Skip to content

Commit 6160621

Browse files
committed
Update mde-sap-custom-detection-rules.md
1 parent 8010439 commit 6160621

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

defender-endpoint/mde-sap-custom-detection-rules.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ Make sure to read the following articles before you begin:
3434
- [Create custom detection rules](/defender-xdr/custom-detection-rules)
3535
- [SAP Documentation: Starting External Commands and ProgramsLocate this document in the navigation structure](https://help.sap.com/doc/saphelp_nw73ehp1/7.31.19/en-US/4b/2b2bed365474fee10000000a421937/frameset.htm)
3636

37-
The SAP BASIS Team and the Security team should co-develop the solution. The SAP BASIS team doesn't have access to the Microsoft Defender portal, and the Security team won't know the specifics of the SAP Batch Jobs and External Commands.
37+
The SAP BASIS Team and the Security team should codevelop the solution. The SAP BASIS team doesn't have access to the Microsoft Defender portal, and the Security team doesn't know the specifics of the SAP Batch Jobs and External Commands.
3838

3939
## Recommended implementation sequence
4040

@@ -45,7 +45,7 @@ The SAP BASIS Team and the Security team should co-develop the solution. The SAP
4545
- [Deployment guidance for Microsoft Defender for Endpoint on Linux for SAP](https://aka.ms/mde4sap-linux)
4646
- [Microsoft Defender for Endpoint on Windows Server with SAP](https://aka.ms/mde4sap-windows)
4747

48-
3. The Security team identifies all the SAP servers and runs a query for "InitiatingProcessName" == "sapxpg", noting which servers are starting SAPXPG.
48+
3. The Security team identifies all the SAP servers and runs a query for `"InitiatingProcessName" == "sapxpg"`, noting which servers are starting SAPXPG.
4949

5050
- It is recommended to limit the number of servers running SAPXPG to a minimum and to disallow SAPXPG on most SAP servers.
5151
- The SAP BASIS team and Security team should limit access to the authorization objects and transaction codes for SAPXPG.

0 commit comments

Comments
 (0)