SAP
Quick answer
SailPoint integrates with SAP to aggregate users and roles/profiles and provision role assignments, often for SoD-sensitive access.
Key takeaways
- SAP connector type: an application connector (SAP)
- Onboarding: aggregate then correlate
- SailPoint can assign and remove SAP roles and profiles, which is central to financial SoD controls.
- Common issues covered in troubleshooting
SAP holds some of the most financially sensitive access in the enterprise, which makes governing it a priority, and often the primary driver for buying SailPoint at all. Integrating SAP lets you aggregate users, roles and profiles and enforce the separation-of-duties controls auditors scrutinise most.
Connector type and how it connects
The SAP integration is an application connector for SAP. It connects through SAP interfaces (for example JCo/BAPIs or SAP GRC-relevant interfaces) using a service user. As with every connector, the flow is the same: authenticate to SAP, read accounts and entitlements during aggregation, and write changes during provisioning.
Onboarding the source
- 1. Configure the connection and credentials for SAP.
- 2. Map the account schema, mapping SAP users, roles and authorization profiles to SailPoint accounts and entitlements.
- 3. Set the correlation logic so SAP accounts attach to the right identities (typically on a stable key such as employee ID or email).
- 4. Run account aggregation and confirm accounts and entitlements load.
- 5. Verify correlation, watching for uncorrelated/orphan accounts.
Provisioning capabilities
SailPoint can assign and remove SAP roles and profiles, create and lock/unlock users, and route these changes through approval and SoD checks. Because SAP access underpins financial controls, automated, governed provisioning here directly supports SOX compliance.
Entitlements and what to govern
The entitlements that matter in SAP are roles and authorization profiles. These are the building blocks of SoD analysis, define your toxic combinations (for example create-vendor versus pay-vendor) as SoD policies over these entitlements.
Troubleshooting
When SAP aggregation or provisioning fails, work through the usual causes in order:
- Confirm the SAP service user and connection (JCo/interface) parameters are correct.
- Verify the service user has authorization to read users and roles and to provision.
- Check network and port access to the SAP system.
- Validate role/profile schema mapping.
Common pitfalls
- Credential expiry (tokens/secrets) silently breaking the connector.
- Insufficient rights on the SAP service account for the operations you need.
- Schema or correlation misconfiguration leaving accounts uncorrelated.
Want to learn this properly?
Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.
Check your understanding
What type of connector is SAP?
- A. an application connector (SAP). It connects via SAP interfaces (e.g. JCo/BAPIs) to read users and roles.
- B. Credentials, network/firewall access and schema mapping.
- C. Configure the connection and credentials, then aggregate accounts and correlate them to identities.
Show answer
A. an application connector (SAP). It connects via SAP interfaces (e.g. JCo/BAPIs) to read users and roles.
an application connector (SAP). It connects via SAP interfaces (e.g. JCo/BAPIs) to read users and roles.
What is the first onboarding step for SAP?
- A. an application connector (SAP). It connects via SAP interfaces (e.g. JCo/BAPIs) to read users and roles.
- B. Configure the connection and credentials, then aggregate accounts and correlate them to identities.
- C. Credentials, network/firewall access and schema mapping.
Show answer
B. Configure the connection and credentials, then aggregate accounts and correlate them to identities.
Configure the connection and credentials, then aggregate accounts and correlate them to identities.
Where do most SAP connector issues come from?
- A. Configure the connection and credentials, then aggregate accounts and correlate them to identities.
- B. an application connector (SAP). It connects via SAP interfaces (e.g. JCo/BAPIs) to read users and roles.
- C. Credentials, network/firewall access and schema mapping.
Show answer
C. Credentials, network/firewall access and schema mapping.
Credentials, network/firewall access and schema mapping.