Forum Discussion
Entra ID Governance vs Saviynt for SAP IGA Use Cases
thanks Lucaraheller for the responses.. they’ve been very helpful.
The strategy is to move forward with a hybrid architecture, where Entra ID Governance serves as the IGA platform (JML, access requests, provisioning) and Saviynt remains responsible for deep SAP SoD analysis.
Since Saviynt requires direct integration with each SAP application for SoD, our in-scope applications are:
- SAP S/4HANA Private Cloud
- SAP Cloud Identity Services (CIS)
- SAP SuccessFactors
- SAP Ariba
We’re now evaluating the provisioning model from Entra’s perspective. Is there a recommended approach to provision access:
- Via SAP Cloud Identity Services (CIS) as the centralized layer, or
- Directly to each individual SAP application?
During a POC last year, we found that the SAP CIS connector did not support importing/reading groups into Entra. As a result, groups had to be manually created in Entra with matching names before provisioning could occur.
If this manual group management is still required across SAP application connectors, it seems more practical to standardize on CIS as the provisioning endpoint.
have you worked with SAP application connectors and can share their current capabilities, particularly around group import/discovery, provisioning, and synchronization? Any recommendations or lessons learned would be greatly appreciated.