Microsoft Sentinel
Cloud and workloads

Connect Your SAP System to Microsoft Sentinel

In brief

A new guide explains prerequisites and steps to connect SAP to Microsoft Sentinel, including Azure resource deployment, required permissions, DCR authorization, and SAP client setup.

What Defender admins need to know

Administrators onboarding the agentless SAP connector can use the guide to complete setup and verify the required Entra ID and monitoring permissions.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

new file mode 100644

title: Connect Your SAP System to Microsoft Sentinel description: Connect your SAP system to Microsoft Sentinel by configuring the agentless SAP data connector. ms.author: monaberdugo author: mberdugo ms.topic: how-to ms.date: 08/04/2026 appliesto: - Microsoft Sentinel in the Microsoft Defender portal - Microsoft Sentinel in the Azure portal ms.collection: usx-security ms.custom: msecd-doc-authoring-1014

  • devx-track-azurecli
  • sfi-image-nochange ai-usage: ai-assisted

#Customer intent: As a security, infrastructure, or SAP BASIS team member, I want to connect my SAP system to Microsoft Sentinel so that I can ingest SAP data into Microsoft Sentinel for enhanced monitoring and threat detection.


Connect your SAP system to Microsoft Sentinel

For the Microsoft Sentinel solution for SAP applications to operate correctly, you must first get your SAP data into Microsoft Sentinel. Do this by connecting the Microsoft Sentinel agentless data connector for SAP.

Before following this article, make sure you've completed the earlier deployment steps: installing the SAP solution in your workspace and preparing your SAP system. For the full list of prerequisites, see the Prerequisites section.

:::image type="content" source="media/deployment-steps/deploy-data-connector-agentless.png" alt-text="Diagram of the SAP solution deployment flow, highlighting the Connect your SAP system step." border="false":::

Content in this article is relevant for your security team.

Prerequisites

Before you connect your SAP system to Microsoft Sentinel:

Watch the connector onboarding video

Use the onboarding video to support the deployment and configuration of the Microsoft Sentinel Solution for SAP - agentless data connector described in this documentation.

[!VIDEO https://www.youtube.com/embed/PbO1S1E29Yk]

Connect your agentless data connector

  1. In Microsoft Sentinel, go to the Configuration > Data connectors page and locate the Microsoft Sentinel for SAP - agentless data connector.

  2. In the Configuration area, expand step 1. Trigger automatic deployment of required Azure resources / SOC Engineer, and select Deploy required Azure resources.

  1. Do one of the following:

    • If you have the Entra ID Application Developer role or higher, continue to the next step.
    • If you don't have the Entra ID Application Developer role or higher:
      • Share the DCR ID with your Entra ID administrator or colleague with the required permissions.
      • Ensure that the Monitoring Metrics Publisher role is assigned on the DCR, with the service principal assignment, using the client ID from the Entra ID app registration.
      • Retrieve the client ID and client secret from the Entra ID app registration to use for authorization on the DCR. The SAP admin uses the client ID and client secret information to post to the DCR.
  2. Scroll down and select Add SAP client.

  3. In the Connect to an SAP Client side pane, enter the following details:

    Field Description
    RFC destination name The name of the RFC destination, taken from your BTP destination.
    SAP Agentless Client ID The clientid value taken from the Process Integration Runtime service key JSON file.
    SAP Agentless Client Secret The clientsecret value taken from the Process Integration Runtime service key JSON file.
    Authorization server URL The tokenurl value taken from the Process Integration Runtime service key JSON file. For example: https://your-tenant.authentication.region.hana.ondemand.com/oauth/token
    Integration Suite Endpoint The url value taken from the Process Integration Runtime service key JSON file. For example: https://your-tenant.it-account-rt.cfapps.region.hana.ondemand.com
  4. Select Connect.

Mass-Onboard SAP systems at scale

To onboard SAP systems to the Sentinel Solution for SAP applications at scale, API and CLI based approaches are recommended. Get started with the SAP Integration Suite tools for Microsoft Sentinel.

Rotate the BTP client secret

We recommend that you periodically rotate the BTP subaccount client secrets used by the data connector. For an automated, platform-based approach, see our Automatic SAP BTP trust store certificate renewal with Azure Key Vault – or how to stop thinking about expiry dates once and for all (SAP blog).

The SAP Integration Suite tools for Microsoft Sentinel demonstrate the automatic process of updating an existing data connector with a new secret.

