Microsoft Sentinel
Cloud and workloads

Microsoft Sentinel solutions for SAP overview

In brief

The Microsoft Sentinel SAP overview now describes separate foundation solutions for SAP applications and SAP BTP, along with SAP LogServ, partner add-ons, and community contributions. It also adds a recent SAP attack example and an attack-replay link.

What Defender admins need to know

Administrators can use the expanded overview to select capabilities matching their SAP landscape. No required configuration change or deadline is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Microsoft Sentinel solutions for SAP applications

SAP systems pose a unique security challenge, as they handle sensitive information, are a prime target for attackers, and traditionally provide little visibility for security operations teams.

An SAP system breach could result in stolen files, exposed data, or a disrupted supply chain. Once an attacker is in the system, there are few controls to detect exfiltration or other bad acts. SAP activity needs to be correlated with other data acrossthroughout the organization for effective threat detection.

Learn from recent SAP attacks

To help close this gap,SAP cyber threats can reach beyond the SAP system itself. In April 2026, a supply chain attack on SAP Cloud Application Programming Model (CAP) showed how compromised development components can put SAP BTP environments and business data at risk. Read the Microsoft Security blog to learn how Defender for Endpoint and Microsoft Sentinel offers help detect and investigate this type of threat.

Watch the end-to-end attack replay to see the detection and response flow and Security Copilot assistance in action.

Sentinel solutions and extensions for SAP

Microsoft Sentinel solutionsprovides two Microsoft-owned foundation solutions for SAP applications, which use components at every level of Microsoft Sentinel to offer end-to-end detection, analysis, investigation, and response to threats inSAP. Deploy the one (or both) that matches your SAP environment.footprint:

  • Microsoft Sentinel solution for SAP applications: Monitors SAP application layers such as business logic, applications, databases, and operating systems. This is the foundation most SAP customers start with.
  • Microsoft Sentinel solution for SAP BTP: Monitors SAP Business Technology Platform (BTP), including BTP-based applications and services. It's independent of the SAP applications solution, so you can deploy it alongside or on its own if BTP is your only SAP footprint.

Extend the SAP applications foundation with:

  • SAP LogServ: Add infrastructure and platform logs collected by SAP SE as part of the RISE with SAP offering.
  • Partner add-ons: Add SAP SE–provided and third-party partner integrations with specialized detections, connectors, and playbooks.
  • Community contributions: Adopt extension patterns, integration recipes, and scenario blueprints that customers, partners, and Microsoft engineers share in the Sentinel for SAP community repository on GitHub.

Understand the solution boundaries

The Microsoft-owned Microsoft Sentinel solution for SAP applications and Microsoft Sentinel solution for SAP BTP are separate solutions for different SAP layers. The BTP solution isn't the agentless data connector. The connector uses SAP Integration Suite, which runs on BTP, as middleware to collect SAP application data.

SIEM and SOAR features

The MicrosoftMicrosoft-owned Sentinel solutionsolutions for SAP applications continuously monitorcombine SIEM and SOAR to cover your SAP systems for threats at all layers - business logic, application, database, and OS. It allows you to:landscape end-to-end:

  • Security information and event management (SIEM): Correlate SAP monitoringapplication and SAP BTP activity with other signals acrossthroughout your organization. Use out-of-the-box and custom detections to monitor sensitive transactions and other business risks,risks such as privilege escalation, unapproved changes, unauthorized access, and unauthorized access.misuse of sensitive transactions or BTP services.

  • Security orchestration, automationautomation, and response (SOAR): Build automated response processes that interact with your SAP systems and BTP tenants to stop active security threats.

Microsoft Sentinel also offers the Microsoft Sentinel solution for SAP BTP, which offers threat monitoring and detection for SAP Business Technology Platform (BTP).

Threat detection coverage

The Microsoft Sentinel solution for SAP applications supports threat detections such as the following, and more:

  • Suspicious privileges operations, such as privileged user creation or usage of break-glass users
  • Attempts to bypass SAP security mechanisms, such as disabling audit logging, or execution of sensitive function modules
  • Backdoor creation (persistency), such as creation of new internet facing interfaces (ICF) or directly accessing sensitive tables by remote-function-call
  • Data exfiltration, such as multiple file downloads or spool takeovers
  • Initial Access, such as brute force or multiple sign-ins from the same IP

For more information, see Built-in analytics rules.

Investigation support

Certification

The Microsoft-owned Microsoft Sentinel Solutionsolutions for SAP applications isare officially availablelisted on the SAP Business Accelerator Hub. It'sThe certified Microsoft Sentinel solution for SAP applications is available for:

  • SAP ECC, Business Suite, alland other SAP NetWeaver NetWeaver-based products running in any cloud andor on-premises.
  • SAP S/4HANA Cloud Private Edition (RISE).
  • We support hybridHybrid deployments that can cover the entire customer estate.

Solution pricing

While the Microsoft Sentinel The Microsoft Sentinel solution for SAP BTP covers SAP applications solution is free to install, there's an extra hourly charge for activating andBusiness Technology Platform tenants using the solution on production systems.

  • The extra hourly charge applies to connected, active production systems only. Inactive systems aren't subject to charges. If a system's status is unknown to Microsoft Sentinel, such as because of permission issues, it's counted as a production system.
  • Microsoft Sentinel identifies a production system by looking at the configuration on theofficial audit log API. For SAP system.

Microsoft Sentinel ingestion costs might varySE–owned and are influenced by the volume of SAP logs ingested. For more information, see:partner-owned solutions, see SAP LogServ and Partner add-ons.

Related content

For more information, see: