Deployment Overview
In brief
The overview removes containerized data connector guidance and now describes the agentless connector as the solution’s deployment model. It also adds links for SAP Cloud Connector sizing, throughput, and isolation.
What Defender admins need to know
Administrators planning SAP deployments should follow the updated agentless deployment flow and linked Cloud Connector guidance. No mandatory action or deadline is stated.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Data connector
The Microsoft Sentinel solution for SAP applications supports both anuses the agentless data connector and a containerized data connector agent. Both agents collectconnector, which collects application logs for all your onboarded SAP SIDs from across the entire SAP system landscape, and then sendsends those logs to your Log Analytics workspace in Microsoft Sentinel.
[!INCLUDE data-connector-agent-deprecation]
Select one of the following tabs to learn more:
Agentless data connector
The Microsoft Sentinel agentless data connector for SAP uses the SAP Cloud Connector and SAP Integration Suite to connect to your SAP system and pull logs from it, as shown in the following image:
:::image type="content" source="media/deployment-overview/agentless-connector.png" alt-text="Diagram that shows the Microsoft Sentinel agentless data connector in an SAP environment." border="false" lightbox="media/deployment-overview/agentless-connector.png":::
By using the SAP Cloud Connector, the agentless data connector profits from already existing setups and established integration processes. This means you don't have to tackle network challenges again, as the people running your SAP Cloud Connector have already gone through that process.
For sizing, throughput tuning, and isolation guidance, see Configure SAP Cloud Connector settings and Optimize SAP Cloud Connector sizing, throughput, and isolation.
The agentless data connector is compatible with SAP NetWeaver based systems. Among them SAP S/4HANA Cloud, Private Edition (RISE with SAP), SAP S/4HANA on-premises, SAP ERP Central Component (ECC), SAP Business Warehouse (BW), and more, ensuring continued functionality of existing security content, including detections, workbooks, and playbooks.
The agentless data connector ingests critical security logs such as the security audit log, change docs logs and user master data including user roles and authorizations.
Containerized data connector agent (deprecated)
For example, the following image shows a multi-SID SAP landscape with a split between production and nonproduction systems, including the SAP Business Technology Platform. All the systems in this image are onboarded to Microsoft Sentinel for the SAP solution.
:::image type="content" source="media/deployment-overview/sap-sentinel-multi-sid-overview.png" alt-text="Diagram that shows a multi-SID SAP landscape with Microsoft Sentinel." lightbox="media/deployment-overview/sap-sentinel-multi-sid-overview.png" border="false":::
The agent connects to your SAP system to pull logs and other data from it, then sends those logs to your Microsoft Sentinel workspace. To do this, the agent has to authenticate to your SAP system, using a user and role created specifically for this purpose.
Microsoft Sentinel supports a few options for storing your agent configuration information, including the configuration for your SAP authentication secrets. The decision of which option might depend on where you deploy your VM and which SAP authentication mechanism you use. Supported options are as follows, listed in order of preference:
AnAzure Key Vaultaccessed through an Azuresystem-assigned managed identityAnAzure Key Vaultaccessed through a Microsoft Entra IDregistered-application service principalA plaintextconfiguration file
You can also authenticate using SAP's Secure Network Communication (SNC) and X.509 certificates. While using SNC provides a higher level of authentication security, it might not be practical for all scenarios.
Security content
The Microsoft Sentinel solutions for SAP applications include the following types of security content to help you gain insight into your organization's SAP environment and detect and respond to security threats:
Deployment flow and personas
Deploying the Microsoft Sentinel solutions for SAP applications involves several steps and requires collaboration across multiple teams, differing depending on whether you're using the agentless data connector or a data connector agent. Select one of the following tabs to learn more:
Agentless data connector
Deploying the Microsoft Sentinel solutionssolution for SAP applications involves several steps and requires collaboration across your security and SAP BASIS teams. The following image shows the steps in deploying the Microsoft Sentinel solutionssolution for SAP applications, with relevant teams indicated:
:::image type="content" source="media/deployment-steps/full-flow-agentless.png" alt-text="Diagram showing the full steps in the deployment flow for the Microsoft Sentinel agentless data connector for SAP applications." border="false":::
Configure your SAP system for the Microsoft Sentinel solution, including configuring SAP authorizations, configuring SAP auditing, and more. We recommend that these steps be done by your SAP BASIS team, and our documentation includes references to SAP documentation. Some of the procedures in this step can be done by the SAP BASIS team before installing the solution.
Connect your SAP systemConnect your SAP system usinganthe agentless data connector with the SAP Cloud Connector. This step is handled by your security team on the Azure portal, using information provided by your SAP BASIS team.Enable SAP detections and threat protection. This step is handled by the security team on the Azure portal.
Containerized data connector agent
Deploying the Microsoft Sentinel solutions for SAP applications involves several steps and requires collaboration across multiple teams, including the security, infrastructure, and SAP BASIS teams. The following image shows the steps in deploying the Microsoft Sentinel solutions for SAP applications, with relevant teams indicated:
:::image type="content" source="media/deployment-steps/full-flow.png" alt-text="Diagram showing the full steps in the Microsoft Sentinel solution for SAP applications deployment flow." border="false":::
We recommend that you involve all relevant teams when planning your deployment to ensure that effort is allocated and the deployment can move smoothly.
Deployment steps include:
Review the prerequisites for deploying the Microsoft Sentinel solution for SAP applications. Some prerequisites require coordination with your infrastructure or SAP BASIS teams.The following steps can happen in parallel as they involve separate teams, and aren't dependent on each other:Deploy the Microsoft Sentinel solution for SAP applications from the content hub. Make sure that you install the correct solution for your environment. This step is handled by the security team on the Azure portal.Configure your SAP system for the Microsoft Sentinel solution, including configuring SAP authorizations, configuring SAP auditing, and more. We recommend that these steps be done by your SAP BASIS team, and our documentation includes references to SAP documentation. Some steps are also performed by the security team.
Connect your SAP system by deploying a containerized data connector agent. This step requires coordination between your security, infrastructure, and SAP BASIS teams.Enable SAP detections and threat protection. This step is handled by the security team on the Azure portal.
Extra options include:
- Collect SAP HANA audit logs
Deploy an SAP data connector agent manuallyDeploy the Microsoft Sentinel solution for SAP BTP
Stop SAP data collection
If you're using the data connector agent and need to stop Microsoft Sentinel from collecting your SAP data, stop log ingestion and disable the connector. Thenor remove the extra user roleagentless data connector and any optional CRs installed on your SAP system.then reverse the SAP-side preparation you applied.
For more information, see Stop SAP data collection.
Related content
For more information, see:
- About Microsoft Sentinel content and solutions
Monitor the health and role of your SAP systemsMicrosoft Sentinel solution for SAP applications overviewUpdate Microsoft Sentinel's SAP data connector agentMonitor the health and role of your SAP systems
Next step
@@ -4,11 +4,12 @@ description: Get an introduction to the process of deploying the Microsoft Senti ms.author: monaberdugo author: mberdugo ms.topic: overview-ms.date: 09/30/2025+ms.date: 08/04/2026 appliesto: - Microsoft Sentinel in the Microsoft Defender portal - Microsoft Sentinel in the Azure portal ms.collection: usx-security+ai-usage: ai-assisted #Customer intent: As a security analyst, I want to deploy and configure a monitoring solution for SAP applications so that I can detect and respond to security threats within my SAP environment. ---@@ -25,42 +26,22 @@ The Microsoft Sentinel solution for SAP applications includes a data connector, ### Data connector -The Microsoft Sentinel solution for SAP applications supports both an agentless data connector and a containerized data connector agent. Both agents collect application logs for all your onboarded SAP SIDs from across the entire SAP system landscape, and then send those logs to your Log Analytics workspace in Microsoft Sentinel.