What a title during Agentic AI times ๐
Dear community,
Bringing SAP workloads under the protection of your SIEM solution is a primary concern for many customers out there.
The window for defenders is small
โCritical SAP vulnerabilities being weaponized in less than 72 hours of a patch release and new unprotected SAP applications provisioned in cloud (IaaS) environments being discovered and compromised in less than three hours.โ
(SAP SE + Onapsis, Apr 6 2024)
Having a turn-key solution as much as possible leads to better adoption of SAP security. Agent-based solutions running in Docker containers, Kubernetes, or other self-hosted environemnts are not for everyone.
Microsoft Sentinel for SAPโs latest new capability re-uses the SAP Cloud Connector to profit from already existing setups, established integration processes, and well-understood SAP components.
Meet agentless โ๐ค
The new integration path leverages SAP Integration Suite to connect Microsoft Sentinel with your SAP systems. The Cloud integration capability of SAP Integration Suite speaks all relevant protocols, has connectivity into all the places where your SAP systems might live, is strategic for most SAP customers, and is fully SAP RISE compatible by design. Are you deployed on SAP Business Technology Platform yet?
Simply upload our Sentinel for SAP integration package (see bottom box in below image) to your SAP Cloud Integration instance, configure it for your environment, and off you go.
Best of all: The already existing SAP security content (detections, workbooks, and playbooks) in Microsoft Sentinel continues to function the same way as it does for the Docker-based collector agent variant.
The integration marks your steppingstone to bring your SAP threat signals into the Unified Security Operations Platform โ a combination of Defender XDR and Sentinel โ that looks beyond SAP at your whole IT estate.
Microsoft Sentinel solution for SAP applications is certified for SAP S/4HANA Cloud, Private Edition RISE with SAP, and SAP S/4HANA on-premises. So, you are all good to go๐
You are already dockerized or agentless? Then proceed to this post to learn more about what to do once the SAP logs arrived in Sentinel.
Final Words
During the private preview we saw drastically reduced deployment times for SAP customers being less familiar with Docker, Kubernetes and Linux administration.
Cherry on the cake: the network challenges donโt have to be tackled again. The colleagues running your SAP Cloud Connector went through that process a long time ago. SAP Basis rocks ๐ค
Get started from here.
Find more details on our blog on the SAP Community and latest Microsoft Learn article.
Cheers
Martin
Updated Jan 07, 2025
Version 3.0MartinPankraz
Microsoft
Joined August 19, 2019
Microsoft Sentinel Blog
Microsoft Sentinel is a cloud-native SIEM, enriched with AI and automation to provide expansive visibility across your digital environment.
When evaluating various solutions, your peers value hearing from people like you whoโve used the product. Review Microsoft Sentinel by filling out a Gartner Peer Insights survey and receive a $25 USD gift card (for customers only). Here are the Privacy/Guideline links: Microsoft Privacy Statement, Gartnerโs Community Guidelines & Gartner Peer Insights Review Guide.