Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This article lists the prerequisites required for deployment of the Microsoft Sentinel solution for SAP applications with the agentless data connector and the SAP Cloud Connector.
Reviewing and ensuring that you have or understand all the prerequisites is the first step in deploying the Microsoft Sentinel solution for SAP applications. Select a connection type to list the prerequisites for your environment.
Content in this article is relevant for your security and SAP BASIS teams.
Azure prerequisites
Typically, Azure prerequisites are managed by your security teams.
| Prerequisite | Description | Required/optional |
|---|---|---|
| Permissions to create Azure resources | You must have: - The necessary permissions to deploy solutions from the Microsoft Sentinel content hub. For more information, see Prerequisites for deploying Microsoft Sentinel solutions and Microsoft Entra built-in roles. Owner on the Microsoft Sentinel resource group, required for: - Creation of data collection rule and data collection endpoint. - Monitoring Metrics Publisher role assignment on data collection rule. |
Required |
| Read permissions to shared keys for the workspace | For more information, see Install Log Analytics agent on Windows computers. | Required |
| Permissions in Microsoft Entra | You must have permissions in Microsoft Entra ID required to create app registrations. This permission can be obtained through membership of built-in Microsoft Entra ID role: - Application Developer. |
Required |
SAP prerequisites for the agentless data connector
We recommend that your SAP BASIS team verify and ensure SAP system prerequisites. The SAP BASIS admin should review SAP notes 3390051 and 382318 to ensure that NetWeaver is set up for integration.
We strongly recommend that any management of your SAP system is carried out by an experienced SAP system administrator.
| Prerequisite | Description |
|---|---|
| Supported SAP versions | The Agentless solution supports SAP NetWeaver systems with SAP_BASIS versions 750 and above. This includes SAP S/4HANA Cloud private edition systems operated by SAP ECS in RISE. For SAP S/4HANA Cloud public edition (SaaS) use SAP's connector instead. Change Docs logs running on Sybase aren't supported. If you're using Sybase, we recommend that you customize your system to turn off ingestion for Change Docs logs. For more information, see Customize data connector behavior (optional). |
| SAP environment | Your SAP environment must have: The RSAU_API_GET_LOG_DATA function module, remote enabled on your SAP System. For more information, see the SAP documentation. An SAP BTP Subaccount with following services enabled: - SAP Integration Suite - SAP Process Integration Runtime - Cloud Foundry Runtime For more information, see the SAP documentation. Trial accounts are supported. The SAP Cloud Connector deployed SAP NetWeaver version 7.5 or higher |
| SAP roles and permissions | You must have the following roles in your SAP systems: In SAP NetWeaver 7.5+: SAP Netweaver Administrator In SAP BTP, all of the following roles: - Subaccount administrator - Integration Provisioner - PI_Administrator - PI_Integration_Developer - PI_Business_Expert |
Plan your ingestion
We recommend that you test your systems to determine the number of logs that each of your SAP systems sends to Microsoft Sentinel. Microsoft Sentinel billing depends on log ingestion size, which in turn depends on factors such as system usage, modules deployed, number of users, running use cases, network traffic, and log types.
For more information, see:
- Solution pricing
- Plan costs and understand Microsoft Sentinel pricing and billing
- Reduce costs for Microsoft Sentinel
- Manage and monitor costs for Microsoft Sentinel