the transaction that needs it. Practical Consequence is if you ever remove that t-code, the manually added objects stay behind and keep giving access. And during upgrades or SU24 changes, those manual objects don't get updated automatically. </P></LI><LI><P class=""><STRONG>Org. Access Maintained at Node Level</STRONG></P><P class="">Organizational field values (Company Code, Plant, Sales Org, etc.) should be maintained through the proper derivation mechanism, via the "Organizational Data" tab in PFCG. Not directly in the authorization data. If you edit them at the node level, the values get corrupted. Look for such values, fix it.</P></LI><LI><P class=""><STRONG>Incorrect / Non-Existing Org Values -</STRONG></P><P class="">SAP also looks for org values in roles that don't exist in the system anymore. Old company codes, retired plants, restructured sales orgs. These don't break anything immediately. Run a periodic cleanup and remove obsolete org values. A quick comparison of values in AGR_1252 against the actual org data would give you the culprits.</P></LI><LI><P class=""><STRONG>Display Roles with Maintenance Access</STRONG></P><P class="">If a role's name contains DISP or REPORT, SAP expects it to have only display/read access. If it also has write activities such as create, change, delete, post etc., that's a problem.</P></LI><LI><P class=""><STRONG>Not Generated Roles</STRONG></P><P class="">After any change to a role, it needs to be regenerated in PFCG. An ingenerated role means users assigned to it get no access at all.</P></LI><LI><P class=""><STRONG>Roles with Open Authorizations</STRONG></P><P class="">Open authorization nodes are objects in the role with no values maintained, means they don't grant access, but they create confusion and make roles hard to audit. Deactivate the nodes you don't need, fill in the values for the ones you do, and regenerate.</P></LI><LI><P class=""><STRONG>Inconsistent Master-Derived Roles</STRONG></P><P class="">SAP checks if derived roles have diverged from their master. Different field values, or worse, the master role no longer exists. This breaks the whole point of the derivation concept and can lead to excess access being granted unintentionally.</P></LI></OL><P><STRONG>4. Fiori Launchpad Administration - </STRONG>SAP gives a lot of attention to FIORI in S4HANA secuirty design reviews. This area surprised me as it felt more like UX administration than security. But from SAP's perspective - its both UX and Security.</P><OL class="lia-list-style-type-lower-greek"><LI><P class=""><STRONG>Use of FIORI Groups</STRONG></P><P class="">The FIORI groups concept is obsolete/deprecated <SPAN>as of SAP S/4HANA 2021</SPAN>. So, if you have older groups created, try to shift to Catalogs, but still you can justify the groups. But dont create any new group at all.</P></LI><LI><P class=""><STRONG>Unused Catalogs and Groups</STRONG></P><P class="">Any catalog not assigned to a PFCG role is invisible to users. It's just dead weight in the system. Clean them up or assign them. SAP is firmly in the Spaces and Pages world now. If you're still using groups, plan your migration. Don't go live with a legacy Fiori structure.</P></LI><LI><P class=""><STRONG>Enterprise Search Authorizations</STRONG></P><P class="">One of the most overlooked items :). People often end up maintaining S_ESH_CONN as * for all the fields. This is both a performance and Security issue. Try to maintain the proper template name and connection ID.</P></LI><LI><P class=""><STRONG>SAP Standard Business Catalogs and Roles</STRONG></P><P class="">Never assign SAP standard Business Roles or catalogs directly to users or PFCG roles. Always copy them into your customer namespace, adjust to your org needs and then assign. This is both a security and a maintainability best practice.</P></LI><LI><P class=""><STRONG>Orphaned Catalogs and Groups</STRONG></P><P class="">Catalogs or groups that exist but aren't assigned anywhere are just clutter. Clean them unless you have an active ongoing project reason to keep them. The same applies to orphaned tiles in Fiori Pages, where tiles pointing to catalog entries that no longer exist. These confuse users and clutter your Fiori setup.</P></LI><LI><P class=""><STRONG>System Alias Consistency</STRONG></P><P class="">Fiori apps rely on system aliases to find the correct backend. If an alias is in error or has warnings, the associated OData service can't register, and the app simply won't work. Check this using SM59 or /UI2/GW_SYS_ALI and fix any discrepancies. Don't let alias issues go into production; they're hard to diagnose for end users.</P></LI><LI><P class=""><STRONG>Granularity of Catalogs</STRONG></P><P class="">SAP doesn't want you to create one catalog per app. Even 2-3 is considered a bad design. Atleast 5 is a good number, if you don't want to get highlighted <span class="lia-unicode-emoji" title=":slightly_smiling_face:">🙂</span></P></LI><LI><P class=""><STRONG>Service Activation</STRONG></P><P class="">Every Fiori app depends on an activated OData service. If the service isn't active or is in error, the app simply won't load, no error message that makes sense to the user, just a broken tile. Review all roles and catalogs and check service status. Implement a periodic control to catch regressions after transports.</P></LI><LI><P class=""><STRONG>OData Metadata Cache</STRONG></P><P class="">Schedule report /UI5/UPD_ODATA_METADATA_CACHE. In test systems, hourly is fine. In production, once per night is the recommendation. This directly affects how fast Fiori apps load. It also needs to be run after importing transports, implementing SAP notes, or changing a service. Make it part of your go-live checklist.</P></LI><LI><P class=""><STRONG>SAP Menu Entry Cache</STRONG></P><P class="">Similarly, run /UI2/EAM_BUILD_CACHE to cache SAP menu entries in the App Finder. Without it, the App Finder either loads very slowly or times out. If the report isn't available in your system, check whether you need to install the required SAP_UI patch level or SAP Note 2545066.</P></LI></OL><P><STRONG>5. Custom Transactions</STRONG></P><OL class="lia-list-style-type-lower-greek"><LI><P class=""><STRONG>Unused Custom Transactions</STRONG></P><P class="">SAP checks for Y* and Z* transactions that exist in the system but aren't in any role menu. These are typically leftovers from earlier development, retired features, or transactions that were built but never formally deployed. Lock or remove the ones you don't need. Unused custom t-codes sitting in the system are a quiet compliance risk, they can be executed by anyone with broad access, and nobody is tracking them.</P></LI><LI><P class=""><STRONG>Custom Transactions Not Maintained in SU24</STRONG></P><P class="">Well, Well, Well, this is the item, which I keep iterating to ABAP teams and the client. Every custom program should have an AUTHORITY-CHECK statement, and not just for the namesake, it should check the most relevant Auth objects, for example, if a custom report is built to get the sales orders report, it should check the objects which are checked by VA03 tcode, if not all, at least few of those. Now, you can remediate this one by just adding a custom obj check in SU24 and roles, but it wont remediate the underlying vulnerability. Ideal flow should be Appropriate checks in Program --> maintained in SU24 --> Added in roles --> Added in GRC risk library (functions). </P></LI></OL><P><STRONG>6. Authorization-Based SAP S/4HANA Enterprise Management (Licensing) - </STRONG></P><P class="">This is the section most teams don't think about, while creating roles. But SAP does. Certain authorization objects automatically trigger Full User Equivalent (FUE) licensing, meaning any user with those objects in their roles gets charged at the highest license tier. The objects that typically come up are things like S_CALENDAR, S_PSE_ADM, S_TRANSPRT, S_USER_GRP, and S_SECPOL etc. </P><P class="">Refer note - <A href="https://me.sap.com/notes/3113382/E" target="_blank" rel="noopener noreferrer">3113382 - Authorization-based SAP S/4HANA User Simulation / FUE Projection</A>.</P><P class=""><STRONG>7. Miscellaneous — Security Profile Parameters - </STRONG>SAP checks quite a few security, rfc, password related parameters if you have an on-premise system. But if you are on RISE, most of these are taken care and SAP checks these parameters -</P><P class=""><STRONG>auth/check/calltransaction</STRONG> — Controls whether authority checks are enforced during CALL TRANSACTION statements. Recommended value is 3. If it's not set correctly, authorization checks can be silently bypassed in background and batch processes.</P><P class=""><STRONG>auth/object_disabling_active</STRONG> — Controls whether authorization checks can be globally switched off for selected objects. Recommended value is N. If this is active, someone with the right access can effectively turn off security for entire authorization objects system-wide. It should be N in any production system.</P><P class=""><STRONG>auth/rfc_authority_check</STRONG> — Controls how authentication is enforced for RFC function module calls. Recommended value is 6. Anything lower means remote function calls can be made without proper authorization checks — essentially leaving a door open for unauthenticated access via RFC. This one is often set to a lower value during development for convenience, and then forgotten. Get your Basis team to set it to 6 before go-live.</P><P class=""> </P><P class=""><STRONG>Final thought</STRONG></P><P class="">The review itself is not the hard part. The hard part is the daily discipline during the project like maintaining SU24, following the menu-based role building approach, keeping org values clean, not letting SAP_ALL sit on users "temporarily". These are all habits, and they're much easier to build early than to fix under review pressure.</P><P class=""><STRONG>Treat your QA system like production. If you won't, SAP certainly will.</STRONG></P>2026-05-10T20:09:03.699000+02:00https://community.sap.com/t5/technology-blog-posts-by-members/securing-sap-ui5-applications-with-a-custom-node-js-backend-using-jwt/ba-p/14400713Securing SAP UI5 Applications with a Custom Node.js Backend using JWT2026-05-22T08:33:34.794000+02:00Shubham_kumar_saphttps://community.sap.com/t5/user/viewprofilepage/user-id/2084304<P>Hi everyone,</P><H3 id="toc-hId-1945332231"><STRONG>Introduction</STRONG></H3><P class="">When I pair SAP UI5 with a custom Node.js backend, there's no BTP or XSUAA to provide security. <STRONG>JWT (JSON Web Token)</STRONG> is the right tool for providing security. It is stateless, lightweight, and works naturally with both Express middleware and the UI5 fetch API.</P><P class="">This guide covers the complete end-to-end setup:</P><UL class=""><LI><STRONG>MySQL</STRONG> — user table with bcrypt-hashed passwords and roles</LI><LI><STRONG>Node.js backend</STRONG> — JWT generation on login, protected routes via middleware</LI><LI><STRONG>SAP UI5 frontend</STRONG> — token storage, role-based routing, authenticated API calls, session expiry handling</LI><LI><STRONG>Local dev proxy</STRONG>—<FONT color="#FFFF00">ui5.yaml</FONT> config so the UI5 dev server forwards <FONT color="#FFFF00">/api</FONT> calls to Node.js</LI></UL><P> </P><H4 id="toc-hId-1877901445">Why I Wrote This</H4><P class="">A few months back, I was working on a project where we had to build a lightweight internal tool on top of an SAP landscape — a UI5 frontend talking to a custom Node.js backend. The moment security came up in the design discussion, I realized there wasn't one clear, end-to-end guide covering this specific combination: SAP UI5 + Node.js + JWT + Role-Based Access Control.</P><P class="">This post walks through the complete flow: setting up the database, generating the JWT on login, storing it in the UI5 frontend, protecting your Node.js APIs with middleware, proxying API calls during local development, and handling session expiry gracefully.</P><P class=""> </P><H4 id="toc-hId-1681387940">First, Let's Understand JWT—The Wristband at the Door</H4><P class="">Before jumping into code, here's how I explain JWT to anyone who's new to it.</P><P class="">Picture a nightclub with a VIP section. The first time you arrive, the bouncer checks your ID (your email and password). Once verified, they hand you a wristband — a JWT. For the rest of the night, you don't show your ID again. You just flash the wristband. The staff trusts it because the club itself issued it and it's tamperproof.</P><P class="">That's exactly what happens here:</P><OL class=""><LI>User submits their credentials to the Login API</LI><LI>The backend verifies them against the database</LI><LI>If valid, the server signs a JWT containing the user's ID, email, and role</LI><LI>The UI5 app stores that token and attaches it to every subsequent request</LI><LI>Each protected API checks the token before responding</LI></OL><P class="">Since the token is cryptographically signed with a secret key only the server knows, no one can fake or modify it.</P><P class=""> </P><H4 id="toc-hId-1484874435">Architecture Overview</H4><P>The setup is a decoupled architecture—UI5 and Node.js live as completely separate projects and talk only through HTTP API calls. Here's the folder structure I used:</P><pre class="lia-code-sample language-javascript"><code>project-root/
│
├── backend/ ← Node.js (Express) server
│ ├── .env ← Secret key and DB credentials (NEVER commit this)
│ ├── server.js ← Entry point — boots Express and registers routes
│ ├── repo/
│ │ └── dbconnection.js ← MySQL connection setup
│ ├── middleware/
│ │ └── authMiddleware.js ← JWT verification guard
│ ├── controller/
│ │ ├── userController.js ← Login logic with bcrypt
│ │ └── adminController.js ← Protected data APIs
│ └── routes/
│ ├── userRoutes.js ← Public routes (login)
│ └── adminRoutes.js ← Protected routes (require JWT)
│
└── frontend/ ← SAP UI5 application
├── ui5.yaml ← Dev server config including API proxy
├── webapp/
│ ├── controller/
│ │ ├── View1.controller.js ← Login page logic
│ │ ├── AdminDashboard.controller.js
│ │ └── UserDashboard.controller.js
│ ├── view/
│ │ ├── App.view.xml ← Root shell (contains App id="app")
│ │ ├── View1.view.xml ← Login screen
│ │ ├── AdminDashboard.view.xml
│ │ └── UserDashboard.view.xml
│ └── manifest.json ← Router config lives here</code></pre><P class=""> </P><H4 id="toc-hId-1288360930">Step 1: Setting Up MySQL</H4><P class="">We need a database to store user credentials and roles. I'm using MySQL here. If you already have it installed, jump straight to the schema part.</P><P class="">Otherwise, install<STRONG> MySQL Community Server</STRONG> from the official MySQL site, along with MySQL Workbench for a visual interface.</P><P class="">Once you're logged into Workbench, open a new SQL tab and run this:</P><pre class="lia-code-sample language-sql"><code>-- Create and select the database
CREATE DATABASE my_ui5_app;
USE my_ui5_app;
-- User table with role-based access
CREATE TABLE `user` (
`user_id` INT NOT NULL AUTO_INCREMENT,
`user_name` VARCHAR(100) NOT NULL,
`email` VARCHAR(100) NOT NULL,
`contact_number` VARCHAR(15) DEFAULT NULL,
`password` VARCHAR(255) NOT NULL,
`role` VARCHAR(20) DEFAULT 'User',
PRIMARY KEY (`user_id`),
UNIQUE KEY `email_UNIQUE` (`email`)
);
INSERT INTO `user` (`user_name`, `email`, `password`, `role`)
VALUES ('System Admin', 'admin@company.com', '$2b$10$cUSzmudHOeDXCF6eToP3buHZULwxuuJ/J5WZYeFkStg7HBpy2uCcW', 'Admin');
INSERT INTO `user` (`user_name`, `email`, `password`, `role`)
VALUES ('Shubham', 'shubham@gmail.com', '$2b$10$xBn6cKLkEuIkSqoLSR3pw.r16EABwE7aHtIDU4KSq2czl3LW5PMpK', 'User');</code></pre><P> <span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-05-21 111316.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/412135iCC8EC4D5F0637C47/image-size/large?v=v2&px=999" role="button" title="Screenshot 2026-05-21 111316.png" alt="Screenshot 2026-05-21 111316.png" /></span></P><P> </P><H4 id="toc-hId-1091847425">Step 2: Backend — Installing Dependencies and Generating Password Hashes</H4><P>Let's get the backend ready first by using commands.</P><P>mkdir backend<BR />cd backend<BR />npm init -y<BR />npm install express mysql2 jsonwebtoken bcrypt dotenv</P><P>Create a <FONT color="#FFFF00">.env</FONT> file in the backend root:</P><P>DB_HOST=localhost<BR />DB_USER=root<BR />DB_PASSWORD=your_mysql_password<BR />DB_NAME=my_ui5_app<BR />SECRET_KEY=your_very_long_random_secret_key_here<BR />PORT=3306</P><P><STRONG>Generating Real Password Hashes<BR /></STRONG>Before inserting test users into MySQL, generate proper bcrypt hashes. Create <FONT color="#FFFF00">generateHash.js</FONT> in your backend folder—this is a one-time utility script, not part of the running app:</P><pre class="lia-code-sample language-javascript"><code>const bcrypt = require('bcrypt');
async function generateHashes() {
const adminHash = await bcrypt.hash('Admin@123', 10);
const userHash = await bcrypt.hash('User@123', 10);
console.log('Admin hash:', adminHash);
console.log('User hash: ', userHash);
}
generateHashes();</code></pre><P> </P><P>Database Connection —<FONT color="#FFFF00">repo/dbconnection.js</FONT></P><pre class="lia-code-sample language-javascript"><code>const mysql = require('mysql2');
require('dotenv').config();
const connection = mysql.createConnection({
host: process.env.DB_HOST,
user: process.env.DB_USER,
password: process.env.DB_PASSWORD,
database: process.env.DB_NAME
});
connection.connect((err) => {
if (err) {
console.error('DB connection failed:', err.message);
return;
}
console.log('Connected to MySQL');
});
module.exports = connection;</code></pre><P> </P><P>Entry Point -<FONT color="#FFFF00"> server.js</FONT> <BR />This boots the whole backend—wires together Express, registers the routes, and starts listening. I prefix all routes with <FONT color="#FFFF00">/api</FONT> to cleanly separate API traffic from any static file serving. </P><pre class="lia-code-sample language-javascript"><code>const express = require('express');
const dotenv = require('dotenv');
dotenv.config();
const userRoutes = require('./routes/userRoutes');
const adminRoutes = require('./routes/adminRoutes');
const app = express();
const PORT = process.env.PORT || 3000;
// Parse incoming JSON request bodies
app.use(express.json());
