Next Generation SSO for SAP Applications with SAML 2.0. SAP TG Solution Management Security April 2010
|
|
|
- Mavis Gallagher
- 9 years ago
- Views:
Transcription
1 Next Generation SSO for SAP Applications with SAML 2.0 SAP TG Solution Management Security April 2010
2 Disclaimer This presentation outlines our general product direction and should not be relied on in making a purchase decision. This presentation is not subject to your license agreement or any other agreement with SAP. SAP has no obligation to pursue any course of business outlined in this presentation or to develop or release any functionality mentioned in this presentation. This presentation and SAP's strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a particular purpose, or non-infringement. SAP assumes no responsibility for errors or omissions in this document, except if such damages were caused by SAP intentionally or grossly negligent. SAP AG All rights reserved. / Page 2
3 Agenda 1. Authentication, SSO, and Identity Federation 2. SAML 2.0 for SAP: SSO and Identity Federation Agreements 3. SAML 2.0: Capabilities Bundled in the Standard SAP AG All rights reserved. / Page 3
4 Key Differentiators of User Authentication and Single Sign-On Technologies Direct User Involvement Must the user interactively prove their identity with something they know, have or are? Must an application act on behalf of the user? Private Credentials? User Agent Which type of user agent (e.g. Web Browser, Web Service Consumer, Mobile Clients, NW BC, SAPGUI) is supported by the SSO technology? SSO Cross-Platform Platform support by the SSO technology? Is it a widely adopted standard in the industry or a vendor-specific technology? Platform A SSO Platform B Cross-Domain Use of SSO technology within a security domain (i.e. the corporate Intranet) or across different domains (e.g. in a B2B scenario)? Domain A SSO Domain B SAP AG All rights reserved. / Page 4
5 SSO as Means to an End for Security Administration Centralizing User Access Management Single point of access administration via SSO token issuers Assign user rights in various applications with one keystroke based on the propagation of user identity information between trusted systems Use system trust configuration to designate and enforce the use of application servers as trusted gateways into trusted system networks Central User Identity Management Consolidate user information in shared user stores Avoid redundant user information Ease identity de-provisioning Lock or delete users centrally SAP AG All rights reserved. / Page 5
6 User Identity Federation Defined SSO Across Business and Application Boundaries SAP AG All rights reserved. / Page 6
7 Identity Federation Models Outside of Software Applications Governments as Identity Provider Governments are an Identity Provider because they issue a Passport as proof of identification Every country vouches for its citizens Governments as Service Provider When an USA citizen travels to Germany, Germany verifies the identity of the USA citizen by checking its passport Germany trusts the Identity Provider (USA) to vouch for all its citizens. It still makes its own access control decision (to let the person in or not) based on identity data (including attributes) that is being asserted USA Government (Identity Provider) Trusted Relationship German Government (Service Provider) SAP AG All rights reserved. / Page 7
8 Web User SSO to SAP Interactive Applications Today Portal or SAP NetWeaver application server Initial user authentication Trusted SSO ticket issuer Intranet CRM Initial logon Send SSO ticket to user browser ERP BI SSO Groupware Other... Web user s browser: Further distribution of issued SSO ticket SAP applications: Pre-configured as SSO ticket acceptors Synchronization of user information in local identity management required SSO capabilities limited technically to DNS domains borders Single Log-out capabilities require additional component customization SAP AG All rights reserved. / Page 8
9 Web browser SAP NetWeaver applications Web User Authentication and SSO to User Interactive SAP Applications Anonymous access Named anonymous users with SAP NetWeaver Portal Interactive user authentication PKI-based authentication SAP user ID / password X.509 client certificates Rule based client authentication 1 Certificate filtering 1 Automated certificate mapping 1 CRL support 1 External authentication SSO via trusted application system SPNego 1 user authentication against a Kerberos infrastructure Header variables 1 SSO Logon tickets Principal solution for SSO in SAP landscapes SAML 1.1 Browser Artifact 1 Interoperable SSO from trusted non-sap token issuers 1 Requires Portal or AS Java Identity Federation, interoperable SSO and Single Log-out Custom authentication 2 SAP SAML 2 IDP planned to be licensed with SAP NetWeaver Identity Management 7.1 and requires SAP NetWeaver 7.2 Java and higher AS platform SAP SAML 2 SP capability planned for release with SAP Business Suite 7.02e, SAP NetWeaver CE 7.2 and AS Java 7.2 Web applications SAP AG All rights reserved. / Page 9 SAML 2 2 Identity Provider (IDP) for centralized user authentication and SAML 2 SSO token issuing authority Service Provider (SP) for accepting SAML 2 SSO token to grant user access to Web enabled content JAAS Login Module 1 Standardized extensions to out-of-the-box authentication mechanisms
10 SAP GUI User SSO to SAP Interactive Applications SAP GUI for Windows External SNC security product External SNC security product Uses SNC components and external security product both specific to SAP GUI as user access channel SAP makes available: NTLM SSO library for Windows OS environments (gssntlm.dll) Kerberos SSO library for Windows 2000 OS environments (gsskrb5.dll) SAP certification available for partner SNC products More Information : SNC User Guide in SAP Help Portal ( AS ABAP Installation and Configuration Guide in SAP Service Marketplace ( SAP AG All rights reserved. / Page 10
11 SSO Options for System-Centric Service Applications Today User Client Service Consumer Service Provider Content display Functionality integration Authenticates user Issues SSO token on their behalf Evaluates credentials from Service Consumer Service and protocol specific service enabling components Shares some trust and identity management infrastructure with Web and GUI user access channels Run over various low level communication protocols Except Web services, low level protocols service protocols offer limited interoperability and security configuration scalability SAP AG All rights reserved. / Page 11
12 Service Consumer Application (e.g. Portal, CE, PI, BPM, Business Suite, non-sap) Options for Service Authentication and SSO in SAP s Service-Centric Applications Propagate authenticated user identity WSS SAML Token Profiles 1.0 * SSO tickets Securely authenticate consumer application WSS X.509 Certificate Token Profile * X.509 client certificate Authenticate service user WSS Username Token Profile * User ID and Password * supported for WS Protocols only Authentication and SSO information exchanged via: SOAP Protocol for secure interoperability and authentication/sso in cross-vendor Web service-based enterprise applications Transport Protocol for performance, backward compatibility and security in SAP centric service-enabled enterprise applications SAP AG All rights reserved. / Page 12
13 SAP s Next Generation Support for Web User SSO and Identity Federation Trust Relationship Application Service Providers (SPs) SAP NetWeaver Identity Management with SAML 2 Identity Provider (IDP) and Security Token Service (STS)* SSO Federation Standardized SAML 2 SSO and Single Log-out Shared infrastructure in user interactive and service applications on the Web Identity management Trust management SOA SSO Federation Efficient user productivity enablement of secure cross-business scenarios * SAML 2 IDP planned for release with a SAP NetWeaver IDM 7.1 license, STS support planned for later SAP NetWeaver IDM releases This presentation and SAP's strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a particular purpose, or non-infringement SAP AG All rights reserved. / Page 13 SAP Applications 3 rd Party Applications
14 Agenda 1. Authentication, SSO, and Identity Federation 2. SAML 2.0 for SAP: SSO and Identity Federation Agreements 3. SAML 2.0: Capabilities Bundled in the Industry Standard SAP AG All rights reserved. / Page 14
15 SAML 2 in a B2B Application Scenario HRA Enable user access and productivity at reasonable costs ITeIO Must do: Manage employees full range of user identity information in compliance with data privacy legislation Enable access to partner applications in compliance with the partner s access and security policy SAP AG All rights reserved. / Page 15 Must do: Define access policy requirements Maintain application authorizations for segregation of duty and least privilege Offer self-service options to HRA partner employees, using ITeIO services (shuttles, lunch, etc.)
16 SSO Agreement Under Aligned User Logon Identifiers with SAML 2 HRA as IDP User identity management prerequisites: Logon id formats and values aligned User authorizations aligned ITeIO as SP abufford abufford Identifier source: Logon Id Logon Alias Profile attribute Identifier source: Logon Id Logon Alias Profile attribute Adam Bufford SAP AG All rights reserved. / Page 16
17 Linking User Accounts with Misaligned User Identifiers for SAML 2 SSO HRA as IDP User identity management prerequisites: Logon id formats and values aligned User authorizations aligned ITeIO as SP abufford adam.bufford User identifier maintained in KPN Windows name X.509 Subject Name user profile attribute Adam Bufford To enable SSO, matching user profile attribute must be provisioned in KPN Windows name X.509 Subject Name user profile attribute SAP AG All rights reserved. / Page 17
18 Linking Federated SSO Accounts with Persistent Federation HRA as IDP User identity management prerequisite: User authorizations aligned ITeIO as SP abufford adam.bufford Logon id alignment bundled in the SAML 2 federated SSO Agreement to federated SSO established: with interactive user agreement triggered by admin with identity provisioning SAP AG All rights reserved. / Page 18 Adam Bufford Logon id alignment bundled in the SAML 2 federated SSO Consent to federated SSO established: with interactive user agreement triggered by admin with identity provisioning automatic new user account creation
19 Service Provider Structuring User Authorization Profiles Under the SAML 2 SSO Agreements, Discussed up to This Point Count Authorization Element Authorization Element Count k SAP User IDs 1 1 SAP User IDs (misaligned) k l User Groups 1:1 record relation User Groups s m User Roles SPs and IDP have to manage an overall equivalent number of federated user accounts User Roles t r p Actions/App Roles Permissions Identity Provider Actions/App Roles Permissions v x SAP AG All rights reserved. / Page 19
20 Federated SSO with User Attribute Information HRA as IDP Contractual prerequisite: Agree on user attributes to exchange ITeIO as SP abufford Issued SAML 2 assertion contains only attributes describing user User profile for application access determined from user attribute values in assertion SAP AG All rights reserved. / Page 20
21 Service Provider Structuring of User Authorization Profiles with Transient Federation Agreements Count Authorization Element Authorization Element Count k SAP User IDs n 1 User ID t l m r p User Groups User Roles Actions/App Roles Permissions N:1 record relation SP manages 1 account per multiple IDP user records. Only IDP must manage full user attribute profile Identity Provider User Role / Group Actions/App Roles Permissions t v x SAP AG All rights reserved. / Page 21
