Support SAP environments with One Identity Manager

SAP IDM_One Identity Manager

SAP announced, that the solutionSAP Identity Manager (IDM) will reach the end of life in 2027, but with an extended maintenance period until 2030. This imposes on organizations using SAP Identity Manager, to search for alternative solutions.

One Identity meets the strict requirements set by the company SAP, which proves that the solution One Identity Manager can be useful to organizations not only when migrating from SAP IDM, but also by providing support for various other SAP products, including SAP FieldGlass, SAP SuccessFactors, and SAP Cloud Identity Services. Through the SAP-certified ABAP connector, One Identity ensures compatibility with the data model of the integrated SAP products as approved by the organization.

SUPPORT BEYOND SAP S/4 HANA

One Identity offers support, not only on SAP S/4 HANA, but also on each SAP system that supports ABAP or SCIM, including SAP IDM and SAP SuccessFactors. Customers of SAP, using One Identity Manager can take advantage of all provided advanced capabilities, including identity lifecycle management (Identity Lifecycle Management), identity management (Identity Governance), control of attest and control of separation of duties (Attestation and Separation of Duties SoD), application management (Application Governance), management based on behavior to(Behavior Driven Governance), compliance and audit reports, access to self-service and other

CERTIFIED CONNECTORS FOR HYBRID ENVIRONMENTS

One Identity Manager comes with a set of certified endorsers and methods for connection, which allow the creation of reliable and scalable opportunities for identity governance (IGA) to hundreds of systems. Customers, using SAP SuccessFactors, SAP Concur, SAP Ariba and othersolutions, hostedin the cloud, can also manage them with One Identity Manager.

COMPREHENSIVE SAP ECOSYSTEM SUPPORT

One Identity Manager also supports SAP IAG (or in some cases replaces it ) and directly integrates SAP applications BusinessTechnology Platform(SAP BTP).

One Identity SAP integration
Integration of One Identity at several different points in the SAP ecosystem.
How does One Identity support SAP environments from an identity and access management ( IAM ) perspective?
Adoption of industry standards

SAP Cloud Identity Services are in the core of SAP’s IAM strategy, and are based on industry standards such as Security Assertion Markup Language (SAML), OpenID Connect (OIDC), X.509 certificates and System for Cross-Domain Identity Management (SCIM). Each solution for identity management should be supported theseprotocols and integrate easily with SAP Cloud IdentityServices.

Maintenance of local workloads

The use of certified integration methods by organizations is critical, as is ensuring that local workloads are supported.

Selection of a partner with migration expertise

Organisations should trust suppliers and partners, with proven experience in migrations from SAP IDM to the selected solutionfor identity management.

The best solution: One Identity Manager
OneIdentity_SAP migration
One Identity has several supported methods for interoperating with SAP products, including certified ABAP and SCIM connectors.
OneIdentity_SAP migration
One Identity Manager can be deployed in the cloud or on-premises in a variety of ways.

The following set of graphics will show an S/4 HANA system being connected Identity Governance Administration (IGA) solution of One Identity.

1. SYSTEM SELECTION

One Identity_SAP integration
Figure 1: An S/4 HANA system is selected.
One Identity SAP integration
Figure 2: Appropriate clients are selected.

2. INTEGRATION WITH ONE IDENTITY MANAGER

One Identity Manager_SAP integration
Figure 3: Within One Identity Manager, the SAP ABAP connector is selected.
One Identity_SAP integration
Figure 4: The appropriate data model is selected. (Note: although R/3 is designated, S/4 is supported.)
One Identity Manager_SAP integration
Figure 5: One Identity Manager synchronizes client specific data as well as system specific information. The below screenshot shows the list of clients on this SAP S4/HANA system.

3. USER AND DATA SYNCHRONIZATION

One Identity Manager_SAP integration
Figure 6: The One Identity Manager’s target system browser allows live browsing. The list of SAP users and their details are shown below.
One Identity Manager_SAP integration
Figure 7: The ABAP connector provides deep-level attribute mapping, as well as the ability to map custom attributes.
One Identity Manager_SAP Integration
Figure 8: Once the S/4 HANA system has been successfully connected with the appropriate Client(s), Users, and attributes mapped, the data model is synchronized into One Identity Manager. Showing the system overview with the SAP clients.

4. ADDITIONAL SYNCHRONIZATION DETAILS

OI IDM SAP
Figure 9: Once the S/4 HANA system has been successfully connected with the appropriate Client(s), Users, and attributed mapped, the data model is synchronized into One Identity Manager. This shows the details of one specific synchronized client.
OI IDM
Figure 10: A User’s SAP roles are synchronized.
OI IDM
Figure 11: All SAP S/4 HANA clients that were selected for synchronization are viewable.
idm_sap
Figure 12: User information for each SAP S/4 HANA client is synchronized.
sap idm
Figures 13a and b: Changes made in One Identity Manager can be reflected back into S/4.
OI IDM
OI IDM
Integration with SAP NetWeaver AS Java

Integration with SAP NetWeaver AS Java allows the connection of systems based on SAP NetWeaver Application Server Java (AS Java), such as SAP IDM and User Management Engine (UME), through custom integration.

Compliance management

With the add-on Compliance for SAP, One Identity Manager given the opportunity to verify of the rules for compliance and monitoring of the regulatory require, mentswhich can to be integratedand with SAP GRC.

Integration with SAP Access Control

SAP Access Control can be inte grated throuth different ways and on different levels. This integration can be use d as engine for working processes and provisioning of resources (system for allocation of obligations). One Identity Manager also features a built-in connector for the SAP HANA database, which givetheoppor tunitytoma nagi ngtheuse rsi denti ti esin thedata base SAP HANA.

Managing hybrid environments and SAP systems

One Identity Manager’s integration capabilities are not limited to integration with SAP IAG but also include direct integration with SAP Business Technology Platform (SAP BTP) applications. A standard connector based on SCIM is provided for this purpose, via the Starling Connect service, which enables integration via SAP Cloud Identity Services. Other cloud-hosted solutions such as SAP SuccessFactors, SAP Concur, and SAP Ariba, can also be managed with One Identity Manager, ensuring end-to-end management for customer environments.

One Identity Manager will help ease the transition from SAP IDM to SAP Cloud solutions, by supporting ABAP, SCIM, and other systems, that customers have in their environments to help them meet their organization’s security requirements.

Share:

More Articles:

Contact us

Contacts

If you need technological expertise, as well as discussing project ideas, please contact us

IT solutions that work for you:
carefree, safe and efficient, every day!

Contact us:

Follow us:

IT solutions that work for you:
carefree, safe and efficient, every day!

Menu

We use cookies

This site uses cookies to improve user experience.

IT solutions that work for you:
carefree, safe and efficient, every day!

Contact us:

Follow us:

IT solutions that work for you:
carefree, safe and efficient, every day!

Menu

We use cookies

This site uses cookies to improve user experience.