Skip to content
IT Canvass

SAP Security Training (S/4HANA, Fiori & Cloud Authorisations)

SAP Security training teaches you to design, build and audit authorisations across the SAP landscape.

  • 40 hours
  • Beginner
  • Live online
  • C_SEC_2405

What is SAP Security Training (S/4HANA, Fiori & Cloud Authorisations)?

SAP Security training teaches you to design, build and audit authorisations across the SAP landscape. You learn the authorisation concept and how checks work, role building and derivation in PFCG, Fiori catalogs, groups, spaces and business roles in S/4HANA, HANA database security, BTP and cloud identity, segregation of duties principles, emergency access, security parameters and hardening, audit preparation, and troubleshooting access failures. It maps to the SAP Certified Associate Security Administrator exam.

What you get

  • Explain the SAP authorisation concept precisely
  • Build single, derived and composite roles in PFCG
  • Design Fiori business roles, catalogs and spaces
  • Identify segregation of duties conflicts and design them out

Who this course is for

New to the field

  • Basis administrators specialising in security
  • IT security and IAM people moving into SAP
  • Support staff handling access requests

Working professionals

  • Audit and compliance teams
  • Consultants preparing for GRC work
  • Anyone targeting the security administrator exam

Prerequisites

  • Basic SAP navigation is useful.
  • Basis, IT security or audit backgrounds are ideal.
  • No coding required.

What you will be able to do

  • Explain the SAP authorisation concept precisely
  • Build single, derived and composite roles in PFCG
  • Design Fiori business roles, catalogs and spaces
  • Identify segregation of duties conflicts and design them out
  • Configure HANA and BTP security alongside ABAP roles
  • Harden a system with parameters, logging and monitoring
  • Diagnose any authorisation failure methodically

Salary range

India
5-24 LPA
United States
90k-140k

Market ranges for SAP Security Consultant, not a guarantee. Actual pay depends on experience, location and employer.

Curriculum

The SAP authorisation concept

Understand exactly how an access check works, because everything else is an application of this.

  • Users, roles, profiles and authorisations
  • Authorisation objects, fields and values
  • How an authority check executes at runtime
  • Transaction start versus object level checks
  • SU24 and check indicator maintenance
  • Authorisation buffer and its pitfalls
  • User types and licence classification
  • Naming conventions and role strategy

Building roles in PFCG

Produce clean, maintainable roles rather than the sprawl most systems end up with.

  • Single, composite and derived roles
  • The role menu and transaction assignment
  • Organisational levels and derivation
  • Manual authorisations and when to avoid them
  • Role generation and profile activation
  • Mass role maintenance and role comparison
  • Transporting roles between systems
  • Role documentation and ownership

Fiori and S/4HANA authorisations

Secure the modern user experience, which behaves differently from classic GUI security.

  • Fiori launchpad security model
  • Business roles, business catalogs and catalog groups
  • Spaces and pages in S/4HANA
  • Front-end versus back-end authorisations
  • OData service authorisations
  • Rapid activation content and its role templates
  • Troubleshooting a missing tile versus a missing authorisation
  • Migrating classic roles to Fiori business roles

Segregation of duties and sensitive access

Design access that survives an audit.

  • Segregation of duties principles in SAP
  • Common toxic combinations by process
  • Sensitive and critical transactions
  • Designing roles to avoid conflicts
  • Mitigating controls where separation is impossible
  • Emergency and firefighter access
  • Privileged user management
  • Reporting conflicts to management

HANA, BTP and cloud security

Extend the security model beyond the ABAP stack.

  • HANA users, roles and privileges
  • Analytic privileges for row-level security
  • BTP role collections and identity providers
  • Identity Authentication and single sign-on
  • Principal propagation across layers
  • Cloud application security basics
  • Certificate and key management
  • Securing hybrid landscapes

Hardening, parameters and monitoring

Reduce the attack surface and notice when something is wrong.

  • Security parameters and password policy
  • Default and standard users: SAP*, DDIC, EARLYWATCH
  • Table and program authorisation groups
  • RFC security and trusted relationships
  • Gateway and message server security
  • Security Audit Log (SM19/SM20)
  • Read Access Logging for sensitive data
  • Patch management and security notes

Audit, troubleshooting and operations

Handle the two things security people are actually judged on: audits and access failures.

  • Preparing for an internal or external audit
  • Standard security reports and evidence
  • User access review support
  • SU53, ST01 and the authorisation trace
  • Diagnosing a failure methodically
  • User provisioning and de-provisioning processes
  • Central User Administration and identity integration
  • Handover to GRC where it exists

Projects you will build

Role redesign

Take a badly built role set with excessive access, redesign it as single and derived roles by organisational level, and prove the reduction in critical access.

Fiori business role build

Configure catalogs, groups and spaces and assign a business role so three personas get exactly the tiles and back-end access they need, and nothing more.

Audit and troubleshooting clinic

Work through a set of authorisation failures using SU53 and the trace, then produce the evidence pack an auditor would ask for.

Tools you will use

PFCG
Role maintenance, derivation and generation. The transaction you live in as an SAP security consultant.
SU01 and SU10
User maintenance individually and in bulk, including licence classification.
SU53 and ST01/STAUTHTRACE
Failure analysis and the authorisation trace, the diagnostic core of the role.
SU24
Check indicator and proposal maintenance, which controls what PFCG suggests for a transaction.
SM19 / SM20
Security Audit Log configuration and analysis, used for monitoring and investigations.
Fiori launchpad content manager
Catalogs, spaces and business roles for the S/4HANA user experience.

Certification

Exam
SAP Certified Associate, Security Administrator
Code
C_SEC_2405
Level
Associate
Exam fee
US$560 (single exam)

What learners say

Derived roles and org levels were the thing I had never properly understood. The redesign project fixed that permanently.

Imran S., SAP Security Consultant

I came from identity management outside SAP. The authorisation concept module bridged the gap in one session.

Sneha T., IAM Analyst

Fiori security is genuinely different and this is the first course I have taken that treated it as its own topic.

Greg P., SAP Basis and Security

Fees and training modes

Choose how you want to learn. No-cost EMI is available on the live and 1-to-1 modes.

Most popular

Live Online Training

Talk to us

Contact for current batch fee

Interactive live batches, weekday or weekend, with the full cohort and lifetime recordings.

Fastest

1-to-1 Training

₹49,000

Fixed for every course, no-cost EMI

Private one-on-one coaching at a pace and schedule you set.

Affordable

Self-paced Training

₹9,000

One-time fee, lowest-cost option

Learn on your own time with recorded sessions and the same materials.

Refunds and cancellations are covered in our refund policy.

What a day looks like

Access queue
New joiners, leavers and change requests, plus anything blocking a business user right now.
Troubleshooting
Working a failed authorisation back through SU53 or a trace to the missing object and value.
Role work
Building or amending roles for a project, keeping derivation and org levels consistent.
Review and reporting
Checking critical access reports and preparing evidence for the next access review.
Project support
Designing the security model for a new module or Fiori rollout with the functional team.

Training a team?

We run this course as private corporate training, tailored to your systems and scheduled around your team. Tell us your group size and what you need to cover.

Request a corporate quote

Frequently asked questions

Security or GRC, which should I learn first?

Security first. GRC governs the roles and requests that security builds, so the concepts here are the foundation. Many people take both, and our GRC course is the natural next step.

Do I need Basis experience?

No, though it helps. Security is a distinct specialisation, and people move into it from audit, IAM and support as often as from Basis.

Is Fiori security really that different?

Different enough to catch people out. You need both front-end catalog access and back-end authorisations, and a missing tile is not the same problem as a missing authorisation. There is a full module on it.

Which certification does this map to?

The SAP Certified Associate Security Administrator exam. Confirm the current code and syllabus with SAP before booking.

Does this cover HANA and cloud security?

Yes, a dedicated module on HANA privileges, BTP role collections and identity providers, because modern landscapes are not only ABAP.

Is there hands-on access?

Yes. You build roles, break access deliberately and diagnose it in a practice system.

Ready to start?

Talk to us about batch dates, the syllabus or anything else.

CallWhatsAppEnquire