22 Identity Federation and B2B SSO The Small Script Contracts must define what can be shared to technically enable a federation agreement Contract provides a skeleton about the information that can/must be shared: not all identity information may be shared due to business or compliance reasons. Contract may include special agreements per target application system or target application system group: facilitate trust established indirectly via intermediary identity provider brokers For data protection and privacy reasons, users (administrative or end) can: agree to sharing the requested data by the accessed via federation resource (SP) from the federation authority (IdP) enforce contractual agreement, with deployment of integrity and confidentiality protection assign and audit policies for different trust relationships SAP AG All rights reserved. / Page 22
23 Agenda 1. Authentication, SSO, and Identity Federation 2. SAML 2.0 for SAP: SSO and Identity Federation Agreements 3. SAML 2.0: Capabilities Bundled in the Standard SAP AG All rights reserved. / Page 23
24 SAML 2.0 Overview Industry standard for cross-vendor SSO and SLO with wide adoption XML-based framework for marshaling security and identity information and exchanging it across administrative and technical domain boundaries SAML profiles describe a variety of end use cases for framework SAML Core technology: Assertions (or claims) about end user subjects Contain statements: authentication, attribute, authorization Issued from a trusted system provider: an active element of a computer/network system Securely identify a principal: an user whose identity can be authenticated Contain a subject: an accountable principal in the context of a secured application SAP AG All rights reserved. / Page 24
25 SAML 2.0 in a Nutshell SAML 2.0 deliverables for interactive Web user federation Authentication Context Enables Service providers to require a type and strength of initial authentication at IDP Metadata Supports automated configuration data import and discovery for Identity and Service providers Profiles Combinations of assertions, protocols and bindings to support a specific use case Bindings Mappings of the SAML Protocol messages onto standard messaging and communication protocols Protocols Requests and Responses for obtaining assertions and managing user identifiers Assertions Authentication, Attribute and entitlement information WS Security deliverables for federation with Web services WSS SAML Token Profile Place a SAML 2.0 Assertion in a SOAP Envelope SAP AG All rights reserved. / Page 25 WS Policy Declare and propagate requirement for a SAML 2.0 Assertion in a SOAP Envelope WS Trust defines mechanisms to negotiate keys and issue, cancel, renew and amend security tokens
26 Lite Protocol Interoperability Matrix from Liberty SAP AG All rights reserved. / Page 26 Feature IDP IDP-Lite SP SP-Lite Web SSO, <AuthnRequest>, HTTP redirect MUST MUST MUST MUST Web SSO, <Response>, HTTP POST MUST MUST MUST MUST Web SSO, <Response>, HTTP POST MUST MUST MUST MUST Artifact Resolution, SOAP MUST MUST MUST MUST Enhanced Client/Proxy SSO, PAOS MUST MUST MUST MUST Name Identifier Management, HTTP redirect (IDP-initiated) Name Identifier Management, SOAP (IDP-initiated) MUST MUST NOT MUST MUST NOT MUST MUST NOT OPTIONAL MUST NOT Name Identifier Management, HTTP redirect MUST MUST NOT MUST MUST NOT Name Identifier Management, SOAP (SP-initiated) MUST MUST NOT OPTIONAL MUST NOT Single Logout (IDP-initiated), HTTP redirect MUST MUST MUST MUST Single Logout (IDP-initiated), SOAP MUST OPTIONAL MUST OPTIONAL Single Logout (SP-initiated), HTTP redirect MUST MUST MUST MUST Single Logout (SP-initiated), SOAP MUST OPTIONAL MUST OPTIONAL Identity Provider Discovery (cookie) MUST MUST OPTIONAL OPTIONAL
27 Thank You! SAP AG All rights reserved. / Page 27
28 Further Information SAP Public Web: SAP Developer Network (SDN): Business Process Expert (BPX) Community: Related SAP Education and Certification Opportunities SAP AG All rights reserved. / Page 28
29 Copyright 2009 SAP AG All Rights Reserved No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP AG. The information contained herein may be changed without prior notice. Some software products marketed by SAP AG and its distributors contain proprietary software components of other software vendors. Microsoft, Windows, Excel, Outlook, and PowerPoint are registered trademarks of Microsoft Corporation. IBM, DB2, DB2 Universal Database, System i, System i5, System p, System p5, System x, System z, System z10, System z9, z10, z9, iseries, pseries, xseries, zseries, eserver, z/vm, z/os, i5/os, S/390, OS/390, OS/400, AS/400, S/390 Parallel Enterprise Server, PowerVM, Power Architecture, POWER6+, POWER6, POWER5+, POWER5, POWER, OpenPower, PowerPC, BatchPipes, BladeCenter, System Storage, GPFS, HACMP, RETAIN, DB2 Connect, RACF, Redbooks, OS/2, Parallel Sysplex, MVS/ESA, AIX, Intelligent Miner, WebSphere, Netfinity, Tivoli and Informix are trademarks or registered trademarks of IBM Corporation. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries. Adobe, the Adobe logo, Acrobat, PostScript, and Reader are either trademarks or registered trademarks of Adobe Systems Incorporated in the United States and/or other countries. Oracle is a registered trademark of Oracle Corporation. UNIX, X/Open, OSF/1, and Motif are registered trademarks of the Open Group. Citrix, ICA, Program Neighborhood, MetaFrame, WinFrame, VideoFrame, and MultiWin are trademarks or registered trademarks of Citrix Systems, Inc. HTML, XML, XHTML and W3C are trademarks or registered trademarks of W3C, World Wide Web Consortium, Massachusetts Institute of Technology. Java is a registered trademark of Sun Microsystems, Inc. JavaScript is a registered trademark of Sun Microsystems, Inc., used under license for technology invented and implemented by Netscape. SAP, R/3, SAP NetWeaver, Duet, PartnerEdge, ByDesign, SAP Business ByDesign, and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP AG in Germany and other countries. Business Objects and the Business Objects logo, BusinessObjects, Crystal Reports, Crystal Decisions, Web Intelligence, Xcelsius, and other Business Objects products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of Business Objects S.A. in the United States and in other countries. Business Objects is an SAP company. All other product and service names mentioned are the trademarks of their respective companies. Data contained in this document serves informational purposes only. National product specifications may vary. These materials are subject to change without notice. These materials are provided by SAP AG and its affiliated companies ("SAP Group") for informational purposes only, without representation or warranty of any kind, and SAP Group shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP Group products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warrant. SAP AG All rights reserved. / Page 29
