SAP Security Training (S/4HANA, Fiori & Cloud Authorisations)
SAP Security training teaches you to design, build and audit authorisations across the SAP landscape.
- 40 hours
- Beginner
- Live online
- C_SEC_2405
What is SAP Security Training (S/4HANA, Fiori & Cloud Authorisations)?
SAP Security training teaches you to design, build and audit authorisations across the SAP landscape. You learn the authorisation concept and how checks work, role building and derivation in PFCG, Fiori catalogs, groups, spaces and business roles in S/4HANA, HANA database security, BTP and cloud identity, segregation of duties principles, emergency access, security parameters and hardening, audit preparation, and troubleshooting access failures. It maps to the SAP Certified Associate Security Administrator exam.
What you get
- Explain the SAP authorisation concept precisely
- Build single, derived and composite roles in PFCG
- Design Fiori business roles, catalogs and spaces
- Identify segregation of duties conflicts and design them out
Who this course is for
New to the field
- Basis administrators specialising in security
- IT security and IAM people moving into SAP
- Support staff handling access requests
Working professionals
- Audit and compliance teams
- Consultants preparing for GRC work
- Anyone targeting the security administrator exam
Prerequisites
- Basic SAP navigation is useful.
- Basis, IT security or audit backgrounds are ideal.
- No coding required.
What you will be able to do
- Explain the SAP authorisation concept precisely
- Build single, derived and composite roles in PFCG
- Design Fiori business roles, catalogs and spaces
- Identify segregation of duties conflicts and design them out
- Configure HANA and BTP security alongside ABAP roles
- Harden a system with parameters, logging and monitoring
- Diagnose any authorisation failure methodically
Salary range
- India
- 5-24 LPA
- United States
- 90k-140k
Market ranges for SAP Security Consultant, not a guarantee. Actual pay depends on experience, location and employer.
Curriculum
The SAP authorisation concept
Understand exactly how an access check works, because everything else is an application of this.
- Users, roles, profiles and authorisations
- Authorisation objects, fields and values
- How an authority check executes at runtime
- Transaction start versus object level checks
- SU24 and check indicator maintenance
- Authorisation buffer and its pitfalls
- User types and licence classification
- Naming conventions and role strategy
Building roles in PFCG
Produce clean, maintainable roles rather than the sprawl most systems end up with.
- Single, composite and derived roles
- The role menu and transaction assignment
- Organisational levels and derivation
- Manual authorisations and when to avoid them
- Role generation and profile activation
- Mass role maintenance and role comparison
- Transporting roles between systems
- Role documentation and ownership
Fiori and S/4HANA authorisations
Secure the modern user experience, which behaves differently from classic GUI security.
- Fiori launchpad security model
- Business roles, business catalogs and catalog groups
- Spaces and pages in S/4HANA
- Front-end versus back-end authorisations
- OData service authorisations
- Rapid activation content and its role templates
- Troubleshooting a missing tile versus a missing authorisation
- Migrating classic roles to Fiori business roles
Segregation of duties and sensitive access
Design access that survives an audit.
- Segregation of duties principles in SAP
- Common toxic combinations by process
- Sensitive and critical transactions
- Designing roles to avoid conflicts
- Mitigating controls where separation is impossible
- Emergency and firefighter access
- Privileged user management
- Reporting conflicts to management
HANA, BTP and cloud security
Extend the security model beyond the ABAP stack.
- HANA users, roles and privileges
- Analytic privileges for row-level security
- BTP role collections and identity providers
- Identity Authentication and single sign-on
- Principal propagation across layers
- Cloud application security basics
- Certificate and key management
- Securing hybrid landscapes
Hardening, parameters and monitoring
Reduce the attack surface and notice when something is wrong.
- Security parameters and password policy
- Default and standard users: SAP*, DDIC, EARLYWATCH
- Table and program authorisation groups
- RFC security and trusted relationships
- Gateway and message server security
- Security Audit Log (SM19/SM20)
- Read Access Logging for sensitive data
- Patch management and security notes
Audit, troubleshooting and operations
Handle the two things security people are actually judged on: audits and access failures.
- Preparing for an internal or external audit
- Standard security reports and evidence
- User access review support
- SU53, ST01 and the authorisation trace
- Diagnosing a failure methodically
- User provisioning and de-provisioning processes
- Central User Administration and identity integration
- Handover to GRC where it exists
Projects you will build
Role redesign
Take a badly built role set with excessive access, redesign it as single and derived roles by organisational level, and prove the reduction in critical access.
Fiori business role build
Configure catalogs, groups and spaces and assign a business role so three personas get exactly the tiles and back-end access they need, and nothing more.
Audit and troubleshooting clinic
Work through a set of authorisation failures using SU53 and the trace, then produce the evidence pack an auditor would ask for.
Tools you will use
- PFCG
- Role maintenance, derivation and generation. The transaction you live in as an SAP security consultant.
- SU01 and SU10
- User maintenance individually and in bulk, including licence classification.
- SU53 and ST01/STAUTHTRACE
- Failure analysis and the authorisation trace, the diagnostic core of the role.
- SU24
- Check indicator and proposal maintenance, which controls what PFCG suggests for a transaction.
- SM19 / SM20
- Security Audit Log configuration and analysis, used for monitoring and investigations.
- Fiori launchpad content manager
- Catalogs, spaces and business roles for the S/4HANA user experience.
Certification
- Exam
- SAP Certified Associate, Security Administrator
- Code
- C_SEC_2405
- Level
- Associate
- Exam fee
- US$560 (single exam)
What learners say
Derived roles and org levels were the thing I had never properly understood. The redesign project fixed that permanently.
I came from identity management outside SAP. The authorisation concept module bridged the gap in one session.
Fiori security is genuinely different and this is the first course I have taken that treated it as its own topic.
Fees and training modes
Choose how you want to learn. No-cost EMI is available on the live and 1-to-1 modes.
Most popular
Live Online Training
Talk to us
Contact for current batch fee
Interactive live batches, weekday or weekend, with the full cohort and lifetime recordings.
Fastest
1-to-1 Training
₹49,000
Fixed for every course, no-cost EMI
Private one-on-one coaching at a pace and schedule you set.
Affordable
Self-paced Training
₹9,000
One-time fee, lowest-cost option
Learn on your own time with recorded sessions and the same materials.
Refunds and cancellations are covered in our refund policy.
What a day looks like
- Access queue
- New joiners, leavers and change requests, plus anything blocking a business user right now.
- Troubleshooting
- Working a failed authorisation back through SU53 or a trace to the missing object and value.
- Role work
- Building or amending roles for a project, keeping derivation and org levels consistent.
- Review and reporting
- Checking critical access reports and preparing evidence for the next access review.
- Project support
- Designing the security model for a new module or Fiori rollout with the functional team.
Training a team?
We run this course as private corporate training, tailored to your systems and scheduled around your team. Tell us your group size and what you need to cover.
Request a corporate quoteFrequently asked questions
Security or GRC, which should I learn first?
Do I need Basis experience?
Is Fiori security really that different?
Which certification does this map to?
Does this cover HANA and cloud security?
Is there hands-on access?
Ready to start?
Talk to us about batch dates, the syllabus or anything else.