SAP Security Training (S/4HANA, Fiori & Cloud Authorisations)
Design and defend SAP access: the authorisation concept, role building in PFCG, Fiori catalogs and business roles, S/4HANA specifics, HANA and BTP security, segregation of duties, audit readiness, and the security monitoring that catches misuse.
SAP Security training teaches you to design, build and audit authorisations across the SAP landscape. You learn the authorisation concept and how checks work, role building and derivation in PFCG, Fiori catalogs, groups, spaces and business roles in S/4HANA, HANA database security, BTP and cloud identity, segregation of duties principles, emergency access, security parameters and hardening, audit preparation, and troubleshooting access failures. It maps to the SAP Certified Associate Security Administrator exam.
Who this course is for
Prerequisite: Basic SAP navigation is useful. Basis, IT security or audit backgrounds are ideal. No coding required.
What makes this different
You configure, not just watch
From the first session you are in a live SAP practice system doing the configuration yourself, with IMG paths, master data and test transactions. That is what makes it stick.
Taught on the current release
No ECC-era screenshots pretending to be current. Everything is shown on S/4HANA and the current cloud releases, including Fiori where the classic GUI screen has been replaced.
One consultant for the whole batch
One working SAP consultant teaches the full course, no rotation, so the configuration story stays consistent from first session to go-live simulation.
Support continues to the offer
Resume rewriting for SAP roles, mock interviews on real implementation scenarios, and referrals. Support does not stop when the last class ends.

Curriculum
7 modules and 3 projects, updated to the current release. Every module maps to real SAP Security work and expands into its full topic list, practised on a live developer instance.
SAP Security Training (S/4HANA, Fiori & Cloud Authorisations) module list: 7 modules, what each one covers, and how many topics it expands into. Full topic lists are in the accordions below.
| # | Module | What you configure | Topics |
|---|---|---|---|
| 01 | The SAP authorisation concept | Understand exactly how an access check works, because everything else is an application of this. | 8 |
| 02 | Building roles in PFCG | Produce clean, maintainable roles rather than the sprawl most systems end up with. | 8 |
| 03 | Fiori and S/4HANA authorisations | Secure the modern user experience, which behaves differently from classic GUI security. | 8 |
| 04 | Segregation of duties and sensitive access | Design access that survives an audit. | 8 |
| 05 | HANA, BTP and cloud security | Extend the security model beyond the ABAP stack. | 8 |
| 06 | Hardening, parameters and monitoring | Reduce the attack surface and notice when something is wrong. | 8 |
| 07 | Audit, troubleshooting and operations | Handle the two things security people are actually judged on: audits and access failures. | 8 |
1The SAP authorisation concept
Understand exactly how an access check works, because everything else is an application of this.
- Users, roles, profiles and authorisations
- Authorisation objects, fields and values
- How an authority check executes at runtime
- Transaction start versus object level checks
- SU24 and check indicator maintenance
- Authorisation buffer and its pitfalls
- User types and licence classification
- Naming conventions and role strategy
2Building roles in PFCG
Produce clean, maintainable roles rather than the sprawl most systems end up with.
- Single, composite and derived roles
- The role menu and transaction assignment
- Organisational levels and derivation
- Manual authorisations and when to avoid them
- Role generation and profile activation
- Mass role maintenance and role comparison
- Transporting roles between systems
- Role documentation and ownership
3Fiori and S/4HANA authorisations
Secure the modern user experience, which behaves differently from classic GUI security.
- Fiori launchpad security model
- Business roles, business catalogs and catalog groups
- Spaces and pages in S/4HANA
- Front-end versus back-end authorisations
- OData service authorisations
- Rapid activation content and its role templates
- Troubleshooting a missing tile versus a missing authorisation
- Migrating classic roles to Fiori business roles
4Segregation of duties and sensitive access
Design access that survives an audit.
- Segregation of duties principles in SAP
- Common toxic combinations by process
- Sensitive and critical transactions
- Designing roles to avoid conflicts
- Mitigating controls where separation is impossible
- Emergency and firefighter access
- Privileged user management
- Reporting conflicts to management
5HANA, BTP and cloud security
Extend the security model beyond the ABAP stack.
- HANA users, roles and privileges
- Analytic privileges for row-level security
- BTP role collections and identity providers
- Identity Authentication and single sign-on
- Principal propagation across layers
- Cloud application security basics
- Certificate and key management
- Securing hybrid landscapes
6Hardening, parameters and monitoring
Reduce the attack surface and notice when something is wrong.
- Security parameters and password policy
- Default and standard users: SAP*, DDIC, EARLYWATCH
- Table and program authorisation groups
- RFC security and trusted relationships
- Gateway and message server security
- Security Audit Log (SM19/SM20)
- Read Access Logging for sensitive data
- Patch management and security notes
7Audit, troubleshooting and operations
Handle the two things security people are actually judged on: audits and access failures.
- Preparing for an internal or external audit
- Standard security reports and evidence
- User access review support
- SU53, ST01 and the authorisation trace
- Diagnosing a failure methodically
- User provisioning and de-provisioning processes
- Central User Administration and identity integration
- Handover to GRC where it exists
What you'll be able to do
Real projects you'll build
Interview-ready scenarios on a live instance, not toy demos.
Role redesign
Take a badly built role set with excessive access, redesign it as single and derived roles by organisational level, and prove the reduction in critical access.
Fiori business role build
Configure catalogs, groups and spaces and assign a business role so three personas get exactly the tiles and back-end access they need, and nothing more.
Audit and troubleshooting clinic
Work through a set of authorisation failures using SU53 and the trace, then produce the evidence pack an auditor would ask for.
Certification and hands-on
Every session runs in a live SAP practice system, so you configure and test rather than watch. The course maps to C_SEC_2405, SAP Certified Associate, Security Administrator, and finishes with an IT Canvass certificate plus a certification roadmap. IT Canvass does not issue the official SAP credential.
SAP certification is role-based and delivered through SAP Learning. Most exams sit at Associate level (implementation or development consultant for a specific solution), with Specialist exams for narrower scopes and Professional exams for architects and experienced consultants. Exams are booked through SAP Certification Hub or as a single exam; SAP re-versions exams with each release, so always confirm the current code before booking.
Certification facts. Vendor figures change, so confirm against the official SAP catalogue before booking.
| Exam code | C_SEC_2405 |
|---|---|
| Credential | SAP Certified Associate, Security Administrator |
| Issued by | SAP SE (not by IT Canvass) |
| Exam duration | 180 minutes |
| Exam cost | US$560 single exam, or included in a SAP Learning Hub subscription |
| Prerequisite | No formal prerequisite. SAP recommends hands-on project exposure before the exam. |
| What IT Canvass issues | An IT Canvass course completion certificate and a certification roadmap |
Tools and transactions you will actually use
The screens and apps you will have open every day in this role. You practise in each of them during the course.
Role maintenance, derivation and generation. The transaction you live in as an SAP security consultant.
User maintenance individually and in bulk, including licence classification.
Failure analysis and the authorisation trace, the diagnostic core of the role.
Check indicator and proposal maintenance, which controls what PFCG suggests for a transaction.
Security Audit Log configuration and analysis, used for monitoring and investigations.
Catalogs, spaces and business roles for the S/4HANA user experience.
Your SAP Security career roadmap
Five stages on the Basis and platform track, with indicative 2026 bands.
Salary snapshot: SAP Security Consultant
Indicative ranges aggregated from public salary data. Actual pay varies by location, employer and experience.
A day in the life of a SAP Security Consultant
What the job is really like once you are in it, so you know what you are training for.
Who hires SAP people
SAP security hires steadily because access must be managed whether or not projects are running. It is also the natural entry point into GRC, which pays more at the senior end.
Employer types and named companies are shown as examples of where this skill is used.
How IT Canvass compares
Against a typical training provider, this SAP Security course is taught on the current SAP release rather than recycled ECC material, gives you hands-on time in a live practice system from the first session, and keeps one working consultant for the whole batch instead of rotating trainers. Every module is mapped to the C_SEC_2405 scope, sessions are recorded with lifetime access, and job support (resume rewriting for SAP roles, mock interviews and referrals) is included in one transparent fee. Most providers still teach screen-by-screen navigation with no configuration practice, and bill system access, support and recordings as add-ons.
Fees and training modes
Choose how you want to learn SAP Security. No-cost EMI available on all modes.
Interactive live batches, weekday or weekend, with the full cohort and lifetime recordings.
Private one-on-one coaching at your pace, whether you need interview-ready fast or hands-on help with your current project.
Learn on your own time with recorded sessions, labs and Q&A doubt support.
Train your team on SAP Security
Tailored curriculum, flexible scheduling, a dedicated SAP consultant, and progress reporting for your managers. Delivered live online or on-site for cohorts of any size, with practice-system access for every learner.
Your trainer
Arjun, SAP Solution Architect, 14+ years
I still deliver S/4HANA implementations and rollouts for manufacturing and retail clients, so I teach from the configuration decisions and cutover problems that are live this quarter, not from a slide deck. In class I show the IMG path, the master data behind it, and the test transaction that proves it works.
Learner reviews
Derived roles and org levels were the thing I had never properly understood. The redesign project fixed that permanently.
I came from identity management outside SAP. The authorisation concept module bridged the gap in one session.
Fiori security is genuinely different and this is the first course I have taken that treated it as its own topic.
Fees, batches and policies
The questions people actually ask before enrolling, answered plainly.
What is the total fee and what does it include?
What are the batch timings, and do they work outside India?
What happens if I miss a session?
How long do I keep access to the recordings?
Is there a refund if the course is not right for me?
Is the certificate issued by SAP?
Frequently asked questions
Security or GRC, which should I learn first?
Do I need Basis experience?
Is Fiori security really that different?
Which certification does this map to?
Does this cover HANA and cloud security?
Is there hands-on access?
Free SAP Security tutorials to read first
Start with these free lessons, then bring your questions to class.