Microsoft Sentinel solution for SAP applications: Deployment overview

Use the Microsoft Sentinel solution for SAP applications to monitor your SAP systems with Microsoft Sentinel, detecting sophisticated threats throughout the business logic and application layers of your SAP applications.

This article introduces you to the Microsoft Sentinel solution for SAP applications deployment.

Solution components

The Microsoft Sentinel solution for SAP applications includes a data connector, which collects logs from your SAP systems and sends them to your Microsoft Sentinel workspace, and out-of-the-box security content, which helps you gain insight into your organization's SAP environment and detect and respond to security threats.

Data connector

The Microsoft Sentinel solution for SAP applications uses the agentless data connector, which collects application logs for all your onboarded SAP SIDs from across the SAP system landscape, and then sends those logs to your Log Analytics workspace in Microsoft Sentinel.

Important

The containerized data connector agent for SAP will be retired and permanently disabled on September 14, 2026. After this date, the agent stops delivering SAP logs to Microsoft Sentinel. Creation of new containerized agents is already disabled. Migrate to the generally available agentless data connector, the supported replacement. Customers who already use the agentless connector aren't affected. Learn more about the agentless approach in the SAP agentless connector announcement.

The Microsoft Sentinel agentless data connector for SAP uses the SAP Cloud Connector and SAP Integration Suite to connect to your SAP system and pull logs from it, as shown in the following image:

Diagram that shows the Microsoft Sentinel agentless data connector in an SAP environment.

By using the SAP Cloud Connector, the agentless data connector profits from already existing setups and established integration processes. This means you don't have to tackle network challenges again, as the people running your SAP Cloud Connector have already gone through that process.

For sizing, throughput tuning, and isolation guidance, see Configure SAP Cloud Connector settings and Optimize SAP Cloud Connector sizing, throughput, and isolation.

The agentless data connector is compatible with SAP NetWeaver based systems. Among them SAP S/4HANA Cloud, Private Edition (RISE with SAP), SAP S/4HANA on-premises, SAP ERP Central Component (ECC), SAP Business Warehouse (BW), and more, ensuring continued functionality of existing security content, including detections, workbooks, and playbooks.

The agentless data connector ingests critical security logs such as the security audit log, change docs logs and user master data including user roles and authorizations.

Security content

The Microsoft Sentinel solutions for SAP applications include the following types of security content to help you gain insight into your organization's SAP environment and detect and respond to security threats:

  • Analytics rules and watchlists for threat detection.
  • Functions for easy data access.
  • Workbooks to create interactive data visualization.
  • Watchlists for customization of the built-in solution parameters.
  • Playbooks that you can use to automate responses to threats.

For more information, see Microsoft Sentinel solution for SAP applications: security content reference.

Deployment flow and personas

Deploying the Microsoft Sentinel solution for SAP applications involves several steps and requires collaboration across your security and SAP BASIS teams. The following image shows the steps in deploying the Microsoft Sentinel solution for SAP applications, with relevant teams indicated:

Diagram showing the full steps in the deployment flow for the Microsoft Sentinel agentless data connector for SAP applications.

We recommend that you involve both teams when planning your deployment to ensure that effort is allocated and the deployment can move smoothly.

Deployment steps include:

  1. Review the prerequisites for deploying the SAP agentless data connector.

  2. Deploy the SAP applications solution from the content hub. This step is handled by the security team on the Azure portal.

  3. Configure your SAP system for the Microsoft Sentinel solution, including configuring SAP authorizations, configuring SAP auditing, and more. We recommend that these steps be done by your SAP BASIS team, and our documentation includes references to SAP documentation. Some of the procedures in this step can be done by the SAP BASIS team before installing the solution.

  4. Connect your SAP system using the agentless data connector with the SAP Cloud Connector. This step is handled by your security team on the Azure portal, using information provided by your SAP BASIS team.

  5. Enable SAP detections and threat protection. This step is handled by the security team on the Azure portal.

Extra options include:

Stop SAP data collection

If you need to stop Microsoft Sentinel from collecting your SAP data, disable or remove the agentless data connector and then reverse the SAP-side preparation you applied.

For more information, see Stop SAP data collection.

For more information, see:

Next step

Begin the deployment of the Microsoft Sentinel solution for SAP applications by reviewing the prerequisites: