Microsoft Sentinel
Cloud and workloads

Sap Solution Security Content

In brief

The page date changed to August 4, 2026, and sections covering static SAP security parameter monitoring and SAP audit-log monitoring were removed.

What Defender admins need to know

Administrators may need to locate this monitoring guidance elsewhere in the updated content. No action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

This section describes a selection of built-in analytics rules provided together with the Microsoft Sentinel solution for SAP applications. The agentless data connector works with a consolidated set of sources. For the most recent updates, check the Microsoft Sentinel content hub for new and updated rules.

:::zone pivot="connection-agent"

Monitor the configuration of static SAP security parameters (Preview)

To secure the SAP system, SAP has identified security-related parameters that need to be monitored for changes. With the "SAP - (Preview) Sensitive Static Parameter has Changed" rule, the Microsoft Sentinel solution for SAP applications tracks over 52 static security-related parameters in the SAP system, which are built into Microsoft Sentinel.

To understand parameter changes in the system, the Microsoft Sentinel solution for SAP applications uses the parameter history table, which records changes made to system parameters every hour.

The parameters are also reflected in the SAPSystemParameters watchlist. This watchlist allows users to add new parameters, disable existing parameters, and modify the values and severities per parameter and system role in production or nonproduction environments.

When a change is made to one of these parameters, Microsoft Sentinel checks to see if the change is security-related and if the value is set according to the recommended values. If the change is suspected as outside the safe zone, Microsoft Sentinel creates an incident detailing the change, and identifies who made the change.

Review the list of parameters that this rule monitors.

Monitor the SAP audit log

Many of the analytics rules in the Microsoft Sentinel solution for SAP applications use SAP audit log data. Some analytics rules look for specific events in the log, while others correlate indications from several logs to create high-fidelity alerts and incidents.

Use the following analytics rules to either monitor all audit log events on your SAP system or trigger alerts only when anomalies are detected:

Rule nameDescription
SAP - Missing configuration in the Dynamic Security Audit Log MonitorBy default, runs daily to provide configuration recommendations for the SAP audit log module. Use the rule template to create and customize a rule for your workspace.
SAP - Dynamic Deterministic Audit Log Monitor (PREVIEW)By default, runs every 10 minutes and focuses on the SAP audit log events marked as Deterministic. Use the rule template to create and customize a rule for your workspace, such as for a lower false positive rate.

This rule requires deterministic alert thresholds and user exclusion rules.
SAP - Dynamic Anomaly based Audit Log Monitor Alerts (PREVIEW)By default, runs hourly and focuses on SAP events marked as AnomaliesOnly, alerting on SAP audit log events when anomalies are detected.

This rule applies extra machine learning algorithms to filter out background noise in an unsupervised manner.

By default, most event types or SAP message IDs in the SAP audit log are sent to the anomaly based Dynamic Anomaly based Audit Log Monitor Alerts (PREVIEW) analytics rule, while the easier to define event types are sent to the deterministic Dynamic Deterministic Audit Log Monitor (PREVIEW) analytics rule. This setting, along with other related settings, can be further configured to suit any system conditions.

The SAP audit log monitoring rules are delivered as part of the Microsoft Sentinel for SAP solution security content, and allow for further fine tuning using the SAP_Dynamic_Audit_Log_Monitor_Configuration and SAP_User_Config watchlists.

For example, the following table lists several examples of how you can use the SAP_Dynamic_Audit_Log_Monitor_Configuration watchlist to configure the types of events that produce incidents, reducing the number of incidents generated.

OptionDescription
Set severities and disable unwanted eventsBy default, both the deterministic rules and the rules based on anomalies create alerts for events marked with medium and high severities.

You might want to configure severities separately production and nonproduction environments. For example, you might set a debugging activity event as high severity in production systems, and turn off the same events entirely in nonproduction systems.
Exclude users by their SAP roles or SAP profilesMicrosoft Sentinel for SAP ingests the SAP user’s authorization profile, including direct and indirect role assignments, groups, and profiles, so that you can speak the SAP language in your SIEM.

You might want to configure an SAP event to exclude users based on their SAP roles and profiles. In the watchlist, add the roles or profiles that group your RFC interface users in the RolesTagsToExclude column, next to the Generic table access by RFC event. This configuration triggers alerts only for users that are missing these roles.
Exclude users by their SOC tagsUse tags to create your own grouping, without relying on complicated SAP definitions or even without SAP authorization. This method is useful for SOC teams that want to create their own grouping for SAP users.

For example, if you don't want specific service accounts to be alerted for Generic table access by RFC events, but can’t find an SAP role or an SAP profile that groups these users, use tags as follows:
1. Add the GenTableRFCReadOK tag next to the relevant event in the watchlist.
2. Go to the SAP_User_Config watchlist and assign the interface users the same tag.
Specify a frequency threshold per event type and system roleWorks like a speed limit. For example, you might configure User Master Record Change events to only trigger alerts if more than 12 activities are observed in an hour, by the same user in a production system. If a user exceeds the 12 per hour limit—for example, 2 events in a 10-minute window—an incident is triggered.
Determinism or anomaliesIf you know the event’s characteristics, use the deterministic capabilities. If you aren't sure how to correctly configure the event, allow the machine learning capabilities to decide to start, and then make subsequent updates as needed.
SOAR capabilitiesUse Microsoft Sentinel to further orchestrate, automate, and respond to incidents created by SAP audit log dynamic alerts. For more information, see Automation in Microsoft Sentinel: Security orchestration, automation, and response (SOAR).

For more information, see Available watchlists and Microsoft Sentinel for SAP News - Dynamic SAP Security Audit Log Monitor feature available now! (blog).

Initial access

Rule nameDescriptionSource actionTactics
SAP - Login from unexpected networkIdentifies a sign-in from an unexpected network.

Maintain networks in the SAP - Networks watchlist.
Sign in to the backend system from an IP address that isn't assigned to one of the networks.

Data sources: SAPcon - Audit Log
Initial Access
SAP - SPNego AttackIdentifies SPNego Replay Attack.Data sources: SAPcon - Audit LogImpact, Lateral Movement
SAP - Dialog logon attempt from a privileged userIdentifies dialog sign-in attempts, with the AUM type, by privileged users in an SAP system. For more information, see the SAPUsersGetPrivileged.Attempt to sign in from the same IP to several systems or clients within the scheduled time interval

Data sources: SAPcon - Audit Log
Impact, Lateral Movement
SAP - Brute force attacksIdentifies brute force attacks on the SAP system using RFC logonsAttempt to sign in from the same IP to several systems/clients within the scheduled time interval using RFC

Data sources: SAPcon - Audit Log
Credential Access
SAP - Multiple Logons by IPIdentifies the sign-in of several users from same IP address within a scheduled time interval.

Sub-use case: Persistency
Sign in using several users through the same IP address.

Data sources: SAPcon - Audit Log
Initial Access
SAP - Multiple Logons by UserIdentifies sign-ins of the same user from several terminals within scheduled time interval.

Available only via the Audit SAL method, for SAP versions 7.5 and higher.
Sign in using the same user, using different IP addresses.

Data sources: SAPcon - Audit Log
Pre-Attack, Credential Access, Initial Access, Collection

Sub-use case: Persistency
SAP - Informational - Lifecycle - SAP Notes were implemented in systemIdentifies SAP Note implementation in the system.Implement an SAP Note using SNOTE/TCI.

Data sources: SAPcon - Change Requests
-
SAP - (Preview) AS JAVA - Sensitive Privileged User Signed InIdentifies a sign-in from an unexpected network.

Maintain privileged users in the SAP - Privileged Users watchlist.
Sign in to the backend system using privileged users.

Data sources: SAPJAVAFilesLog
Initial Access
SAP - (Preview) AS JAVA - Sign-In from Unexpected NetworkIdentifies sign-ins from an unexpected network.

Maintain privileged users in the SAP - Networks watchlist.
Sign in to the backend system from an IP address that isn't assigned to one of the networks in the SAP - Networks watchlist

Data sources: SAPJAVAFilesLog
Initial Access, Defense Evasion

Data exfiltration

Rule nameDescriptionSource actionTactics
SAP - FTP for non authorized serversIdentifies an FTP connection for a nonauthorized server.Create a new FTP connection, such as by using the FTP_CONNECT Function Module.

Data sources: SAPcon - Audit Log
Discovery, Initial Access, Command and Control
SAP - Insecure FTP servers configurationIdentifies insecure FTP server configurations, such as when an FTP allowlist is empty or contains placeholders.Don't maintain values that contain placeholders in the SAPFTP_SERVERS table, using the SAPFTP_SERVERS_V maintenance view. (SM30)

Data sources: SAPcon - Audit Log
Initial Access, Command and Control
SAP - Multiple Files DownloadIdentifies multiple file downloads for a user within a specific time-range.Download multiple files using the SAPGui for Excel, lists, and so on.

Data sources: SAPcon - Audit Log
Collection, Exfiltration, Credential Access
SAP - Multiple Spool ExecutionsIdentifies multiple spools for a user within a specific time-range.Create and run multiple spool jobs of any type by a user. (SP01)

Data sources: SAPcon - Spool Log, SAPcon - Audit Log
Collection, Exfiltration, Credential Access
SAP - Multiple Spool Output ExecutionsIdentifies multiple spools for a user within a specific time-range.Create and run multiple spool jobs of any type by a user. (SP01)

Data sources: SAPcon - Spool Output Log, SAPcon - Audit Log
Collection, Exfiltration, Credential Access
SAP - Sensitive Tables Direct Access By RFC LogonIdentifies a generic table access by RFC sign in.

Maintain tables in the SAP - Sensitive Tables watchlist.

Relevant for production systems only.
Open the table contents using SE11/SE16/SE16N.

Data sources: SAPcon - Audit Log
Collection, Exfiltration, Credential Access
SAP - Spool TakeoverIdentifies a user printing a spool request that was created by someone else.Create a spool request using one user, and then output it in using a different user.

Data sources: SAPcon - Spool Log, SAPcon - Spool Output Log, SAPcon - Audit Log
Collection, Exfiltration, Command and Control
SAP - Dynamic RFC DestinationIdentifies the execution of RFC using dynamic destinations.

Sub-use case: Attempts to bypass SAP security mechanisms
Execute an ABAP report that uses dynamic destinations (cl_dynamic_destination). For example, DEMO_RFC_DYNAMIC_DEST.

Data sources: SAPcon - Audit Log
Collection, Exfiltration
SAP - Sensitive Tables Direct Access By Dialog LogonIdentifies generic table access via dialog sign-in.Open table contents using SE11/SE16/SE16N.

Data sources: SAPcon - Audit Log
Discovery
SAP - (Preview) File Downloaded From a Malicious IP AddressIdentifies download of a file from an SAP system using an IP address known to be malicious. Malicious IP addresses are obtained from threat intelligence services.Download a file from a malicious IP.

Data sources: SAP security Audit log, Threat Intelligence
Exfiltration
SAP - (Preview) Data Exported from a Production System using a TransportIdentifies data export from a production system using a transport. Transports are used in development systems and are similar to pull requests. This alert rule triggers incidents with medium severity when a transport that includes data from any table is released from a production system. The rule creates a high severity incident when the export includes data from a sensitive table.Release a transport from a production system.

Data sources: SAP CR log, SAP - Sensitive Tables
Exfiltration
SAP - (Preview) Sensitive Data Saved into a USB DriveIdentifies export of SAP data via files. The rule checks for data saved into a recently mounted USB drive in proximity to an execution of a sensitive transaction, a sensitive program, or direct access to a sensitive table.Export SAP data via files and save into a USB drive.

Data sources: SAP Security Audit Log, DeviceFileEvents (Microsoft Defender for Endpoint), SAP - Sensitive Tables, SAP - Sensitive Transactions, SAP - Sensitive Programs
Exfiltration
SAP - (Preview) Printing of Potentially Sensitive dataIdentifies a request or actual printing of potentially sensitive data. Data is considered sensitive if the user obtains the data as part of a sensitive transaction, execution of a sensitive program, or direct access to a sensitive table.Print or request to print sensitive data.

Data sources: SAP Security Audit Log, SAP Spool logs, SAP - Sensitive Tables, SAP - Sensitive Programs
Exfiltration
SAP - (Preview) High Volume of Potentially Sensitive Data ExportedIdentifies export of a high volume of data via files in proximity to an execution of a sensitive transaction, a sensitive program, or direct access to sensitive table.Export high volume of data via files.

Data sources: SAP Security Audit Log, SAP - Sensitive Tables, SAP - Sensitive Transactions, SAP - Sensitive Programs
Exfiltration

Persistency

Rule nameDescriptionSource actionTactics
SAP - Activation or Deactivation of ICF ServiceIdentifies activation or deactivation of ICF Services.Activate a service using SICF.

Data sources: SAPcon - Table Data Log
Command and Control, Lateral Movement, Persistence
SAP - Function Module testedIdentifies the testing of a function module.Test a function module using SE37 / SE80.

Data sources: SAPcon - Audit Log
Collection, Defense Evasion, Lateral Movement
SAP - (PREVIEW) HANA DB - User Admin actionsIdentifies user administration actions.Create, update, or delete a database user.

Data Sources: Linux Agent - Syslog*
Privilege Escalation
SAP - New ICF Service HandlersIdentifies creation of ICF Handlers.Assign a new handler to a service using SICF.

Data sources: SAPcon - Audit Log
Command and Control, Lateral Movement, Persistence
SAP - New ICF ServicesIdentifies creation of ICF Services.Create a service using SICF.

Data sources: SAPcon - Table Data Log
Command and Control, Lateral Movement, Persistence
SAP - Execution of an Obsolete or an Insecure Function ModuleIdentifies the execution of an obsolete or insecure ABAP function module.

Maintain obsolete functions in the SAP - Obsolete Function Modules watchlist. Make sure to activate table logging changes for the EUFUNC table in the backend. (SE13)

Relevant for production systems only.
Run an obsolete or insecure function module directly using SE37.

