Skip to content

Commit 4c21fa4

Browse files
authored
Merge pull request #291804 from batamig/attack-disrupt-remove
removing attack disrupt for SAP
2 parents 4e2914a + 533b8db commit 4c21fa4

11 files changed

+21
-204
lines changed

articles/sap/workloads/integration-get-started.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn about the various integration points in the Microsoft ecosyst
44
ms.service: sap-on-azure
55
ms.subservice: sap-vm-workloads
66
ms.topic: concept-article
7-
ms.date: 12/15/2022
7+
ms.date: 06/22/2025
88
author: MartinPankraz
99
ms.author: mapankra
1010

@@ -234,7 +234,7 @@ Discover partner offerings for SAP security on the [Azure Marketplace](https://a
234234

235235
#### Microsoft Sentinel for SAP
236236

237-
Microsoft Sentinel integrates natively with Microsoft Defender XDR in the Defender portal. See the integration in action with [Automatic attack disruption for SAP](../../sentinel/sap/deployment-attack-disrupt.md).
237+
Microsoft Sentinel integrates directly with Microsoft Defender XDR and the Microsoft Defender portal. SAP solutions are available in the Defender portal as part of [Microsoft's unified security operations platform](/unified-secops-platform/), and with [Microsoft Sentinel in the Defender portal](/azure/sentinel/microsoft-sentinel-defender-portal).
238238

239239
For more information about [SAP certified](https://www.sap.com/dmc/exp/2013_09_adpd/enEN/#/solutions?id=s:33db1376-91ae-4f36-a435-aafa892a88d8) threat monitoring with Microsoft Sentinel for SAP, see the following Microsoft resources:
240240

articles/sap/workloads/rise-integration-security.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@ It can be used with any data source that Defender XDR and Sentinel support, incl
5353
This image shows an example of the Microsoft Security Copilot experience using a prompt to investigate an SAP incident.
5454
:::image-end:::
5555

56-
In addition to that the Security Copilot experience is embedded on the Defender XDR portal. Next to an AI-generated summary, recommendations and remediation like password reset for SAP are provided out-of-the-box. Learn more about automatic SAP attack disruption [here](../../sentinel/sap/deployment-attack-disrupt.md).
56+
In addition to that, the Security Copilot experience is embedded on the Defender XDR portal, with an out-of-the-box AI-generated summary and recommendations for SAP.
5757

5858
:::image type="complex" source="./media/sap-rise-integration/sap-rise-security-copilot-defender-portal.png" alt-text="Screenshot of embedded Security Copilot experience in Defender with SAP RISE/ECS incidents." lightbox="./media/sap-rise-integration/sap-rise-security-copilot-defender-portal.png":::
5959
This image shows an example of Microsoft Security Copilot analyzing an incident detected on SAP RISE through Defender XDR. Data ingestion is done through the Microsoft Sentinel solution for SAP applications.

articles/sentinel/TOC.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -188,8 +188,6 @@
188188
href: sap/reference-systemconfig.md
189189
- name: Enable SAP detections and threat protection
190190
href: sap/deployment-solution-configuration.md
191-
- name: Automatic attack disruption for SAP
192-
href: sap/deployment-attack-disrupt.md
193191
- name: Integrate SAP across multiple workspaces
194192
href: sap/cross-workspace.md
195193
- name: Monitor SAP systems

articles/sentinel/feature-availability.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: bagol
66
ms.topic: feature-availability
77
ms.custom: references_regions
88
ms.service: microsoft-sentinel
9-
ms.date: 11/26/2024
9+
ms.date: 06/22/2025
1010

1111

1212
#Customer intent: As a security operations manager, I want to understand the Microsoft Sentinel's feature availability across different Azure environments so that I can effectively plan and manage our security operations.
@@ -25,8 +25,6 @@ This article describes the features available in Microsoft Sentinel across diffe
2525

2626
Microsoft Sentinel is also available in the [Microsoft Defender portal](microsoft-sentinel-defender-portal.md). In the Defender portal, all features in general availability are available in commercial, GCC, GCC High and DoD clouds. Features still in preview are available only in the commercial cloud.
2727

