Episode #302
Introduction
In episode 302 of our SAP on Azure video podcast we talk about Modernize SAP Identity Management with Microsoft Entra.
A lot of companies are currently rethinking how they manage identities across their SAP landscape. Many organizations have both SAP for their ERP and Microsoft Entra ID is used for Windows, Microsoft 365, Azure, and many other applications across the enterprise. At the same time, SAP Identity Management is reaching end of life, and customers are looking for a replacement. Over the last years, Microsoft and SAP have been working closely together to make this easier. With Microsoft Entra, SAP Cloud Identity Services, and SAP Identity Access Governance, customers can automate joiner, mover, and leaver processes, improve governance, and apply access policies more consistently across their environment. There are also some important new capabilities: more flexible provisioning patterns, support for SAP-specific extension attribute, and deeper integration between Microsoft Entra ID Governance and SAP Identity Access Governance. To tell us more about all of this, I’m very happy to welcome Sri to the show.
Find all the links mentioned here: https://www.saponazurepodcast.de/episode302
Reach out to us for any feedback / questions:
- Goran Condric: https://www.linkedin.com/in/gorancondric/
- Holger Bruchelt: https://www.linkedin.com/in/holger-bruchelt/
#Microsoft #SAP #Azure #SAPonAzure #SAPIAS #EntraID #MicrosoftEntra #IdentityGovernance #ZeroTrust #SAPSecurity #SAPCloudIdentityServices
Summary created by AI
- SAP Identity Management Modernization:
- Holger and Sri discussed replacing SAP Identity Management as it approaches end of life by using Microsoft Entra ID, SAP Cloud Identity Services, and SAP Identity Access Governance to centralize identity lifecycle management and governance.
- Replacement Strategy: SAP Identity Management is reaching end of life, and SAP recommends Microsoft Entra ID as part of the modernization path. The broader solution combines Microsoft Entra, SAP Cloud Identity Services, and SAP Identity Access Governance to automate joiner, mover, and leaver processes, apply access policies, and improve governance across SAP and Microsoft environments.
- Joint Development: Holger explained that Microsoft and SAP have held joint development workshops and customer and partner engagements to identify missing functionality and simplify migration. Sri confirmed that both companies continue to develop the integration based on shared customer feedback rather than treating the work as a one-time release.
- Partner Ecosystem: Sri said Microsoft and SAP have identified approximately 17 joint partners across regions including Brazil, Europe, and North America. Customers migrating from SAP Identity Management to Entra ID or modernizing their SAP landscape were encouraged to use these partners and consult the related materials.
- Customer Feedback: Sri asked customers and partners to continue submitting questions, comments, and requests through available feedback channels because this input helps prioritize investments. Holger referenced hands-on sessions with customers, including participants from the German-speaking SAP user group, as examples of how feedback has shaped the integration.
- Integration Capabilities And Release Status:
- Sri outlined newly released and upcoming capabilities linking Microsoft Entra with SAP Cloud Identity Services, SAP Identity Access Governance, and SAP Access Control, while clarifying that SAP Access Control is in public preview and the SAP Enterprise Identity Governance integration is moving to general availability.
- Provisioning Updates: The latest capabilities include more flexible provisioning patterns between Microsoft Entra and SAP Cloud Identity Services, support for custom Microsoft Entra extension attributes needed by SAP scenarios, account discovery for identifying SAP Cloud Identity Services accounts not yet present in Entra, bidirectional provisioning for users and groups, and migration to OAuth 2.0 client credentials.
- Governance Integration: Sri announced the integration between Microsoft Entra ID Governance and SAP Identity Access Governance, describing it as entering public preview for SAP Access Control-related capabilities. She also clarified that the SAP Enterprise Identity Governance integration is moving to general availability, correcting Holger’s initial assumption that all referenced capabilities were already generally available.
- Customer Zero Experience: Sri explained that Microsoft Finance served as an internal customer for capabilities developed with SAP. She said the teams used that experience to expand the solution to the broader customer base, while continuing investment in cloud governance scenarios and migration from traditional on-premises setups.
- Future Capabilities: Sri said additional capabilities are planned, including more advanced simulations, agentic and AI-related scenarios, and separation-of-duties conflict functionality. These items represent continuing development beyond the initial set of released integration scenarios.