Data sources: SAPcon - Table Data Log
Discovery, Command and Control
SAP - Execution of Obsolete/Insecure ProgramIdentifies the execution of an obsolete or insecure ABAP program.

Maintain obsolete programs in the SAP - Obsolete Programs watchlist.

Relevant for production systems only.
Run a program directly using SE38/SA38/SE80, or by using a background job.

Data sources: SAPcon - Audit Log
Discovery, Command and Control
SAP - Multiple Password ChangesIdentifies multiple password changes by user.Change user password

Data sources: SAPcon - Audit Log
Credential Access
SAP - (Preview) AS JAVA - User Creates and Uses New UserIdentifies the creation or manipulation of users by admins within the SAP AS Java environment.Sign in to the backend system using users that you have created or manipulated.

Data sources: SAPJAVAFilesLog
Persistence

Attempts to bypass SAP security mechanisms

Rule nameDescriptionSource actionTactics
SAP - Client Configuration ChangeIdentifies changes for client configuration such as the client role or the change recording mode.Perform client configuration changes using the SCC4 transaction code.

Data sources: SAPcon - Audit Log
Defense Evasion, Exfiltration, Persistence
SAP - Data has Changed during Debugging ActivityIdentifies changes for runtime data during a debugging activity.

Sub-use case: Persistency
1. Activate Debug ("/h").
2. Select a field for change and update its value.

Data sources: SAPcon - Audit Log
Execution, Lateral Movement
SAP - Deactivation of Security Audit LogIdentifies deactivation of the Security Audit Log,Disable security Audit Log using SM19/RSAU_CONFIG.

Data sources: SAPcon - Audit Log
Exfiltration, Defense Evasion, Persistence
SAP - Execution of a Sensitive ABAP ProgramIdentifies the direct execution of a sensitive ABAP program.

Maintain ABAP Programs in the SAP - Sensitive ABAP Programs watchlist.
Run a program directly using SE38/SA38/SE80.

Data sources: SAPcon - Audit Log
Exfiltration, Lateral Movement, Execution
SAP - Execution of a Sensitive Transaction CodeIdentifies the execution of a sensitive Transaction Code.

Maintain transaction codes in the SAP - Sensitive Transaction Codes watchlist.
Run a sensitive transaction code.

Data sources: SAPcon - Audit Log
Discovery, Execution
SAP - Execution of Sensitive Function ModuleIdentifies the execution of a sensitive ABAP function module.

Sub-use case: Persistency

Relevant for production systems only.

Maintain sensitive functions in the SAP - Sensitive Function Modules watchlist, and make sure to activate table logging changes in the backend for the EUFUNC table. (SE13)
Run a sensitive function module directly using SE37.

Data sources: SAPcon - Table Data Log
Discovery, Command and Control
SAP - (PREVIEW) HANA DB - Audit Trail Policy ChangesIdentifies changes for HANA DB audit trail policies.Create or update the existing audit policy in security definitions.

Data sources: Linux Agent - Syslog
Lateral Movement, Defense Evasion, Persistence
SAP - (PREVIEW) HANA DB - Deactivation of Audit TrailIdentifies the deactivation of the HANA DB audit log.Deactivate the audit log in the HANA DB security definition.

Data sources: Linux Agent - Syslog
Persistence, Lateral Movement, Defense Evasion
SAP - Unauthorized Remote Execution of a Sensitive Function ModuleDetects unauthorized executions of sensitive FMs by comparing the activity with the user's authorization profile while disregarding recently changed authorizations.

Maintain function modules in the SAP - Sensitive Function Modules watchlist.
Run a function module using RFC.

Data sources: SAPcon - Audit Log
Execution, Lateral Movement, Discovery
SAP - System Configuration ChangeIdentifies changes for system configuration.Adapt system change options or software component modification using the SE06 transaction code.

Data sources: SAPcon - Audit Log
Exfiltration, Defense Evasion, Persistence
SAP - Debugging ActivitiesIdentifies all debugging related activities.

Sub-use case: Persistency
Activate Debug ("/h") in the system, debug an active process, add breakpoint to source code, and so on.

Data sources: SAPcon - Audit Log
Discovery
SAP - Security Audit Log Configuration ChangeIdentifies changes in the configuration of the Security Audit LogChange any Security Audit Log Configuration using SM19/RSAU_CONFIG, such as the filters, status, recording mode, and so on.

Data sources: SAPcon - Audit Log
Persistence, Exfiltration, Defense Evasion
SAP - Transaction is unlockedIdentifies unlocking of a transaction.Unlock a transaction code using SM01/SM01_DEV/SM01_CUS.

Data sources: SAPcon - Audit Log
Persistence, Execution
SAP - Dynamic ABAP ProgramIdentifies the execution of dynamic ABAP programming. For example, when ABAP code was dynamically created, changed, or deleted.

Maintain excluded transaction codes in the SAP - Transactions for ABAP Generations watchlist.
Create an ABAP Report that uses ABAP program generation commands, such as INSERT REPORT, and then run the report.

Data sources: SAPcon - Audit Log
Discovery, Command and Control, Impact

Suspicious privileges operations

Rule nameDescriptionSource actionTactics
SAP - Change in a Sensitive Privileged UserIdentifies changes of sensitive privileged users.

Maintain privileged users in the SAP - Privileged Users watchlist.
Change user details / authorizations using SU01.

Data sources: SAPcon - Audit Log
Privilege Escalation, Credential Access
SAP - (PREVIEW) HANA DB -Assign Admin AuthorizationsIdentifies admin privilege or role assignment.Assign a user with any admin role or privileges.

Data sources: Linux Agent - Syslog
Privilege Escalation
SAP - Sensitive privileged user logged inIdentifies the Dialog sign-in of a sensitive privileged user.

Maintain privileged users in the SAP - Privileged Users watchlist.
Sign in to the backend system using SAP* or another privileged user.

Data sources: SAPcon - Audit Log
Initial Access, Credential Access
SAP - Sensitive privileged user makes a change in other userIdentifies changes of sensitive, privileged users in other users.Change user details / authorizations using SU01.

Data Sources: SAPcon - Audit Log
Privilege Escalation, Credential Access
SAP - Sensitive Users Password Change and LoginIdentifies password changes for privileged users.Change the password for a privileged user and sign into the system.
Maintain privileged users in the SAP - Privileged Users watchlist.

Data sources: SAPcon - Audit Log
Impact, Command and Control, Privilege Escalation
SAP - User Creates and uses new userIdentifies a user creating and using other users.

Sub-use case: Persistency
Create a user using SU01, and then sign in, using the newly created user and the same IP address.

Data sources: SAPcon - Audit Log
Discovery, Pre-Attack, Initial Access
SAP - User Unlocks and uses other usersIdentifies a user being unlocked and used by other users.

Sub-use case: Persistency
Unlock a user using SU01, and then sign in using the unlocked user and the same IP address.

Data sources: SAPcon - Audit Log, SAPcon - Change Documents Log
Discovery, Pre-Attack, Initial Access, Lateral Movement
SAP - Assignment of a sensitive profileIdentifies new assignments of a sensitive profile to a user.

Maintain sensitive profiles in the SAP - Sensitive Profiles watchlist.
Assign a profile to a user using SU01.

Data sources: SAPcon - Change Documents Log
Privilege Escalation
SAP - Assignment of a sensitive roleIdentifies new assignments for a sensitive role to a user.

Maintain sensitive roles in the SAP - Sensitive Roles watchlist.
Assign a role to a user using SU01 / PFCG.

Data sources: SAPcon - Change Documents Log, Audit Log
Privilege Escalation
SAP - (PREVIEW) Critical authorizations assignment - New Authorization ValueIdentifies the assignment of a critical authorization object value to a new user.

Maintain critical authorization objects in the SAP - Critical Authorization Objects watchlist.
Assign a new authorization object or update an existing one in a role, using PFCG.

Data sources: SAPcon - Change Documents Log
Privilege Escalation
SAP - Critical authorizations assignment - New User AssignmentIdentifies the assignment of a critical authorization object value to a new user.

Maintain critical authorization objects in the SAP - Critical Authorization Objects watchlist.
Assign a new user to a role that holds critical authorization values, using SU01/PFCG.

Data sources: SAPcon - Change Documents Log
Privilege Escalation
SAP - Sensitive Roles ChangesIdentifies changes in sensitive roles.

Maintain sensitive roles in the SAP - Sensitive Roles watchlist.
Change a role using PFCG.

Data sources: SAPcon - Change Documents Log, SAPcon – Audit Log
Impact, Privilege Escalation, Persistence

:::zone-end

:::zone pivot="connection-agentless"

| SAP - Execution of an Obsolete or an Insecure Function Module |Identifies the execution of an obsolete or insecure ABAP function module.

Maintain obsolete functions in the SAP - Obsolete Function Modules watchlist. Make sure to activate table logging changes for the EUFUNC table in the backend. (SE13)

Relevant for production systems only. | Run an obsolete or insecure function module directly using SE37.

Data sources: SAPcon - Table Data Log | Discovery, Command and Control | - | | SAP - Execution of Obsolete/Insecure Program |Identifies the execution of an obsolete or insecure ABAP program.

Maintain obsolete programs in the SAP - Obsolete Programs watchlist.

Relevant for production systems only. | Run a program directly using SE38/SA38/SE80, or by using a background job.

