Security - General SAP Guides
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Security

SAP manages the security in Amazon Web Services account managed by SAP. You can implement additional security mechanisms in your own Amazon Web Services account.

Single Sign-On – SAP Business Technology Platform (BTP) and Amazon IAM Identity Center

In RISE with SAP, you can integrate your own Identity Provided (IdP), such as Amazon IAM, Okta, Ping, Microsoft Windows Azure Active Directory, and others using Identity Authentication of SAP BTP.

The following image shows the integration between Identity Authentication from SAP BTP and Amazon IAM Identity Center.

Integrating SAP BTP IAS and IAM Identity Center

Authentication flow

  1. User accesses SAP Fiori via an Internet browser.

  2. Identity Authentication intercepts and routes request to IAM Identity Center.

  3. Access to SAP S/4HANA in RISE with SAP VPC is enabled on successful authentication.

Use Amazon services to enhance security in RISE with SAP

Integrate RISE with SAP VPC with Amazon VPC in your own Amazon Web Services account that is not managed by SAP at the network layer to implement security mechanisms. For more information, see VPC to VPC connectivity.

The network traffic can be routed through Amazon services that strengthen security and operate on a network layer, coming in and out of the RISE with SAP VPC. For more information, see Infrastructure OU – Network account.

You can use the following Amazon services to enhance RISE with SAP security.

The following image shows RISE with SAP security enhancement with Amazon services.

Traffic flow for RISE with SAP security enhancements.

Traffic flow

  1. User accesses SAP Fiori via an Internet browser.

  2. The traffic is routed through the inbound VPC managed by you. The entire traffic flow is via Amazon Transit Gateway.

  3. The traffic is routed to the firewall VPC managed by you. Based on your company's security policies, the traffic may be filtered by a Network Firewall.

  4. The traffic is now passed to an Amazon EC2 instance running in Amazon Web Services account managed by SAP.

  5. Amazon EC2 instance response is routed back to customer managed firewall VPC.

  6. The response traffic is now passed on to the outbound VPC managed by you.

  7. The response traffic reaches the user.