Microsoft Sentinel
Architecture and deployment

Deploy Sap Security Content

In brief

The page removes agent-based deployment sections, related imagery, and multi-workspace setup guidance. It now describes installing the SAP solution with the agentless data connector and viewing deployed security content.

What Defender admins need to know

Administrators should use the revised agentless deployment steps when consulting this page.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

This article shows you how to install the Microsoft Sentinel solution for SAP applications from the content hub. The solution includes an SAP data connector, which collects logs from your SAP systems and sends them to your Microsoft Sentinel workspace, and out-of-the-box security content—including workbooks and analytics rules—that helps you gain insight into your organization's SAP environment and detect and respond to security threats. Installing your solution is a required step before you can configure your data connector. Before you start, make sure you meet the prerequisites for deploying the Microsoft Sentinel solution for SAP applications.

:::zone pivot="connection-agent"

[!INCLUDE data-connector-agent-deprecation]

:::image type="content" source="media/deployment-steps/install-solution.png" alt-text="Diagram of the SAP solution deployment flow, highlighting the Install solution content step." border="false":::

:::zone-end

:::zone pivot="connection-agentless"

:::image type="content" source="media/deployment-steps/install-solution-agentless.png" alt-text="Diagram of the SAP solution deployment flow, highlighting the Install solution content step." border="false":::

:::zone-end

Content in this article is relevant for your security team.

:::zone pivot="connection-agentless"

:::zone-end

Prerequisites

Make sure that you also review the prerequisites for deploying Microsoft Sentinel solution for SAP applications, especially Azure prerequisites.

:::zone pivot="connection-agentless"

Install the solution

Installing the Microsoft Sentinel Solution for SAP makes both the data connector agent and the agentless data connector available to you from the Microsoft Sentinel Configuration > Data connectors page. The solution also deploys security content, such as the SAP -Audit Controls workbook and SAP-related analytics rules.

  1. In the Microsoft Sentinel Content hub, search for SAP to install the SAP applications solution.

    :::image type="content" source="./media/deploy-sap-security-content/sap-solution.png" alt-text="Screenshot that shows the Microsoft Sentinel solution for SAP applications solution pane." lightbox="./media/deploy-sap-security-content/sap-solution.png":::

  2. On the default Basics tab, scroll down to select where to install the solution. If you're working with the Microsoft Sentinel solution for SAP applications in multiple workspaces, select Some of the data is on a different workspace, and then define your target workspace, your SOC workspace, and SAP workspace. For example:

    For example:

    :::image type="content" source="./media/deploy-sap-security-content/sap-multi-workspace.png" alt-text="Screenshot that shows how to configure the Microsoft Sentinel solution for SAP applications to work across multiple workspaces.":::

  3. Select Review + create or Next to browse through the solution components. When you're ready, select Create

    The deployment process can take a few minutes. After the deployment is finished, you can view the deployed content in Microsoft Sentinel.

For more information, see Discover and manage Microsoft Sentinel out-of-the-box content.

:::zone-end

:::zone pivot="connection-agent"

Install the solution

Installing the Microsoft Sentinel Solution for SAP makes both the data connector agent and the agentless data connector available to you from the Microsoft Sentinel Configuration > Data connectors page. The solution also deploys security content, such as the SAP -Audit Controls workbook and SAP-related analytics rules.

  1. In the Microsoft Sentinel Content hub, search for SAP to install the SAP applications solution.

  2. On the Microsoft Sentinel solution for SAP applications page, select Create to define deployment settings. For example:

    :::image type="content" source="./media/deploy-sap-security-content/sap-solution.png" alt-text="Screenshot that shows the Microsoft Sentinel solution for SAP applications solution pane." lightbox="./media/deploy-sap-security-content/sap-solution.png":::

  3. On the default Basics tab, scroll down to select where to install the solution. If you're working with the Microsoft Sentinel solution for SAP applications in multiple workspaces, select Some of the data is on a different workspace, and then define your target workspace, your SOC workspace, and SAP workspace. For example:

    For example:

    :::image type="content" source="./media/deploy-sap-security-content/sap-multi-workspace.png" alt-text="Screenshot that shows how to configure the Microsoft Sentinel solution for SAP applications to work across multiple workspaces.":::

  4. Select Review + create or Next to browse through the solution components. When you're ready, select Create

    The deployment process can take a few minutes. After the deployment is finished, you can view the deployed content in Microsoft Sentinel.

For more information, see Discover and manage Microsoft Sentinel out-of-the-box content.

:::zone-end

View deployed content

When the SAP applications solution deployment is finished, display your new content by browsing again to the Microsoft Sentinel for SAP applications solution from the Content hub. Alternatively:Alternatively, to view the deployed content without returning to the Content hub:

Your data connector doesn't appear as connected until you configure your data connectorconfigure your data connector and complete the connection.

Next step