SAP Identity Management reaches end of mainstream maintenance in December 2027, and every IGA vendor is offering a replacement. But most migration guidance misses a critical gap: organizations following SAP's recommended path to Microsoft Entra will still lack proper Active Directory lifecycle management. This leaves identities, entitlements, and compliance exposure unresolved when the clock runs out.
Nitish Deshpande, Senior Analyst at KuppingerCole Analysts, will examine the identity governance transformation that SAP IDM end of life demands, beyond just the platform replacement. He will assess the market landscape, outline what organizations most commonly overlook in migration planning, and discuss how behavioral-driven governance strengthens compliance and reduces entitlement risk across hybrid environments.
Robert Kraczek, Global Strategist at One Identity, will present a practical approach to SAP IDM migration using Identity Manager available on-premises or hosted via Identity Manager On Demand, alongside Active Roles for AD and Entra ID lifecycle management. He will explain why Entra alone does not close the AD governance gap, how Identity Manager's consistent governance model spans SAP and non-SAP systems regardless of deployment model, and what organizations should prioritize to reach the 2027 deadline without sacrificing governance continuity.
Hello, everyone, and welcome to the KuppingerCole webinar, From SAP IDM to Modern IGA. My name is Nitish Deshpande. I'm from KuppingerCole Analysts, and today I'm joined by Robert Kraczek. He's a global strategist from One Identity Global.
Robert, thank you for being here. Maybe you can quickly introduce yourself.
Thanks, Nitish. It's a pleasure to be here. It's always great to present with Kuppinger. I'm Rob Kraczek, my global strategist at One Identity. I cover all our identity security products, and I speak to analysts such as the TESS, as well as our large global customers. So thanks for having me. Perfect.
Thank you, Robert. In this webinar, we will take a look at some of the key considerations, challenges, as well as several, you can say, success factors that are responsible for this migration, and then Robert will come in and give also their efforts, one idea's approach on how to tackle this problem. So before we begin, quickly some housekeeping rules. You all are centrally muted, so you don't need to mute or unmute yourself. We are controlling these features.
As always, we like to keep these webinars interactive, so we will be running a couple of polls during this webinar. So I would like to encourage all our attendees to take part in this poll and provide your feedback, and I look forward to discussing the results during the final Q&A session. So for the Q&A session, you can enter your questions at any time using the Livestream control panel. And finally, we are recording this webinar, so the recording and the slide deck will be made available for download in the coming days on our website. Here's a quick look at the agenda for today's webinar.
So we would like to maybe touch base on what are the key success factors, challenges, considerations from a migration point of view, and finally then Robert will take over to provide their perspective on migrating from SAP IDM to modern IGA, and finally the Q&A session. And I would like to start today's webinar immediately with the first poll question, and that is, where is your organization in its SAP IDM transition journey?
Is it one, not yet started? Is it two, you're evaluating options? Is it three, tools choice complete and you're preparing to migrate? Or is it four, that you are actively migrating? You can enter your options in the polls tab in the control panel, and I look forward to discussing the results towards the end of the session.
Okay, so the timeline and the migration. Now we know about 2030, it feels far away, it's around three and a half years to be honest, but it really isn't. And when you look at all the different components that are part of this migration, when you look at that, you realize that it's, there isn't enough time really. So if you want to modernize your IAM or move away from your SAP IDM in a more controlled manner, in a low risk way, then you have to start early. So the first phase is about planning and strategy.
Now, ideally, you should have already started with the strategy at the start of 2026 or maybe in 2025, and this is about choosing your next tool. So it's about your defining your overall IAM and IGS strategy. It's about understanding what your future identity requirements will be, what your future identity fabric should look like, and also aligning your application access governance approach, SAP and non-SAP as well into one single frame. The next step in this migration is the planning phase. So in the next step, you need to move into a more detailed planning phase.
That means creating a blueprint and a roadmap. You need to define the architecture, you need to create a strong list of requirements specifications that includes not just your current needs, but also your future needs. And once you have done these three steps, then you can then move ahead towards the part of tools choice. And that tools choice includes then comparisons, POCs, and more structured decision process that involves all the right stakeholders that should be part of this process. So once you have finalized on your tools choice, then the implementation can begin.
And implementation is basically building the new environment, it's migrating in stages, and then it also involves testing, improvising, optimizing as you go along this process. And finally, before 2030 ideally, or by 2030 onwards, you need to focus on just evolving the business. So it's not just a project, it's a process, it's a program. So you cannot say it's finished by 2030, you need to keep on evolving the business. So I guess the important thing here is that doing all of these elements in this timeline is a lot. So it needs to be done correctly, it needs to be started as soon as possible.
And ideally, not rush towards the end, which can then create several mistakes, and can be costly as well. For example, if you go for the wrong tools choice, and then you have to go back again to the planning phase, and then again, that can delay the process. So I guess the message is to start early and do the right things at the right time.
There are some also key factors that you can look at when you're doing a successful delivery of an IAM project, and that includes doing delivery on time, at budget, in quality, it should be complete and distinct, should be user friendly, and also it should address future needs. So when we look at the overall key success factors, the main point is having a strong IAM program from the beginning.
And to get there, what we need is four elements, we need solid requirements analysis, we need continuous updates, and also make sure that all these analyses are not done just based on what you have right now, but also on the future trends, such as expected future regulatory changes, evolving business expectations as well. So that's why it's a clear vision, clear blueprint of where you are right now, and where you're going, and the proper program and project planning is essential.
Planning, budgeting, and stakeholder management also a very important role here. The people, the process, and the policies are equally important. So you need to rethink your organizational models. So just not structuring your teams around tools like the SAP department, but also business processes and outcomes. And many businesses and many organizations are still relying on processes or policies that are designed 10 years ago or 15 years ago, and no one has to question them because why fix something when it's not broken, but you need to understand how they were done.
And only after that you can then move on to the strategy, planning, requirements, people, and the process. The process then we move on to the implementation phase. So I guess if you do the groundwork here properly, then the implementation becomes much more manageable, and then that can also lead to a successful delivery of the IAM project. A few things maybe is that is also the tooling side I mentioned. I forgot to mention here is the you can do portfolio fit cap analysis for that. You want to define your target operating model.
So overall, these four elements can then make sure that you have successful delivery of the project. But there are some challenges, and these challenges can range from a wide wide parameters. So for example, you are aiming for one-step migration, you are attempting to migrate everything all at once. That can be complex, that can be risky as well, and it can create business disruption as well. So that is something which should be avoided.
Abandoning SAP GRC too early can also be a challenge as you are rebuilding your policies and compliance controls from scratch can be costly, may result in let's say a valuable loss. Also premature decommissioning of SAP IADM is a challenge. You have to make sure that you are not retiring your SAP IADM way too early before you have your new platform in place. Unnecessary migration of migration components. This is about failing to identify which components are essential for migration and which are not.
And thus when you identify unnecessary components that can create unnecessary burden and extra efforts and also along with that can be a transfer of technical debt. Finally, it's about ignoring the requirements. So it's ignoring especially SAP specific functional requirements. So assuming the target IAM platform can natively handle SAP authorization models, provisioning logic and risk analysis, this can result in significant functionality gaps. So you need to have some considerations in place and these can be let's say divided in two parts.
One are the technical considerations and the other are the operational considerations. If you take a look at the technical considerations, the first one is about provisioning continuity. It's about maintaining your lifecycle management processes, maintaining your joint removal lever processes across SAP and also non-SAP systems throughout this migration. Next is the governance preservation. It's ensuring the access certifications, SOD rules, controls that have been operational. Target architectural consideration is also another technical consideration.
You need to choose between whether you want a direct replacement sidecar or dual-stack approaches based on how your requirements are, based on the complexity and the risk profile. And finally, the fourth technical consideration is about data model and workflow translation and this is about mapping SAP IDM attributes, entries, types, routes and custom workflows to your target platform, your target let's say IGA platform.
From an operational point of view, all of the considerations should be already done inventory so you need to understand and assess your current configurations, connectors, roles, your current independencies and ID assets before you are doing the migration. Stakeholder alignment is very important. You need to engage all your business application owners, your development teams, IM teams and audit teams early in planning before taking on the migration process.
Parallel operations and cutover planning, that is the fourth one and that means running your legacy and new platforms in parallel with contingency plans and rollback procedures. So you need to have that in place before you do the full decommissioning of the old one. And evidence retention and decommissioning, as I mentioned, is you need to have a system in place where you can preserve your audit records, your archival requirements and documents before you do the final decommissioning. And that leads us to now the final step is around the planning and execution of the replacement.
Over here, there are a few options in front of you. The first one is that you just tag along with SAP IDM where there are no changes, no features will be added. You are taking on several risks here such as there will be continuous deterioration of your status quo compared to competitors. There will be definitely additional costs or patching. There will be increasing cost for maintenance and overall the potential business might slip away because of not having a proper migration plan. And this choice can only lead up until 2030. The other one is the tool selection.
It's about now finding the right tool that fits your requirement. It's consolidating your entire IGA landscape. There are some risks as well here is that if the investment is not correct, if the trial and error is not also done properly, it can lead to several delays as well. And wrong approach can lead to wrong tool choice selection. And that means you have to now go back again to your planning phase, understanding your requirements and then again going through the comparisons, POCs and trying to find the right tool for a solution.
So when done correctly, this timeline can be around 6 to 12 months. And then once you're done, the tool choice is now the migration phases. You want to now automate and optimize the processes and technical topics. You have better support for your governance requirements. Once done correctly, you will have a cleanup of databases. You will have uncontrolled growth and technical depths can be avoided as well. But there are also some risks around when you do the migration is that if not done correctly, then this technical debt can be transferred to the new tool.
Also, the next risk is about project delivery and investment. So it's a big commitment. It's a big project. It's expensive. So you need to do it correctly with the right parameters. Migration phase, when done in phases, can be around 12 to 24 months. I think that takes me to maybe the next question, old question for today's webinar, and that is that what you're trying to do is identify what is the biggest challenge you expect in moving away from SAP IDM? Is it first, migrating identities, roles and workflows? Is it second, maintaining compliance and audit readiness?
Is it third, maintaining active directory and ID lifecycle processes? Or is it fourth, limited internal resources and expertise? So you have the question again in your Livestorm control panel. And I would again encourage all attendees to take part in this poll, and I look forward to seeing the results towards the end of the session.
Next up, I would like to invite Robert in the stage. Robert, if you're here.
Well, thanks, Ditesh. That was all interesting stuff.
Obviously, you know, the timeline hasn't changed. And, you know, people, process and technology is your part and parcel for any advisory services. So what I thought I'd do today, I'm going to keep Ditesh on here and keep him trapped in my now my presentation. And we're going to do a recap of what Ditesh just talked about and why this is important. For those of you, obviously, if you're on this session, you know, there's an issue with SAP IDM migration. And that's changed, even since the last time I was on here doing a webinar with Martin Cuffinger and George Cervone from SAP.
So in 2024, SAP announced the Microsoft Entra partnership, which is to help uplift some use cases into Entra. We saw the December 2027 timeframe, as Ditesh spoke about, where mainstream maintenance ends and NetWeaver is completely shut down by 2030. And that affects even more than SAP IDM. So if we look at that timeframe, what's changed since the last time I presented with what my esteemed colleagues and friends at Cuffinger call. So we have the SAP Microsoft guidance was published. And that was released, I think, at the DSAG in 2024, around what could and couldn't be done with Entra.
But since then, we've, of course, had this huge NHI and AI push. I mean, things have changed in two years, like I haven't seen in this industry in a long time. So now we have a lot of embedded agents that are being introduced into a lot of SAP products.