28-
While [attack disruption in the Defender portal](/defender-xdr/automatic-attack-disruption) is generally available, [SAP support for attack disruption](/defender-xdr/automatic-attack-disruption#automated-response-actions-for-sap-with-microsoft-sentinel) in the Defender portal available only in the commercial cloud.
29-
3028
For more information, see [Microsoft Defender XDR for US Government customers](/defender-xdr/usgov).
3129

3230
## Analytics

articles/sentinel/microsoft-sentinel-defender-portal.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn about the Microsoft Sentinel experience when you onboard Micr
44
author: batamig
55
ms.author: bagol
66
ms.topic: conceptual
7-
ms.date: 05/04/2025
7+
ms.date: 06/22/2025
88
appliesto:
99
- Microsoft Sentinel in the Microsoft Defender portal
1010
ms.collection: usx-security

articles/sentinel/sap/deployment-attack-disrupt.md

Lines changed: 0 additions & 54 deletions
This file was deleted.

articles/sentinel/sap/deployment-solution-configuration.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: This article shows you how to configure initial security content fo
44
author: batamig
55
ms.author: bagol
66
ms.topic: how-to
7-
ms.date: 09/15/2024
7+
ms.date: 12/11/2024
88
appliesto:
99
- Microsoft Sentinel in the Microsoft Defender portal
1010
- Microsoft Sentinel in the Azure portal
@@ -94,6 +94,5 @@ For more information, see:
9494

9595
For more information, see:
9696

97-
- [Automatic attack disruption for SAP (Preview)](deployment-attack-disrupt.md)
9897
- [Monitor the health of your SAP system](../monitor-sap-system-health.md)
9998
- [Update Microsoft Sentinel's SAP data connector agent](update-sap-data-connector.md)

articles/sentinel/sap/preparing-sap.md

Lines changed: 4 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -52,15 +52,13 @@ To allow the SAP data connector to connect to your SAP system, you must create a
5252

5353
:::zone pivot="connection-agent"
5454

55-
- **To include both log retrieval and [attack disruption response actions](https://aka.ms/attack-disrupt-defender)**, we recommend creating this role by loading role authorizations from the [**/MSFTSEN/SENTINEL_RESPONDER**](https://aka.ms/SAP_Sentinel_Responder_Role) file.
55+
We recommend creating this role by deploying the *NPLK900271* SAP change request (CR): [K900271.NPL](https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/SAP/CR/K900271.NPL) | [R900271.NPL](https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/SAP/CR/R900271.NPL)
5656

57-
- **To include log retrieval only**, we recommend creating this role by deploying the *NPLK900271* SAP change request (CR): [K900271.NPL](https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/SAP/CR/K900271.NPL) | [R900271.NPL](https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/SAP/CR/R900271.NPL)
57+
Deploy the CRs on your SAP system as needed just as you'd deploy other CRs. We strongly recommend that deploying SAP CRs is done by an experienced SAP system administrator. For more information, see the [SAP documentation](https://help.sap.com/docs/ABAP_PLATFORM_NEW/4a368c163b08418890a406d413933ba7/e15d9acae75c11d2b451006094b9ea64.html?locale=en-US&version=LATEST).
5858

59-
Deploy the CRs on your SAP system as needed just as you'd deploy other CRs. We strongly recommend that deploying SAP CRs is done by an experienced SAP system administrator. For more information, see the [SAP documentation](https://help.sap.com/docs/ABAP_PLATFORM_NEW/4a368c163b08418890a406d413933ba7/e15d9acae75c11d2b451006094b9ea64.html?locale=en-US&version=LATEST).
60-
61-
Alternately, load the role authorizations from the [**MSFTSEN_SENTINEL_CONNECTOR**](https://aka.ms/SAP_Sentinel_Connector_Role) file, which includes all the basic permissions for the data connector to operate.
59+
Alternately, load the role authorizations from the [**MSFTSEN_SENTINEL_CONNECTOR**](https://aka.ms/SAP_Sentinel_Connector_Role) file, which includes all the basic permissions for the data connector to operate.
6260