// Register routes
app.use('/api/user', userRoutes);
app.use('/api/admin', adminRoutes);
app.get('/api/health', (req, res) => {
res.status(200).json({ status: 'Server is up and running' });
});
app.listen(PORT, () => {
console.log(`Backend running at http://localhost:${PORT}`);
});</code></pre><P>Start the server by giving commands to the terminal:<BR />node server.js<BR />npx nodemon server.js</P><P> </P><H4 id="toc-hId-895333920">Step 3: Backend — Login API with bcrypt and JWT</H4><P class="">When the UI5 frontend submits credentials, the backend needs to:</P><OL class=""><LI>Find the user in the DB by email</LI><LI>Compare the submitted password against the stored bcrypt hash using <FONT color="#FFFF00">bcrypt.compare()</FONT></LI><LI>If it matches, sign a JWT containing the user's ID, email, and role.</LI></OL><P><FONT color="#FFFF00">controller/userController.js:</FONT></P><pre class="lia-code-sample language-javascript"><code>const jwt = require('jsonwebtoken');
const bcrypt = require('bcrypt');
const db = require('../repo/dbconnection');
async function loginUser(req, res) {
const { email, password } = req.body;
if (!email || !password) {
return res.status(400).json({ message: "Email and password are required." });
}
// Fetch user by email
const query = 'SELECT * FROM user WHERE email = ?';
db.query(query, [email], async (err, results) => {
if (err) {
console.error('DB error:', err);
return res.status(500).json({ message: "Internal server error." });
}
if (results.length === 0) {
return res.status(401).json({ message: "Invalid email or password." });
}
const user = results[0];
// bcrypt.compare() checks the submitted password against the stored hash
const passwordMatch = await bcrypt.compare(password, user.password);
if (!passwordMatch) {
return res.status(401).json({ message: "Invalid email or password." });
}
// Build the JWT payload
const tokenPayload = {
user_id: user.user_id,
email: user.email,
role: user.role
};
// Sign the token using the secret key from .env — expires in 24 hours
const token = jwt.sign(
tokenPayload,
process.env.SECRET_KEY,
{ expiresIn: '24h' }
);
return res.status(200).json({
message: "Login successful",
token: token,
user: { role: user.role, name: user.user_name }
});
});
}
module.exports = { loginUser };</code></pre><P> </P><P><FONT color="#FFFF00">routes/userRoutes:</FONT></P><pre class="lia-code-sample language-javascript"><code>const express = require('express');
const router = express.Router();
const { loginUser } = require('../controller/userController');
router.post('/login', loginUser);
module.exports = router;</code></pre><P> </P><H4 id="toc-hId-698820415">Step 4: Backend — The Middleware Guard </H4><P class="">This is the piece that protects every route requiring authentication. Every request to a secured endpoint passes through this function before reaching the controller.</P><P class=""><FONT color="#FFFF00">middleware/authMiddleware.js:</FONT></P><pre class="lia-code-sample language-javascript"><code>const jwt = require('jsonwebtoken');
const verifyToken = (req, res, next) => {
const authHeader = req.headers['authorization'];
// Reject immediately if no Authorization header is present
if (!authHeader || !authHeader.startsWith('Bearer ')) {
return res.status(403).json({ message: "Access denied. No token provided." });
}
// Strip the "Bearer" prefix to get the raw token string
const token = authHeader.split(' ')[1];
jwt.verify(token, process.env.SECRET_KEY, (err, decoded) => {
if (err) {
// Token is expired or has been tampered with
return res.status(401).json({ message: "Session expired or invalid token." });
}
req.user = decoded;
next();
});
};
module.exports = { verifyToken };</code></pre><P> </P><P class="">To protect a route, inject this middleware between the route path and the controller function:</P><P class=""><FONT color="#FFFF00">routes/adminRoutes:</FONT></P><pre class="lia-code-sample language-javascript"><code>const express = require('express');
const router = express.Router();
const { verifyToken } = require('../middleware/authMiddleware');
const { getItemDetails } = require('../controller/adminController');
// verifing Token
router.get('/getItemDetails', verifyToken, getItemDetails);
module.exports = router;</code></pre><P> </P><P><FONT color="#FFFF00">controller/adminController.js</FONT>:</P><pre class="lia-code-sample language-javascript"><code>const db = require('../repo/dbconnection');
function getItemDetails(req, res) {
const query = 'SELECT * FROM user';
db.query(query, (err, results) => {
if (err) {
console.error('DB error:', err);
return res.status(500).json({ message: "Internal server error." });
}
return res.status(200).json(results);
});
}
module.exports = { getItemDetails };</code></pre><P> </P><H4 id="toc-hId-502306910">Step 5: Frontend—Configuring manifest.json</H4><P>Open manifest. JSON. First, add sap.ui.layout to libraries inside manifest.json since I am using the SimpleForm control in the login view.</P><pre class="lia-code-sample language-javascript"><code>"libs": {
"sap.m": {},
"sap.ui.core": {},
"sap.ui.layout": {}
}</code></pre><P>Then replace the entire routing section with this:</P><pre class="lia-code-sample language-javascript"><code>"routing": {
"config": {
"routerClass": "sap.m.routing.Router",
"controlAggregation": "pages",
"controlId": "app",
"transition": "slide",
"type": "View",
"viewType": "XML",
"path": "ui5nodeapp.view",
"async": true,
"viewPath": "ui5nodeapp.view"
},
"routes": [
{
"name": "RouteLogin",
"pattern": "",
"target": ["TargetLogin"]
},
{
"name": "RouteAdminDashboard",
"pattern": "admin",
"target": ["TargetAdminDashboard"]
},
{
"name": "RouteUserDashboard",
"pattern": "user",
"target": ["TargetUserDashboard"]
}
],
"targets": {
"TargetLogin": {
"id": "View1",
"name": "View1",
"viewLevel": 1
},
"TargetAdminDashboard": {
"id": "AdminDashboard",
"name": "AdminDashboard",
"viewLevel": 2
},
"TargetUserDashboard": {
"id": "UserDashboard",
"name": "UserDashboard",
"viewLevel": 2
}
}
}</code></pre><P> </P><H4 id="toc-hId-305793405">Step 6: Frontend — Proxying API Calls in Development</H4><P>The UI5 dev server runs on <STRONG>port 8080</STRONG> by default, while the Node.js backend runs on <STRONG>port 3000</STRONG>. So, I added the backend port to 3000 in the ui5.yaml file.</P><pre class="lia-code-sample language-javascript"><code>server:
customMiddleware:
- name: fiori-tools-proxy
afterMiddleware: compression
configuration:
ignoreCertErrors: false
backend:
- path: /api
url: http://localhost:3000 # Forward all /api calls to the Node.js backend
ui5:
path:
- /resources
- /test-resources
url: https://ui5.sap.com
- name: fiori-tools-appreload
afterMiddleware: compression
configuration:
port: 35729
path: webapp
delay: 300
- name: fiori-tools-preview
afterMiddleware: fiori-tools-appreload
configuration:
flp:
theme: sap_horizon</code></pre><P> </P><H4 id="toc-hId--388437195">Step 7: Frontend — The Login View (XML)</H4><P><FONT color="#FFFF00">view/View1.view.xml</FONT>:</P><pre class="lia-code-sample language-markup"><code><mvc:View
controllerName="ui5nodeapp.controller.View1"
xmlns:mvc="sap.ui.core.mvc"
xmlns="sap.m"
xmlns:f="sap.ui.layout.form"
displayBlock="true">
<Page title="Login" showHeader="false">
<content>
<VBox
justifyContent="Center"
alignItems="Center"
height="100%"
class="sapUiMediumMarginTop">
<Panel
width="380px"
class="sapUiResponsivePadding sapUiMediumPadding">
<VBox alignItems="Center" class="sapUiSmallMarginBottom">
<Title
text="Welcome Back"
level="H2"
class="sapUiSmallMarginBottom"/>
<Label text="Sign in to continue"/>
</VBox>
<f:SimpleForm
editable="true"
layout="ResponsiveGridLayout"
labelSpanL="12"
labelSpanM="12"
emptySpanL="0"
emptySpanM="0"
columnsL="1"
columnsM="1">
<f:content>
<Label text="Email Address" required="true"/>
<Input
id="loginUserId"
placeholder="Enter your email"
type="Email"
width="100%"
submit=".onLoggedIn"/>
<Label text="Password" required="true"/>
<Input
id="loginPassword"
placeholder="Enter your password"
type="Password"
width="100%"
submit=".onLoggedIn"/>
</f:content>
</f:SimpleForm>
<VBox alignItems="Center" class="sapUiSmallMarginTop">
<Button
text="Login"
type="Emphasized"
width="100%"
press=".onLoggedIn"/>
</VBox>
</Panel>
</VBox>
</content>
</Page>
</mvc:View></code></pre><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-05-21 121256.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/412202i3D4220C836B78939/image-size/large?v=v2&px=999" role="button" title="Screenshot 2026-05-21 121256.png" alt="Screenshot 2026-05-21 121256.png" /></span> </P><H4 id="toc-hId--584950700">Step 8: Frontend — The Login Controller</H4><P class="">The login controller sends credentials to the backend, stores the token, and routes the user based on their role.</P><P class=""><FONT color="#FFFF00">controller/View1.controller.js:</FONT></P><pre class="lia-code-sample language-javascript"><code>sap.ui.define([
"sap/ui/core/mvc/Controller",
"sap/m/MessageToast"
], function (Controller, MessageToast) {
"use strict";
return Controller.extend("ui5nodeapp.controller.View1", {
onInit: function () {
},
onLoggedIn: async function () {
const sEmail = this.byId("loginUserId").getValue().trim();
const sPassword = this.byId("loginPassword").getValue();
if (!sEmail || !sPassword) {
MessageToast.show("Please enter both email and password.");
return;
}
try {
const response = await fetch("/api/user/login", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({ email: sEmail, password: sPassword })
});
const result = await response.json();
if (!response.ok) {
throw new Error(result.message || "Login failed.");
}
// sessionStorage clears token automatically when the tab is closed
sessionStorage.setItem("myAppToken", result.token);
sessionStorage.setItem("myAppUser", JSON.stringify(result.user));
// Route to the correct dashboard based on role
const oRouter = this.getOwnerComponent().getRouter();
if (result.user.role === "Admin") {
oRouter.navTo("RouteAdminDashboard");
} else {
oRouter.navTo("RouteUserDashboard");
}
} catch (error) {
MessageToast.show(error.message || "Something went wrong. Please try again.");
}
}
});
});</code></pre><P> </P><P>After logging in, we can check the token by clicking "inspect," then "application," then "session storage," and here we can see the generated token. <span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="token.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/412223i8C91F99F7F0A3222/image-size/large?v=v2&px=999" role="button" title="token.png" alt="token.png" /></span></P><P> </P><H4 id="toc-hId--781464205">Step 9: Frontend — Making Secure API Calls from the Dashboard</H4><P class="">Any time the dashboard needs protected data, it reads the token from sessionStorage and attaches it to the Authorization header. It also handles session expiry cleanly.</P><P class=""><FONT color="#FFFF00">controller/Dashboard.controller.js:</FONT></P><pre class="lia-code-sample language-javascript"><code>sap.ui.define([
"sap/ui/core/mvc/Controller",
"sap/ui/model/json/JSONModel",
"sap/m/MessageToast"
], function (Controller, JSONModel, MessageToast) {
"use strict";
return Controller.extend("ui5nodeapp.controller.Dashboard", {
onInit: function () {
this.loadSecureData();
},
loadSecureData: async function () {
const token = sessionStorage.getItem("myAppToken");
if (!token) {
this._redirectToLogin("No active session. Please log in.");
return;
}
try {
const response = await fetch("/api/admin/getItemDetails", {
method: "GET",
headers: {
"Accept": "application/json",
"Authorization": "Bearer " + token
}
});
// 401 = token expired or tampered or missing token header
if (response.status === 401 || response.status === 403) {
this._redirectToLogin("Your session has expired. Please log in again.");
return;
}
if (!response.ok) {
throw new Error("Failed to load data. Please try again.");
}
const data = await response.json();
const oModel = new JSONModel(data);
this.getView().setModel(oModel, "secureData");
} catch (error) {
console.error("API error:", error);
MessageToast.show(error.message);
}
},
_redirectToLogin: function (message) {
sessionStorage.removeItem("myAppToken");
sessionStorage.removeItem("myAppUser");
MessageToast.show(message);
this.getOwnerComponent().getRouter().navTo("RouteLogin");
},
onLogout: function () {
this._redirectToLogin("You have been logged out.");
}
});
});</code></pre><P> </P><H4 id="toc-hId--977977710"><STRONG>A Few Things to Keep in Mind:</STRONG></H4><P class=""><STRONG>On sessionStorage vs localStorage:</STRONG> I chose sessionStorage because it clears automatically when the browser tab closes, reducing the exposure window on shared machines. Both are vulnerable to XSS attacks, so consider a content security policy header in production.</P><P class=""><STRONG>HTTPS is non-negotiable:</STRONG> JWTs in transit are meaningless without HTTPS. Local development over HTTP is fine, but before you deploy anywhere, put the app behind HTTPS.</P><P class=""><STRONG>Token expiry:</STRONG> The 24-hour expiry works for many internal tools. For anything more sensitive, tighten it to 1–2 hours and consider adding a refresh token mechanism.</P><P class=""><STRONG>Role checks on the backend too:</STRONG> The frontend role-based routing is purely a UX decision — it is not a security control. Always enforce role checks on the backend as well. </P><P class=""> </P><H3 id="toc-hId--881088208">Conclusion:</H3><P>That's the complete picture—from MySQL setup and real bcrypt password hashing through JWT generation and middleware protection on the backend to the UI5 frontend handling token storage, role-based routing, and secure API calls.</P>2026-05-22T08:33:34.794000+02:00https://community.sap.com/t5/technology-blog-posts-by-sap/from-hype-to-hands-on-level-up-your-ai-skills-this-may/ba-p/14406752From Hype to Hands-On: Level Up Your AI Skills This May2026-05-29T13:59:36.224000+02:00shannabauerhttps://community.sap.com/t5/user/viewprofilepage/user-id/1698292<P><SPAN>In the age of AI, the skills we build today will define how we work tomorrow. That’s why we’ve launched a monthly blog series that spotlights the latest AI learning assets and upcoming learning opportunities. </SPAN></P><P><SPAN>Building on my</SPAN> <SPAN><A href="https://community.sap.com/t5/technology-blog-posts-by-sap/from-hype-to-hands-on-level-up-your-ai-skills-this-october/ba-p/14240442" target="_blank">first blog</A>, where I introduced you to our AI live <A href="https://dam.sap.com/mac/app/p/pdf/asset/preview/UC5poz7?ltr=a&rc=10&doi=SAP1239031" target="_blank" rel="noopener noreferrer">sessions Beyond Hype</A></SPAN> <SPAN>(which are all about getting productive with SAP Business AI), I wanted to address some of your most asked questions. But before I do that, I’m excited to share that the sessions are <STRONG>now ungated</STRONG> and no longer require a SAP Learning Hub subscription!</SPAN></P><OL><LI><STRONG><SPAN>How does SAP ensure that frontier models can be trusted?<BR /></SPAN></STRONG>It’s a shared responsibility across SAP, the model vendor, and the customer, managed through a layered and continuous improvement approach:</LI></OL><UL><LI><SPAN>SAP: Selects enterprise-grade vendors; conducts security and responsible AI reviews; integrates models behind SAP identity, authorization, logging, and data protection; applies guardrails; monitors behavior and coordinates fixes/updates.</SPAN></LI><LI><SPAN>Model vendor: Owns model quality and defects; contractually obligated to address safety issues and deliver improvements when identified by either party.</SPAN></LI><LI><SPAN>Customer: Configures authorizations and data access; defines permissible use cases and safety settings; participates in monitoring and feedback.<BR /><BR /></SPAN><SPAN>SAP cannot change a vendor’s model weights or eliminate all model-intrinsic limitations. Instead, SAP mitigates risk through configuration and guardrails, protects business data via SAP’s application security, monitors performance, and escalates issues to the vendor under defined contracts and SLAs. If needed, SAP can adjust configurations, deploy compensating controls, or replace/disable a model to protect customers.<BR /><BR /></SPAN>Find more answers in the publicly available <A href="https://www.sap.com/products/artificial-intelligence/ai-ethics.html?pdf-asset=447a6b1f-dd7e-0010-bca6-c68f7e60039b" target="_blank" rel="noopener noreferrer">SAP Business AI - Responsible AI FAQ</A><SPAN>.</SPAN></LI></UL><OL><LI><STRONG><SPAN>What are the most common security mistakes SAP customers make when implementing an AI?<BR /><BR /></SPAN></STRONG><SPAN>For AI features embedded in existing business applications, the underlying system typically enforces data controls and authorization; the AI component itself doesn’t determine access, the host application does. When teams build custom AI applications, or add new components, they must implement the right authorization and access controls for those pieces. Overall, AI adoption is still experimental. While custom implementations vary widely by organization, one recurring theme is content moderation: Some teams keep it on, while others relax or disable it to support domain-specific use cases (for example, medical contexts). That configuration choice is worth highlighting. Beyond that, patterns are highly situational and we refrain from framing them as mistakes so much as considerations that differ by approach.<BR /><BR /></SPAN><A href="https://dam.sap.com/mac/app/p/video/asset/preview/r47fNp5?ltr=a&rc=10&doi=SAP1179681" target="_blank" rel="noopener noreferrer"><STRONG>Watch</STRONG></A><SPAN> AI Security – What is it about? And understand how SAP is developing, deploying, using, and selling AI systems with the highest ethical, security, and privacy standards. </SPAN></LI></OL><OL><LI><STRONG><SPAN>Why should I use SAP AI Core for agent assisted coding?<BR /></SPAN></STRONG><SPAN><BR />AI Core uses a secure environment where the LLMs are hosted, and the data is not used for further training compared to public LLMs. To deliver consistent, secure, and compliant outcomes across your landscape, you can bring the AI coding environment of your choice (e.g. Claude Code or Cline).<BR /><BR /></SPAN>You can learn more about agent assisted coding with Cline and AI Core in the <A href="https://architecture.learning.sap.com/docs/ref-arch/e5eb3b9b1d/10" target="_blank" rel="noopener noreferrer">SAP Architecture Center</A><SPAN>.</SPAN></LI></OL><P><SPAN>Agent‑assisted coding began as a developer aid to speed up prototyping, refactoring, test generation, and debugging. It has since evolved into a broader set of AI agents that translate natural language into software artifacts, connect design and code, scaffold data and infrastructure, and automate tedious workflows. This shift lowers the barrier to software creation and lets more roles contribute directly, effectively democratizing development by allowing anyone to create natural language prompts instead of traditional codes. These developments unlock a wide range of new use cases, enabling you to work more creatively and productively while creating higher-quality technical documentation.</SPAN></P><P><SPAN><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="use cases vibe coding.jpg" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/415544iD18D04FC8593128C/image-size/large?v=v2&px=999" role="button" title="use cases vibe coding.jpg" alt="use cases vibe coding.jpg" /></span></SPAN></P><P><SPAN>One of these new use cases is spreadsheet automation, which is especially valuable for non-technical users. I</SPAN><SPAN>magine you are working with a set of marketing data spread across different channels. Instead of manually cleaning and analyzing it, you simply ask the system to help you create a structured spreadsheet with performance insights. What happens next is that the system automatically organizes your data and generates a clear Excel file. It can include multiple sheets such as campaign performance, channel performance, and daily trends. At the end, it also adds a short summary that highlights the key insights from your data. Behind the scenes, the system generates a custom Python script that processes your raw data and builds the Excel file automatically. The important part is that you don’t need to write any code or manually structure the spreadsheet, you can simply review the output and use it directly.</SPAN></P><P><A href="https://community.sap.com/source-Ids-list" target="1_hrgtieq8" rel="nofollow noopener noreferrer"> </A></P><P><SPAN>Another example comes from a product management use case, where you might want to build a new time tracking feature. You can start by asking the system to support you with competitive research. For example, you explore how existing tools like Asana and ClickUp handle time tracking and what features they offer. The system gathers and summarizes this information into a structured overview of competitors and their capabilities. From there, you can take the next step and ask it to generate a product requirements document (PRD). Instead of starting from a blank page, you receive a complete draft that includes goals, success metrics, and a clear breakdown of requirements such as “must-have”, “should-have”, and “nice-to-have” features, as well as non-functional requirements. </SPAN></P><P><SPAN>But it doesn’t stop there: As a product manager, you can go further and ask the system to break the PRD down into actionable work items. This means it can generate epics and tasks that you can directly use in your planning tools. As a result, you can review, adjust, and refine the output together with your team. Rather than manually compiling research, writing documents, and structuring tasks from scratch, you start from a strong, AI-generated foundation that accelerates your entire product development process.</SPAN></P><P><A href="https://community.sap.com/source-Ids-list" target="1_dyjp1ght" rel="nofollow noopener noreferrer"> </A></P><P><SPAN>Now it’s your turn! <A href="https://github.com/SAP-samples/cloud-cap-vibe-with-cline" target="_blank" rel="noopener nofollow noreferrer"><STRONG>Try yourself</STRONG></A> with this sample scenario and use Cline to rapidly build enterprise-grade SAP CAP Application with Fiori UI.</SPAN></P><P><STRONG><SPAN>Want to dive deeper into the content? </SPAN></STRONG><SPAN>Rewatch the session and access the session material:</SPAN></P><UL><LI><SPAN>All Things Business AI: Latest Insights, Updates & Live Demos (<A href="https://learning.sap.com/live-sessions/q3-update-what-s-new-in-sap-learning-for-sap-business-ai" target="_blank" rel="noopener noreferrer">recording</A>) </SPAN></LI><LI><SPAN>Build AI securely - Avoid Pitfalls in the Development and Operations Lifecycle (<A href="https://learning.sap.com/live-sessions/build-ai-securely-avoid-pitfalls-in-the-development-and-operations-lifecycle" target="_blank" rel="noopener noreferrer">recording</A>)</SPAN></LI><LI><SPAN>Agent Assisted Coding with AI Core (<A href="https://learning.sap.com/live-sessions/agent-assisted-coding-with-ai-core" target="_blank" rel="noopener noreferrer">recording</A>)</SPAN></LI></UL><P><STRONG><SPAN>Hi Joule, where should I get started with the latest learning resources? *</SPAN></STRONG></P><P><SPAN>Apart from live enablement sessions, explore our latest on-demand learning resources: </SPAN></P><UL><LI><STRONG><SPAN>NEW! </SPAN></STRONG><SPAN><A href="https://learning.sap.com/learning-journeys/driving-sap-joule-for-consultants-adoption?searchId=1b59fd50-7d25-4ab2-8aca-5e2f65dbda9a&listPosition=3" target="_blank" rel="noopener noreferrer"><STRONG>Driving SAP Joule for Consultants Adoption</STRONG></A> Learning Journey: Understand SAP Joule for Consultants value across the project lifecycle, enable consultant daily use, engage stakeholders, deploy SAP’s adoption asset library, and use usage data to optimize and demonstrate business impact.</SPAN></LI><LI><STRONG><SPAN>NEW! </SPAN></STRONG><SPAN><A href="https://learning.sap.com/courses/building-confidence-in-ai-with-sap" target="_blank" rel="noopener noreferrer"><STRONG>Building Confidence in AI with SAP</STRONG></A> Learning Journey: Understand Responsible AI in SAP; how ethics, security, privacy, and compliance govern data, how SAP safeguards via policies and certifications, and how customers control usage and involve experts to drive trusted, confident adoption.</SPAN></LI><LI><STRONG><SPAN>NEW! </SPAN></STRONG><SPAN><A href="https://architecture.learning.sap.com/docs/ai-golden-path" target="_blank" rel="noopener noreferrer"><STRONG>SAP's AI Golden Path</STRONG></A><STRONG>: </STRONG>The SAP's AI Golden Path is the starting point for developing AI applications across the SAP ecosystem. It contains recommendations, best practices, and tutorials to help you understand the AI technology stack, identify suitable tools and services, and design, deliver, and extend enterprise-grade AI solutions on SAP technology.</SPAN></LI></UL><P><SPAN>* Powered by the machine learning technology of SAP AI Business Services, <A href="https://help.sap.com/docs/successfactors-learning/understanding-learning-home-page/personalized-recommendations-on-new-learning-home-page?locale=en-US&version=LATEST" target="_blank" rel="noopener noreferrer">personalized recommendations</A> are generated for employees, in one place on the Learning home page, based on employee data.</SPAN></P><P><SPAN>As we look ahead, we’re excited to share with you a new lineup of learning opportunities designed to help you expand your knowledge and make AI an advantage in your role:</SPAN></P><UL><LI><SPAN>June 18, 15:00 CET: <A href="https://learning.sap.com/live-sessions/q3-update-what-s-new-in-sap-learning-for-sap-business-ai" target="_blank" rel="noopener noreferrer"><STRONG>All Things Business AI: Latest Insights, Updates & Live Demos</STRONG></A><STRONG>. </STRONG>Discover current AI trends, recent updates across SAP’s AI portfolio, and see live demos showcasing how Business AI can drive efficiency and innovation in real-world business processes.</SPAN></LI><LI><SPAN>July 6-9: <A href="https://learning.sap.com/artificial-intelligence/adoption-learning-week" target="_blank" rel="noopener noreferrer"><STRONG>SAP AI Adoption & Learning Week.</STRONG> </A> Get ready for a week of expert</SPAN>‑<SPAN>led sessions delivering fresh insights, practical strategies, and the latest innovations shaping the year ahead.</SPAN> </LI></UL><P><SPAN>Stay tuned for more, and happy learning! <SPAN class=""><SPAN class=""><span class="lia-unicode-emoji" title=":rocket:">🚀</span></SPAN></SPAN></SPAN></P><P><SPAN>Further Resources:</SPAN></P><UL><LI><SPAN><A href="https://community.sap.com/t5/technology-blog-posts-by-sap/from-hype-to-hands-on-level-up-your-ai-skills-this-october/ba-p/14240442" target="_blank">From Hype to Hands-On: Level Up Your AI Skills This October</A></SPAN></LI><LI><SPAN><A href="https://community.sap.com/t5/technology-blog-posts-by-sap/from-hype-to-hands-on-level-up-your-ai-skills-this-november/ba-p/14259219" target="_blank">From Hype to Hands-On: Level Up Your AI Skills This November</A></SPAN></LI><LI><SPAN><A href="https://community.sap.com/t5/technology-blog-posts-by-sap/from-hype-to-hands-on-level-up-your-ai-skills-this-december/ba-p/14294383" target="_blank">From Hype to Hands-On: Level Up Your AI Skills This December</A></SPAN></LI><LI><SPAN><A href="https://community.sap.com/t5/technology-blog-posts-by-sap/from-hype-to-hands-on-level-up-your-ai-skills-this-january/ba-p/14308508" target="_blank">From Hype to Hands-On: Level Up Your AI Skills This January</A></SPAN></LI><LI><SPAN><A href="https://community.sap.com/t5/technology-blog-posts-by-sap/from-hype-to-hands-on-level-up-your-ai-skills-this-february/ba-p/14339453" target="_blank">From Hype to Hands-On: Level Up Your AI Skills This February</A></SPAN></LI><LI><SPAN><A href="https://community.sap.com/t5/technology-blog-posts-by-sap/from-hype-to-hands-on-level-up-your-ai-skills-this-march/ba-p/14354402" target="_blank">From Hype to Hands-On: Level Up Your AI Skills This March</A> </SPAN></LI></UL><P><SPAN><a href="https://community.sap.com/t5/c-khhcw49343/SAP+AI+Core/pd-p/73554900100800003641" class="lia-product-mention" data-product="405-1">SAP AI Core</a> <a href="https://community.sap.com/t5/c-khhcw49343/Security/pd-p/49511061904067247446167091106425" class="lia-product-mention" data-product="1143-1">Security</a> <a href="https://community.sap.com/t5/c-khhcw49343/Artificial+Intelligence/pd-p/c3c3a408-33ea-4c2a-ae6f-05461e76982d" class="lia-product-mention" data-product="307-1">Artificial Intelligence</a> <a href="https://community.sap.com/t5/c-khhcw49343/Joule/pd-p/d0136351-8a9c-4881-aebc-bf414b785998" class="lia-product-mention" data-product="1207-1">Joule</a> </SPAN></P>2026-05-29T13:59:36.224000+02:00https://community.sap.com/t5/technology-blog-posts-by-sap/secure-by-design-how-sap-and-nvidia-are-redefining-agent-execution/ba-p/14406128Secure by Design: How SAP and NVIDIA Are Redefining Agent Execution2026-06-01T07:50:00.019000+02:00ratulshahhttps://community.sap.com/t5/user/viewprofilepage/user-id/604338<P><SPAN>I am still reveling in the excitement of SAP Sapphire Orlando, May 11 to May 13, 2026. It started with the SAP <A href="https://www.youtube.com/watch?v=9aa-etRsaLU" target="_blank" rel="noopener nofollow noreferrer">keynote ,</A> highlighting our future direction. A personal moment of pride filled the screens around minute 42, when the CEO of NVIDIA Jensen Huang introduced how SAP and NVIDIA are making enterprise software more powerful and security. </SPAN></P><P><SPAN> </SPAN><SPAN>On Wednesday, I hosted a strategy talk between Sebastian Mahr, Chief Development Architect, SAP SE and Shahriar Hooshmand, GenAI Technical Lead, NVIDIA. Today, I am sharing more details about their discussion for redefining agent execution. The AI first experience for building happens in <A href="https://www.sap.com/products/artificial-intelligence/joule-studio.html" target="_blank" rel="noopener noreferrer">Joule Studio</A> and Joule Studio runtime with NVIDIA makes it easy to deploy and secure for enterprise scale. </SPAN></P><P><SPAN>AI agents are moving from conversation to action. They are beginning to execute tasks, invoke tools, cross system boundaries, and operate inside the business processes where decisions are made and value is created. For enterprises, this changes the trust equation. A chatbot can suggest; an agent can act. And once agents can engage with systems of record across finance, procurement, supply chain, manufacturing, and customer operations, the question becomes much sharper: how do we safely deploy autonomous AI? SAP and NVIDIA’s collaboration is designed to answer exactly that question. The SAP Business AI Platform uses the NVIDIA OpenShell secure runtime to make agents safe, governable, and auditable by design. Joule Studio acts as an "agent harness" that combines Large Language Model intelligence with business data and domain expertise.</SPAN></P><P><STRONG>Autonomy, Intelligence, and Security</STRONG></P><P><SPAN>Every enterprise agent sits in a tension between <STRONG>Autonomy</STRONG>, <STRONG>Intelligence</STRONG>, and <STRONG>Security</STRONG>. Highly autonomous agents can move fast, intelligent agents can reason through complex business contexts, and secure agents can operate within clear technical and business boundaries. In real-world enterprise environments, you cannot simply maximize all three at once. A loan-processing agent, a production-line response agent, and a strategic planning agent should not run with the same level of freedom, the same approval model, or the same risk posture. The more autonomous the agent, the more important it becomes to define what it can see, what it can do, who approves its actions, and how those actions are traced.</SPAN></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ratulshah_0-1779986145025.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/415164iADEA03266F1B2B27/image-size/medium?v=v2&px=400" role="button" title="ratulshah_0-1779986145025.png" alt="ratulshah_0-1779986145025.png" /></span></P><P> </P><P><STRONG><SPAN>Responsibility</SPAN></STRONG><SPAN> and secure execution must become the layer around agentic enterprise AI. Security is about container isolation, credentials, networks, APIs and risk management for unauthorized spending, compliance violations, reputational damage, liability, and audit readiness. Enterprises need a way to choose the right balance for each workload: </SPAN></P><UL><LI><SPAN>Autonomous and secure for repeatable tasks, </SPAN></LI><LI><SPAN>Intelligent and secure for high-context work with human oversight, or </SPAN></LI><LI><SPAN>Autonomous and intelligent only in tightly controlled development and testing environments. </SPAN></LI></UL><P><SPAN>Responsibility defines who decides the operating mode, who bears the risk, and how the system adapts as the workload becomes more capable or more sensitive.</SPAN></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ratulshah_1-1779986145030.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/415166i962A516662D4D927/image-size/medium?v=v2&px=400" role="button" title="ratulshah_1-1779986145030.png" alt="ratulshah_1-1779986145030.png" /></span></P><P> </P><P><SPAN>In <A href="https://www.sap.com/products/artificial-intelligence/joule-studio.html#managed-runtime" target="_blank" rel="noopener noreferrer">Joule Studio runtime</A>, NVIDIA OpenShell provides the secure runtime foundation for agent execution, including isolated environments, filesystem and network policy enforcement, and runtime-level containment to limit impact if agent logic fails. SAP brings the enterprise context: roles, skills, identity, lifecycle, policy semantics, observability, auditability, and governance across business landscapes. Put simply, OpenShell helps answer, “<EM>Can this agent action safely execute?</EM>” Joule Studio runtime helps answer, “<EM>Should this action happen at all?</EM>” Together, they close the gap between technical containment and business accountability.</SPAN></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ratulshah_2-1779986145031.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/415165i188D16D3B1ABB91E/image-size/medium?v=v2&px=400" role="button" title="ratulshah_2-1779986145031.png" alt="ratulshah_2-1779986145031.png" /></span></P><P> </P><P><SPAN>The SAP and NVIDIA collaboration, which includes SAP as a key contributor to the NVIDIA OpenShell open source project, also reflects NVIDIA's broader full-stack view of AI. NVIDIA’s founder and CEO, Jensen Huang, has framed AI as a <A href="https://blogs.nvidia.com/blog/ai-5-layer-cake/" target="_blank" rel="noopener nofollow noreferrer">five-layer stack</A>; energy, chips, infrastructure, models, and applications; the application layer is where AI creates value in real workflows. For SAP customers, that point matters. Enterprise AI becomes real when agents can operate inside the business applications, identities, policies, and audit models that companies already depend on. SAP and NVIDIA’s work on <A href="https://www.sap.com/products/artificial-intelligence/joule-studio.html#managed-runtime" target="_blank" rel="noopener noreferrer">Joule Studio runtime</A> is about making that next step practical: allowing agents to act, while staying within the boundaries enterprises require.</SPAN></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ratulshah_3-1779986145033.png" style="width: 400px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/415167i23A2F691CFC9311E/image-size/medium?v=v2&px=400" role="button" title="ratulshah_3-1779986145033.png" alt="ratulshah_3-1779986145033.png" /></span></P><P> </P><P><SPAN>This week at Computex / GTC Taipei, NVIDIA is announcing new open source software and models to continue making it easier to build and deploy autonomous agents. And now, the next step is to put this into the hands of builders. SAP customers and partners building custom agents should engage with the new <STRONG><A href="https://www.sap.com/campaigns/nl/joule-studio" target="_blank" rel="noopener noreferrer">Joule Studio early access / Early Adopter Program</A></STRONG> to start shaping their own trusted agent execution model. Explore how SAP enterprise with OpenShell-based runtime security and governance powered by OpenShell can help you understand your security posture, define workload-specific risk profiles, and move from pilots to production with confidence. Autonomous enterprise is no longer only a vision. With SAP and NVIDIA working together on secure, responsible agent execution, it is beginning now.</SPAN></P><P><SPAN>Now is the time to <A href="https://www.sap.com/campaigns/nl/joule-studio" target="_blank" rel="noopener noreferrer">get in line</A>.</SPAN></P>2026-06-01T07:50:00.019000+02:00https://community.sap.com/t5/human-capital-management-blog-posts-by-sap/sap-successfactors-cybersecurity-%C3%BCbersicht/ba-p/14410290SAP SuccessFactors Cybersecurity Übersicht2026-06-04T10:34:04.345000+02:00BerndGrossbachhttps://community.sap.com/t5/user/viewprofilepage/user-id/24183<P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BGR4SF_0-1780475581407.png" style="width: 783px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/417668iD2B8767A804AE64F/image-dimensions/783x456?v=v2" width="783" height="456" role="button" title="BGR4SF_0-1780475581407.png" alt="BGR4SF_0-1780475581407.png" /></span></P><H1 id="toc-hId-1688085754">SAP SuccessFactors Cybersecurity</H1><P>SAP SuccessFactors gehört als Human Capital Management (HCM) Suite zu den sensibelsten Cloud-Anwendungen im SAP-Portfolio: SuccessFactors verarbeitet personenbezogene Mitarbeiterdaten, darunter Gehaltsabrechnungen, Leistungsbeurteilungen und Bewerbungsunterlagen. Datenkategorien, die unter den regulatorischen Schutz der Datenschutz-Grundverordnung (DSGVO) fallen.</P><P>Dieser Artikel möchte Ihnen einen Einblick in die Cybersecurity-Maßnahmen rund um SAP SuccessFactors geben. Folgende Themen greifen wir auf:</P><UL><LI>SAP SuccessFactors Cloud Security Konzept</LI><LI>Datensicherheit – Verschlüsselung, Trennung, Löschung von Daten</LI><LI>Anwendungssicherheit – Zugriffe, Protokolle, SuccessFactors Mobile App</LI><LI>Betriebssicherheit – Monitoring, Resilienz, Patch-Mgmnt, Business Continuity</LI><LI>Vertragliche Grundlage</LI><LI>Transparenz und Compliance – Zertifikate und Prüfberichte</LI><LI>Übergreifendes Cybersecurity Konzept für SAP Cloud Services</LI></UL><H2 id="toc-hId-1620654968">Cloud Security Konzept SAP SuccessFactors</H2><P>SAP SuccessFactors ist eine Software as a Service (SaaS) Lösung. In diesem Cloud Modell liegt eine erhebliche Sicherheitsverantwortung beim Cloud Service Provider.</P><P>SAP verantwortet die Infrastruktur, einschließlich Bereitstellung der kundenspezifischen Instanzen. Dies umfasst auch die folgenden Leistungsmerkmale und Aufgaben:</P><UL><LI>Sichere Softwareentwicklung</LI><LI>Betriebsführung</LI><LI>Sicherung der Plattformarchitektur</LI><LI>24x7 Security Monitoring & Logging</LI><LI>Patch- und Bedrohungsmanagement</LI><LI>Pentests und Schwachstellentests</LI><LI>Resilienz und Hochverfügbarkeit</LI><LI>Business Continuity Management</LI><LI>Managed Backup and Restore</LI><LI>Incident and Change Management</LI><LI>24x7 Kunden Support</LI><LI>Prüfung und Einbindung von Unterauftragsverarbeitern</LI><LI>Security-Zertifikate und Prüfberichte</LI><LI>Dokumentierte Compliance der Cloud-Services</LI></UL><P>Bei SAP SuccessFactors verantwortet der Kunde die Konfiguration sowie die Benutzer- und Datenpflege in einer Instanz. Das umfasst auch die folgenden Aufgaben:</P><UL><LI>Einrichtung Benutzer</LI><LI>Einrichtung Identity Management</LI><LI>Definition und Zuweisung von Benutzerrollen und Benutzergruppen</LI><LI>Definition der Berechtigungen</LI><LI>Konfiguration der Geschäftsprozesse</LI><LI>Einrichtung und Aktivierung von Integrationen</LI><LI>Berücksichtigung von Compliance-Anforderungen</LI><LI>Security Audit Logging Verantwortung in der Instanz</LI><LI>Pflege der Daten</LI><LI>Fristgerechte Löschung von Daten</LI></UL><P>SAP klassifiziert alle Kundendaten in SAP SuccessFactors als vertraulich und wendet die im Datenverarbeitungsvertrag (SAP DPA) definierten Sicherheitsmaßnahmen (TOMs) an.</P><P>SAP SuccessFactors wird im Rahmen eines regionalen Bereitstellungsmodell angeboten. Die Rechenzentren für unsere europäischen Kunden befinden sich in der Europäischen Union, dem EWR oder der Schweiz. Dabei greift SAP auf eine Kombination aus eigenen Rechenzentren und Hyperscaler Infrastrukturen zurück.</P><H2 id="toc-hId-1424141463">Cloud Datensicherheit</H2><P>Der Schutzbedarf der Daten in SAP SuccessFactors ist hoch. Personenbezogene Daten, darunter möglicherweise besondere Kategorien personenbezogener Daten gemäß Artikel 9, DSGVO, treten im Kontext mit unternehmensbezogenen Daten auf, die vertraulich und geschäftskritisch sein können, aber auch Konfigurationsdaten, die als sicherheitsrelevant eingestuft werden müssen, da Fehlkonfigurationen die Verarbeitung gefährden können.</P><P>Zum Schutz dieser Daten werden die folgenden Maßnahmen bereitgestellt.</P><H3 id="toc-hId-1356710677">Verschlüsslung gespeicherter Daten</H3><P>SAP stellt Data-at-Rest-Verschlüsslung im Standard bereit. Wenn Daten abgelegt werden, dann werden sie auch verschlüsselt. Die Verschlüsselung erfolgt mittels AES 256 Standard. Für die Verwaltung der Schlüssel ist SAP verantwortlich.</P><P>Darüber hinaus bietet SAP für SAP SuccessFactors auch <STRONG>kundeneigene Verschlüsselung</STRONG> an d.h. Unternehmen und Organisationen, die Kontrolle über ihre kryptografischen Schlüssel benötigen, können den (aufpreispflichtigen) SAP Key Management Service (SAP KMS) nutzen. Dieser unterstützt drei Betriebsszenarien:</P><UL><LI>Customer Specific Encryption Keys (CSEK)</LI><LI>Bring Your Own Key (BYOK)</LI><LI>Hold Your Own Key (HYOK)</LI></UL><P>SAP KMS bietet FIPS-140-2-Konformität im Level 3, Funktionstrennung (Segregation of Duties), Master Key Management und die Protokollierung aller Schlüsselzugriffe.</P><H3 id="toc-hId-1160197172">Verschlüsslung übertragener Daten</H3><P>Daten während der Übertragung (Data-in-Transit) werden mittels TLS 1.2 oder TLS 1.3. Protokoll und starken Chiffren verschlüsselt.</P><P>Beim Datenaustausch via OData API‘s wird zertifikatbasierte Authentifizierung unterstützt.</P><P>Dateiaustausche werden via SFTP geschützt. Der Schutz der Dateien kann durch eine Verschlüsselung auf Pretty Good Privacy (PGP) Basis noch ausgeweitet werden.</P><H3 id="toc-hId-963683667">Datensicherung</H3><P>SAP SuccessFactors stellt standardmäßig für alle Kundendatenbanksicherungen folgendes bereit:</P><UL><LI>Tägliche inkrementelle Sicherungen.</LI><LI>Wöchentliche vollständige Datenbanksicherungen.</LI><LI>Alle Sicherungen werden nach dem AES-256-Bit-Standard verschlüsselt.</LI><LI>Sicherungen werden sowohl im Produktivrechenzentrum als auch im Backuprechenzentrum des Kunden gespeichert.</LI><LI>Sicherungen werden 30 Tage lang gespeichert.</LI><LI>Produktionskunden können eine Wiederherstellung aus einer Sicherung über den Kundensupport anfordern.</LI></UL><P>SAP verfügt über einen formalen Systemsicherungsprozess und -zeitplan für die SAP-Cloud-Lösungen, der hardwareunabhängige Wiederherstellungs- und Wiederherstellungsfunktionen umfasst. Es sind geeignete Prozesse und automatisierte Tools vorhanden, um die Integrität der Sicherung zu validieren, und Sicherungsprotokolle werden täglich überprüft, um Sicherungsfehler zu erkennen und zu korrigieren.</P><H3 id="toc-hId-767170162">Sichere Datentrennung</H3><P>SuccessFactors läuft als Mehr-Mandanten-Anwendung mit logischer Datentrennung auf Datenbankebene. Die logische Trennung von kundenspezifischen Daten wird mittels HANA Datenbankschemen umgesetzt. Ein Kunde kann nur auf die Daten seines Unternehmens zugreifen.</P><H3 id="toc-hId-570656657">Datenlöschung</H3><P>Die Einhaltung von Löschfristen wird durch das Datenaufbewahrungsmanagement in SAP SuccessFactors gesteuert. Hier können maßgeschneiderte Löschkonzepte abgebildet werden, orientiert an relevanten Zeitpunkten und abgestimmt auf die relevante Datenkategorie z.B. Daten der Bewerbenden sowie auf das betroffene Land, in dem die Löschregel zum Einsatz kommt.</P><P>Basierend auf diesen Regeln, können wiederkehrende Löschläufe durch den Kunden eingeplant werden. Sobald die erfolgreiche Prüfung der Ergebnisse vorliegt, kann eine Freigabe erfolgen und die Löschung durchgeführt werden.</P><P>Nach Vertragsende werden SAP SuccessFactors Daten durch SAP gemäß den vereinbarten Prozessen und den geltenden Datenschutzvorgaben sicher gelöscht. Der Datenlöschungsprozess wird automatisch ausgelöst, sobald ein Vertrag endet oder gekündigt wird. Die vollständige Löschung der Daten erfolgt nach Validierung und Ablauf von Kulanzfristen. Die sichere Entfernung und Vernichtung von Datenträgern ist Bestandteil der SAP-Standards und wird durch Audits überprüft.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="BGR4SF_1-1780474754880.png" style="width: 708px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/417664i46456D953ED072DF/image-dimensions/708x271?v=v2" width="708" height="271" role="button" title="BGR4SF_1-1780474754880.png" alt="BGR4SF_1-1780474754880.png" /></span></P><P> </P><H2 id="toc-hId-245060433"> </H2><H2 id="toc-hId-48546928"> </H2><H2 id="toc-hId-199287780"> </H2><H2 id="toc-hId-2774275"> </H2><H2 id="toc-hId--193739230"> </H2><H2 id="toc-hId--390252735">Cloud Anwendungssicherheit</H2><H3 id="toc-hId--880169247">Identitätsmanagement</H3><P>SAP SuccessFactors wird mit dem <A href="https://help.sap.com/docs/cloud-identity-services?locale=de-DE" target="_blank" rel="noopener noreferrer">SAP Identity Management Services</A> bereitgestellt. Diese bieten Authentifizierung über Industriestandards wie SAML 2.0 und unterstützen Single Sign-On sowie die Delegation an unternehmenseigene Identity Provider wie Azure Active Directory.</P><P>Benutzeridentitäten zwischen Quell- und Zielsystemen können auf Basis des SCIM-Standards synchronisiert werden.</P><P>SAP SuccessFactors unterstützt zudem die zertifikatsbasierte Authentifizierung für die sichere API-Kommunikation.</P><H3 id="toc-hId--1076682752">Zugriffssteuerung</H3><P>Die Zugriffssteuerung von SAP SuccessFactors basiert auf rollenbasierten Berechtigungen, einem granularen, rollenbasierten Zugriffssteuerungssystem. Zugriffsrechte sind granular, werden auf Feld-, Datensatz- und Funktionsebene definiert und werden Benutzern, Rollen oder Gruppen zugewiesen.</P><H3 id="toc-hId--1273196257">Sichere Softwareentwicklung</H3><P>SAP entwickelt SAP SuccessFactors nach dem <STRONG>Secure Software Development and Operations Lifecycle</STRONG>, der risikobasierte Sicherheitsanforderungen in jede Entwicklungsphase integriert.</P><P>Security Gates, Threat Modeling sowie Statische (SAST) und dynamische (DAST) Sicherheitsanalysen sind nur einige Elemente dieses umfassenden Vorgehens bei der Entwicklung.</P><H3 id="toc-hId--1469709762">Audit Trails und Protokolle</H3><P>SAP SuccessFactors bietet Kunden Zugang zu Application Security Audit Logs auf Anwendungsebene, darunter befinden sich u.a. der General Audit Bericht, die Änderungsverfolgung (Change Audit), Kontrollierte Einsicht (Read Access) für sensible Daten. Sicherheitsprotokolle auf Ebene der SAP SuccessFactors Instanz können in ein kundeneigenes SIEM-System überführt werden.</P><P>Darüber hinaus existieren spezialisierte Audit-Funktionen wie Audit Trails im Recruiting und in Performance & Goals, wesentlich für die Nachvollziehbarkeit von Personalentscheidungen.</P><H3 id="toc-hId--1666223267">SAP SuccessFactors Mobile App</H3><P>Die SAP SuccessFactors Mobile App wird für iOS und Android Betriebssysteme bereitgestellt. Die Installation ist auf unternehmenseigenen und privaten Endgeräten möglich.</P><P>Die Authentifizierung bei Zugriffen durch die Mobile App erfolgt mittels OAuth Token. Die App kann mittels Passwortes oder gerätespezifischer Möglichkeiten (Fingerabdruck, Gesichtsscan) vor unberechtigtem Zugriff geschützt werden.</P><P>Unabhängig vom Endgerät sind die Berechtigungen der Nutzenden auf der SAP SuccessFactors Mobile App: Basis sind die im System hinterlegten Berechtigungen.</P><P>Alle Datenübertragungen sind verschlüsselt, wenn es zu einer Ablage von Daten auf der App kommt, so sind auch diese verschlüsselt.</P><P>Die SAP SuccessFactors Applikation für Mobilgeräte unterstützt die marktführenden Mobile Device Management (MDM) Systeme.</P><H2 id="toc-hId--1569333765">Cloud Betriebssicherheit</H2><H3 id="toc-hId--1891066586">Netzwerksicherheit</H3><P>SAP hat eine mehrstufige Netzwerk-Architektur implementiert, die Zero-Trust-Prinzipien folgt und eine Strategie der "Tiefenverteidigung“ nutzt. Der Netzwerkverkehr wird kontinuierlich durch ein Intrusion Prevention System (NIPS) überwacht und protokolliert.</P><P>SAP unterhält intern eine strikte Zugriffssteuerungsrichtlinie, die einen rollenbasierten Zugriff auf alle Ressourcen (Anwendungen, Betriebssysteme, Netzwerkgeräte usw.) fordert sowie eine eindeutige ID für alle Personen. Berechtigungen werden nach den Segregation-of-Duties und Need-to-Know Prinzipien vergeben.</P><P>Die Sicherheit des SAP-Netzwerks einschließlich der SAP-Endbenutzerausrüstung wird zusätzlich durch Lösungen wie Netzwerkzugangssteuerung, Netzwerkfilterung, starke Authentifizierung, Internet-Inhaltsfilterung und Antiviren-Scanner gewährleistet.</P><H3 id="toc-hId--2087580091">Monitoring</H3><P>SAP betreibt ein <STRONG>24/7 Security Monitoring</STRONG> für die SAP SuccessFactors-Plattform. Sicherheitsereignisse werden zentral in einem SIEM System korreliert; bei verdächtigen oder bösartigen Aktivitäten werden automatische Alerts und Security Incident Tickets erzeugt.</P><P>Die Nachverfolgung von Tickets durch die Mitarbeitenden im Operations-Team folgt dem SAP Security Incident Management Prozess, die Tätigkeiten werden dokumentiert und sind revisionsfähig.</P><H3 id="toc-hId-2010873700">Logging</H3><P>Alle relevanten technischen Infrastruktur-Komponenten die den Betrieb des SAP SuccessFactors Service unterstützen, sind an ein SIEM System angeschlossen. Die dort protokollierten Daten umfassen auch alle Login-Versuche um ggf. forensische Untersuchungen zu unterstützen.</P><H3 id="toc-hId-1814360195">Resiliente Plattformarchitektur</H3><P>SAP stellt für SAP SuccessFactors eine Multi-Availability-Zone-Architektur bereit. Diese wird jeweils ergänzt durch ein Sekundär-Rechenzentrum um eine zeitnahe Widerherstellung des Services bei einem Rechenzentrumsausfall zu gewährleisten.</P><H3 id="toc-hId-1617846690">Business Continuity Management</H3><P>SAP SuccessFactors ist nach ISO 22301 zertifiziert (Business Continuity Management System).</P><P>SAP SuccessFactors sichert die Daten seiner Auftraggeber kontinuierlich und hält diese über einen Zeitraum von 30 Tagen zur Verfügung. Eine Kopie der Datensicherung befindet sich jederzeit in dem vorgesehenen BackUp Rechenzentrum.</P><P>Es werden jährliche Disaster Recovery Tests durchgeführt, der zu Grunde liegende Disaster Recovery Plan wird regelmäßig geprüft und aktualisiert.</P><H3 id="toc-hId-1421333185">Vulnerability Management und Penetration Testing</H3><P>SAP führt regelmäßige Schwachstellenanalysen (Vulnerability Scans) und Penetrationstests durch und stellt diese seinen Kunden auf Nachfrage zur Verfügung. Kunden können, in Abstimmung mit SAP, eigene Penetrationstests durchführen.</P><H3 id="toc-hId-1224819680">Patch- und Change-Management</H3><P>SAP verwaltet das Patching der SAP SuccessFactors-Plattform, einschließlich Sicherheits-Patches für Betriebssysteme, Datenbank, Middleware und Anwendungsschicht.</P><P>Bei der Priorisierung von Schwachstellen orientiert sich SAP am <STRONG>Common Vulnerability Scoring System</STRONG> (CVSS).</P><H2 id="toc-hId-1321709182">Vertragliche Grundlage</H2><P>Die SAP SuccessFactors Vertragsgrundlage umfasst folgende Dokumente:</P><TABLE><TBODY><TR><TD width="217"><P><STRONG>Vertragsbestandteil</STRONG></P></TD><TD width="384"><P><STRONG>Inhalt</STRONG></P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://assets.cdn.sap.com/agreements/product-use-and-support-terms/cls/en/sample-order-form-for-cloud-services-english-v4-2016.pdf" target="_blank" rel="noopener noreferrer">Order Form</A></STRONG></P></TD><TD width="384"><P>Kunde & SAP (Kontaktdaten, Leistungsumfang, Beginn & Ende…)</P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://www.sap.com/about/trust-center/agreements/cloud/cloud-services.html?search=General+Terms+and+Conditions&sort=title_asc&tag=region-country:europe/germany" target="_blank" rel="noopener noreferrer">AGB’s</A></STRONG></P></TD><TD width="384"><P>Nutzungsrechte, SAP Verantwortlichkeiten und Pflichten, Vergütung, Gewährleistung, Vertraulichkeit, Kündigung…</P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://www.sap.com/about/trust-center/agreements/cloud/cloud-services.html?sort=latest_desc&search=Supplement%20SuccessFactors%20HCM%20Suite&tag=language:german" target="_blank" rel="noopener noreferrer">Ergänzende Bedingungen</A></STRONG></P></TD><TD width="384"><P>Nutzungsmetriken, zusätzl. Bedingungen, Disaster Recovery…</P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://www.sap.com/about/trust-center/agreements/cloud/cloud-services.html?sort=title_asc&search=Support%20Schedule&tag=language:german" target="_blank" rel="noopener noreferrer">Support Schedule</A></STRONG></P></TD><TD width="384"><P>Kontaktkanäle, Sprachen, Prioritäten und Reaktionszeiten</P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://www.sap.com/about/trust-center/agreements/cloud/cloud-services.html?search=Service%20Level%20Agreement&sort=title_asc&tag=language:german" target="_blank" rel="noopener noreferrer">Service Level Agreement</A></STRONG></P></TD><TD width="384"><P>Systemverfügbarkeit, Wartungsfenster, Gutschriften</P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://www.sap.com/about/trust-center/agreements/cloud/cloud-services.html?sort=title_asc&search=Data%20Processing%20Agreement%20for%20Cloud%20Services&tag=language:german" target="_blank" rel="noopener noreferrer">Auftragsverarbeitungs-vertrag</A></STRONG></P></TD><TD width="384"><P>Sicherheit Verarbeitung, Leistungspflichten SAP, Zertifizierung und Audits, Unterauftragsverarbeiter…</P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://www.sap.com/about/trust-center/agreements/cloud/cloud-services.html?sort=latest_desc&tag=agreements:security-measures/security-measures-for-cloud-services&tag=language:german" target="_blank" rel="noopener noreferrer">Sicherheitsmaßnahmen</A> (TOM´s)</STRONG></P></TD><TD width="384"><P>Governance der Informationssicherheit, Sicherheits-zertifizierungen und -bescheinigungen, Organisatorische, physische und technische Sicherheitsmaßnahmen, Resilienz, Umgang mit Sicherheitsvorfällen…</P></TD></TR></TBODY></TABLE><H2 id="toc-hId-1125195677">Transparenz und Compliance</H2><P>SAP SuccessFactors unterliegt regelmäßigen, unabhängigen Audits und hält eine Vielzahl von