Integration with Cloud IAG

Integration with Cloud IAG

| Martin Raepple |

Identity IAG


Episode #307

Introduction

In episode 307 of our SAP on Azure video podcast we talk about Integration with Cloud Identity Access Governance

Identity and access management is one of those foundational topics that becomes especially important when SAP landscapes span cloud services, on-premises systems, and multiple user sources.

In todays episode, we are happy to welcome back Martin Raepple. We will continue to talk about his blog series on identity and access management with Microsoft Entra where we build on the identity provisioning scenario from the previous SuccessFactors episode.

Find all the links mentioned here: https://www.saponazurepodcast.de/episode307

Reach out to us for any feedback / questions:

Summary created by AI

Identity & Access Governance Integration (SAP + Microsoft Entra): Holger and Martin discussed and demonstrated a joint SAP–Microsoft identity governance scenario where Entra access packages trigger SAP Cloud Identity Access Governance (IAG) workflows to manage business role approvals and provisioning. 10:01 Martin explained the co-engineering initiative between SAP and Microsoft to integrate Entra ID governance with SAP Cloud Identity Services, IAG, and related SAP security tools. 4:52 The context included SAP Identity Management end-of-life planning, encouraging migration toward Entra-based identity governance integrations. 4:33 The focus was on extending Entra access packages to include SAP business roles coming from IAG alongside Microsoft resources (e.g., SharePoint, Teams). 11:24

End-to-End Access Request Workflow Demo: Martin presented a live demo showing how a user request flows across Entra and SAP systems with dual governance and approval paths. 16:30 A user requests an access package in Entra via My Access, which includes an SAP business role from IAG. 21:57 The request triggers an IAG workflow where the user’s manager (approver) reviews and approves or rejects based on SAP governance rules like SOD and risk checks. 34:32 If SAP-side approval fails, the entire request is denied to maintain consistency across SAP and Microsoft resources. 15:28 After approval, a provisioning job in IAG assigns the technical SAP role to the backend system user. 36:16

Technical Architecture & Integration Components: The discussion covered the hybrid architecture enabling cross-platform identity governance. Entra ID governance connects to SAP IAG using a connector secured via Azure Key Vault and BTP service keys. 17:46 Cloud Identity Services acts as a central identity proxy and authentication bridge between SAP and Entra systems. 19:12 Provisioning flows from IAG through SAP Connectivity Service and Cloud Connector into the SAP backend system. 20:19

Demo Validation & Outcome: The demo confirmed end-to-end provisioning success. A test user initially had no SAP backend roles assigned before the request. 23:25 After approval and provisioning, the SAP backend role was successfully assigned to the user. 38:06 Status updates in Entra were slightly delayed, with a noted lag of several minutes before reflecting “delivered.” 38:44

Key Takeaway Theme: The meeting highlighted a unified governance model where Entra handles access request experience while SAP IAG enforces SAP-specific compliance, risks, and role governance, ensuring both sides must approve before access is granted.