Data sources: SAPcon - Audit Log | Discovery, Command and Control | - | | SAP - Multiple Password Changes | Identifies multiple password changes by user. | Change user password

Data sources: SAPcon - Audit Log | Credential Access | ✔️ | | SAP - New ICF Service Handlers | Identifies the creation of a new Internet Communication Framework (ICF) service handler. | Assign a new handler to a service using SICF.

Data sources: SAPcon - Audit Log | Command and Control, Initial Access, Persistence | - |

Attempts to bypass SAP security mechanisms

| SAP - Critical authorizations assignment - New User Assignment | Identifies the assignment of a critical authorization object value to a new user.

Maintain critical authorization objects in the SAP - Critical Authorization Objects watchlist. | Assign a new user to a role that holds critical authorization values, using SU01/PFCG.

Data sources: SAPcon - Change Documents Log | Privilege Escalation | - | | SAP - Sensitive Roles Changes |Identifies changes in sensitive roles.

Maintain sensitive roles in the SAP - Sensitive Roles watchlist. | Change a role using PFCG.

Data sources: SAPcon - Change Documents Log, SAPcon – Audit Log | Impact, Privilege Escalation, Persistence | - |

:::zone-end

Available watchlists

These watchlists provide the configuration for the Microsoft Sentinel solution for SAP applications. The SAP watchlists are available in the Microsoft Sentinel GitHub repository.

:::zone pivot="connection-agent"

Watchlist nameDescription and fields
SAP - Critical AuthorizationsCritical Authorizations object, where assignments should be governed.

- AuthorizationObject: An SAP authorization object, such as S_DEVELOP, S_TCODE, or Table TOBJ
- AuthorizationField: An SAP authorization field, such as OBJTYP or TCD
- AuthorizationValue: An SAP authorization field value, such as DEBUG
- ActivityField : SAP activity field. For most cases, this value is ACTVT. For Authorizations objects without an Activity, or with only an Activity field, filled with NOT_IN_USE.
- Activity: SAP activity, according to the authorization object, such as: 01: Create; 02: Change; 03: Display, and so on.
- Description: A meaningful Critical Authorization Object description.
SAP - Excluded NetworksFor internal maintenance of excluded networks, such as to ignore web dispatchers, terminal servers, and so on.

-Network: A network IP address or range, such as 111.68.128.0/17.
-Description: A meaningful network description.
SAP Excluded UsersSystem users who are signed in to the system and must be ignored. For example, alerts for multiple sign-ins by the same user.

- User: SAP User
-Description: A meaningful user description.
SAP - NetworksInternal and maintenance networks for identification of unauthorized logins.

- Network: Network IP address or range, such as 111.68.128.0/17
- Description: A meaningful network description.
SAP - Privileged UsersPrivileged users that are under extra restrictions.

- User: the ABAP user, such as DDIC or SAP
- Description: A meaningful user description.
SAP - Sensitive ABAP ProgramsSensitive ABAP programs (reports), where execution should be governed.

- ABAPProgram: ABAP program or report, such as RSPFLDOC
- Description: A meaningful program description.
SAP - Sensitive Function ModuleInternal and maintenance networks for identification of unauthorized logins.

- FunctionModule: An ABAP function module, such as RSAU_CLEAR_AUDIT_LOG
- Description: A meaningful module description.
SAP - Sensitive ProfilesSensitive profiles, where assignments should be governed.

- Profile: SAP authorization profile, such as SAP_ALL or SAP_NEW
- Description: A meaningful profile description.
SAP - Sensitive TablesSensitive tables, where access should be governed.

- Table: ABAP Dictionary Table, such as USR02 or PA008
- Description: A meaningful table description.
SAP - Sensitive RolesSensitive roles, where assignment should be governed.

- Role: SAP authorization role, such as SAP_BC_BASIS_ADMIN
- Description: A meaningful role description.
SAP - Sensitive TransactionsSensitive transactions where execution should be governed.

- TransactionCode: SAP transaction code, such as RZ11
- Description: A meaningful code description.
SAP - SystemsDescribes the landscape of SAP systems according to role, usage, and configuration.

- SystemID: the SAP system ID (SYSID)
- SystemRole: the SAP system role, one of the following values: Sandbox, Development, Quality Assurance, Training, Production
- SystemUsage: The SAP system usage, one of the following values: ERP, BW, Solman, Gateway, Enterprise Portal
- InterfaceAttributes: an optional dynamic parameter for use in playbooks.
SAPSystemParametersParameters to watch for suspicious configuration changes. This watchlist is prefilled with recommended values (according to SAP best practice), and you can extend the watchlist to include more parameters. If you don't want to receive alerts for a parameter, set EnableAlerts to false.

