Blog Post

Microsoft Entra Blog
5 MIN READ

Modernize SAP Identity Management with Microsoft Entra

Mark_Wahl's avatar
Mark_Wahl
Icon for Microsoft rankMicrosoft
Jul 23, 2026

See how Microsoft Entra and SAP help automate provisioning, strengthen governance, and modernize access across SAP and non-SAP applications.

Many organizations are rethinking how they manage identity across their SAP landscape as they move away from on-premises identity management systems and adopt a more unified cloud strategy. That shift often starts with a practical question: how do you connect SAP identity processes with the rest of your application estate without introducing more complexity?

That is where the ongoing work between Microsoft Entra and SAP can help. Over the past several years, we have continued to expand integration points that help organizations automate lifecycle changes, apply access policies more consistently, and strengthen governance across SAP and non-SAP applications.

If you are transitioning from SAP Identity Management (SAP IDM), modernizing an existing SAP identity architecture, or looking for better access governance across business-critical systems, the latest integrations in Microsoft Entra can help.

In this post, I’ll highlight what’s new, recap the key integration points, and explain how these capabilities can support your identity modernization journey.

What’s new in Microsoft Entra and SAP integrations

Over the past two years, Microsoft Entra and SAP have continued to deepen interoperability and support more deployment models. Key updates include:

  • More flexible provisioning patterns between Microsoft Entra and SAP Cloud Identity Services
  • Support for custom extension attributes on Microsoft Entra users for SAP-specific scenarios
  • Account discovery to identify accounts in SAP Cloud Identity Services that are not yet correlated with users in Microsoft Entra
  • OAuth 2.0 client credentials support to secure service-to-service communication between Microsoft Entra and SAP Cloud Identity Services
  • Integration between Microsoft Entra ID Governance and SAP Identity Access Governance (SAP Identity Access Governance), so organizations can request and govern SAP business roles alongside other access rights

Together, these capabilities help organizations create a more unified identity control plane across SAP and the rest of the enterprise.

“This partnership brings together the best of both worlds: Microsoft Entra’s identity-first foundation and SAP Access Governance’s (SAP Identity Access Governance and SAP Access Control) deep business and access risk context, enriched with AI to transform access governance into a continuous, intelligent trust model.” 

Swetta Singh, Strategic Product Manager for Access Governance solutions, SAP

A centralized identity control plane for SAP and beyond

Microsoft Entra provides a centralized identity layer that integrates with SAP applications and platforms. With it, organizations can automate joiner, mover, and leaver processes, apply access policies more consistently, and strengthen governance across a broader set of systems.

That kind of consistency matters in complex environments. For example, Cenibra used Microsoft Entra ID Governance to modernize identity management across more than 80 systems, including SAP as a core platform. That approach helped reduce manual work, improve audit readiness, and create a more scalable foundation for managing access.

SAP Cloud Identity Services: More flexible provisioning

SAP Cloud Identity Services centralizes authentication and provisioning across SAP applications. It provides single sign-on and helps organizations provision users and groups more consistently to downstream SAP systems.

The latest integration improvements with Microsoft Entra give organizations more flexibility in synchronizing users and groups across both environments through standards-based approaches. This flexibility helps teams maintain consistent identity data between Microsoft Entra and SAP environments while using SAP Cloud Identity Services to distribute identities to downstream cloud-hosted and on-premises SAP applications.

Some of the recent updates include:

Custom extension attributes for SAP-specific scenarios

Many SAP environments depend on attributes tied to business processes, regions, or organizational structures. Microsoft Entra now supports provisioning custom extension attributes on users in those scenarios, making it easier to align identity data with the needs of SAP applications.

Account discovery for SAP Cloud Identity Services

Microsoft Entra account discovery retrieves accounts from SAP Cloud Identity Services so you can identify accounts that are not yet correlated with users in Microsoft Entra. This visibility can help teams reduce manual investigation and strengthen governance.

OAuth 2.0 client credentials for connector authentication

We have also updated connector authentication to use OAuth 2.0 client credentials. This change helps secure service-to-service communication between Microsoft Entra and SAP Cloud Identity Services and supports a more modern integration approach.

SAP Identity Access Governance integration

SAP Identity Access Governance is SAP’s cloud-based access governance solution. The integration between Microsoft Entra ID Governance and SAP Identity Access Governance connects SAP role governance to a broader access strategy, allowing users to request or receive SAP business roles through Microsoft Entra access packages alongside non-SAP access rights.

This integration matters because access governance often spans applications: employees, contractors, and partners may need coordinated access across SAP and non-SAP resources. Organizations can use the integration to manage those requests consistently across applications.

When a user requests assignment to an access package with an SAP business role through Microsoft Entra, the request is sent automatically to SAP Identity Access Governance. SAP Identity Access Governance then enforces approvals and additional checks within its own governance process. This approach helps organizations connect enterprise-wide access packages in Microsoft Entra with the business role and risk context available in SAP Identity Access Governance.

Microsoft Entra integrates with SAP Cloud Identity Services and SAP Identity Access Governance to support authentication, user provisioning, and identity governance across SAP applications.

Migration projects move faster with the right partner support

A successful transition from legacy IAM products such as SAP IDM often depends on practical experience across both SAP environments and enterprise identity platforms. Many organizations work with partners who can support SAP system integration, Microsoft Entra identity and governance capabilities, and identity strategies that connect SAP with the rest of the application estate.

If you are planning a migration and want to involve a partner, review the partner list in Migrate identity management scenarios from SAP IDM to Microsoft Entra.

Beyond identity: Microsoft Security for SAP

Identity establishes the foundation for securing SAP in your security environment. In addition to Microsoft Entra, Microsoft delivers SAP-aware capabilities aligned with the NIST Cybersecurity Framework:

  • Identify: Microsoft Purview discovers and classifies sensitive SAP data—including data mirrored into Microsoft Fabric through SAP Datasphere—helping organizations apply more consistent data security policies.
  • Protect: Microsoft Defender safeguards the endpoints, servers, and cloud resources surrounding SAP applications with continuous, adaptive controls.
  • Detect: Microsoft Sentinel connects SAP signals across your estate to detect incidents, with built-in analytics rules in an SAP-certified solution that cover known threats.
  • Respond: Microsoft Security Copilot accelerates investigation and guides response, helping teams contain SAP incidents faster.

Together with the identity investments described above, these capabilities advance an identity-first Zero Trust strategy across the SAP environment. Microsoft uses these same capabilities across its global SAP estate.

Get started

If you are evaluating your SAP identity strategy, now is a good time to review how your current architecture maps to the latest integration options in Microsoft Entra.

Start with these resources:

As always, I would love to hear about your SAP identity modernization journey and the topics you would like us to cover next.

Thanks for reading,

Mark Wahl
Product Architect, Microsoft Entra
Mark Wahl | LinkedIn

 

Additional resources

 

Learn more about Microsoft Entra

Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.

 

 

 

Updated Jul 23, 2026
Version 1.0