anerkannten Zertifikaten und Prüfberichte bereit. Darunter befinden sich:</P><TABLE><TBODY><TR><TD width="217"><P><STRONG>Zertifikat, Prüfbericht</STRONG></P></TD><TD width="384"><P><STRONG>Inhalt</STRONG></P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://www.sap.com/about/trust-center/certification-compliance/compliance-finder.html?sort=title_asc&tag=compliance-document:compliance-entity/sap-successfactors&tag=compliance-document:compliance-offering/iso-27001" target="_blank" rel="noopener noreferrer">ISO 27001</A></STRONG></P></TD><TD width="384"><P>Informationssicherheits-Managementsystem</P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://www.sap.com/about/trust-center/certification-compliance/compliance-finder.html?sort=title_asc&tag=compliance-document:compliance-entity/sap-successfactors&tag=compliance-document:compliance-offering/iso-27017" target="_blank" rel="noopener noreferrer">ISO 27017</A></STRONG></P></TD><TD width="384"><P>Schutz personenbezogener Daten in der Cloud</P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://www.sap.com/about/trust-center/certification-compliance/compliance-finder.html?sort=title_asc&tag=compliance-document:compliance-entity/sap-successfactors&tag=compliance-document:compliance-offering/iso-27018" target="_blank" rel="noopener noreferrer">ISO 27018</A></STRONG></P></TD><TD width="384"><P>Sicherheitsmaßnahmen für Cloud‑Dienste</P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://www.sap.com/about/trust-center/certification-compliance/compliance-finder.html?sort=title_asc&tag=compliance-document:compliance-entity/sap-successfactors&tag=compliance-document:compliance-offering/iso-22301" target="_blank" rel="noopener noreferrer">ISO 22301</A></STRONG></P></TD><TD width="384"><P>Business Continuity Managementsystem</P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://www.sap.com/about/trust-center/certification-compliance/compliance-finder.html?sort=title_asc&tag=compliance-document:compliance-offering/bs-10012" target="_blank" rel="noopener noreferrer">BS 10012</A></STRONG></P></TD><TD width="384"><P>Datenschutz-Managementsystem</P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://www.sap.com/about/trust-center/certification-compliance/compliance-finder.html?sort=title_asc&tag=compliance-document:compliance-entity/sap-successfactors&tag=compliance-document:compliance-offering/eu-cloud-coc" target="_blank" rel="noopener noreferrer">EU Cloud Code of Conduct</A></STRONG></P></TD><TD width="384"><P>Genehmigte Verhaltensregeln, Artikel 41/42 DSGVO</P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://www.sap.com/about/trust-center/certification-compliance/compliance-finder.html?sort=title_asc&tag=compliance-document:compliance-entity/sap-successfactors&tag=compliance-document:compliance-offering/c5" target="_blank" rel="noopener noreferrer">ISAE 3000 BSI C5 Type II</A> </STRONG></P></TD><TD width="384"><P>Prüfbericht Sicherheitsmaßnahmen gem. BSI</P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://www.sap.com/about/trust-center/certification-compliance/compliance-finder.html?sort=title_asc&tag=compliance-document:compliance-entity/sap-successfactors&tag=compliance-document:compliance-offering/soc-1" target="_blank" rel="noopener noreferrer">ISAE 3402 SOC 1 Type II</A></STRONG></P></TD><TD width="384"><P>Prüfbericht interne Kontrollen</P></TD></TR><TR><TD width="217"><P><STRONG><A href="https://www.sap.com/about/trust-center/certification-compliance/compliance-finder.html?sort=title_asc&tag=compliance-document:compliance-entity/sap-successfactors&tag=compliance-document:compliance-offering/soc-2" target="_blank" rel="noopener noreferrer">ISAE 3000 SOC 2 Type II</A></STRONG></P></TD><TD width="384"><P>Prüfbericht Sicherheitsmaßnahmen</P></TD></TR></TBODY></TABLE><P>Aktuelle Zertifikate und Prüfberichte können im SAP Trust Center eingesehen oder beantragt werden: <A href="https://www.sap.com/about/trust-center/certification-compliance/compliance-finder.html?sort=title_asc&tag=compliance-document:compliance-entity/sap-successfactors" target="_blank" rel="noopener noreferrer">Alle Zertifikate Auditberichte SF</A></P><H2 id="toc-hId-928682172">Übergreifendes Cybersecurity Konzept für SAP Cloud Services</H2><P>Alle vorgestellten Sicherheitsmaßnahmen betten sich in die übergeordneten, konzernweiten Maßnahmen der SAP ein, beschrieben durch das SAP Security Policy Framework und durchgesetzt mit dem NIST Cyber Security Framework.</P><H3 id="toc-hId-606949351">SAP Security Policy Framework</H3><P>Die SAP Global Security Policy ist das übergeordnete Dokument, das die Management-Intention, Erwartungen und strategische Ausrichtung festlegt. Es definiert die strategischen Ziele und Vorgaben für ein höchstmögliches Sicherheitsniveau bei der Bereitstellung von SAP Cloud Services.</P><P>Konkret dient es als Leitfaden, der mit anerkannten Standards, klaren Sicherheitsregeln und Best Practices die Grundlage für Planung, Entwicklung, Konfiguration und Betrieb von SAP Cloud Lösungen darstellt.</P><P>Das Ziel: Einen einheitlichen, hohen Sicherheitsstandard über alle SAP Cloud Services zu gewährleisten!</P><P><A href="https://www.sap.com/about/trust-center/security.html" target="_blank" rel="noopener noreferrer">Secure Data, Applications, and Data Centers | SAP Security</A></P><H3 id="toc-hId-410435846">Einsatz des NIST Cyber Security Frameworks</H3><P>SAP hat erfolgreich das NIST Cyber Security Framework (NIST CSF) implementiert und den Tier 3 Reifegrad erreicht.</P><P>In einer sich kontinuierlich wandelnden Bedrohungslandschaft bietet das NIST Cybersecurity Framework (CSF) eine effektive und strukturierte Grundlage, um Sicherheits-Maßnahmen flexibel anzupassen und kontinuierlich weiterzuentwickeln. Es unterstützt uns dabei, neue Risiken systematisch zu identifizieren, zu bewerten und geeignete Schutzmaßnahmen gezielt an sich verändernde Anforderungen und Bedrohungen auszurichten.</P><P>SAP Security Policy Framework und NIST Cyber Security Framework ergänzen sich, stellen in ihrer Verbindung sicher, das alle Sicherheits-Vorgaben im Rahmen eines aktiven Risiko-Managements kontinuierlich geprüft und gegebenenfalls angepasst werden.</P><P>Das Erreichen von NIST CSF Tier 3 soll nicht nur das Vertrauen in unsere Produkte und Dienstleistungen stärken, sondern auch unser Engagement, Kunden zu schützen sowie Prozesse und Daten dauerhaft wirksam abzusichern.</P><P><A href="https://www.sap.com/documents/2024/08/e49580a9-d27e-0010-bca6-c68f7e60039b.html" target="_blank" rel="noopener noreferrer">How SAP is safeguarding its customers: Implementing the NIST Cybersecurity Framework achieving Tier 3 alignment</A></P><H2 id="toc-hId-507325348">Fazit</H2><P>SAP SuccessFactors steht aufgrund der Sensitivität von HR-Daten im Brennpunkt regulatorischer und sicherheitstechnischer Anforderungen.</P><P>SAP verfolgt einen durchgängigen Sicherheitsansatz, vom Shared-Responsibility-Modell mit klarer Verantwortungstrennung zwischen SAP und Kunde, über Datenverschlüsselung, granulare rollenbasierte Berechtigungen, nativ integrierte SAP Identity Management Services, bis hin zu 24x7-Security-Monitoring, Cyber Threat Intelligence und umfassender Audit- und Compliance-Berichte.</P><P>Die Wirksamkeit dieses Sicherheitsmodells hängt jedoch auch von der aktiven Mitwirkung des Kunden ab -- insbesondere bei der Konfiguration von Berechtigungen, beim Identity Management, Datenschutzeinstellungen und der regelmäßigen Überprüfung von Security Audit Logs.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="BGR4SF_2-1780474754882.png" style="width: 477px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/417663iF240EEEFEBB99F3C/image-dimensions/477x421?v=v2" width="477" height="421" role="button" title="BGR4SF_2-1780474754882.png" alt="BGR4SF_2-1780474754882.png" /></span></P><P> </P><P> </P><P> </P><P> </P><P> </P><P> </P><P> </P><P> </P><P> </P><P><A href="https://www.sap.com/germany/about/trust-center/security.html" target="_blank" rel="noopener noreferrer">Erfahren Sie mehr zu Sicherheit mit SAP für Daten, Anwendungen und Rechenzentren </A></P>2026-06-04T10:34:04.345000+02:00https://community.sap.com/t5/technology-blog-posts-by-sap/understanding-security-in-sap-joule-s-runtime/ba-p/14414450Understanding Security in SAP Joule’s Runtime2026-06-09T12:32:18.641000+02:00AlexDevassyhttps://community.sap.com/t5/user/viewprofilepage/user-id/2158816<P>Every time you ask <a href="https://community.sap.com/t5/c-khhcw49343/Joule/pd-p/d0136351-8a9c-4881-aebc-bf414b785998" class="lia-product-mention" data-product="1207-1">Joule</a> a question, your request passes through multiple layers of security, each one independently verifying, isolating, and constraining what happens. Here's what that journey looks like from the inside<span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="joule_image.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/419540i804103D5E4F53CA4/image-size/large?v=v2&px=999" role="button" title="joule_image.png" alt="joule_image.png" /></span></P><P><EM>Every Joule request flow through two core runtime layers: the Orchestration Runtime, where scenarios are resolved and reasoning happens, and the Execution Runtime, where Joule Functions run. The sections below trace your request through these layers, and the security controls that travel with it.<BR /></EM></P><H2 id="toc-hId-1817289435">1. At the Front Door - Proving Who You Are</H2><P>The moment you interact with Joule; your identity is verified through <SPAN class=""><A href="https://help.sap.com/docs/joule/serviceguide/authentication-of-requests?locale=en-US&version=CLOUD&q=saml&ai=true#business-user" target="_blank" rel="noopener noreferrer">OAuth2 via SAP Identity Authentication Service.</A></SPAN> A signed token is issued, and this isn't a one-time check. Every single service in Joule's pipeline independently re-validates that token.</P><P><EM>Layer: Runtime Entry</EM></P><H2 id="toc-hId-1620775930">2. Everywhere - Controls That Follow Your Request Across All Layers</H2><P>Some security controls aren't tied to a single layer; they're enforced uniformly at every boundary your request crosses.</P><P><SPAN><A href="https://help.sap.com/docs/joule/serviceguide/network-and-communication-security?locale=en-US&version=CLOUD" target="_blank" rel="noopener noreferrer">Your identity is re-verified at every hop.</A></SPAN> All inter-service communication uses mutual TLS (mTLS), both sides of every connection prove their identity. There is no "trusted internal zone." Whether your request is at the runtime entry, orchestration, or execution layer, the service handling it independently validates your authentication token and the calling service's certificate. This creates a zero-trust internal mesh.</P><P><SPAN><A href="https://help.sap.com/docs/joule/serviceguide/what-is-joule?locale=en-US&version=CLOUD&q=Multi%E2%80%91tenant#multi-tenancy" target="_blank" rel="noopener noreferrer">Your data is isolated from every other customer's.</A></SPAN> Each tenant's data lives in its own isolated database schema, Joule cannot query across tenant boundaries. Conversation identifiers are cryptographically derived, making them impossible to guess or enumerate. Your conversations, context, and business data are unreachable by any other customer on the platform.</P><P><EM>Applies to: All layers</EM></P><H2 id="toc-hId-1424262425">3. Routing Your Request - Only What You're Allowed to Invoke</H2><P>Once authenticated, your request reaches Joule's orchestration layer. Before any AI processing begins, your available scenarios are filtered.</P><P>Joule supports role-based access to AI scenarios, capability developers define <SPAN><A href="https://help.sap.com/docs/joule/joule-development-guide-ba88d1ec6a1b442098863d577c19b0c0/role-based-scenario-access?locale=en-US&version=CLOUD#definition-of-a-visibility-condition" target="_blank" rel="noopener noreferrer">visibility conditions</A></SPAN> that restrict which scenarios are available to which users. These conditions can be based on navigation authorizations or identity attributes from the user's authentication token. A finance analyst and a warehouse manager see different Joule scenarios, enforced server-side, not by hiding UI elements.</P><P><EM>Layer: Orchestration Runtime</EM></P><H2 id="toc-hId-1227748920">4. Safer Conversations - Filtering Harmful Content</H2><P>Joule's reasoning runs through large language models accessed via SAP's centralised AI orchestration platform. That <A href="https://help.sap.com/docs/sap-ai-core/generative-ai/input-filtering" target="_blank" rel="noopener noreferrer">platform brings a content-safety layer</A> with it, and Joule turns it on by default. </P><P>The filter screens AI inputs and outputs for harmful content and operates on both sides of the model:</P><P>- Before your message reaches the LLM, the input is checked.</P><P>- Before any model-generated text returns to you, the output is checked.</P><P>The platform attaches the filter automatically when an AI call is made. Capability developers don't have to remember to switch it on; safety is the default path.</P><P>By consolidating on a centrally managed safety service rather than per-team guardrails, Joule benefits from continuous improvements to the underlying classifiers without every capability needing to change its own code.</P><P><EM>Layer: Orchestration</EM> <EM>Runtime</EM></P><H2 id="toc-hId-1031235415">5. Taking Action - The AI Can't Run Wild</H2><P>When Joule resolves your request into a backend action such as querying an SAP system, updating a record, running a calculation, etc. that action executes inside a hardened sandbox:</P><P>- <SPAN><A href="https://help.sap.com/docs/joule/joule-development-guide-ba88d1ec6a1b442098863d577c19b0c0/spring-expression-language" target="_blank" rel="noopener noreferrer">Expression sandbox</A></SPAN>: only pre-approved operations can execute. Arbitrary code is structurally impossible; the sandbox uses a strict allowlist of permitted types and methods.</P><P>- <SPAN><A href="https://help.sap.com/docs/joule/joule-development-guide-ba88d1ec6a1b442098863d577c19b0c0/handlebars" target="_blank" rel="noopener noreferrer">Template engine</A></SPAN>: scripting is limited to template logic, not general-purpose computation. The engine evaluates structure, never executes code.</P><P>- <A href="https://help.sap.com/docs/joule/joule-development-guide-ba88d1ec6a1b442098863d577c19b0c0/configure-api-request-timeout" target="_blank" rel="noopener noreferrer">Resource governors</A>: execution timeouts, response size caps, and iteration limits prevent any single action from consuming unbounded resources.</P><P>Even in an adversarial scenario, the execution environment constrains what can physically happen, code execution and resource exhaustion are architecturally prevented.</P><P><EM>Layer: Execution Runtime</EM></P><H2 id="toc-hId-834721910">6. Reaching Backend Systems - Only Where You've Approved, Only What You Can See</H2><P>Joule doesn't have open network access. All outbound connectivity is routed through a fixed, <SPAN><A href="https://help.sap.com/docs/joule/integrating-joule-with-sap/configure-destinations" target="_blank" rel="noopener noreferrer">admin-configured allowlist of approved hosts</A></SPAN>. Combined with IP-range blocking, this means:</P><P>- Joule can only communicate with systems your organisation has explicitly permitted</P><P>- No AI-generated URL or parameter can redirect connectivity to an unapproved host</P><P>When Joule does reach a backend system, it acts “as you”, not as a privileged service account. </P><P>Backend calls use principal propagation, meaning your existing authorization rules are enforced by the backend itself. If you can't access a purchase order in SAP directly, you can't access it through Joule either.</P><P>Your administrators control the network boundary. Your backend controls the data boundary. Joule inherits both.</P><P><EM>Layer: Execution Runtime</EM></P><H2 id="toc-hId-638208405">7. The Response - Secure All the Way Back</H2><P>The response travels back through the same authenticated, encrypted service mesh. Every hop is mTLS-protected, every service re-validates the request context, and tenant isolation ensures your response data never intermingles with another customer's pipeline.</P><H2 id="toc-hId-441694900">Security by Architecture, Not by Afterthought</H2><P>Joule wasn't secured after the fact - security is built into how requests flow through the system. Identity is verified at every boundary. Data is isolated at the infrastructure level. Code execution is sandboxed by design. Network access is bounded by admin policy.</P><P>The result: an enterprise AI assistant where security isn't a layer on top, it's the architecture itself. </P>2026-06-09T12:32:18.641000+02:00https://community.sap.com/t5/technology-blog-posts-by-members/check-and-then-re-check-your-cloud-foundry-org-and-spaces-for-correct-user/ba-p/14426926Check and then Re-Check Your Cloud Foundry Org and Spaces for Correct User Assignments2026-06-25T07:38:01.950000+02:00AshGoyalhttps://community.sap.com/t5/user/viewprofilepage/user-id/6574<P class=""><U><STRONG>Summary</STRONG></U><STRONG>:</STRONG><EM> A user can have zero access to SAP BTP Global and SubAccount and still be able to create, read, edit, or delete every service key in BTP! All you need is access at the Cloud Foundry level. Your landscape can be compromised leading to data privacy issues and business continuity can be disrupted significantly. Read more to find out how.</EM></P><P class="">Most of the organizations use SAP BTP Integration Suite to connect systems across their landscape. A standard pattern is exposing HTTP endpoints (or other inbound endpoints) to third party systems so they can trigger integration flows.</P><P class="">To authenticate against those endpoints, you create service keys on the Process Integration Runtime service instance (integration-flow). These are basically API credentials in a way which we call Service keys (the other API credentials are available in the API Management - Developer Hub) and they live at the Cloud Foundry space tied to the service instance. Anyone with those credentials can call your integration endpoints directly and send or read data.