Blog Post

Microsoft Sentinel Blog
2 MIN READ

Go agentless with Microsoft Sentinel for SAP

MartinPankraz's avatar
MartinPankraz
Icon for Microsoft rankMicrosoft
Dec 17, 2024
What a title during Agentic AI times ๐Ÿ˜‚

 

Dear community,

Bringing SAP workloads under the protection of your SIEM solution is a primary concern for many customers out there.

The window for defenders is small

โ€œCritical SAP vulnerabilities being weaponized in less than 72 hours of a patch release and new unprotected SAP applications provisioned in cloud (IaaS) environments being discovered and compromised in less than three hours.โ€

(SAP SE + Onapsis, Apr 6 2024)

Having a turn-key solution as much as possible leads to better adoption of SAP security. Agent-based solutions running in Docker containers, Kubernetes, or other self-hosted environemnts are not for everyone.

Microsoft Sentinel for SAPโ€™s latest new capability re-uses the SAP Cloud Connector to profit from already existing setups, established integration processes, and well-understood SAP components.

Meet agentless โŒ๐Ÿค–

The new integration path leverages SAP Integration Suite to connect Microsoft Sentinel with your SAP systems. The Cloud integration capability of SAP Integration Suite speaks all relevant protocols, has connectivity into all the places where your SAP systems might live, is strategic for most SAP customers, and is fully SAP RISE compatible by design. Are you deployed on SAP Business Technology Platform yet?

Simply upload our Sentinel for SAP integration package (see bottom box in below image) to your SAP Cloud Integration instance, configure it for your environment, and off you go.

Best of all: The already existing SAP security content (detections, workbooks, and playbooks) in Microsoft Sentinel continues to function the same way as it does for the Docker-based collector agent variant.

 

The integration marks your steppingstone to bring your SAP threat signals into the Unified Security Operations Platform โ€“ a combination of Defender XDR and Sentinel โ€“ that looks beyond SAP at your whole IT estate.

Microsoft Sentinel solution for SAP applications is certified for SAP S/4HANA Cloud, Private Edition RISE with SAP, and SAP S/4HANA on-premises. So, you are all good to go๐Ÿ˜Ž

You are already dockerized or agentless? Then proceed to this post to learn more about what to do once the SAP logs arrived in Sentinel.

Final Words

During the private preview we saw drastically reduced deployment times for SAP customers being less familiar with Docker, Kubernetes and Linux administration.

Cherry on the cake: the network challenges donโ€™t have to be tackled again. The colleagues running your SAP Cloud Connector went through that process a long time ago. SAP Basis rocks ๐Ÿค˜

Get started from here.

 

Find more details on our blog on the SAP Community and latest Microsoft Learn article.

 

Cheers

Martin

Updated Dec 17, 2024
Version 2.0
No CommentsBe the first to comment