App Provisioning Sap
Updated> - Keep user attributes synchronized between Microsoft Entra ID and SAP ECC.
Daily.Entra.NewsThis was a documentation-led day: all 11 supplied changes were Microsoft Learn updates, with no new or removed items and no Message Center announcement. The strongest administrator-relevant edits clarify existing Identity Protection, reporting, provisioning, and hardware-attestation guidance. The supplied record does not identify a new feature, preview, general-availability transition, retirement, or changed product behavior.
The updated Identity Protection Policies article focuses on identifying risk-based Conditional Access policies. This is security guidance and documentation clarification; the supplied record does not say that Conditional Access behavior, availability, or enforcement changed.
The updated guidance documents two recovery paths: an SSPR password update, or a secure password change involving MFA and password change. It also describes subsequent updates to the risk state and details for users, sign-ins, and related risk detections. This supports runbook review but is not evidence of a new remediation capability.
The Reports Data Retention update states that log storage varies by report type and license, and documents routing audit and sign-in activity through Azure Monitor to an Azure storage account to retain it beyond the default period. This is retention and configuration guidance, not a stated change to default retention.
The updated configuration guide covers provisioning users from Microsoft Entra ID into SAP ECC with NetWeaver 7.0 or later and points users of other SAP R/3 versions to Connector for MIM 2016 guides as a reference for building a provisioning template. It refreshes integration guidance; it does not announce a new connector or support expansion.
The Microsoft Entra ID attestation page was updated to explain requirements for preparing FIDO2 hardware for attestation. The supplied summary identifies no new requirement, availability state, or enforcement change, so this is security and vendor documentation rather than a product launch.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
> - Keep user attributes synchronized between Microsoft Entra ID and SAP ECC.
The following documentation provides configuration and tutorial information demonstrating how to provision users from Microsoft Entra ID into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver 7.0 or later. If you're using other versions of SAP R/3, you can still use the guides provided in the [Connectors for Microsoft Identity Manager 2016](https://www.microsoft.com/download/details.aspx?id=51495) download as a reference to build your own template for provisioning.
The Microsoft Entra provisioning agent and generic web services connector provides connectivity to on-premises SAP ECC SOAP endpoints, including SAP BAPIs.
Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
Log storage within Microsoft Entra varies by report type and license type. You can retain the audit and sign-in activity data for longer than the default retention period outlined in the previous table by routing it to an Azure storage account using Azure Monitor. For more information, see [Archive Microsoft Entra logs to an Azure storage account](./howto-archive-logs-to-storage-account.md).
1. Select the **Resource** link to go directly to the app registration for the app.
Learn how to investigate risky users, detections, and sign-ins in Microsoft Entra ID Protection.
If a user is prompted to use self-service password reset (SSPR) to remediate user risk, they are prompted to update their password as shown in the [Microsoft Entra ID Protection user experience](concept-identity-protection-user-experience.md) article. Once they update their password, the user risk is remediated. A secure password change (MFA and password change) can also remediate user risk. The user can then proceed to sign in with their new password. The risk state and risk details for the user, sign-ins, and corresponding risk detections are updated as follows:
Identifying risk-based Conditional Access policies
author: shlipsey3
Once you have users in Microsoft Entra ID, you can provision those users from Microsoft Entra ID to SAP Cloud Identity Services or SAP ECC, to enable them to sign in to SAP applications. If you have [`SAP S/4HANA On-Premise`](https://help.sap.com/docs/identity-provisioning/identity-provisioning/target-sap-s-4hana-on-premise), then provision users from Microsoft Entra ID to SAP Cloud Identity Directory. SAP Cloud Identity Services then provisions the users originating from Microsoft Entra ID that are in the SAP Cloud Identity Directory into the downstream SAP applications to SAP S/4HANA On-Premise through the SAP cloud connector.