SAP Master Data Governance- Hiding fields in the change request User Interface
SAP Master Data Governance- Hiding fields in the change request User Interface Applies to: ERP 6 Ehp 5 SAP Master Data Governance. For more information, visit the Master Data Management homepage. Summary
Compliant, Business-Driven Identity Management using. SAP NetWeaver Identity Management and SBOP Access Control. February 2010
Compliant, Business-Driven Identity Management using SAP NetWeaver Identity Management and SBOP Access Control February 2010 Disclaimer This presentation outlines our general product direction and should
Integrating Easy Document Management System in SAP DMS
Integrating Easy Document Management System in SAP DMS Applies to: SAP Easy Document Management System Version 6.0 SP12. For more information, visit the Product Lifecycle Management homepage. Summary This
Single Sign-On between SAP Portal and SuccessFactors
Single Sign-On between SAP Portal and SuccessFactors Dimitar Mihaylov 7/1/2012 Contents 1. Overview... 3 2. Trust between SAP Portal 7.3 and SuccessFactors... 5 2.1. Initial configuration in SAP Portal
Alert Notification in SAP Supply Network Collaboration. SNC Extension Guide
Alert Notification in SAP Supply Network Collaboration SNC Extension Guide Version: 1.2 Date 08.02.2010 1 The SNC Extension Guide is a collection of tips and tricks on how to extend SAP Supply Network
Maintaining Different Addresses and Email Ids for a Business Partner via CRM Web UI
Maintaining Different Addresses and Email Ids for a Business Partner via CRM Web UI Applies to: CRM 7.0 SP09. For more information, visit the Customer Relationship Management homepage. Summary This article
TM111. ERP Integration for Order Management (Shipper Specific) COURSE OUTLINE. Course Version: 15 Course Duration: 2 Day(s)
TM111 ERP Integration for Order Management (Shipper Specific). COURSE OUTLINE Course Version: 15 Course Duration: 2 Day(s) SAP Copyrights and Trademarks 2014 SAP SE. All rights reserved. No part of this
Business One in Action - How can we post bank fees and charges while posting Incoming or Outgoing Payment transactions?
Business One in Action - How can we post bank fees and charges while posting Incoming or Outgoing Payment transactions? Applies to: SAP Business One, Accounting, Banking and Reconciliation Summary: This
Enterprise Software - Applications, Technologies and Programming
Enterprise Software - Applications, Technologies and Programming Dr. Uwe Kubach, Dr. Gregor Hackenbroich, Dr. Ralf Ackermann SAP Research 2010 SAP AG. All rights reserved. / Page 1 Abstract This lecture
Data Archiving in CRM: a Brief Overview
Data Archiving in CRM: a Brief Overview Applies to: Developing Archiving Solutions in SAP CRM technology. For more information, visit the Customer Relationship Management homepage. Summary This document
NetWeaver Business Client (NWBC) for Incentives and Commissions Management (ICM)
NetWeaver Business Client (NWBC) for Incentives and Commissions Management (ICM) Applies to: Enhancement Pack 5 (Ehp5), EA-APPL, Incentives and Commissions Management (FS-ICM). Summary This article discusses
R/3 and J2EE Setup for Digital Signature on Form 16 in HR Systems
R/3 and J2EE Setup for Digital Signature on Form 16 in HR Systems Agenda 1. R/3 - Setup 1.1. Transaction code STRUST 1.2. Transaction code SM59 2. J2EE - Setup 2.1. Key Storage 2.2. Security Provider 2.3.
Sending Additional Files from SAP Netweaver PI to third Party System
Sending Additional Files from SAP Netweaver PI to third Party System Applies to: SAP Netweaver PI. Summary The document describes about a scenario where the requirement is to send multiple files from one
Budget Control by Cost Center
SAP Business One Budget Control by Cost Center Ecosystem & Channels Readiness July 2011 Allows a precise follow up of costs booked using the cost accounting dimensions functionality as introduced in SAP
Process Archiving using NetWeaver Business Process Management
Process Archiving using NetWeaver Business Process Management Applies to: NetWeaver Composition Environment 7.2, 7.3. For more information, visit the Business Process Modeling homepage. Summary This document
UI Framework Logo exchange without skin copy. SAP Enhancement Package 1 for SAP CRM 7.0
UI Framework Logo exchange without skin copy SAP Enhancement Package 1 for SAP CRM 7.0 1 Objectives At the end of this unit, you will be able to: Change the logo within CRM 7.0 WebClient UI Add a logo
Table of Contents. How to Find Database Index usage per ABAP Report and Creating an Index
How to Find Database Index usage per ABAP Report and Creating an Index Applies to: SAP NETWEAVER WEB AS ABAP. For more information, visit the ABAP homepage Summary The aim of this article is to show how
Understanding HR Schema and PCR with an Example
Understanding HR Schema and PCR with an Example Applies to: SAP ECC 6.0 version, SAP HCM module. For more information, visit the Enterprise Resource Planning homepage. Summary This document will provide
SAPFIN. Overview of SAP ERP Financials COURSE OUTLINE. Course Version: 15 Course Duration: 2 Day(s)
SAPFIN Overview of SAP ERP Financials. COURSE OUTLINE Course Version: 15 Course Duration: 2 Day(s) SAP Copyrights and Trademarks 2014 SAP AG. All rights reserved. No part of this publication may be reproduced
Data Source Enhancement Using User Exit