+The Microsoft Sentinel solution for SAP applications uses the agentless data connector, which collects application logs for all your onboarded SAP SIDs from across the SAP system landscape, and then sends those logs to your Log Analytics workspace in Microsoft Sentinel. [!INCLUDE [data-connector-agent-deprecation](../includes/data-connector-agent-deprecation.md)] -Select one of the following tabs to learn more:--### [Agentless data connector](#tab/agentless)- The Microsoft Sentinel agentless data connector for SAP uses the SAP Cloud Connector and SAP Integration Suite to connect to your SAP system and pull logs from it, as shown in the following image: :::image type="content" source="media/deployment-overview/agentless-connector.png" alt-text="Diagram that shows the Microsoft Sentinel agentless data connector in an SAP environment." border="false" lightbox="media/deployment-overview/agentless-connector.png"::: By using the SAP Cloud Connector, the agentless data connector profits from already existing setups and established integration processes. This means you don't have to tackle network challenges again, as the people running your SAP Cloud Connector have already gone through that process. +For sizing, throughput tuning, and isolation guidance, see [Configure SAP Cloud Connector settings](preparing-sap.md#configure-sap-cloud-connector-settings) and [Optimize SAP Cloud Connector sizing, throughput, and isolation](preparing-sap.md#optimize-sap-cloud-connector-sizing-throughput-and-isolation).+ The agentless data connector is compatible with [SAP NetWeaver based systems](https://help.sap.com/docs/SAP_NETWEAVER?state=PRODUCTION&version=ALL). Among them SAP S/4HANA Cloud, Private Edition (RISE with SAP), SAP S/4HANA on-premises, SAP ERP Central Component (ECC), SAP Business Warehouse (BW), and more, ensuring continued functionality of existing security content, including detections, workbooks, and playbooks. The agentless data connector ingests critical security logs such as the security audit log, change docs logs and user master data including user roles and authorizations. -### [Containerized data connector agent (deprecated)](#tab/agent)--For example, the following image shows a multi-SID SAP landscape with a split between production and nonproduction systems, including the SAP Business Technology Platform. All the systems in this image are onboarded to Microsoft Sentinel for the SAP solution.--:::image type="content" source="media/deployment-overview/sap-sentinel-multi-sid-overview.png" alt-text="Diagram that shows a multi-SID SAP landscape with Microsoft Sentinel." lightbox="media/deployment-overview/sap-sentinel-multi-sid-overview.png" border="false":::--The agent connects to your SAP system to pull logs and other data from it, then sends those logs to your Microsoft Sentinel workspace. To do this, the agent has to authenticate to your SAP system, using a user and role created specifically for this purpose.--Microsoft Sentinel supports a few options for storing your agent configuration information, including the configuration for your SAP authentication secrets. The decision of which option might depend on where you deploy your VM and which SAP authentication mechanism you use. Supported options are as follows, listed in order of preference:--- An **Azure Key Vault** accessed through an Azure **system-assigned managed identity**-- An **Azure Key Vault** accessed through a Microsoft Entra ID **registered-application service principal**-- A plaintext **configuration file**--You can also authenticate using SAP's Secure Network Communication (SNC) and X.509 certificates. While using SNC provides a higher level of authentication security, it might not be practical for all scenarios.------ ### Security content The Microsoft Sentinel solutions for SAP applications include the following types of security content to help you gain insight into your organization's SAP environment and detect and respond to security threats:@@ -75,11 +56,7 @@ For more information, see [Microsoft Sentinel solution for SAP applications: sec ## Deployment flow and personas -Deploying the Microsoft Sentinel solutions for SAP applications involves several steps and requires collaboration across multiple teams, differing depending on whether you're using the agentless data connector or a data connector agent. Select one of the following tabs to learn more:--### [Agentless data connector](#tab/agentless)--Deploying the Microsoft Sentinel solutions for SAP applications involves several steps and requires collaboration across your **security** and **SAP BASIS** teams. The following image shows the steps in deploying the Microsoft Sentinel solutions for SAP applications, with relevant teams indicated:+Deploying the Microsoft Sentinel solution for SAP applications involves several steps and requires collaboration across your **security** and **SAP BASIS** teams. The following image shows the steps in deploying the Microsoft Sentinel solution for SAP applications, with relevant teams indicated: :::image type="content" source="media/deployment-steps/full-flow-agentless.png" alt-text="Diagram