Pathlock

Connect SAP ERP and SAP S/4 to Pathlock Cloud

The SAP ERP and SAP S/4 connector for Pathlock Cloud enables comprehensive integration for managing and analyzing user access, roles, and permissions—including fine-grained permission extraction, segregation of duties (SoD) analysis, user provisioning, access certifications, usage and change logging, and Firefighter session management—supported by extensive out-of-the-box rulesets covering hundreds of SoD and sensitive access risks across core business processes.

Overview

SAP ERP is an integrated software system that helps businesses manage core processes such as finance, supply chain, manufacturing, and human resources.

The SAP ERP and SAP S/4 connector enables seamless integration between Pathlock Cloud and SAP ERP systems. This connector supports segregation of duties (SoD) analysis, user provisioning, access certifications, role management, usage logging, change logging, and the establishment of Firefighter sessions.

Supported Use Cases

  • Analyzing segregation of duties (SoD) and sensitive access for users and roles
  • Creating, updating, locking, and unlocking users
  • Adding and removing roles to users
  • Facilitating user access certifications
  • Tracking activities executed by users
  • Establishing audit-ready Firefighter sessions

Critical Capabilities

Fine-Grained Permission Extraction

Pathlock can extract fine-grained permissions from various applications, surpassing the user and entitlement data typically pulled by traditional IGA solutions. This allows organizations to analyze risks at the permission level, revealing true risk exposure rather than relying solely on role-based assumptions.

Detailed Feature List

  • Read the list of users
  • Create and update user accounts
  • Enable and disable user access
  • Modify user properties (rename, change password)
  • Read usage data for users in the system
  • Read the last logon date of users
  • Read the list of roles
  • Update and modify user roles (provision of role to user, revoke role from user)
  • Update and delete roles
  • Read role-related activities
  • Read activities in functions

Out-of-the-Box Rulesets

  • The SAP ECC ruleset includes over 207 SoD and around 20 Sensitive Access risks across application areas.
  • The SAP S/4HANA ruleset includes over 137 SoD and around 20 Sensitive Access risks across business processes.