Data Source Enhancement Using User Exit Applies to: Any SAP system from which data needs to be pulled into SAP BI system. Summary This document describes how to enhance a data source in the source system
How to Configure Access Control for Exchange using PowerShell Cmdlets A Step-by-Step guide
SAP How-to Guide Mobile Device Management SAP Afaria How to Configure Access Control for Exchange using PowerShell Cmdlets A Step-by-Step guide Applicable Releases: SAP Afaria 7 SP3 HotFix 06, SAP Afaria
How to Create a Support Message in SAP Service Marketplace
How to Create a Support Message in SAP Service Marketplace Summary This document explains how to create a message (incident) on the SAP Service Marketplace. It is assumed that the customer has never logged
UI Framework Simple Search in CRM WebClient based on NetWeaver Enterprise Search (ABAP) SAP Enhancement Package 1 for SAP CRM 7.0
UI Framework Simple Search in CRM WebClient based on NetWeaver Enterprise Search (ABAP) SAP Enhancement Package 1 for SAP CRM 7.0 1 Objectives At the end of this unit, you will be able to: Use the new
User Experience in Custom Apps
User Experience in Custom Apps p o w e r e d b y t h e S A P M o b i l e P l a t f o r m S e a n L o n g U X A r c h i t e c t M a n u e l S a e z - D i r e c t o r M o b i l e I n n o v a t i o n C e
HR400 SAP ERP HCM Payroll Configuration
HR400 SAP ERP HCM Payroll Configuration. COURSE OUTLINE Course Version: 15 Course Duration: 5 Day(s) SAP Copyrights and Trademarks 2014 SAP AG. All rights reserved. No part of this publication may be reproduced
Log Analysis Tool for SAP NetWeaver AS Java
Log Analysis Tool for SAP NetWeaver AS Java Applies to: SAP NetWeaver 6.40, 7.0x, 7.1x, 7.20 and higher Summary Log Analysis is an SAP tool for analyzing list formatted logs and traces in Application Server
Integration of SAP Netweaver User Management with LDAP
Integration of SAP Netweaver User Management with LDAP Applies to: SAP Netweaver 7.0/7.1 Microsoft Active Directory 2003 Summary The document describes the detailed steps of configuring the integration
Third Party Digital Asset Management Integration
Third Party Digital Asset Management Integration Objectives At the end of this unit, you will be able to: Assign Digital Assets to CRM Objects Work with the Where-Used List Describe the necessary customizing
Business Requirements... 3 Analytics... 3 Typical Use Cases... 8 Related Content... 9 Copyright... 10
SAP BW Data Mining Analytics: Process Reporting Applies to: SAP BW Data Mining. For more information, visit the Analytics homepage. Summary SAP BW Data Mining serves as a process design platform for a
K in Identify the differences between the universe design tool and the information design tool
K in Identify the differences between the universe design tool and the information design tool The information design tool is a new modeling tool for the semantic layer that enables you to manipulate metadata
How to Add an Attribute to a Case, Record and a Document in NW Folder Management (ex-records Management)
How to Add an Attribute to a Case, Record and a Document in NW Folder Management (ex-records Management) Applies to: SAP Folder Management 2.4 & 3.0. For more information, visit the Enterprise Performance
Consume an External Web Service in a Nutshell with good old ABAP
Consume an External Web Service in a Nutshell with good old ABAP Applies to: SAP_BASIS, Release 701, SP Level 8 Summary Have you ever tried to consume an external web service out of ABAP? This document
USDL XG WP3 SAP use case. Kay Kadner
XG WP3 SAP use case Kay Kadner Customer Marketplace Company B Runtime Company D Innovation & Community Community Company A Repository Company C Repository Provider Provider 2 Integrated Demonstrator -
Xcelsius Dashboards on SAP NetWaver BW Implementation Best Practices
Xcelsius Dashboards on SAP NetWaver BW Implementation Best Practices Patrice Le Bihan, SAP Intelligence Platform & NetWeaver RIG, Americas Dr. Gerd Schöffl, SAP Intelligence Platform & NetWeaver RIG, EMEA
Variable Exit in Sap BI 7.0 - How to Start
Variable Exit in Sap BI 7.0 - How to Start Applies to: This article is applicable to SAP BI 7.0. For more information, visit the Business Intelligence homepage. Summary This document provides an introduction
SAP NetWeaver BRM 7.3
SAP NetWeaver BRM 7.3 New Features Overview Arti Gopalan Solution Specialist SAP NetWeaver BRM NetWeaver Orchestration SAP Labs India Agenda Technical Components of NW BRM Rules Composer Rules Manager
ERP Quotation and Sales Order in CRM WebClient UI Detailed View. SAP Enhancement Package 1 for SAP CRM 7.0 CRM Sales - SFA
ERP Quotation and Sales Order in CRM WebClient UI Detailed View SAP Enhancement Package 1 for SAP CRM 7.0 CRM Sales - SFA ERP Quote, Order, Quantity Contract in CRM WebClient UI Recognizing that many SAP
SAP Central Process Scheduling (CPS) 8.0 by Redwood
SAP Central Process Scheduling (CPS) 8.0 by Redwood What s new in SAP CPS 8.0? November 2010 Agenda 1. SAP Central Process Scheduling by Redwood Architecture Overview 2. Enhanced User Interface 3. New
Configuring Single Sign-on for SAP HANA
Configuring Single Sign-on for SAP HANA Applies to: SAP BusinessObjects Business Intelligence platform 4.0 Feature Pack 3. For more information, visit the Business Objects homepage. Summary This document
SAP Portfolio and Project Management
SAP Portfolio and Project New Features and Functions in 5.0 Suite Solution, SAP AG November 2010 Legal Disclaimer This presentation outlines our general product direction and should not be relied on in
Intelligent Business Operations Chapter 1: Overview & Strategy
Intelligent Business Operations Chapter 1: Overview & Strategy Legal Disclaimer The information in this presentation is confidential and proprietary to SAP and may not be disclosed without the permission
Sample Universe on Microsoft OLAP Cube
Sample Universe on Microsoft OLAP Cube Applies to: SAP BusinessObjects XI4, the information design tool and Microsoft Analysis Services 2005 & 2008. For more information, visit the Business Objects homepage.
AC200. Basics of Customizing for Financial Accounting: General Ledger, Accounts Receivable, Accounts Payable COURSE OUTLINE
AC200 Basics of Customizing for Financial Accounting: General Ledger, Accounts Receivable, Accounts Payable. COURSE OUTLINE Course Version: 15 Course Duration: 5 Day(s) SAP Copyrights and Trademarks 2015
Integration of Universal Worklist into Microsoft Office SharePoint
Integration of Universal Worklist into Microsoft Office SharePoint Applies to: SAP NetWeaver Portal 7.01 SP3 Microsoft Office SharePoint 2007 For more information, visit the Portal and Collaboration homepage.
Application Lifecycle Management
Application Lifecycle Management Best Practice Process Document ALM Process: ITSM - Incident Management Application Lifecycle Management Process ITSM Incident Management Problem Description: How to create,
Duet Enterprise Add SAP ERP Reports and SAP BI Queries/Workbooks to Duet Enterprise Configuration
Duet Enterprise Add SAP ERP Reports and SAP BI Queries/Workbooks to Duet Enterprise Configuration Applies to: Duet Enterprise 1.0, Feature Pack 1 for Duet Enterprise Summary This paper gives an overview
SAP Cloud Strategy - Timeless Software. Frank Stienhans on behalf of Kaj van de Loo SAP
SAP Strategy - Timeless Software Frank Stienhans on behalf of Kaj van de Loo SAP Decades-Long Relationships With the World s Largest Enterprises Trading Industries Consumer Industries Financial Process
Business Process Change Analyzer in SAP Solution Manager 7.1
Business Process Change Analyzer in SAP Solution Manager 7.1 Applies to: SAP Solution Manager 7.1 SP5 Summary Business Process change Analyzer is an application within SAP Solution Manager which helps
Download and Install Crystal Reports for Eclipse via the Eclipse Software Update Manager
Download and Install Crystal Reports for Eclipse via the Eclipse Software Update Manager Applies to: Crystal Reports for Eclipse version 2 Summary This document provides a step-by-step guide on how to
SAP Business ByDesign Reference Systems. Scenario Outline. SAP ERP Integration Scenarios
SAP Business ByDesign Reference Systems Scenario Outline SAP ERP Integration Scenarios Content Scenario Overview Business Scenarios in a Reference System Introduction Typical Usage Process Illustration
OData in a Nutshell. August 2011 INTERNAL
OData in a Nutshell August 2011 INTERNAL Objectives At the end of this module, you will be able to: Understand the OData Standard and how it works. Understand how OData uses the Atom Protocol. Understand
Portfolio and Project Management 5.0: Excel Integration for Financial and Capacity Planning
Portfolio and Project Management 5.0: Excel Integration for Financial and Capacity Planning Applies to: Portfolio and Project Management 5.0 Summary Financial and Capacity planning for item, initiative
Matthias Steiner SAP. SAP HANA Cloud Platform A guided tour
Matthias Steiner SAP SAP HANA Cloud Platform A guided tour SAP HANA Cloud Platform A guided tour Matthias Steiner April, 2011 Overview Platform Capabilities Portal Mobile Collaboration Integration Analytics
UI Framework Task Based User Interface. SAP Enhancement Package 1 for SAP CRM 7.0
UI Framework Task Based User Interface SAP Enhancement Package 1 for SAP CRM 7.0 1 Agenda 1. Overview 2. Task Based User Interface 3. Further Information SAP 2009 / Page 2 2 Objectives of the Presentation
BW Workspaces Use Cases
BW Workspaces Use Cases Applies to SAP NetWeaver Business Warehouse 7.30 (BW7.30) SP05 and SAP NetWeaver Business Warehouse Accelerator 7.20 (BWA7.20)/HANA 1.0 running as a database for SAP NetWeaver BW
LO Extraction Part 1: SD Application Short Overview
LO Extraction Part 1: SD Application Short Overview Applies to: SAP BI, NW2004s Business Intelligence, ABAP, BI. For more information, visit the EDW homepage. Summary This article explains about LO extraction
Unified Service Description Language Enabling the Internet of Services
Unified Service Description Language Enabling the Internet of Services Dr. Kay Kadner, SAP AG, SAP Research, Chair USDL XG [email protected], 2011-05-16 Growth due to increasing service orientation Source:
How To Use the BPC Mass User Management Tool in BPC 10.0 NW
How To Use the BPC Mass User Management Tool in BPC 10.0 NW Applies to: SAP BusinessObjects Planning & Consolidation 10.0, version for SAP NetWeaver. For more information, visit the Enterprise Performance
SAP Sustainability Solutions: Achieving Customer Strategies
SAP Sustainability Solutions: Achieving Customer Strategies BALAMURUGAN KALIA Vice President, Strategic Business Development SAP SEE YOUR WAY CLEAR Strategies for Success in the New Reality Pop Quiz? SAP
Accounts Receivable. SAP Best Practices
Accounts Receivable SAP Best Practices Purpose, Benefits, and Key Steps Purpose This scenario deals with posting accounting data for customers in Accounts Receivable. Benefits The Accounts Receivable is
How-to-Guide: Middleware Settings for Download of IPC Configuration (KB) Data from R/3 to CRM System
How-to-Guide: Middleware Settings for Download of IPC Configuration (KB) Data from R/3 to CRM System Applies to: The IPC (Internet Pricing and Configurator). For more information, visit the Customer Relationship
Using User Exit for Variables in BEx Reporting
Using User Exit for Variables in BEx Reporting Applies to: SAP BI system & BEx. For more information, visit the Business Intelligence homepage. Summary To describe the process followed to use a user exit
Secure MobiLink Synchronization using Microsoft IIS and the MobiLink Redirector
Secure MobiLink Synchronization using Microsoft IIS and the MobiLink Redirector A whitepaper from ianywhere Author: Joshua Savill, Product Manager This whitepaper was written in the context of SQL Anywhere
SAP DSM/BRFPlus System Architecture Considerations
SAP DSM/BRFPlus System Architecture Considerations Applies to: SAP DSM and BRFPlus all releases. For more information, visit the SAP NetWeaver Decision Service Management Summary This document throws some
SAP Service Tools for Performance Analysis
SAP Service Tools for Performance Analysis Kerstin Knebusch Active Global Support Month 05, 2013 Public Performance Analysis Wait event based Focus on statements causing high load and / or high wait time
GRC 10.0 Pre-Installation
GRC 10.0 Pre-Installation Customer Solution Adoption April 4 th 2011 Version 1.1 Purpose of this document To give readers an initial understanding of the GRC 10.0 technical requirements, architecture and
Mass Maintenance of Procurement Data in SAP
Mass Maintenance of Procurement Data in SAP Applies to: SAP ECC 5.0 & SAP ECC 6.0. For more information, visit the Enterprise Resource Planning homepage. Summary: This document helps the P2P consultants
Finding the Leak Access Logging for Sensitive Data. SAP Product Management Security
Finding the Leak Access Logging for Sensitive Data SAP Product Management Security Disclaimer This document does not constitute a legally binding proposal, offer, quotation or bid on the part of SAP. SAP
Sales Planning Detailed View. SAP Enhancement Package 1 for SAP CRM 7.0 CRM Sales - SFA
Sales Planning Detailed View SAP Enhancement Package 1 for SAP CRM 7.0 CRM Sales - SFA Table of Contents 1. Overview of Sales Planning 2. Key Features of Sales Planning 3. Architecture 4. Further Information
Ariba Network Integration to SAP ECC
Ariba Network Integration to SAP ECC Mark Willner Principal Technical Solutions Consultant Ariba an SAP Company» October 2014 ERP Materials Management Core Integration Scenario Ariba Collaborative Commerce,
How to Set Up an Authorization for a Business Partner in Customer Relationship Management (CRM) Internet Sales: Sample Case
How to Set Up an Authorization for a Business Partner in Customer Relationship Management (CRM) Internet Sales: Sample Case Applies to: SAP CRM 4.0 Internet Sales and beyond Summary You want to set up
How to Schedule Report Execution and Mailing
How To Guide SAP Business One Document Version: 1.0 2012-09-02 Applicable Releases: SAP Business One 8.81 PL10 and higher, SAP Business One 8.82 Typographic Conventions Type Style Example Description Words
Learning Series: SAP NetWeaver Process Orchestration, secure connectivity add-on 1c SFTP Adapter
Learning Series: SAP NetWeaver Process Orchestration, secure connectivity add-on 1c SFTP Adapter Applies to: SAP NetWeaver Process Orchestration, Secure Connectivity Add-on 1.0 SP0 Summary This article
Using SAP Logon Tickets for Single Sign on to Microsoft based web applications
Collaboration Technology Support Center - Microsoft - Collaboration Brief March 2005 Using SAP Logon Tickets for Single Sign on to Microsoft based web applications André Fischer, Project Manager CTSC,
How To Use the ESR Eclipse Tool with the Enterprise Service Repository
How To Use the ESR Eclipse Tool with the Enterprise Service Repository Applies to: SAP NetWeaver Process Orchestration 7.31 SP2 SAP NetWeaver Process Integration PI 7.31 SP2 Summary With PI 7.31 SP2, an
SOP through Long Term Planning Transfer to LIS/PIS/Capacity. SAP Best Practices
SOP through Long Term Planning Transfer to LIS/PIS/Capacity SAP Best Practices Purpose, Benefits, and Key Steps Purpose Check if the budgeted sales quantities can be produced, assess material requirements
AC 10.0 Centralized Emergency Access
AC 10.0 Centralized Emergency Access Customer Solution Adoption June 2011 Version 2.0 Purpose of this document This document is a detailed guide on the emergency access capability of Access Control 10.0.