- Bidirectional Governance And Lifecycle Management:
- Sri and Holger highlighted bidirectional provisioning and Entra Entitlement Management as foundations for consolidating joiner, mover, leaver, guest, and downstream application access processes across SAP and Microsoft environments.
- Bidirectional Provisioning: Sri identified bidirectional provisioning as a particularly important release because customers had requested it for a long time. The capability supports synchronization of users and groups between Microsoft Entra and SAP Cloud Identity Services and provides a foundation for future intelligent and agentic SAP scenarios.
- Entitlement Management: The integration with Microsoft Entra Entitlement Management allows customers to manage identity lifecycle and access processes—including joiners, movers, leavers, and guests—in Entra while governing access to downstream applications. This is intended to consolidate practices that were previously distributed across systems.
- Customer Example: Sri referenced a case study involving Synibra, which consolidated identity governance across more than 80 systems, including multiple long-standing SAP systems, using Microsoft Entra. The example demonstrated how the solution can modernize and simplify a broad application landscape.
- Usability And Security: Sri said the product direction aims to make access processes straightforward for administrators, business users, end users, and guests while retaining strong security. The intended experience is that users receive the access needed to begin work with minimal friction, while governance controls remain in place.
- Separation Of Duties Integration:
- Sri identified SAP-specific separation-of-duties conflict handling as a key upcoming capability that will connect conflict detection and resolution between SAP and Microsoft Entra rather than leaving the systems disconnected.
- Conflict Synchronization: Sri said Microsoft is working toward seamless separation-of-duties integration in which conflicts identified in SAP are reflected in Microsoft Entra and conflicts identified in Entra are reflected in SAP. The goal is a shared governance experience across both systems.
- Intelligent Resolution: The planned capability is intended to provide more intelligent conflict resolution for access decisions. Sri noted that Entitlement Management already has separation-of-duties functionality, but the SAP integration must incorporate SAP’s established capabilities and requirements.
- Planned Follow-Up: Sri asked viewers to watch for the SAP-specific separation-of-duties functionality as it develops. Holger also suggested inviting Sri back for a deeper update once the announced roadmap items become available.
- Common Identity Foundation:
- Holger connected the identity governance work to broader SAP and Microsoft integrations, explaining that a common identity foundation is required for secure lifecycle cleanup and integrations involving Microsoft 365, Work IQ, Joule, and Copilot.
- Cross-Platform Foundation: Holger explained that integrations between SAP and Microsoft services depend on a common identity model across both environments. Entra and SAP governance capabilities provide the foundation for connecting applications and maintaining consistent identities.
- Offboarding Controls: Holger raised the scenario of an employee leaving the company and asked how organizations can ensure that related identities and access across SAP and Microsoft are removed. The discussion positioned integrated governance as the mechanism for coordinating cleanup across both platforms.
- Broader Integrations: Holger referenced integrations involving Microsoft 365, Work IQ, Joule, and Copilot as examples of scenarios enabled by consistent identity management. Sri’s described provisioning and governance capabilities support these broader integration patterns.
- 0:00 Intro
- 0:28 Why SAP identity modernization matters
- 1:26 Welcome Sri
- 1:44 Sri’s role in Microsoft Entra ID Governance
- 2:16 SAP IDM end of life and customer needs
- 3:15 Microsoft and SAP collaboration
- 4:52 Recent Microsoft Entra and SAP updates
- 5:14 Flexible provisioning and custom SAP attributes
- 5:30 Account discovery and OAuth client credentials
- 5:46 Entra ID Governance and SAP Identity Access Governance
- 6:09 From Microsoft internal use to customer availability
- 7:02 What is coming next
- 7:28 Public preview and GA updates
- 8:01 SAP as customer zero and joint learning
- 9:05 Customer and partner feedback
- 10:32 Highlights from the latest functionality
- 10:44 Bi-directional provisioning
- 11:18 Entitlement management and lifecycle processes
- 12:36 Balancing usability and security
- 13:19 Identity as the foundation for SAP and Microsoft integration
- 14:00 Joiner, mover, leaver and cleanup scenarios
- 14:49 Separation of duties outlook
- 15:41 Wrap-up
