Forum Discussion
Entra ID Governance vs Saviynt for SAP IGA Use Cases
Lucaraheller thank you so much for the detailed reponses. A key follow-up based on SOD considering a hybrid IAM solution where Entra does IGA (birthright provisioning to CIS + access request) and Saviynt does SOD for its depth capabilities:
- Can Entra invoke or poll a third-party IAM platform (e.g., Saviynt) during the access request process to perform a preventative SoD check before provisioning?
- If Saviynt performs the deep SoD analysis, does that imply the request catalog/ruleset in Entra would also need to differ, given Entra is primarily requesting CIS groups rather than application entitlements?
Yes, Entra can integrate with Saviynt through custom extensions/Logic Apps, but Saviynt should remain the authoritative SoD decision point for deep SAP risk analysis. And yes, the Entra request catalog should be intentionally modeled around the same business roles or risk-relevant bundles that Saviynt evaluates, rather than using broad CIS groups that hide the underlying SAP entitlement risk.
- carltonflewis1Jul 07, 2026Tin Contributor
Follow-up: Hybrid Entra IGA + Saviynt SoD Integration
Thanks Lucaraheller for the responses so far they’ve been very helpful.
The strategy is to move forward with a hybrid architecture, where Entra ID Governance serves as the IGA platform (JML, access requests, provisioning) and Saviynt remains responsible for deep SAP SoD analysis.
Since Saviynt requires direct integration with each SAP application for SoD, our in-scope applications are:
- SAP S/4HANA Private Cloud
- SAP Cloud Identity Services (CIS)
- SAP SuccessFactors
- SAP Ariba
We’re now evaluating the provisioning model from Entra’s perspective. Is there a recommended approach to provision access:
- via SAP Cloud Identity Services (CIS) as the centralized layer, or
- Directly to each individual SAP application?
During a POC last year, we found that the SAP CIS connector did not support importing/reading groups into Entra. As a result, groups had to be manually created in Entra with matching names before provisioning could occur.
If this manual group management is still required across SAP application connectors, it seems more practical to standardize on CIS as the provisioning endpoint.
What are the SAP application connectors and could you kindly share their current capabilities, particularly around group import, provisioning, and synchronization? Any recommendations or lessons learned would be greatly appreciated.