RUN BETTER Become a Best-Run Business with Remote Support Platform for SAP Business One
RUN BETTER Become a Best-Run Business with Remote Support Platform for SAP Business One September 2013 Customer External Become a Best-Run Business with Remote Support Platform for SAP Business One Run
Configuring Distribution List in Compliant User Provisioning
Configuring Distribution List in Compliant User Provisioning Applies To: GRC Access Control Suite for 5.3 Summary: Configuration of Distribution List in Compliant User Provisioning will allow a group of
Supplier Master Data Governance
SAP Solution Brief SAP Business Suite SAP Master Data Governance Supplier Master Data Governance for SAP Business Suite Control Data Creation, Quality, and Consistency The SAP Master Data Governance application
Installation Guide Customized Installation of SQL Server 2008 for an SAP System with SQL4SAP.VBS
Installation Guide Customized Installation of SQL Server 2008 for an SAP System with SQL4SAP.VBS Target Audience Technology Consultants System Administrators PUBLIC Document version: 1.00 09/16/2008 Document
LO Extraction Part 2 Database Update Logic
LO Extraction Part 2 Database Update Logic Applies to: SAP BI, NW2004s Business Intelligence, ABAP, BI For more information, visit the EDW homepage. Summary This article explains about LO extraction logic,
Production Subcontracting (External Processing) SAP Best Practices
Production Subcontracting (External ing) SAP Best Practices Purpose, Benefits, and Key Steps Purpose During the Manufacturing process, when a "Planned Order" for Production is converted to a "Production
SAP NetWeaver BPM Tutorial for Beginners: My Name and Age BPM Tutorial
SAP NetWeaver BPM Tutorial for Beginners: My Name and Age BPM Tutorial Applies to: SAP NetWeaver Composition Environment 7.20 SAP Business Process Management/ SAP BPM. Summary SAP BPM-Tutorial for Beginners.
Implementing SSO between the Enterprise Portal and the EPM Add-In
Implementing SSO between the Enterprise Portal and the EPM Add-In Applies to: SAP BusinessObjects Planning and Consolidation 10, version for SAP NetWeaver SP1 and higher EPM Add-In, SP3 and higher. For
Learning Series: SAP NetWeaver Process Orchestration, business to business add-on EDI Separator Adapter
Learning Series: SAP NetWeaver Process Orchestration, business to business add-on EDI Separator Adapter Applies to: SAP NetWeaver Process Orchestration, business to business add-on 1.0 SP00 Summary This
How To Improve Your Business Process With Sap
Business Process Analytics & Improvement SAP Solution Manager 7.1 SAP AG August, 2011 Disclaimer This presentation outlines our general product direction and should not be relied on in making a purchase
How To Configure MDM to Work with Oracle ASM-Based Products
SAP NetWeaver How-To Guide How To Configure MDM to Work with Oracle ASM-Based Products Applicable Releases: MDM 7.1 SP10 and later Version 1.0 June 2013 Copyright 2013 SAP AG. All rights reserved. No part
Next Generation Digital Banking with SAP
Next Generation Digital Banking with SAP Thorsten Weinrich, Director Business Development, Banking, SAP EMEA October, 2014 Use this title slide only with an image Legal Disclaimer The information in this
SAP How-To Guide: Develop a Custom Master Data Object in SAP MDG (Master Data Governance)
SAP How-To Guide: Develop a Custom Master Data Object in SAP MDG (Master Data Governance) Applies to: SAP Master Data Governance running on SAP ERP 6 EhP 6 Master Data Governance. The Guide can also be
Project Governance The Role Of The Business Process Owner
Project Governance The Role Of The Business Process Owner Applies to: The Role of the Business Process Owner in Project Governance. For more information, visit the Organizational Change Management homepage.
AP 7.00. Integration with BRFplus VERSION V1.00 22 APRIL 2011 - SAP AG
AP 7.00 Integration with BRFplus VERSION V1.00 22 APRIL 2011 - SAP AG Table of Contents 1. Introduction... 3 1.1 Time based prices... 3 1.2 Usage of BRFplus... 3 1.3 About this document... 3 1.4 Target
Query, Read, Create and Update CLOUD FOR CUSTOMER ODATA SERVICE QUERY, READ, CREATE AND UPDATE
ODATA SERVICE Query, Read, Create and Update CLOUD FOR CUSTOMER ODATA SERVICE QUERY, READ, CREATE AND UPDATE Version Date Completed Author Description/Comment 1.0 12-06-2014 Raghavendra Jadi, Unnati Hasija,
Performance Best Practices Guide for SAP NetWeaver Portal 7.3
SAP NetWeaver Best Practices Guide Performance Best Practices Guide for SAP NetWeaver Portal 7.3 Applicable Releases: SAP NetWeaver 7.3 Document Version 1.0 June 2012 Copyright 2012 SAP AG. All rights
Developing Applications for Integration between PI and SAP ERP in Different Network Domains or Landscapes
Developing Applications for Integration between PI and SAP ERP in Different Network Domains or Landscapes Applies to: SAP NetWeaver Process Integration 7.1+ SAP NetWeaver 7.02 (ABAP) Summary This document
BW362. SAP BW powered by SAP HANA COURSE OUTLINE. Course Version: 10 Course Duration: 5 Day(s)
BW362 SAP BW powered by SAP HANA. COURSE OUTLINE Course Version: 10 Course Duration: 5 Day(s) SAP Copyrights and Trademarks 2015 SAP SE. All rights reserved. No part of this publication may be reproduced
Supporting SAP POS Best Practices Setting Log File Sizes and Retention
Supporting SAP POS Best Practices Setting Log File Sizes and Retention Summary: This paper will serve as a primer in order to familiarize users of SAP POS with the log configuration and location of SAP
Microsoft Excel 2007 & SAP Business Explorer Compatibility
Microsoft Excel 2007 & SAP Business Explorer Compatibility Update on Latest Developments Marc Bernard SAP Intelligence Platform and NetWeaver RIG May 2010 Disclaimer The information in this presentation
