Microsoft Sentinel
Cloud and workloads

Monitored SAP security parameters for detecting suspicious configuration changes

In brief

The article now directs administrators to confirm that SAP_COLLECTOR_FOR_PERFMONITOR runs hourly and links to the agentless SAP connector documentation. The analytics-rule reference was also updated.

What Defender admins need to know

Verify the hourly SAP job with your SAP BASIS team to support regular PAHI table monitoring.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Monitored SAP security parameters for detecting suspicious configuration changes

This article lists the static security parameters in the SAP system that the Microsoft Sentinel solution for SAP applications monitors as part of the SAP - (Preview) Sensitive Static Parameter has Changed analytics ruleSAP - (Preview) Sensitive Static Parameter has Changed analytics rule.

The Microsoft Sentinel solution for SAP applications provides updates for this content according to SAP best practice changes. Add parameters to watch for by changing values according to your organization's needs, and turn off specific parameters in the SAPSystemParameters watchlistSAPSystemParameters watchlist.

This article doesn't describe the parameters, and isn't a recommendation to configuring the parameters. For configuration considerations, consult your SAP admins. For parameter descriptions, see the SAP documentation.

Prerequisites

For the Microsoft Sentinel solution for SAP applications to successfully monitor the SAP security parameters, the solution needs to successfully monitor the SAP PAHI table at regular intervals. For more information, see Verify that the PAHI table is updated at regular intervals.Confirm with your SAP BASIS team that the SAP_COLLECTOR_FOR_PERFMONITOR job is scheduled to run hourly so that the PAHI table stays current.

Authentication parameters

For more information, see: