Skip to content
IT Canvass
SAP Fiori · Lesson

Security

Quick answer

Fiori widens SAP’s exposure to browsers and mobile, so its attack surface must be controlled: least-privilege roles, only-needed services activated, encrypted transport, and proper authentication.

Key takeaways

  • A secure, working setup grants a user exactly the apps they need (frontend) and exactly the backend authorizations those apps…
  • Frontend: catalogs/groups in roles control which apps appear.
  • Backend: authorization objects (checked by the OData services and CDS) control what data and actions are allowed.
  • Watch out: Over-granting backend authorizations.

The two layers of Fiori access

  • Frontend: catalogs/groups in roles control which apps appear.
  • Backend: authorization objects (checked by the OData services and CDS) control what data and actions are allowed.

Both must align

A secure, working setup grants a user exactly the apps they need (frontend) and exactly the backend authorizations those apps require, no more. Over-granting backend authorizations is a security risk; under-granting breaks the app. Least privilege applies to both layers.

Communication and platform security

  • Enforce HTTPS/TLS for the launchpad and OData traffic.
  • Secure the gateway and ICF services (only activate what is needed).
  • Use SSO/MFA at the identity provider for authentication.
  • Apply CDS access control (DCL) for row-level data authorization.

Why it matters

Fiori widens SAP’s exposure to browsers and mobile, so its attack surface must be controlled: least-privilege roles, only-needed services activated, encrypted transport, and proper authentication. Security review of Fiori apps is a standard part of go-live.

Common pitfalls

  • Over-granting backend authorizations.
  • Activating unnecessary services, widening the attack surface.
  • HTTP instead of HTTPS for launchpad/OData.

Want to learn this properly?

Our live, instructor-led SAP Training covers this hands-on, with real projects and a certification path.

Check your understanding

  1. Which statement is true of Security?

    • A. SAP’s use cases span the end-to-end processes that run a business.
    • B. SD configuration (customizing) sets up sales and distribution to match how the organisation sells, enterprise…
    • C. Over-granting backend authorizations is a security risk; under-granting breaks the app.
    Show answer

    C. Over-granting backend authorizations is a security risk; under-granting breaks the app.

    Covered in the “Both must align” section of this lesson.

  2. Which of these also applies to Security?

    • A. Row-by-row processing instead of set-based SQL.
    • B. Least privilege applies to both layers.
    • C. Wrong asset class, incorrect depreciation rules.
    Show answer

    B. Least privilege applies to both layers.

    Covered in the “Both must align” section of this lesson.

  3. Which part of the Learn SAP curriculum covers Security?

    • A. SAP installation
    • B. SAP Fiori
    • C. SAP MM
    Show answer

    B. SAP Fiori

    This lesson sits in the SAP Fiori section of the Learn SAP course.

Frequently asked questions

What does Security mean in SAP Fiori?

Fiori security spans the frontend (who sees which apps) and the backend (who can run the services and access data), plus secure communication. Because Fiori exposes SAP over the web, getting its security right is essential.

Where does Security sit in the Fiori stack?

Fiori widens SAP’s exposure to browsers and mobile, so its attack surface must be controlled: least-privilege roles, only-needed services activated, encrypted transport, and proper authentication.

What else is worth knowing about Security?

A secure, working setup grants a user exactly the apps they need (frontend) and exactly the backend authorizations those apps require, no more.

What tends to go wrong with Security in SAP Fiori?

Over-granting backend authorizations. Activating unnecessary services, widening the attack surface. HTTP instead of HTTPS for launchpad/OData.
CallWhatsAppEnquire