Deployment prerequisites for the Microsoft Sentinel solutions for SAP applications

This article lists the prerequisites required for deployment of the Microsoft Sentinel solution for SAP applications with the agentless data connector and the SAP Cloud Connector.

Reviewing and ensuring that you have or understand all the prerequisites is the first step in deploying the Microsoft Sentinel solution for SAP applications. Select a connection type to list the prerequisites for your environment.

Diagram of the steps included in deploying the Microsoft Sentinel solution for SAP applications, with the prerequisites step highlighted.

Content in this article is relevant for your security and SAP BASIS teams.

Azure prerequisites

Typically, Azure prerequisites are managed by your security teams.

Prerequisite Description Required/optional
Permissions to create Azure resources You must have:

- The necessary permissions to deploy solutions from the Microsoft Sentinel content hub. For more information, see Prerequisites for deploying Microsoft Sentinel solutions and Microsoft Entra built-in roles.
Owner on the Microsoft Sentinel resource group, required for:

- Creation of data collection rule and data collection endpoint.

- Monitoring Metrics Publisher role assignment on data collection rule.
Required
Read permissions to shared keys for the workspace For more information, see Install Log Analytics agent on Windows computers. Required
Permissions in Microsoft Entra You must have permissions in Microsoft Entra ID required to create app registrations. This permission can be obtained through membership of built-in Microsoft Entra ID role:

- Application Developer.
Required

SAP prerequisites for the agentless data connector

We recommend that your SAP BASIS team verify and ensure SAP system prerequisites. The SAP BASIS admin should review SAP notes 3390051 and 382318 to ensure that NetWeaver is set up for integration.

We strongly recommend that any management of your SAP system is carried out by an experienced SAP system administrator.

Prerequisite Description
Supported SAP versions The Agentless solution supports SAP NetWeaver systems with SAP_BASIS versions 750 and above. This includes SAP S/4HANA Cloud private edition systems operated by SAP ECS in RISE. For SAP S/4HANA Cloud public edition (SaaS) use SAP's connector instead.

Change Docs logs running on Sybase aren't supported. If you're using Sybase, we recommend that you customize your system to turn off ingestion for Change Docs logs. For more information, see Customize data connector behavior (optional).
SAP environment Your SAP environment must have:

The RSAU_API_GET_LOG_DATA function module, remote enabled on your SAP System. For more information, see the SAP documentation.
An SAP BTP Subaccount with following services enabled:
- SAP Integration Suite
- SAP Process Integration Runtime
- Cloud Foundry Runtime
For more information, see the SAP documentation. Trial accounts are supported.

The SAP Cloud Connector deployed

SAP NetWeaver version 7.5 or higher
SAP roles and permissions You must have the following roles in your SAP systems:

In SAP NetWeaver 7.5+: SAP Netweaver Administrator

In SAP BTP, all of the following roles:
- Subaccount administrator
- Integration Provisioner
- PI_Administrator
- PI_Integration_Developer
- PI_Business_Expert

Plan your ingestion

We recommend that you test your systems to determine the number of logs that each of your SAP systems sends to Microsoft Sentinel. Microsoft Sentinel billing depends on log ingestion size, which in turn depends on factors such as system usage, modules deployed, number of users, running use cases, network traffic, and log types.

For more information, see:

Next step