Episode #307
Introduction
In episode 307 of our SAP on Azure video podcast we talk about Integration with Cloud Identity Access Governance
Identity and access management is one of those foundational topics that becomes especially important when SAP landscapes span cloud services, on-premises systems, and multiple user sources.
In todays episode, we are happy to welcome back Martin Raepple. We will continue to talk about his blog series on identity and access management with Microsoft Entra where we build on the identity provisioning scenario from the previous SuccessFactors episode.
Find all the links mentioned here: https://www.saponazurepodcast.de/episode307
Reach out to us for any feedback / questions:
Goran Condric: https://www.linkedin.com/in/gorancondric/
Holger Bruchelt: https://www.linkedin.com/in/holger-bruchelt/
#Microsoft #SAP #Azure #SAPonAzure #MicrosoftEntra #IdentityGovernance #SAPSecurity #SAPBTP #SAPCloudIdentityServices
Summary created by AI
Identity & Access Governance Integration (SAP + Microsoft Entra): Holger and Martin discussed and demonstrated a joint SAP–Microsoft identity governance scenario where Entra access packages trigger SAP Cloud Identity Access Governance (IAG) workflows to manage business role approvals and provisioning. 10:01 Martin explained the co-engineering initiative between SAP and Microsoft to integrate Entra ID governance with SAP Cloud Identity Services, IAG, and related SAP security tools. 4:52 The context included SAP Identity Management end-of-life planning, encouraging migration toward Entra-based identity governance integrations. 4:33 The focus was on extending Entra access packages to include SAP business roles coming from IAG alongside Microsoft resources (e.g., SharePoint, Teams). 11:24
End-to-End Access Request Workflow Demo: Martin presented a live demo showing how a user request flows across Entra and SAP systems with dual governance and approval paths. 16:30 A user requests an access package in Entra via My Access, which includes an SAP business role from IAG. 21:57 The request triggers an IAG workflow where the user’s manager (approver) reviews and approves or rejects based on SAP governance rules like SOD and risk checks. 34:32 If SAP-side approval fails, the entire request is denied to maintain consistency across SAP and Microsoft resources. 15:28 After approval, a provisioning job in IAG assigns the technical SAP role to the backend system user. 36:16
Technical Architecture & Integration Components: The discussion covered the hybrid architecture enabling cross-platform identity governance. Entra ID governance connects to SAP IAG using a connector secured via Azure Key Vault and BTP service keys. 17:46 Cloud Identity Services acts as a central identity proxy and authentication bridge between SAP and Entra systems. 19:12 Provisioning flows from IAG through SAP Connectivity Service and Cloud Connector into the SAP backend system. 20:19
Demo Validation & Outcome: The demo confirmed end-to-end provisioning success. A test user initially had no SAP backend roles assigned before the request. 23:25 After approval and provisioning, the SAP backend role was successfully assigned to the user. 38:06 Status updates in Entra were slightly delayed, with a noted lag of several minutes before reflecting “delivered.” 38:44
Key Takeaway Theme: The meeting highlighted a unified governance model where Entra handles access request experience while SAP IAG enforces SAP-specific compliance, risks, and role governance, ensuring both sides must approve before access is granted.
- Identity and Access Management with Microsoft Entra, Part IV: Integration with SAP Cloud IAG
- #203 - The one with SAP IDM and Entra ID (Jannis Rondorf, Chris Radkowski, Mark Wahl,Martin Raepple)
- #226 - The one with User Provisioning in a hybrid environment (Martin Raepple) | SAP on Azure Video
- #246 - TOW Customize Access Governance Workflows (Martin Raepple) | SAP on Azure Video Podcast
- #263 - ToW SuccessFactors integration & Role provisioning (Martin Raepple) | SAP on Azure Video
- #302 - Modernize SAP Identity Management with Microsoft Entra (Sri Ponnada) | SAP on Azure Video
- 0:00 Intro
- 0:55 Welcome back Martin Raepple
- 3:35 Recap Entra ID and SAP IAM blog series
- 4:27 SAP IDM end of life and joint SAP/Microsoft work
- 6:03 Previous scenarios provisioning, workflows, and SuccessFactors
- 9:03 SAP Cloud Identity Access Governance focus
- 9:45 Access packages and SAP business roles
- 11:44 Combining SAP and non-SAP access governance
- 14:20 Approval flows and all-or-nothing access
- 16:18 Demo architecture overview
- 21:12 Demo flow and SAP backend user check
- 24:02 SAP IAG business role setup
- 25:26 Entra entitlement management and access packages
- 27:16 IAG connector and Azure Key Vault
- 30:25 User requests access in My Access portal
- 32:10 SAP IAG approval workflow
- 35:19 Provisioning the approved role to SAP
- 38:37 Wrap-up, SAP TechEd, and blog post
