IT CanvassTalk to an advisor
SAP Fiori · LessonBy , SAP Trainer, 13 yrs · Published · Updated · SAP S/4HANA 2023 · all levels

SAP Fiori Security

Fiori security spans the frontend (who sees which apps) and the backend (who can run the services and access data), plus secure communication. Because Fiori exposes SAP over the web, getting its security right is essential.

Quick answer

Fiori widens SAP’s exposure to browsers and mobile, so its attack surface must be controlled: least-privilege roles, only-needed services activated, encrypted transport, and proper authentication.

Key takeaways
  • A secure, working setup grants a user exactly the apps they need (frontend) and exactly the backend authorizations those apps…
  • Frontend: catalogs/groups in roles control which apps appear.
  • Backend: authorization objects (checked by the OData services and CDS) control what data and actions are allowed.
  • Watch out: Over-granting backend authorizations.

The two layers of Fiori access

  • Frontend: catalogs/groups in roles control which apps appear.
  • Backend: authorization objects (checked by the OData services and CDS) control what data and actions are allowed.

Both must align

A secure, working setup grants a user exactly the apps they need (frontend) and exactly the backend authorizations those apps require, no more. Over-granting backend authorizations is a security risk; under-granting breaks the app. Least privilege applies to both layers.

Communication and platform security

  • Enforce HTTPS/TLS for the launchpad and OData traffic.
  • Secure the gateway and ICF services (only activate what is needed).
  • Use SSO/MFA at the identity provider for authentication.
  • Apply CDS access control (DCL) for row-level data authorization.

Why it matters

Fiori widens SAP’s exposure to browsers and mobile, so its attack surface must be controlled: least-privilege roles, only-needed services activated, encrypted transport, and proper authentication. Security review of Fiori apps is a standard part of go-live.

Common pitfalls

  • Over-granting backend authorizations.
  • Activating unnecessary services, widening the attack surface.
  • HTTP instead of HTTPS for launchpad/OData.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
Which statement is true of Security?
Already working on SAP and stuck on a live ticket?Get an expert SAP developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support