- ParameterName: The name of the parameter.
- Comment: The SAP standard parameter description.
- EnableAlerts: Defines whether to enable alerts for this parameter. Values are true and false.
- Option: Defines in which case to trigger an alert: If the parameter value is greater or equal (GE), less or equal (LE), or equal (EQ)
For example, if the login/fails_to_user_lock SAP parameter is set to LE (less or equal), and a value of 5, once Microsoft Sentinel detects a change to this specific parameter, it compares the newly reported value and the expected value. If the new value is 4, Microsoft Sentinel doesn't trigger an alert. If the new value is 6, Microsoft Sentinel triggers an alert.
- ProductionSeverity: The incident severity for production systems.
- ProductionValues: Permitted values for production systems.
- NonProdSeverity: The incident severity for nonproduction systems.
- NonProdValues: Permitted values for nonproduction systems.
SAP - Excluded UsersSystem users that are logged in and need to be ignored, such as for the Multiple logons by user alert.

- User: SAP User
- Description: A meaningful user description
SAP - Excluded NetworksMaintain internal, excluded networks for ignoring web dispatchers, terminal servers, and so on.

- Network: Network IP address or range, such as 111.68.128.0/17
- Description: A meaningful network description
SAP - Obsolete Function ModulesObsolete function modules, whose execution should be governed.

- FunctionModule: ABAP Function Module, such as TH_SAPREL
- Description: A meaningful function module description
SAP - Obsolete ProgramsObsolete ABAP programs (reports), whose execution should be governed.

- ABAPProgram:ABAP Program, such as TH_ RSPFLDOC
- Description: A meaningful ABAP program description
SAP - Transactions for ABAP GenerationsTransactions for ABAP generations whose execution should be governed.

- TransactionCode: Transaction Code, such as SE11.
- Description: A meaningful Transaction Code description
SAP - FTP ServersFTP Servers for identification of unauthorized connections.

- Client: such as 100.
- FTP_Server_Name: FTP server name, such as http://contoso.com/
-FTP_Server_Port:FTP server port, such as 22.
- DescriptionA meaningful FTP Server description
SAP_Dynamic_Audit_Log_Monitor_ConfigurationConfigure the SAP audit log alerts by assigning each message ID a severity level as required by you, per system role (production, nonproduction). This watchlist details all available SAP standard audit log message IDs. The watchlist can be extended to contain extra message IDs you might create on your own using ABAP enhancements on their SAP NetWeaver systems. This watchlist also allows for configuring a designated team to handle each of the event types, and excluding users by SAP roles, SAP profiles or by tags from the SAP_User_Config watchlist. This watchlist is one of the core components used for configuring the built-in SAP analytics rules for monitoring the SAP audit log. For more information, see Monitor the SAP audit log.

- MessageID: The SAP Message ID, or event type, such as AUD (User master record changes), or AUB (authorization changes).
- DetailedDescription: A markdown enabled description to be shown on the incident pane.
- ProductionSeverity: The desired severity for the incident to be created with for production systems High, Medium. Can be set as Disabled.
- NonProdSeverity: The desired severity for the incident to be created with for nonproduction systems High, Medium. Can be set as Disabled.
- ProductionThreshold The "Per hour" count of events to be considered as suspicious for production systems 60.
- NonProdThreshold The "Per hour" count of events to be considered as suspicious for nonproduction systems 10.
- RolesTagsToExclude: This field accepts SAP role name, SAP profile names or tags from the SAP_User_Config watchlist. These are then used to exclude the associated users from specific event types. See options for role tags at the end of this list.
- RuleType: Use Deterministic for the event type to be sent off to the SAP - Dynamic Deterministic Audit Log Monitor rule, or AnomaliesOnly to have this event covered by the SAP - Dynamic Anomaly based Audit Log Monitor Alerts (PREVIEW) rule. For more information, see Monitor the SAP audit log.
- TeamsChannelID: an optional dynamic parameter for use in playbooks.
- DestinationEmail: an optional dynamic parameter for use in playbooks.

For the RolesTagsToExclude field:
- If you list SAP roles or SAP profiles, this excludes any user with the listed roles or profiles from these event types for the same SAP system. For example, if you define the BASIC_BO_USERS ABAP role for the RFC related event types, Business Objects users won't trigger incidents when making massive RFC calls.
- Tagging an event type is similar to specifying SAP roles or profiles, but tags can be created in the workspace, so SOC teams can exclude users by activity without depending on the SAP BASIS team. For example, the audit message IDs AUB (authorization changes) and AUD (user master record changes) are assigned the MassiveAuthChanges tag. Users assigned this tag are excluded from the checks for these activities. Running the workspace SAPAuditLogConfigRecommend function produces a list of recommended tags to be assigned to users, such as Add the tags ["GenericTablebyRFCOK"] to user SENTINEL_SRV using the SAP_User_Config watchlist.
SAP_User_ConfigAllows for fine tuning alerts by excluding /including users in specific contexts and is also used for configuring the built-in SAP analytics rules for monitoring the SAP audit log. For more information, see Monitor the SAP audit log.