Of course, they have the autonomous, was the autonomous enterprise announcement that just came out, and they're using Juul, the AI to help affect services. So any old legacy products that you have, like SAP IDM, are definitely not going to be uplifted to that environment. So you have that now to worry about and be concerned. CleanCore is a new thing that came out, I think, in 2025. You correct me if I'm wrong, Ditesh, but it was fairly recent.
And that, again, makes changes to how you externalize IDM scripts and other things that affect your S4 environment. And then, of course, you have RISE, which is another thing that's been going on for a while, where you're uplifting your traditional SAP solution set into the RISE environment, which, again, affects SAP IDM as well, among other products.
And then, of course, you have the SAP Access Control Survey that Carpenter does every, I think it's, I believe it's every two years, or is it every year? I forget. And that's where they try to pinpoint the vendors that have the most capabilities towards your line of business applications, in particular SAP. So you have all these things that have happened, either cyclically with the survey or new announcements from SAP that complicate or affect your SAP environment even more, in particular, your migration away from SAP IDM.
So if we take a, if we double click on the Entra initiative with SAP, it does a lot of things well. So, of course, SSO and MFA can now be utilized with the models, some of the models you built in SAP IDM. You have some HR capabilities, integration through success factors, entitlement management for cloud roles, cloud-only roles. BTP and S4 HANA can be integrated into Entra, and you have some workload capabilities. But if you look at how SAP IDM was utilized, or could be utilized, I haven't seen every environment, there's several hundred of them out there. It did a lot of AD lifecycle stuff.
That's how it performed its functions. It was tied to Active Directory. The Entra capabilities really doesn't do that as well as it does AD Entra groups, or if you've federated some of it. It definitely doesn't do a lot with now the NHI and agentic AI issues, what SAP calls technical users, aren't really touched by the Entra environment. And service accounts could be managed in SAP IDM. Complex ABAP connections, so things that a traditional IGA solution would do to an on-prem or even a solution, if you moved S4 to RISE, that ABAP connection is still very important.
SODs for cross-platform use cases are part of the Entra use cases. Hybrid governance and then, of course, again, agentic AI governance are not part of what the Entra capabilities can do today. So while there is a great opportunity for you to uplift some functionality from SAP IDM to Entra, it's not going to do everything. Which brings us to what's being overlooked from a risk perspective. So if you look at it from a technical perspective, we have this mapping.
But now if we look at some of the risks that you're looking at, if you still have SAP IDM in place today, and you're trying to push it beyond the 2027 deadline, you have, of course, the AD lifecycle gap, which is something that Entra is not going to be able to do alone. You have non-human identity explosion. You have API keys, all kinds of things that SAP IDM couldn't ever do, and you can do partially in Entra. So where does that solution lie? Where are you going to put that governance and that JML management of those types of identities?
And then SAP IDM had a lot of custom scripts, had a lot of ad hoc things that were done. Typically, it was implemented as part of a larger implementation to pull identities out of a SAP system and manipulate them. So you have a lot of things that you have to consider when you're migrating away. As Nitesh mentioned, there's a process that needs to take place. You can't just lift and shift. So there's a lot of legacy risk exposure as part of that environment.
So as Nitesh mentioned, the people process technology trifecta is something that needs to be considered when you're moving away from SAP IDM, and that's, number one, assessment.
And frankly, you should have probably had that done already, considering the timeline, particularly if you're using it for critical identity management of specific accounts that affect your SAP environment, especially if you're going to RISE, if you're moving away from on-prem to RISE, you need to make sure that you have that functionality at least duplicated in a modern IGA solution or, I mean, I would say identified as a risk so that you know what to move. Right?
And you need to make sure that if you have SOD functionality in place, you have NHIs being, service accounts being manipulated, you need to decide on the platform where you're going to put it and then how you're going to connect to your SAP environment, because I would assume that if you're replacing SAP IDM with something else, you still want to retain that identity manipulation capability of your SAP accounts. So then you have to look at when you're going to build it. I would put a recommended thing of Q4 2026. If you haven't assessed by this year, that might push, right?