63-
Experienced SAP administrators might choose to create the role manually and assign it the appropriate permissions. In such cases, create a role manually with the relevant authorizations required for the logs you want to ingest. For more information, see [Required ABAP authorizations](required-abap-authorizations.md). Examples in our documentation use the **/MSFTSEN/SENTINEL_RESPONDER** name.
61+
Experienced SAP administrators might choose to create the role manually and assign it the appropriate permissions. In such cases, create a role manually with the relevant authorizations required for the logs you want to ingest. For more information, see [Required ABAP authorizations](required-abap-authorizations.md). Examples in our documentation use the **/MSFTSEN/SENTINEL_RESPONDER** name.
6462

6563
When configuring the role, we recommend that you:
6664

articles/sentinel/sap/required-abap-authorizations.md

Lines changed: 5 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Understand the ABAP authorizations required if you want to manually
44
author: batamig
55
ms.author: bagol
66
ms.topic: how-to
7-
ms.date: 09/16/2024
7+
ms.date: 12/11/2024
88
appliesto:
99
- Microsoft Sentinel in the Microsoft Defender portal
1010
- Microsoft Sentinel in the Azure portal
@@ -15,16 +15,12 @@ ms.collection: usx-security
1515

1616
# Required ABAP authorizations
1717

18-
This article lists the ABAP authorizations required to ensure that the SAP user account used by Microsoft Sentinel's SAP data connector can correctly retrieve logs from the SAP systems and [run attack disruption response actions](/defender-xdr/automatic-attack-disruption).
18+
This article lists the ABAP authorizations required to ensure that the SAP user account used by Microsoft Sentinel's SAP data connector can correctly retrieve logs from the SAP systems.
1919

20-
The required authorizations are listed here by their purpose. You only need the authorizations that are listed for the kinds of logs you want to bring into Microsoft Sentinel and the attack disruption response actions you want to apply.
20+
The required authorizations are listed here by their purpose. You only need the authorizations that are listed for the kinds of logs you want to bring into Microsoft Sentinel.
2121

22-
> [!TIP]
23-
> To create a role with all the required authorizations, load the role authorizations from the [**/MSFTSEN/SENTINEL_RESPONDER**](https://aka.ms/SAP_Sentinel_Responder_Role) file.
24-
>
25-
> Alternately, to enable only log retrieval, without attack disruption response actions, deploy the SAP *NPLK900271* CR on the SAP system to create the **/MSFTSEN/SENTINEL_CONNECTOR** role, or load the role authorizations from the [**/MSFTSEN/SENTINEL_CONNECTOR**](https://aka.ms/SAP_Sentinel_Connector_Role) file.
26-
27-
If needed, you can [remove the user role and any optional CR installed on your ABAP system](stop-collection.md#remove-the-user-role-and-any-optional-cr-installed-on-your-abap-system).
22+
- To create a role with all the required authorizations, load the role authorizations from the [**/MSFTSEN/SENTINEL_RESPONDER**](https://aka.ms/SAP_Sentinel_Responder_Role) file.
23+
- If needed, you can [remove the user role and any optional CR installed on your ABAP system](stop-collection.md#remove-the-user-role-and-any-optional-cr-installed-on-your-abap-system).
2824

2925
## ABAP application log
3026

@@ -140,20 +136,6 @@ If needed, you can [remove the user role and any optional CR installed on your A
140136
| S_TABU_NAM | ACTVT | Display |
141137
| S_TABU_NAM | TABLE | T000 |
142138

143-
## Attack disruption response actions
144-
145-
<a name=attack-disrupt></a>
146-
147-
| Authorization object | Field | Value |
148-
| -------------------- | ----- | ----- |
149-
|S_RFC |RFC_TYPE |Function Module |
150-
|S_RFC |RFC_NAME |BAPI_USER_LOCK |
151-
|S_RFC |RFC_NAME |BAPI_USER_UNLOCK |
152-
|S_RFC |RFC_NAME |TH_DELETE_USER <br>In contrast to its name, this function doesn't delete users, but ends the active user session. |
153-
|S_USER_GRP |CLASS |* <br>We recommend replacing S_USER_GRP CLASS with the relevant classes in your organization that represent dialog users. |
154-
|S_USER_GRP |ACTVT |03 |
155-
|S_USER_GRP |ACTVT |05 |
156-
157139
## Configuration history
158140

159141
| Authorization object | Field | Value |

0 commit comments

Comments
 (0)