</P><DIV class=""><DIV class=""><DIV class=""><P> </P></DIV></DIV><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AshGoyal_1-1782365335305.png" style="width: 922px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/425963iD0252ABA2E3A23D0/image-dimensions/922x245?v=v2" width="922" height="245" role="button" title="AshGoyal_1-1782365335305.png" alt="AshGoyal_1-1782365335305.png" /></span></DIV><P class="">BTP admins generally manage user access carefully at SubAccount and Global Account level but generally find it too taxing to manage carefully at Cloud Foundry org and space level. When offboarding someone, most admins remove the user from the SubAccount and Global Account either manually or using IAS and then stop there. If that person still has any kind of CF access, they retain full access to every service key -- and they don't need the BTP cockpit to use it. In fact they won't have access to these using the BTP Cockpit. All they need is CF CLI or CF API to access these. The CF CLI and CF API are available to anyone on the internet for download, and a few commands is all it takes to create, read or delete any service key in the BTP environment.</P><P class="">I have found this security hole at many customers I am working with. The team has removed the user from the SubAccount but the user is still active in Cloud Foundry with no one having bothered to remove them from there thinking that removing them from SubAccount using IAS is enough. It is not! Even if you remove someone through IAS you must separately ensure they are fully removed from CF membership, not just their roles.</P><P class="">Concrete Example: say Target orders flow into S/4HANA via Integration Suite secured by service keys. A disgruntled ex-employee with no BTP cockpit access but still active in CF can delete every one of those keys. Integrations go down, orders stop getting received, and the business stops!</P><P class="">SAP does offer a connector to automate CF user and role management via SAP IPS (Identity Provisioning Service): <A class="" href="https://community.sap.com/t5/technology-blog-posts-by-sap/streamlining-user-management-integrating-sap-integration-suite-with-sap/ba-p/14069705" target="_blank">https://community.sap.com/t5/technology-blog-posts-by-sap/streamlining-user-management-integrating-sap-integration-suite-with-sap/ba-p/14069705</A></P><P class="">If you have used, please comment and share you experience especially on how easy it is to use it.</P><P class="" data-unlink="true">A Big thanks to the <A href="https://www.terrabt.com/products/btp-xid" target="_blank" rel="noopener nofollow noreferrer">SAP BTP xID</A> tool because of which I was able to find this issue.</P><P class="">In the meanwhile I urge all SAP BTP Administrators to check their CF Orgs and Spaces for any assigned users who should not be there.</P><P class="">Update: Possibly, the following security standards get violated when you just rely on controlling S user lifetime to control access to the API and Service Keys. </P><P>1. ISO/IEC 27001:2022 (Information Security Management) - <STRONG>Control A.5.15 (Access Control):</STRONG><SPAN> </SPAN>Requires access to assets to be restricted based on business and security requirements.</P><P>2. NIST SP 800-53 (Security and Privacy Controls) - AC-2 (Account Management)</P><P>3. PCI DSS 4.0 (Payment Card Industry Data Security Standard) - <STRONG>Requirement 8.6:</STRONG><SPAN> </SPAN>Strictly regulates the use of application accounts</P><P>4. SOC 2 Type II (Trust Services Criteria) - <STRONG>Logical Access Controls (CC6.1/CC6.2):</STRONG><SPAN> </SPAN>Internal controls must prevent unauthorized logical access to data.</P><P>5. Sarbanes-Oxley (SOX) Section 404 (Internal Controls) Compliance - Section 404 mandates that management and auditors establish, maintain, and regularly assess the effectiveness of internal controls over financial reporting to prevent fraud and data tampering. Financial data generally passes through these integrations on a regular basis. If the keys are freely accessible, it is possible, that a rogue internal or external actor can tamper with integrations, run them with incorrect data with no way to find out later who did it.</P><P><STRONG>My recommendation:</STRONG> <SPAN> I would recommend that apart from one nominated administrator, nobody else should have access to the Production SAP BTP Cloud Foundry Environment in normal course of business. The access should be given to the CF environment only as temporary firefighter access same as is today done in SAP ERP or S/4HANA Production systems. Developers generally do not have unhindered access in these systems, most of the time not even read only access. The same concept needs to be applied to SAP BTP production environments also. This needs to be matured as part of SAP BTP Governance setup.</SPAN></P>2026-06-25T07:38:01.950000+02:00https://community.sap.com/t5/enterprise-resource-planning-blog-posts-by-sap/enhancing-the-support-for-rise-on-aws-amp-gcp-logserv-with-sentinel-for-sap/ba-p/14428222Enhancing the Support for RISE on AWS & GCP - LogServ with Sentinel for SAP Part 52026-06-26T16:23:26.302000+02:00Hemanth_Kusampudihttps://community.sap.com/t5/user/viewprofilepage/user-id/1619343<P><EM><SPAN>Find your way to our central blog series entry </SPAN></EM><SPAN><A href="https://community.sap.com/t5/enterprise-resource-planning-blog-posts-by-members/ultimate-blog-series-sap-logserv-integration-with-microsoft-sentinel/ba-p/14126401" target="_blank"><EM>here</EM></A><EM>.</EM></SPAN></P><P><SPAN>Co-authored by <A href="https://community.sap.com/t5/user/viewprofilepage/user-id/143781" target="_blank">Martin Pankraz (SAP Security PM, Microsoft)</A> & <a href="https://community.sap.com/t5/user/viewprofilepage/user-id/1728478">@krishnarajapantula</a> </SPAN></P><P><SPAN>Dear community,</SPAN></P><P><SPAN>The wait is over. Finally, RISE on AWS, RISE on GCP and customers on any platform can be protected with Microsoft Sentinel Solution for SAP with SAP LogServ. How is that different from RISE on Azure, you are asking?</SPAN></P><P><SPAN>Well, Azure customers have a native LogServ data pipeline with turn-on experience where SAP does the heavy lifting for you. Customers in other hyperscalers’ can still profit from Microsoft Sentinel for SAP integration using the <A href="https://pypi.org/project/sap-ecs-log-forwarder/" target="_blank" rel="noopener nofollow noreferrer">python-based log forwarder</A> provided by SAP ECS. It has a dedicated Microsoft Sentinel for SAP module.</SPAN></P><P><STRONG><SPAN>Architecture Overview with RISE on AWS sample</SPAN></STRONG></P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Hemanth_Kusampudi_0-1782482655465.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/426515i5693FBF7001E6403/image-size/large?v=v2&px=999" role="button" title="Hemanth_Kusampudi_0-1782482655465.png" alt="Hemanth_Kusampudi_0-1782482655465.png" /></span></P><P> </P><P><STRONG><SPAN>Architecture Overview with RISE on GCP sample</SPAN></STRONG></P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Hemanth_Kusampudi_1-1782482655465.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/426516i98D144C86B877C78/image-size/large?v=v2&px=999" role="button" title="Hemanth_Kusampudi_1-1782482655465.png" alt="Hemanth_Kusampudi_1-1782482655465.png" /></span></P><P> </P><H1 id="toc-hId-1689247388"><SPAN>How to integrate SAP LogServ with Microsoft Sentinel for SAP</SPAN></H1><OL><LI><SPAN>SAP RISE customers who subscribed to LogServ, should install <A href="https://marketplace.microsoft.com/product/sap_jasondau.azure-sentinel-solution-saplogserv?tab=Overview" target="_blank" rel="noopener nofollow noreferrer">SAP LogServ (RISE), S/4 HANA Cloud Private Edition</A> from Microsoft Sentinel Content Hub. Use the Data Connectors screen to deploy the connector – either from classic Azure Portal or the new view on the Defender Portal.</SPAN><OL class="lia-list-style-type-lower-alpha"><LI><SPAN>The connector deployment tries to create all resources in one go. Among them a Microsoft Entra ID app registration. In case the user doing the deployment has not enough rights, this process needs to be split up. Click the button anyways, which finalizes the creation of the Data Collection Endpoint and Data Collection Rule in the same resource group as your Log Analytics Workspace. </SPAN></LI><LI><SPAN>Take note of the fields generated. They will be required for the log forwarder config.</SPAN></LI><LI>If needed, in a second step create your app registration, supply a secret, and assign that Entra ID app id to the Data Collection rule with the role "<A href="https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles/monitor#monitoring-metrics-publisher" target="_blank" rel="noopener nofollow noreferrer">Monitoring Metrics Publisher</A><SPAN>".</SPAN></LI></OL></LI></OL><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="MartinPankraz_0-1782483589612.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/426530i01F74E99EDFF6E27/image-size/large?v=v2&px=999" role="button" title="MartinPankraz_0-1782483589612.png" alt="MartinPankraz_0-1782483589612.png" /></span></P><P><SPAN>2. Once installed the customer should reach out to their: </SPAN></P><OL class="lia-list-style-type-lower-alpha"><LI><SPAN>ECS CDM or ECS TSM to share log forwarder onboarding details. CDM and TSM's can find Sentinel onboarding steps in LogServ SAP internal wiki.</SPAN></LI><LI><SPAN>Put <A href="mailto:sap-logserv-sentinel-integration@service.microsoft.com" target="_blank" rel="noopener nofollow noreferrer">sap-logserv-sentinel-integration@service.microsoft.com</A> in cc </SPAN></LI><LI><SPAN>Use the subject line: "<STRONG>SAP LogServ and Microsoft Sentinel - Activation" </STRONG>Please include your SAP RISE customer details in the email.</SPAN></LI></OL><P><SPAN>3. Request virtual network peering (AWS VPC, GCP VPC peering) if not yet deployed</SPAN></P><P><SPAN>4. Retrieve the LogServ connection details from the self-service section of the SAP ECS Security Portal.</SPAN></P><P> </P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Hemanth_Kusampudi_3-1782482655465.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/426518iD0925E6FE351FE38/image-size/large?v=v2&px=999" role="button" title="Hemanth_Kusampudi_3-1782482655465.png" alt="Hemanth_Kusampudi_3-1782482655465.png" /></span></P><P> </P><P><SPAN>5. Deploy the <A href="https://pypi.org/project/sap-ecs-log-forwarder/" target="_blank" rel="noopener nofollow noreferrer">log forwarder provided by SAP</A>:</SPAN></P><OL class="lia-list-style-type-lower-alpha"><LI><SPAN>Deploy a virtual machine with line of sight to the LogServ assets and access to the peered private network.</SPAN></LI><LI><SPAN>Install the python-based <A href="https://pypi.org/project/sap-ecs-log-forwarder/" target="_blank" rel="noopener nofollow noreferrer">SAP ECS Logforwarder</A>.</SPAN></LI><LI><SPAN>Configure the log forwarder with the config details collected from ECS Security Portal. Use the Sentinel configuration section together with the values noted down in step 1a.</SPAN></LI></OL><P><SPAN>6. Use the <A href="https://learn.microsoft.com/azure/sentinel/sap/sap-logserv-overview#sap-logserv-insights-workbook" target="_blank" rel="noopener nofollow noreferrer">SAP LogServ Insights workbook</A> to verify successful log data ingest.</SPAN></P><P><span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Hemanth_Kusampudi_4-1782482655465.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/426519i1218E61A6FA198F2/image-size/large?v=v2&px=999" role="button" title="Hemanth_Kusampudi_4-1782482655465.png" alt="Hemanth_Kusampudi_4-1782482655465.png" /></span></P><P> </P><H1 id="toc-hId-1492733883"><SPAN>What next?</SPAN></H1><UL><LI><SPAN>See the <A href="https://community.sap.com/t5/enterprise-resource-planning-blog-posts-by-members/ultimate-blog-series-sap-logserv-integration-with-microsoft-sentinel/ba-p/14126401" target="_blank">blog series</A> for an architecture overview, and log type details.</SPAN></LI><LI><SPAN>Understand the agentless data connector for the application layer from <A href="https://learn.microsoft.com/en-us/azure/sentinel/sap/deployment-overview?tabs=agentless" target="_blank" rel="noopener nofollow noreferrer">this Microsoft Learn article</A>.</SPAN></LI></UL><H1 id="toc-hId-1296220378"><SPAN>Get Started Today </SPAN></H1><P><SPAN>Don't miss this opportunity to enhance your security posture with the powerful combination of SAP LogServ and Microsoft Sentinel Solution for SAP. Activate today and be among the first to experience the benefits. </SPAN></P><P><SPAN>We look forward to your participation and to helping you incorporate your SAP RISE environments into your overall IT estate. </SPAN></P><P><SPAN>Check blog <A href="https://community.sap.com/t5/enterprise-resource-planning-blog-posts-by-members/how-to-customize-your-sap-logserv-solution-in-microsoft-sentinel/ba-p/14110388" target="_blank">part 2</A> to cherry pick the log types you need from LogServ for real-time threat protection and which ones should go into cost-efficient long-term storage on the Sentinel Data Lake, <A href="https://community.sap.com/t5/enterprise-resource-planning-blog-posts-by-members/deploy-built-in-sap-logserv-detection-rules-in-microsoft-sentinel-and/ba-p/14141749" target="_blank">part 3</A> to craft your own detections, <A href="https://community.sap.com/t5/enterprise-resource-planning-blog-posts-by-members/gaining-operational-insights-with-the-sap-logserv-workbook-on-microsoft/ba-p/14165489" target="_blank">part 4</A> to understand the monitoring.</SPAN></P><P><SPAN>And finally, <A href="https://community.sap.com/t5/enterprise-resource-planning-blog-posts-by-members/microsoft-sentinel-for-sap-goes-agentless/ba-p/13960238" target="_blank">part 1</A> of the series to discover the analytic rules for the application layer powering Microsoft’s correlation engine.</SPAN></P><H1 id="toc-hId-1099706873"><SPAN>Final Words</SPAN></H1><P><SPAN>That’s a wrap</SPAN><span class="lia-unicode-emoji" title=":burrito:">🌯</span><SPAN>. You saw today how to onboard your SAP LogServ instance running RISE on AWS or GCP to Microsoft Sentinel for SAP. The approach is applicable to all other SAP ECS supported environments. You understand the difference to RISE on Azure deployments integrated with Microsoft Sentinel for SAP. Otherwise, go check again the intro paragraph.</SPAN></P><P><SPAN>Get started with your deployment today. See the art-of-the-possible for the <STRONG>agentic SOC</STRONG> on <A href="https://demos.microsoft.com/Microsoft/play/6373" target="_blank" rel="noopener nofollow noreferrer">this video</A>.</SPAN></P><P><SPAN>Which detections or analytic rules for RISE do you need most? Let me know in the comments or reach out directly.</SPAN></P><P><STRONG>Cheers Hemanth & Martin</STRONG></P>2026-06-26T16:23:26.302000+02:00https://community.sap.com/t5/abap-blog-posts/how-to-scan-custom-abap-for-security-issues-in-eclipse-step-by-step/ba-p/14432681How to Scan Custom ABAP for Security Issues in Eclipse (Step-by-Step)2026-07-03T10:20:40.741000+02:00vahagnhttps://community.sap.com/t5/user/viewprofilepage/user-id/760188<P>Disclosure: I work on this tool at RedRays. This post is a straightforward setup guide, not a product pitch.</P><P>This post walks through connecting Eclipse to a static analysis backend that scans custom ABAP for common security issues (SQL injection, missing authorization checks, hard-coded credentials, weak crypto, and similar) and returns findings directly in the IDE.</P><P>Prerequisites</P><P>- Eclipse 2024-09 or newer<BR />- SAP ABAP Development Tools (ADT) installed<BR />- Java 17<BR />- Network access to the backend you plan to scan against (in this walkthrough, a demo instance)</P><P>Step 1: Get an API key</P><P>The plugin needs an API key to authenticate against a scan backend. For testing, there's a self-service demo instance:</P><P>1. Open get.abap-security.com.<BR />2. Enter a name and email address.<BR />3. Click Create my Eclipse API key.<BR />4. Copy the key immediately - it is displayed once.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vahagn1_0-1783066920118.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/428776i8BB52724E950C78B/image-size/large?v=v2&px=999" role="button" title="vahagn1_0-1783066920118.png" alt="vahagn1_0-1783066920118.png" /></span></P><P> </P><P>Notes on the demo instance:<BR />- Limited to one key per IP address per time window.<BR />- It is a shared instance - do not submit confidential or production code to it. For real use, point the plugin at your own tenant or an on-premise instance instead (see "Beyond the demo" below).</P><P>Step 2: Install the plugin</P><P>In Eclipse:</P><P>1. Help → Install New Software…<BR />2. Click Add… and enter the update site: plugin.abap-security.com<BR />3. Select RedRays ABAP Scanner from the list.<BR />4. Finish the wizard and restart Eclipse when prompted.</P><P>Step 3: Configure the connection</P><P>1. Window → Preferences → RedRays Scanner<BR />2. Set Working mode to RedRays.<BR />3. Set RedRays URL to <A href="https://demo.abap-security.com:8443/" target="_blank" rel="noopener nofollow noreferrer">https://demo.abap-security.com:8443/</A> (or your own instance's URL).<BR />4. Paste the API key from Step 1 into RedRays API key.<BR />5. Click Test connection and confirm it succeeds before continuing.</P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vahagn1_0-1783066782307.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/428775iD8C8BE3FF61E2273/image-size/large?v=v2&px=999" role="button" title="vahagn1_0-1783066782307.png" alt="vahagn1_0-1783066782307.png" /></span></P><P> </P><P>Step 4: Run a scan</P><P>1. Right-click any ABAP object in the Project Explorer.<BR />2. Select Scan with RedRays.<BR />3. Choose the Quick scan profile for a first run.<BR />4. Findings appear in a dedicated Eclipse view as the scan completes.</P><P>Reading the results</P><P>- Findings are grouped by severity: Critical, High, Medium, Low.<BR />- Double-clicking a finding opens the source at the exact line.<BR />- Each finding includes a CVSS score and an automated exploitability check, intended to reduce false positives that would otherwise need manual triage.</P><P>Categories currently covered include: SQL/ADBC injection, OS command execution, dynamic WHERE/ORDER BY clauses, path traversal on OPEN DATASET, RFC trust issues, missing AUTHORITY-CHECK, hard-coded credentials, and weak cryptographic algorithms (MD5/SHA-1), among others.