showing the full steps in the deployment flow for the Microsoft Sentinel agentless data connector for SAP applications." border="false"::: @@ -93,52 +70,28 @@ We recommend that you involve both teams when planning your deployment to ensure 1. [Configure your SAP system for the Microsoft Sentinel solution](preparing-sap.md), including configuring SAP authorizations, configuring SAP auditing, and more. We recommend that these steps be done by your SAP BASIS team, and our documentation includes references to SAP documentation. Some of the procedures in this step can be done by the SAP BASIS team before installing the solution. -1. [Connect your SAP system](deploy-data-connector-agent-container.md) using an agentless data connector with the SAP Cloud Connector. This step is handled by your security team on the Azure portal, using information provided by your SAP BASIS team.--1. [Enable SAP detections and threat protection](deployment-solution-configuration.md). This step is handled by the security team on the Azure portal.--### [Containerized data connector agent](#tab/agent)--Deploying the Microsoft Sentinel solutions for SAP applications involves several steps and requires collaboration across multiple teams, including the **security**, **infrastructure**, and **SAP BASIS** teams. The following image shows the steps in deploying the Microsoft Sentinel solutions for SAP applications, with relevant teams indicated:--:::image type="content" source="media/deployment-steps/full-flow.png" alt-text="Diagram showing the full steps in the Microsoft Sentinel solution for SAP applications deployment flow." border="false":::--We recommend that you involve all relevant teams when planning your deployment to ensure that effort is allocated and the deployment can move smoothly.--**Deployment steps include**:--1. [Review the prerequisites for deploying the Microsoft Sentinel solution for SAP applications](prerequisites-for-deploying-sap-continuous-threat-monitoring.md). Some prerequisites require coordination with your infrastructure or SAP BASIS teams.--1. The following steps can happen in parallel as they involve separate teams, and aren't dependent on each other:-- 1. [Deploy the Microsoft Sentinel solution for SAP applications from the content hub](deploy-sap-security-content.md). Make sure that you install the correct solution for your environment. This step is handled by the security team on the Azure portal.-- 1. [Configure your SAP system for the Microsoft Sentinel solution](preparing-sap.md), including configuring SAP authorizations, configuring SAP auditing, and more. We recommend that these steps be done by your SAP BASIS team, and our documentation includes references to SAP documentation. Some steps are also performed by the security team.--1. [Connect your SAP system](deploy-data-connector-agent-container.md) by deploying a containerized data connector agent. This step requires coordination between your security, infrastructure, and SAP BASIS teams.+1. [Connect your SAP system](deploy-data-connector-agentless.md) using the agentless data connector with the SAP Cloud Connector. This step is handled by your security team on the Azure portal, using information provided by your SAP BASIS team. 1. [Enable SAP detections and threat protection](deployment-solution-configuration.md). This step is handled by the security team on the Azure portal. **Extra options include:** - [Collect SAP HANA audit logs](collect-sap-hana-audit-logs.md)-- [Deploy an SAP data connector agent manually](sap-solution-deploy-alternate.md)+- [Deploy the Microsoft Sentinel solution for SAP BTP](deploy-sap-btp-solution.md) ## Stop SAP data collection -If you're using the data connector agent and need to stop Microsoft Sentinel from collecting your SAP data, stop log ingestion and disable the connector. Then remove the extra user role and any optional CRs installed on your SAP system.+If you need to stop Microsoft Sentinel from collecting your SAP data, disable or remove the agentless data connector and then reverse the SAP-side preparation you applied. For more information, see [Stop SAP data collection](stop-collection.md). ----- ## Related content For more information, see: - [About Microsoft Sentinel content and solutions](../sentinel-solutions.md)+- [Microsoft Sentinel solution for SAP applications overview](sap-applications-overview.md) - [Monitor the health and role of your SAP systems](../monitor-sap-system-health.md)-- [Update Microsoft Sentinel's SAP data connector agent](update-sap-data-connector.md) ## Next step 