- SAPUser: The SAP user
- Tags: Tags are used to identify users against certain activity. For example Adding the tags ["GenericTablebyRFCOK"] to user SENTINEL_SRV will prevent RFC related incidents to be created for this specific user
Other active directory user identifiers
- AD User Identifier
- User On-Premises Sid
- User Principal Name

:::zone-end

:::zone pivot="connection-agentless"

| SAP - Obsolete Programs | Obsolete ABAP programs (reports), whose execution should be governed.

- ABAPProgram:ABAP Program, such as TH_ RSPFLDOC
- Description: A meaningful ABAP program description | - | | SAP - Transactions for ABAP Generations | Transactions for ABAP generations whose execution should be governed.

- TransactionCode: Transaction Code, such as SE11.
- Description: A meaningful Transaction Code description | - | | SAP - FTP Servers | FTP Servers for identification of unauthorized connections.

- Client: such as 100.
- FTP_Server_Name: FTP server name, such as http://contoso.com/
-FTP_Server_Port:FTP server port, such as 22.
- DescriptionA meaningful FTP Server description | - | | SAP_Dynamic_Audit_Log_Monitor_Configuration | Configure the SAP audit log alerts by assigning each message ID a severity level as required by you, per system role (production, nonproduction). This watchlist details all available SAP standard audit log message IDs. The watchlist can be extended to contain extra message IDs you might create on your own using ABAP enhancements on their SAP NetWeaver systems. This watchlist also allows for configuring a designated team to handle each of the event types, and excluding users by SAP roles, SAP profiles or by tags from the SAP_User_Config watchlist. This watchlist is one of the core components used for configuring the built-in SAP analytics rules for monitoring the SAP audit log. For more information, see Monitor the SAP audit log.

- MessageID: The SAP Message ID, or event type, such as AUD (User master record changes), or AUB (authorization changes).
- DetailedDescription: A markdown enabled description to be shown on the incident pane.
- ProductionSeverity: The desired severity for the incident to be created with for production systems High, Medium. Can be set as Disabled.
- NonProdSeverity: The desired severity for the incident to be created with for nonproduction systems High, Medium. Can be set as Disabled.
- ProductionThreshold The "Per hour" count of events to be considered as suspicious for production systems 60.
- NonProdThreshold The "Per hour" count of events to be considered as suspicious for nonproduction systems 10.
- RolesTagsToExclude: This field accepts SAP role name, SAP profile names or tags from the SAP_User_Config watchlist. These are then used to exclude the associated users from specific event types. See options for role tags at the end of this list.
- RuleType: Use Deterministic for the event type to be sent off to the SAP - Dynamic Deterministic Audit Log Monitor rule, or AnomaliesOnly to have this event covered by the SAP - Dynamic Anomaly based Audit Log Monitor Alerts (PREVIEW) rule. For more information, see Monitor the SAP audit log.
- TeamsChannelID: an optional dynamic parameter for use in playbooks.
- DestinationEmail: an optional dynamic parameter for use in playbooks.

For the RolesTagsToExclude field:
- If you list SAP roles or SAP profiles,SAP profiles, this excludes any user with the listed roles or profiles from these event types for the same SAP system. For example, if you define the BASIC_BO_USERS ABAP role for the RFC related event types, Business Objects users won't trigger incidents when making massive RFC calls.
- Tagging an event type is similar to specifying SAP roles or profiles, but tags can be created in the workspace, so SOC teams can exclude users by activity without depending on the SAP BASIS team. For example, the audit message IDs AUB (authorization changes) and AUD (user master record changes) are assigned the MassiveAuthChanges tag. Users assigned this tag are excluded from the checks for these activities. Running the workspace SAPAuditLogConfigRecommend function produces a list of recommended tags to be assigned to users, such as Add the tags ["GenericTablebyRFCOK"] to user SENTINEL_SRV using the SAP_User_Config watchlist. | ✔️ | | SAP_User_Config | Allows for fine tuning alerts by excluding /including users in specific contexts and is also used for configuring the built-in SAP analytics rules for monitoring the SAP audit log. For more information, see Monitor the SAP audit log.

- SAPUser: The SAP user
- Tags: Tags are used to identify users against certain activity. For example Adding the tags ["GenericTablebyRFCOK"] to user SENTINEL_SRV will prevent RFC related incidents to be created for this specific user
Other active directory user identifiers
- AD User Identifier
- User On-Premises Sid
- User Principal Name | ✔️ |

:::zone-end

Available playbooks