Customize data connector behavior (optional)

If you have an SAP agentless data connector for Microsoft Sentinel, you can use the SAP Integration Suite to customize how the agentless data connector ingests data from your SAP system into Microsoft Sentinel.

This procedure is only relevant when you want to customize the SAP agentless data connector behavior. Skip this procedure if you're satisfied with the default functionality. For example, if you're using Sybase, we recommend that you turn off ingestion for Change Docs logs in your SAP Integration Suite integration flow by configuring the collect-changedocs-logs parameter. Due to database performance issues, ingesting Change Docs logs Sybase isn't supported.

Prerequisites for customizing data connector behavior

Before you customize data connector behavior, make sure the following prerequisites are met:

  • You must have access to the SAP Integration Suite, with permissions to create and edit value mappings.
  • A separate SAP integration package, either existing or new, that is dedicated to hosting the value mapping artifact. The Microsoft Sentinel for SAP integration package installed from the marketplace is in configure-only mode, so you can't add it there.

Create the value mapping artifact and customize settings

Create a value mapping artifact in your SAP Integration Suite tenant and add only the parameters you want to override. Any parameter you don't define keeps its default value.

You have two options for getting the artifact in place:

  • Option 1 (recommended): Import the prebuilt Key Value Map from the Microsoft Sentinel for SAP community repository. The repository ships a Data Collector Customizing (Key Value Map) pre-populated blueprint for customizing. Download the latest base package from the releases page and import it into your SAP Integration Suite tenant. Then continue with the customization steps below.
  • Option 2: Create the artifact manually. In your dedicated package, create a new Value Mapping artifact. For more information, see the SAP documentation on creating a value mapping.

After the value mapping artifact is in place, customize and activate it:

  1. Add the entries that customize your data connector behavior. Use one of the following approaches:

    • To customize settings across all SAP systems, add value mappings under the global bi-directional mapping agency, using the parameter name as the source key and your override as the target value.
    • To customize settings for specific SAP systems, create a separate bi-directional mapping agency for each SAP system. Name each agency to exactly match the name of the RFC destination that you want to customize (for example, myRfc, key, myRfc, value), and add the parameter entries under that agency.

    For more information, see the SAP documentation on configuring value mappings.

  2. Save and deploy the value mapping artifact to activate the updated settings.

:::image type="content" source="./media/deploy-data-connector-agent-container/agentless-value-mapping-artifact.png" alt-text="Screenshot placeholder of the value mapping artifact in SAP Cloud Integration with example agentless data connector parameters." lightbox="./media/deploy-data-connector-agent-container/agentless-value-mapping-artifact.png":::

Use the following table as a guide for what to enter in the value mapping artifact. Add only the rows for the parameters you want to override:

Field in the value mapping artifactWhat to enter
Agency (source and target)global for all SAP systems, or the RFC destination name (for example, myRfc) to scope the override to a specific SAP system.
Identifier (source and target)key as the source identifier and value as the target identifier.
Source valueThe parameter name from the customizable parameters table (for example, collect-changedocs-logs).
Target valueThe override value for that parameter (for example, false).

The following table lists the customizable parameters for the SAP agentless data connector for Microsoft Sentinel:

General collection controls

The following parameters control overall data collection behavior for the agentless connector.

ParameterDescriptionAllowed valuesDefault value
changedocs-object-classesList of object classes that are ingested from Change Docs logs.Comma separated list of object classesBANK, CLEARING, IBAN, IDENTITY, KERBEROS, OA2_CLIENT, PCA_BLOCK, PCA_MASTER, PFCG, SECM, SU_USOBT_C, SECURITY_POLICY, STATUS, SU22_USOBT, SU22_USOBX, SUSR_PROF, SU_USOBX_C, USER_CUA
collect-audit-logsDetermines whether Audit Log data is ingested or not to the table ABAPAuditLog.true: Ingested
false: Not ingested
true
collect-changedocs-logsDetermines whether Change Docs logs are ingested or not into the table ABAPChangeDocsLog.true: Ingested
false: Not ingested
true
force-audit-log-to-read-from-all-clientsDetermines whether the Audit Log is read from all clients.true: Read from all clients
false: Not read from all clients
false
ingestion-cycle-daysTime, in days, given to ingest the full User Master data, including all roles and users. This parameter doesn't affect the ingestion of changes to User Master data.Integer, between 1-147
collect-user-master-data-usersDetermines whether User Details data is ingested or not to the tables ABAPUserDetails.true: Ingested, false: Not ingestedtrue
collect-user-master-data-rolesDetermines whether Role Authorization data is ingested or not to the tables ABAPAuthorizationDetails.true: Ingested, false: Not ingestedtrue
excluded-audit-usersSAP users excluded from audit log selection. Often used to balance chatty batch jobs user log volumes vs. threat protection value.Comma separated list of user names
offset-in-secondsDetermines the offset, in seconds, for both the start and end times of a data collection window. Use this parameter to delay data collection by the configured number of seconds.Integer, between 1-60060

Audit Log parameters

The following parameters control Audit Log collection behavior.

ParameterDescriptionAllowed valuesDefault value
force-audit-log-to-read-from-all-clientsDetermines whether the Audit Log is read from all clients.true: Read from all clients, false: Not read from all clientsfalse
force-sal-filesystemEnables Security Audit Log filesystem-only optimization. When set to true, the connector uses both ID_FILESYSTEM_SEL_ONLY and ID_FILE_SEL_SIMPLE for retrieval.true: Enabled, false: Disabledfalse
max-rowsActs as a safeguard that limits the number of Audit Log records processed in a single data collection window. This parameter no longer applies to Change Docs collection.Integer, between 1-1000000150000

Change Docs parameters

The following parameters control Change Docs log collection.

ParameterDescriptionAllowed valuesDefault value
changedocs-object-classesList of object classes that are ingested from Change Docs logs.Comma separated list of object classesBANK, CLEARING, IBAN, IDENTITY, KERBEROS, OA2_CLIENT, PCA_BLOCK, PCA_MASTER, PFCG, SECM, SU_USOBT_C, SECURITY_POLICY, STATUS, SU22_USOBT, SU22_USOBX, SUSR_PROF, SU_USOBX_C, USER_CUA
max-changedocs-headersActs as a safeguard that limits the number of Change Docs header records (CDHDR records) processed in a single data collection window. Use this parameter to reduce runtime and memory pressure during spikes in header volume.Integer, between 1-10000001000
max-changedocs-detailsActs as a safeguard that limits the number of Change Docs detail records (CDPOS records) processed in a single data collection window. Use this parameter to tune throughput versus memory usage.Integer, between 1-100000010000
change-docs-batch-sizeNumber of Change Docs header records used per detail-fetch call. Reduce this value if RFC calls time out.Integer, between 1-10001000

User Details parameters

The following parameters control User Details collection.

ParameterDescriptionAllowed valuesDefault value
max-usersActs as a safeguard that limits the number of unique users processed in a single collection cycle.Integer, between 1-1000000125
user-batch-sizeNumber of users processed per batch when retrieving active user data. Reduce this value if RFC calls time out.Integer, between 1-1000125
role-profiles-maxDetermines the maximum combined number of profiles and roles that can be emitted for a user before the connector writes a wildcard truncation marker instead of the full list.Integer, between 1-100001000
role-profiles-batch-sizeNumber of profiles or roles written per output row. Users with more profiles or roles than this value are split across multiple rows.Integer, between 1-100014

Role Authorization parameters

The following parameters control Role Authorization data collection.

ParameterDescriptionAllowed valuesDefault value
max-rolesActs as a safeguard that limits the number of roles processed in a single collection cycle.Integer, between 1-100000050
max-roles-authz-overallActs as a safeguard that limits the cumulative number of role authorization records fetched across all roles in a single collection cycle.Integer, between 1-100000025000
max-roles-authz-individualActs as a safeguard that limits the number of authorization records fetched for an individual role. Roles that exceed this limit are skipped.Integer, between 1-10000005000
role-authz-batch-sizeNumber of records fetched per batch when retrieving role authorization data. Reduce this value if RFC calls time out.Integer, between 1-1000100

Truncation behavior of the safeguards

When either limit is reached, a marker record is written to the output with a descriptive message indicating which limit was hit, the actual record count, and the collection time window. The two limits produce distinct markers (TRUNCATED_HEADERS and TRUNCATED_DETAILS) so they can be distinguished in Sentinel.

Check connectivity and health

After you deploy the SAP data connector, check the connector's health and connectivity. For more information, see Monitor the health and role of your SAP systems.

Once the connector is deployed, proceed to configure the Microsoft Sentinel solution for SAP applications content. Specifically, configuring details in the watchlists is an essential step in enabling detections and threat protection.

Next step

[!div class="nextstepaction"] Enable SAP detections and threat protection