</P><P>Beyond the demo</P><P>The same plugin can point at a privately provisioned tenant or an on-premise instance instead of the shared demo, with isolated access per subaccount and no source retention (code is scanned in memory and discarded; only findings are stored). There is also a REST API for scanning from CI/CD, including an endpoint that returns an allow/block decision for a transport based on a severity threshold - useful as a pre-import gate.</P><P>Resources</P><P>- Plugin overview: redrays.io/abap-scanner-eclipse-plugin<BR />- Demo / API key: get.abap-security.com</P>2026-07-03T10:20:40.741000+02:00https://community.sap.com/t5/technology-blog-posts-by-sap/q2-2026-quarterly-release-highlights-for-sap-btp-security-and-identity-amp/ba-p/14437441Q2 2026: Quarterly Release Highlights for SAP BTP Security and Identity & Access Management2026-07-10T10:32:22.335000+02:00RegineSchimmerhttps://community.sap.com/t5/user/viewprofilepage/user-id/8286<P><SPAN>The world of security never stands still, and neither do we. Here's a quick look at the latest SAP BTP Security and Identity & Access Management updates from this quarter, with the features and improvements worth adding to your radar. </SPAN></P><P><SPAN>For a complete overview of feature deliveries for SAP Cloud Identity Services, check out our list of all new feature announcements in the <A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/what-s-new-for-identity-authentication" target="_blank" rel="noopener noreferrer">SAP Cloud Identity Services Release Notes</A> on the SAP Help Portal.</SPAN></P><H2 id="toc-hId-1819225820"><SPAN>SAP Cloud Identity Services: Technical users</SPAN></H2><P><SPAN>SAP Cloud Identity Services now supports technical users—a new user type designed for non-human identities that enable secure, automated system-to-system communication and integrations. Technical users are managed separately from regular users through the new <EM>Technical Users</EM> tile under <EM>Users & Authorizations</EM> in the administration console, making it easier to create, organize, and maintain service identities. For step-by-step instructions, see <A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/create-new-user-fd1a6362963a4fb6a627a0afb31ed99e?locale=en-US&state=PRODUCTION&version=Cloud" target="_blank" rel="noopener noreferrer">Managing Technical Users</A>. </SPAN></P><H2 id="toc-hId-1622712315"><SPAN>SAP Cloud Identity Services: Block and delete users</SPAN></H2><P><SPAN>Keeping your Identity Directory clean has just become easier. You can configure SAP Cloud Identity Services to automatically delete users who were created but never signed in to an application, helping reduce inactive accounts and simplify user lifecycle management. We’ve extended this functionality by adding a grace period. For configuration details, check <A href="https://help.sap.com/docs/cloud-identity-services/cloud-identity-services/block-or-delete-users-due-to-inactivity?version=Cloud" target="_blank" rel="noopener noreferrer">Block or Delete Users Due to Inactivity.</A></SPAN></P><H2 id="toc-hId-1426198810"><SPAN>SAP Cloud Identity Services: Automatic creation of Identity Provisioning tenants on SAP Cloud Identity for Neo tenants</SPAN></H2><P><SPAN>Starting June 10, 2026, SAP automatically creates a new Identity Provisioning tenant on the SAP Cloud Identity infrastructure for every existing Identity Provisioning tenant running on the Neo environment that is linked to a shared IAM tenant with Identity Authentication.</SPAN></P><P><SPAN>This automatic provisioning gives you access to the latest Identity Provisioning capabilities and configuration options available on the SAP Cloud Identity infrastructure—features that are not supported on Neo. The newly created tenant is used for integrations related to bundled SAP cloud solutions, helping prepare your landscape for future enhancements. For migration details, see</SPAN> <SPAN><A href="https://help.sap.com/docs/identity-provisioning/identity-provisioning/migrate-identity-provisioning-bundle-tenant?version=Cloud" target="_blank" rel="noopener noreferrer">Migrate Identity Provisioning Bundle Tenant</A></SPAN>.</P><H2 id="toc-hId-1229685305"><SPAN>SAP Secure Login Service for SAP GUI: Now available in China</SPAN></H2><P><SPAN>Organizations in China can now subscribe to the SAP Secure Login Service for SAP GUI and run the service on infrastructure located within China. This availability helps customers meet local deployment requirements while modernizing authentication for SAP GUI. They will be able to simplify integration by connecting more easily with enterprise identity providers, and strengthen security with enhanced support for multifactor authentication (MFA). </SPAN></P><P><SPAN>You can see the supported data centers <A href="https://help.sap.com/docs/SAP%20SECURE%20LOGIN%20SERVICE/c35917ca71e941c5a97a11d2c55dcacd/55cd045f3ddd442f93b0ca958bff0e07.html?cta_id=information-txt-right&pttid=7895&InteractionType=%7b%7blead.Contact+Profile+Status%7d%7d&LID=%7b%7blead.p_encrypted_leadid%7d%7d" target="_blank" rel="noopener noreferrer">here</A>. For more information on the SAP Secure Login Service for SAP GUI, check the <A href="https://help.sap.com/docs/SAP%20SECURE%20LOGIN%20SERVICE/c35917ca71e941c5a97a11d2c55dcacd/28d654c4459d4693bbf34e5103867f97.html?version=Cloud" target="_blank" rel="noopener noreferrer">SAP Help Portal</A>. </SPAN></P><H2 id="toc-hId-1033171800"><SPAN>Application Vulnerability Report for SAP BTP </SPAN></H2><P><SPAN>In December 2025, SAP introduced the Application Vulnerability Report (beta) for SAP BTP, providing an API-driven way to identify open-source vulnerabilities in your Cloud Foundry applications.</SPAN></P><P><SPAN>The service has now been enhanced with its first <A href="https://community.sap.com/t5/technology-blog-posts-by-sap/visualize-your-application-vulnerabilities-in-the-btp-cockpit/ba-p/14380080" target="_blank">graphical user interface</A>, available directly in the SAP BTP Cockpit. The new interface features an intuitive findings dashboard with a severity breakdown, along with a detailed findings view that provides actionable remediation guidance to help you address identified vulnerabilities.</SPAN></P><P><SPAN>The Application Vulnerability Report is currently available as a beta service in the EU10 region. While subscriptions are not yet available in other SAP BTP landscapes, the service's <A href="https://community.sap.com/t5/technology-blog-posts-by-sap/application-vulnerability-report-now-scanning-your-applications-beyond-eu/ba-p/14393613" target="_blank">scanning scope</A> has been expanded significantly. It now scans applications deployed across 42 Cloud Foundry landscapes worldwide, including regions in the United States, Asia Pacific, Japan, Brazil, and additional European landscapes beyond the original EU10 region.</SPAN></P><H2 id="toc-hId-836658295"><SPAN>Stay in the loop</SPAN></H2><P><SPAN>Join the <A href="https://pages.community.sap.com/topics/btp-security" target="_blank" rel="noopener noreferrer">SAP BTP Security</A> and <A href="https://pages.community.sap.com/topics/cloud-identity-services" target="_blank" rel="noopener noreferrer">SAP Cloud Identity Services</A> communities to get updates, share feedback, and connect with others! </SPAN></P>2026-07-10T10:32:22.335000+02:00https://community.sap.com/t5/technology-blog-posts-by-members/bridging-sap-authorization-models-amp-databricks-an-architecture-pattern/ba-p/14443497Bridging SAP Authorization Models & Databricks : An Architecture Pattern for Security Migration2026-07-20T13:15:40.749000+02:00sampurnosarkarhttps://community.sap.com/t5/user/viewprofilepage/user-id/2309132<H1 id="toc-hId-1690947619"><STRONG>Introduction</STRONG></H1>
<P><SPAN>As organizations modernize their analytics platforms, migrating business data from SAP to modern Lakehouse architectures has become increasingly common. However, one critical aspect is often overlooked—security migration.</SPAN></P>
<P><SPAN>SAP's authorization model is built upon roles, authorization objects, organizational restrictions, and user-role assignments that collectively determine access to business data. Simply migrating the underlying data without preserving these access controls can lead to governance and compliance challenges.</SPAN></P>
<P><SPAN>Rather than directly exposing SAP security tables to downstream platforms, this article proposes a CDS View-based Security Semantic Layer that standardizes authorization metadata and provides a reusable foundation for enterprise security modernization initiatives.</SPAN></P>
<P><SPAN>In this article, we will explore the core SAP security tables involved in authorization management, design reusable CDS Views for metadata extraction, and architect a unified Security Semantic Layer for downstream consumers.</SPAN></P>
<H3 id="toc-hId-1752599552"><STRONG>Figure 1: High-Level Security Metadata Extraction Architecture</STRONG></H3>
<P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="High-Level Security Metadata Extraction Architecture" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/434953i3CB7A9EF6C1786DB/image-size/large?v=v2&px=999" role="button" title="sampurnosarkar_2-1784539251033.jpeg" alt="High-Level Security Metadata Extraction Architecture" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">High-Level Security Metadata Extraction Architecture</span></span></P>
<P><STRONG>Understanding SAP Authorization Metadata</STRONG></P>
<P><SPAN>SAP's authorization framework is built upon multiple layers of security metadata that collectively determine a user's access to business data. Unlike traditional role-based access control models, SAP combines user-role assignments, authorization objects, authorization values, and organizational restrictions to enforce security policies.</SPAN></P>
<P><SPAN>At a high level, the authorization flow can be represented as follows:</SPAN></P>
<H3 id="toc-hId-1556086047"><STRONG>Figure 2: SAP Authorization Metadata Flow</STRONG></H3>
<P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SAP Authorization Metadata Flow" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/434957i900DAD38CCA9C214/image-size/large?v=v2&px=999" role="button" title="sampurnosarkar_3-1784539336130.jpeg" alt="SAP Authorization Metadata Flow" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">SAP Authorization Metadata Flow</span></span></P>
<P><SPAN>The core SAP security tables involved in authorization management are:</SPAN></P>
<TABLE>
<TBODY>
<TR>
<TD>
<P><STRONG>SAP Table</STRONG></P>
</TD>
<TD>
<P><STRONG>Purpose</STRONG></P>
</TD>
</TR>
<TR>
<TD>
<P><STRONG>AGR_DEFINE</STRONG></P>
</TD>
<TD>
<P><SPAN>Stores role definitions and metadata</SPAN></P>
</TD>
</TR>
<TR>
<TD>
<P><STRONG>AGR_USERS</STRONG></P>
</TD>
<TD>
<P><SPAN>Stores user-to-role assignments</SPAN></P>
</TD>
</TR>
<TR>
<TD>
<P><STRONG>AGR_1251</STRONG></P>
</TD>
<TD>
<P><SPAN>Stores authorization objects, fields, and values</SPAN></P>
</TD>
</TR>
<TR>
<TD>
<P><STRONG>TOBJ</STRONG></P>
</TD>
<TD>
<P><SPAN>Stores authorization object metadata</SPAN></P>
</TD>
</TR>
</TBODY>
</TABLE>
<P><SPAN>Each table plays a specific role in defining who can access business data and under what conditions.</SPAN></P>
<UL>
<LI><STRONG>AGR_DEFINE</STRONG><SPAN> acts as the role master table and contains information about SAP roles.</SPAN></LI>
<LI><STRONG>AGR_USERS</STRONG><SPAN> maps SAP users to their assigned roles.</SPAN></LI>
<LI><STRONG>AGR_1251</STRONG><SPAN> contains the actual authorization rules, including authorization objects, field values, and organizational restrictions.</SPAN></LI>
<LI><STRONG>TOBJ</STRONG><SPAN> provides semantic information about authorization objects used throughout the SAP authorization framework.</SPAN></LI>
</UL>
<P><SPAN>Together, these tables provide all the metadata required to design a reusable Security Semantic Layer for downstream analytics and governance platforms.</SPAN></P>
<H3 id="toc-hId-1359572542"><STRONG>Why Only These Tables?</STRONG></H3>
<P><SPAN>For most authorization migration and metadata extraction initiatives, these four tables provide the minimum and sufficient set of security metadata required to represent:</SPAN></P>
<UL>
<LI><SPAN>Role Definitions</SPAN></LI>
<LI><SPAN>User-to-Role Assignments</SPAN></LI>
<LI><SPAN>Authorization Rules</SPAN></LI>
<LI><SPAN>Organizational Restrictions</SPAN></LI>
<LI><SPAN>Authorization Object Metadata</SPAN></LI>
</UL>
<P><SPAN>By standardizing the information contained within these tables, organizations can create a business-friendly representation of SAP's authorization model without directly exposing low-level SAP security structures to downstream consumers.</SPAN></P>
<H1 id="toc-hId-904893599"><STRONG>Designing CDS Views for Security Extraction</STRONG></H1>
<P><SPAN>Directly exposing SAP authorization tables to downstream platforms may appear to be the simplest approach for security migration. However, tightly coupling external consumers to SAP's underlying security tables introduces maintainability and extensibility challenges.</SPAN></P>
<P><SPAN>A better approach is to introduce a reusable Security Semantic Layer using CDS Views that abstracts SAP's authorization model into business-friendly entities.</SPAN></P>
<H3 id="toc-hId-966545532"><STRONG>Why CDS Views?</STRONG></H3>
<P><SPAN>CDS Views provide several advantages when designing authorization extraction frameworks:</SPAN></P>
<UL>
<LI><SPAN>Semantic abstraction of SAP security metadata.</SPAN></LI>
<LI><SPAN>Centralized authorization metadata management.</SPAN></LI>
<LI><SPAN>Improved maintainability and extensibility.</SPAN></LI>
<LI><SPAN>Reduced dependency on underlying SAP table structures.</SPAN></LI>
<LI><SPAN>Reusability across multiple downstream consumers.</SPAN></LI>
</UL>
<P><SPAN>Instead of exposing raw SAP tables, CDS Views allow us to represent authorization metadata in a standardized and reusable format.</SPAN></P>
<H2 id="toc-hId-640949308"><STRONG>CDS View Architecture</STRONG></H2>
<P><SPAN>The following architecture illustrates the proposed CDS View design.</SPAN></P>
<P><STRONG>Figure 3: CDS View Architecture </STRONG></P>
<P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CDS View Architecture" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/434959i52CDFF93E1AAC6EE/image-size/large?v=v2&px=999" role="button" title="sampurnosarkar_4-1784539413624.jpeg" alt="CDS View Architecture" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">CDS View Architecture</span></span></P>
<H2 id="toc-hId-444435803"><STRONG>Proposed CDS Views</STRONG></H2>
<TABLE>
<TBODY>
<TR>
<TD>
<P><STRONG>CDS View</STRONG></P>
</TD>
<TD>
<P><STRONG>Source Table</STRONG></P>
</TD>
<TD>
<P><STRONG>Purpose</STRONG></P>
</TD>
</TR>
<TR>
<TD>
<P><SPAN>ZI_ROLE_MASTER</SPAN></P>
</TD>
<TD>
<P><SPAN>AGR_DEFINE</SPAN></P>
</TD>
<TD>
<P><SPAN>Role metadata</SPAN></P>
</TD>
</TR>
<TR>
<TD>
<P><SPAN>ZI_ROLE_USER_MAPPING</SPAN></P>
</TD>
<TD>
<P><SPAN>AGR_USERS</SPAN></P>
</TD>
<TD>
<P><SPAN>User-to-role mapping</SPAN></P>
</TD>
</TR>
<TR>
<TD>
<P><SPAN>ZI_ROLE_AUTHORIZATION</SPAN></P>
</TD>
<TD>
<P><SPAN>AGR_1251</SPAN></P>
</TD>
<TD>
<P><SPAN>Authorization rules and restrictions</SPAN></P>
</TD>
</TR>
<TR>
<TD>
<P><SPAN>ZI_AUTHORIZATION_METADATA</SPAN></P>
</TD>
<TD>
<P><SPAN>TOBJ</SPAN></P>
</TD>
<TD>
<P><SPAN>Authorization object metadata</SPAN></P>
</TD>
</TR>
<TR>
<TD>
<P><SPAN>ZI_SAP_SECURITY_MODEL</SPAN></P>
</TD>
<TD>
<P><SPAN>Composite CDS View</SPAN></P>
</TD>
<TD>
<P><SPAN>Unified security model</SPAN></P>
</TD>
</TR>
</TBODY>
</TABLE>
<H2 id="toc-hId-247922298"><STRONG>Recommended Development Sequence</STRONG></H2>
<P><SPAN>The CDS Views should be developed in the following order:</SPAN></P>
<OL>
<LI><SPAN>ZI_ROLE_MASTER</SPAN></LI>
<LI><SPAN>ZI_ROLE_USER_MAPPING</SPAN></LI>
<LI><SPAN>ZI_ROLE_AUTHORIZATION</SPAN></LI>
<LI><SPAN>ZI_AUTHORIZATION_METADATA</SPAN></LI>
<LI><SPAN>ZI_SAP_SECURITY_MODEL</SPAN></LI>
</OL>
<P><SPAN>The Unified Security Model should consume all the previously created CDS Views and act as the canonical representation of SAP authorization metadata.</SPAN></P>
<H2 id="toc-hId-51408793"><STRONG>Unified Security Model</STRONG></H2>
<P><SPAN>The final CDS View should expose a business-friendly representation of SAP's authorization framework.</SPAN></P>
<P><SPAN>Example:</SPAN></P>
<P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sampurnosarkar_5-1784539529898.jpeg" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/434964i96E7BA9EE61F81F5/image-size/large?v=v2&px=999" role="button" title="sampurnosarkar_5-1784539529898.jpeg" alt="sampurnosarkar_5-1784539529898.jpeg" /></span></P>
<P><SPAN>By introducing a layered CDS View architecture, organizations can create a reusable and semantically rich Security Semantic Layer that simplifies authorization metadata extraction while remaining independent of any specific downstream technology.</SPAN></P>
<H1 id="toc-hId-495552652"><STRONG>Building the Security Semantic Layer</STRONG></H1>
<P><SPAN>Once the CDS Views have been designed, the final step is to expose a Unified Security Model that can act as the single source of truth for SAP authorization metadata.</SPAN></P>
<P><SPAN>Rather than tightly coupling downstream systems to SAP's internal security tables, the Security Semantic Layer provides a standardized and reusable representation of roles, authorizations, and organizational restrictions.</SPAN></P>
<H3 id="toc-hId--287766867"><STRONG>Figure 4: Security Semantic Layer Architecture</STRONG></H3>
<P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Security Semantic Layer Architecture" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/434968i74148ADAACC3D5EA/image-size/large?v=v2&px=999" role="button" title="sampurnosarkar_6-1784539585488.jpeg" alt="Security Semantic Layer Architecture" /><span class="lia-inline-image-caption" onclick="event.preventDefault();">Security Semantic Layer Architecture</span></span></P>
<P><SPAN>The Security Semantic Layer enables organizations to:</SPAN></P>
<UL>
<LI><SPAN>Standardize authorization metadata.</SPAN></LI>
<LI><SPAN>Simplify downstream integrations.</SPAN></LI>
<LI><SPAN>Decouple analytics platforms from SAP's internal table structures.</SPAN></LI>
<LI><SPAN>Improve maintainability and extensibility of security metadata.</SPAN></LI>
</UL>
<P><SPAN>Since the Security Semantic Layer is technology agnostic, it can be leveraged by various analytics, governance, and modernization platforms without requiring changes to the underlying SAP authorization model.</SPAN></P>
<H1 id="toc-hId-102525642"><STRONG>5. Conclusion</STRONG></H1>
<P><SPAN>Security migration should not be treated as an afterthought during enterprise analytics modernization initiatives. Authorization metadata is just as critical as business data and deserves the same level of architectural consideration.</SPAN></P>
<P><SPAN>By introducing a layered CDS View architecture and a reusable Security Semantic Layer, organizations can preserve SAP's mature authorization framework while simplifying future integrations with modern analytics and governance platforms.</SPAN></P>
<P><SPAN>Rather than exposing low-level SAP security tables directly, standardizing authorization metadata at the SAP layer provides a scalable, maintainable, and business-friendly foundation for enterprise security modernization initiatives.</SPAN></P>2026-07-20T13:15:40.749000+02:00https://community.sap.com/t5/enterprise-resource-planning-blog-posts-by-sap/announcing-preview-of-sap-logserv-integration-with-google-secops-for-sap/ba-p/14446000Announcing Preview of SAP LogServ integration with Google SecOps for SAP Cloud ERP Private customers2026-07-22T17:07:08.276000+02:00LPanovhttps://community.sap.com/t5/user/viewprofilepage/user-id/1899540<P><SPAN>This blog was co-authored by </SPAN><A href="https://profile.sap.com/u/ajith_urimajalu" target="_blank" rel="noopener noreferrer"><SPAN>Ajith Urimajalu</SPAN></A><SPAN> (Engineering, Google), </SPAN><A href="https://profile.sap.com/u/Brad_Nixon" target="_blank" rel="noopener noreferrer"><SPAN>Brad Nixon</SPAN></A><SPAN> (Product, Google), </SPAN><A href="https://profile.sap.com/u/jespermc" target="_blank" rel="noopener noreferrer"><SPAN>Jesper Christensen</SPAN></A><SPAN> (SAP Architect, Google), <A href="https://www.linkedin.com/in/krishna-rajapantula-19747314/" rel="noopener nofollow noreferrer" target="_blank">Krishna Rajapantula</A> (ECS Lead of Security Engineering Operations), <a href="https://community.sap.com/t5/user/viewprofilepage/user-id/1619343">@Hemanth_Kusampudi</a> (ECS Service Owner)</SPAN></P><P><SPAN>We are thrilled to announce the preview integration between SAP LogServ and Google Security Operations, exclusively for SAP Cloud ERP Private customers around the globe.</SPAN></P><P><STRONG>SAP LogServ</STRONG><SPAN> is an SAP Enterprise Cloud Services (ECS) service aimed to provide SAP Cloud ERP Private customers access to their infrastructure and OS logs. LogServ centralizes the logs from all systems, applications, and ECS services used by a registered customer into a storage location.</SPAN></P><H2 id="toc-hId-1820115581"><SPAN>Main Features include:</SPAN></H2><UL><LI><STRONG>Near Real Time Log Collection:</STRONG><SPAN> Integrate into a customer's SIEMs or Log Management systems.</SPAN></LI><LI><STRONG>Log Retention:</STRONG><SPAN> Retain logs indefinitely or with an adjustable retention policy for each data source.</SPAN></LI><LI><STRONG>Recovery of logs:</STRONG><SPAN> Ability to recover logs which were retained.</SPAN></LI></UL><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LPanov_0-1784703471324.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/435847iF2BAB438493F0063/image-size/large?v=v2&px=999" role="button" title="LPanov_0-1784703471324.png" alt="LPanov_0-1784703471324.png" /></span></P><P><STRONG>Google SecOps</STRONG><SPAN>, with its </SPAN><STRONG>Triage and Investigation Agent (TIN)</STRONG><SPAN>, is setting new standards in cybersecurity innovation. TIN is an AI-powered investigation assistant embedded directly in Google SecOps. The agent automatically analyzes alerts using Mandiant principles and industry best practices, determines if the alerts are true or false positives, and provides a summarized explanation for its assessment. By dynamically refining search queries, enriching data with Google Threat Intelligence (GTI), and reconstructing process trees, it offers a cutting-edge solution to protect critical business data.</SPAN></P><P><span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LPanov_1-1784703608141.png" style="width: 999px;"><img src="https://community.sap.com/t5/image/serverpage/image-id/435848iFD5BAABB8E490484/image-size/large?v=v2&px=999" role="button" title="LPanov_1-1784703608141.png" alt="LPanov_1-1784703608141.png" /></span></P><P><SPAN>The innovative integration with SAP LogServ enables SAP RISE customers to leverage the powerful security analytics and AI-driven threat intelligence capabilities of Google SecOps, seamlessly integrated with the log management features of SAP LogServ. This collaboration aims to enhance your security operations and provide comprehensive protection beyond your SAP environments to your whole IT estate.</SPAN></P><P><SPAN>LogServ complements the existing Google SecOps threat monitoring and detections with the log types provided by SAP ECS as the system provider. This includes logs like: ICM, SAP Web Dispatcher, SAP Gateway, SAP HANA Audit logs.</SPAN></P><H2 id="toc-hId-1623602076"><SPAN>Benefits of the Integration</SPAN></H2><UL><LI><STRONG>SAP-centric Setup:</STRONG><SPAN> Using SAP LogServ and the Application Telemetry Collector, logs are seamlessly forwarded to Google SecOps via Cloud Storage and Bindplane agents.</SPAN></LI><LI><STRONG>Enhanced Security:</STRONG><SPAN> Gain deeper insights into potential threats and vulnerabilities spanning beyond your SAP systems looking at your IT estate using Google SecOps' Unified Data Model (UDM).</SPAN></LI><LI><STRONG>Centralized Monitoring:</STRONG><SPAN> Streamline your security operations by adding log data from SAP LogServ directly into your Google SecOps feeds.</SPAN></LI><LI><STRONG>AI-Powered Response:</STRONG><SPAN> Using the Triage and Investigation Agent (TIN), significantly reduces manual triage time as the AI evaluates incoming alerts, executes an investigation plan, and provides a structured analysis of its findings and reasoning.</SPAN></LI><LI><STRONG>Proactive Threat Detection:</STRONG><SPAN> Respond to threats in real-time utilizing detection rules built specifically for SAP environments</SPAN><SPAN><BR /></SPAN></LI></UL><P><SPAN><STRONG>Securing the Crown Jewels: Why SAP RISE Customers Need Google SecOps and SAP LogServ Today</STRONG></SPAN></P><P><SPAN>Your SAP environment houses the crown jewels of your enterprise—financial data, supply chain operations, and critical IP. Yet, for many Security Operations Centers (SOC), the SAP landscape remains a blind spot. Traditional security tools often fail to ingest, parse, and analyze complex SAP application logs at scale, leaving organizations vulnerable to sophisticated lateral movement and insider threats.</SPAN></P><P><SPAN>The days of flying blind are over.</SPAN></P><H3 id="toc-hId-1556171290"><STRONG>Why This is a Game-Changer for SAP Security</STRONG></H3><P><SPAN>Until now, correlating threats that originate in your broader IT environment and move into your SAP systems was a highly manual, complex, and slow process. By pairing SAP LogServ’s deep, system-level visibility with Google SecOps' planetary-scale analytics and AI, we are eliminating those silos.</SPAN></P><P><STRONG>For SAP Managers and CISO Leaders:</STRONG></P><UL><LI><STRONG>Mandiant Expertise in a Box:</STRONG><SPAN> Google SecOps now includes the </SPAN><STRONG>Triage and Investigation Agent (TIN)</STRONG><SPAN>. TIN is an AI-powered investigation assistant that doesn't just flag alerts—it acts on them. Using Mandiant principles and industry best practices, TIN automatically analyzes alerts, determines true/false positives, dynamically refines search queries, and reconstructs process trees. It summarizes its findings instantly, drastically reducing manual triage time and mitigating SOC burnout.</SPAN></LI><LI><STRONG>Proactive Defense, Not Reactive Scrambling:</STRONG><SPAN> Instead of waiting for an audit failure or a breach notification, you can now respond to threats in real-time utilizing out-of-the-box detection rules built </SPAN><I><SPAN>specifically</SPAN></I><SPAN> for SAP environments.</SPAN></LI></UL><P><STRONG>For SAP Technical Architects and Security Engineers:</STRONG></P><UL><LI><STRONG>Unprecedented Visibility:</STRONG><SPAN> SAP LogServ (an SAP Enterprise Cloud Services offering) centralizes critical infrastructure and OS logs—including ICM, SAP Web Dispatcher, SAP Gateway, and SAP HANA Audit logs.</SPAN></LI><LI><STRONG>Unified Data Model (UDM):</STRONG><SPAN> Using the Application Telemetry Collector, logs are seamlessly forwarded to Google SecOps via Cloud Storage and Bindplane agents. Once ingested, they are mapped to Google’s UDM, allowing your security engineers to query SAP data alongside network, endpoint, and cloud data in sub-seconds.</SPAN></LI><LI><STRONG>Near Real-Time Collection & Indefinite Retention:</STRONG><SPAN> Maintain compliance and investigative power with adjustable, long-term log retention and near real-time SIEM integration.</SPAN></LI></UL><H3 id="toc-hId-1359657785"><STRONG>The Real-World Impact</STRONG></H3><P><I><SPAN>Consider this scenario:</SPAN></I><SPAN> A compromised credential from a phishing attack allows a threat actor to access a standard corporate workstation. From there, they attempt to pivot into your SAP Web Dispatcher.</SPAN></P><P><SPAN>Without this integration, the initial phishing alert sits in one queue, while the SAP login anomaly sits buried in an un-parsed log file. With </SPAN><STRONG>SAP LogServ and Google SecOps</STRONG><SPAN>, TIN instantly correlates the endpoint alert with the SAP HANA audit log, reconstructs the process tree, enriches the data with Google Threat Intelligence (GTI), and presents your SOC analyst with a structured analysis and containment plan—all before the attacker can exfiltrate your financial data.</SPAN></P><H3 id="toc-hId-1163144280"><STRONG>Don't Wait for the Next Threat. Get Started Today.</STRONG></H3><P>Don't miss this opportunity to enhance your security posture with the powerful combination of SAP LogServ and Google SecOps. Threat actors are increasingly targeting ERP environments. Delaying your SAP security modernization is a risk you cannot afford.</P><P><STRONG>Your 3-Step Action Plan:</STRONG></P><OL><LI><STRONG>Engage SAP:</STRONG><SPAN> Coordinate with your SAP ECS representative immediately to enable LogServ and provision your destination Cloud Storage bucket and Pub/Sub notifications.</SPAN></LI><LI><STRONG>Deploy & Ingest:</STRONG><SPAN> Follow our detailed documentation to deploy the Application Telemetry Collector and create your Google SecOps feeds: [Set up log ingestion for SAP RISE].</SPAN></LI><LI><STRONG>Activate Defenses:</STRONG><SPAN> Download and deploy our out-of-the-box detection capabilities directly from the [SAP Detection Rules repository on GitHub].</SPAN></LI></OL><P><SPAN>Secure your SAP crown jewels with the intelligence of Mandiant and the scale of Google.</SPAN></P><P><SPAN>To get started, coordinate with your SAP ECS representative to enable LogServ and provision your destination Cloud Storage bucket and Pub/Sub notifications. For detailed instructions on preparing your environment, deploying the Application Telemetry Collector, and creating Google SecOps feeds, visit the </SPAN><A href="https://docs.cloud.google.com/sap/docs/secops/ingest-sap-rise-logs" target="_blank" rel="noopener nofollow noreferrer"><SPAN>Set up log ingestion for SAP RISE documentation</SPAN></A><SPAN>.</SPAN></P><P><SPAN>You can also explore out-of-the-box detection capabilities in Google’s </SPAN><A href="https://github.com/chronicle/detection-rules/tree/main/rules/community/sap" target="_blank" rel="noopener nofollow noreferrer"><SPAN>SAP Detection Rules repository on GitHub</SPAN></A><SPAN>.</SPAN></P>2026-07-22T17:07:08.276000+02:00https://community.sap.com/t5/technology-blog-posts-by-members/automating-sap-security-tasks-and-sod-analysis-with-zsectools-open-source/ba-p/14443450Automating SAP Security Tasks and SoD Analysis with ZSecTools (Open-Source)2026-07-23T13:06:52.357000+02:00ValerioAngelonihttps://community.sap.com/t5/user/viewprofilepage/user-id/2146531<P>Hi SAP Community,</P><P>As SAP Security administrators, we all know that keeping an ABAP stack secure, compliant, and clean involves a lot of repetitive tasks, custom queries, and sometimes a bit of frustration. While enterprise governance solutions manage high-level corporate compliance, security professionals on the ground often need a localized, agile set of utilities for immediate daily operations and deep-dive analysis.</P><P>That is why I created <STRONG>ZSecTools</STRONG>—an open-source toolkit designed specifically to support SAP Security professionals in their day-to-day activities.</P><P><SPAN>The tool was originally developed for personal use to support day-to-day SAP security administration and SOD analysis work. It is now shared as open source in the hope that it can be useful to others facing similar needs.<BR /><BR />I've been working in the SAP security field since 2011, and I've come to realize that I would like to share my knowledge with the community to create and share value.<BR /></SPAN></P><P>You can find the full source code and documentation on GitHub: <span class="lia-unicode-emoji" title=":backhand_index_pointing_right:">👉</span> <STRONG><A class="" href="https://github.com/va87git/zsectools" target="_blank" rel="noopener nofollow noreferrer">https://github.com/va87git/zsectools</A></STRONG></P><H3 id="toc-hId-1949112926"> </H3><H3 id="toc-hId-1752599421">What is ZSecTools?</H3><P>ZSecTools is not a certified governance tool, nor is it meant to replace robust enterprise risk management software. Instead, think of it as a <STRONG>professional Swiss Army knife</STRONG>. It is built to provide immediate added value, automating heavy tasks and offering deep visibility into the security authorization model of your SAP systems.</P><H3 id="toc-hId-1556085916"> </H3><H3 id="toc-hId-1359572411">Architecture Overview & Deployment</H3><P>To keep deployment simple, clean, and isolated, ZSecTools leverages a modern architecture that can be run in two different ways depending on your environment:</P><UL><LI><P><STRONG>Backend & Processing:</STRONG> Powered by a <STRONG>Node.js</STRONG> engine that handles the heavy lifting, including complex SoD calculations and mass operations.</P></LI><LI><P><STRONG>Data Layer:</STRONG> Uses a localized <STRONG>PostgreSQL</STRONG> database to store configuration matrices, imported data, and report results securely.</P></LI><LI><P><STRONG>Flexible Deployment Options:</STRONG></P><UL><LI><P><STRONG>Dockerized Stack:</STRONG> You can spin up the full environment with a simple container setup to keep everything isolated.</P></LI><LI><P><STRONG>Self-Contained / Portable Scripts:</STRONG> If you cannot or prefer not to use Docker, the repository includes automation scripts that use <CODE>curl</CODE> to pull down <STRONG>portable versions</STRONG> of Node.js and PostgreSQL. This creates a fully local, self-contained installation that doesn't require administrator privileges or permanent system installations.</P></LI></UL></LI><LI><P><STRONG>SAP Connectivity (BYOD):</STRONG> To connect to your ABAP backend, the tool relies on a <STRONG>Bring Your Own Dependencies</STRONG> approach. Out of respect for SAP licensing compliance, the repository does not include proprietary files. Users must download the required <STRONG>SAP NW RFC SDK</STRONG> libraries directly from the SAP Me portal using their own S-User account, as detailed in the README setup instructions.</P></LI></UL><H3 id="toc-hId-1163058906"> </H3><H3 id="toc-hId-966545401">Key Features & Capabilities</H3><UL><LI><P><STRONG>Segregation of Duties (SoD) Analysis:</STRONG> Run targeted SoD checks directly through the toolkit to identify conflicting access risks within your user base.</P></LI><LI><P><STRONG>Custom Security Quality Reports:</STRONG> The tool includes several built-in custom reports designed to measure and audit the overall quality and health of your SAP security configuration.</P></LI><LI><P><STRONG>Mass Maintenance Operations:</STRONG> Managing roles and users one by one can be time-consuming. ZSecTools includes powerful mass functionalities to streamline user and role administration.</P></LI><LI><P><STRONG>License Exposure Estimation (STAR-aligned):</STRONG> By uploading a properly configured SoD matrix, you can run a report to estimate your license risk profile based on critical permissions. Since the official STAR matrix is publicly available on the SAP Support Portal, you can easily map these criteria within the tool to evaluate your system's license exposure ahead of official measurements.</P></LI></UL><H3 id="toc-hId-770031896"> </H3><H3 id="toc-hId-573518391">Pre-configured SAP Role Included</H3><P>To make the deployment straightforward, the repository includes a dedicated SAP role export file. Importing this file provides a pre-configured role with the minimum authorization objects and RFC call permissions required for the toolkit to function safely, allowing you to review exactly what the tool can access before running it.</P><H3 id="toc-hId-377004886"> </H3><H3 id="toc-hId-180491381">Designed for Practitioners</H3><P>I want to emphasize that ZSecTools is built to support people who already have a solid understanding of SAP authorization objects and security concepts. It acts as an accelerator for your existing skills, giving you the technical utility you need to manage your systems more efficiently.</P><H3 id="toc-hId--91253493"> </H3><H3 id="toc-hId--287766998">Get Involved & Active Development</H3><P>The project is published under an open-source license and is <STRONG>currently under active development</STRONG>. This means new features, optimizations, and reports are planned for the near future.</P><P>Feel free to explore the repository, try it out in your sandbox environments, and share your thoughts or open an issue on GitHub if you have suggestions or find it useful!</P>2026-07-23T13:06:52.357000+02:00