You might be in a 2027 build, which would put you really close to that unsupported milestone. But, you know, deployment in your environment of choice in your, on your platform of choice should be happening frankly now, if not sooner. And you have to decide how you're going to connect those systems and what systems you're going to connect, because obviously SAP has, I don't know, Natasha, a couple of hundred applications that they provide to the industry.
So, you know, understanding what your footprint is and what you can manipulate and how you're going to is extremely important. And, you know, a lot of modern systems like our own, we have, you know, we have behavior analytics capabilities and things that you never could have dreamed of even a decade ago or, you know, whatever SAP IDM was put in place.
So, yeah, maybe 15 years ago, but it's something that you need to think about as you're moving. And then, of course, you know, running SAP IDM in parallel is obviously that's a part and parcel of an advisory engagement is you want to make sure that the old mirrors the new in some capacities before you turn the old off.
But, you know, ensuring that your environment is clean, it's set up with a modern architecture, a potentially clean core if you're going to go down that road would be something you'd want to take a look at as well. And then finally, you know, cut over in a perfect world mid-2027 right before the, hopefully right before the deadline, you flick the switch.
But, you know, understanding what, how this, this is just a model that I kind of came up with if I were to put my advisory hat back on. Obviously, time is ticking on this thing. And the sooner rather than later, I think even in 2024, Mr. Cuffinger said you should be doing it now. So it's been two years. Hopefully you've gone down this road already. But if not, this is a, you know, this is a roadmap that you could potentially use along with Nitesh's information.
Nitesh, do you have anything to add to this? Yeah, definitely. I can add to it. So the timeline, which I mentioned was, let's say that we can call it the window, the big window. This is the, let's say that what you're presenting here is the ideal actual timeline that should be followed, I guess, is if you have not done your assessment until now, I think it's high time.
Ideally, you should be right now in your building phase, assessment phase and migrating phase as well at the same time. So I agree with your timeline that you mentioned. Yeah.
Yeah, I agree. I think the clock's definitely ticking, particularly if you're using it for mission-critical JML functions. And in my experience and the customers I was talking to that are still running SAP IDM, they are not the people that set it up. In a lot of cases, it was configured by a consultancy or an internal team that is no longer at the organization. So what they're dealing with now is relearning SAP IDM to then understand what it's doing to then migrate it.
So it's a deeper process than if you had subject matter experts on site who already knew the platform and then decided, okay, I know what I did, so now I can move it. In many cases, I think in every case that I've experienced, they don't know what it's doing. They leave it running because they don't want to break it. But that has to happen. And I would, again, I would argue this is an aggressive timeline because you need to be aggressive right now.
So before I go into the one identity things, I wanted to, Nitesh, if you don't mind, ask you, you know, on my assessment of the intra-integration with the SAP environment, you know, that's a great platform, but it doesn't really address the on-premise or the hybrid models. I know in some of your surveys, particularly the SAP line of business survey, there were a lot of pointed questions around how you do, you know, break glass scenarios and that sort of thing.
Do you see that the SAP IDM migration to a modern platform, do you see that as an opportunity to create those break glass scenarios, to create more of a layered structure around managing the SAP identities, or do you think clients are more well-served by just migrating the exact same thing to a new platform? Oh, I'm on mute, sorry.
Yeah, definitely. It's an opportunity, I think, that should be taken. You're moving your full system to a different platform, and that also gives an opportunity to address, let's say, your unnecessary components, as I mentioned earlier, your technical debt, you have to address those by not carrying them over.
Also, then in place, understand what could be added more into the system, and that can be improved as well. So, definitely people can take an advantage of that.
Yeah, so you heard it from someone who's not a vendor, but I want to point out that, you know, I've always told people through chaos comes opportunity. And so, by understanding what your SAP IDM footprint is doing today, and what your gaps are when you go to a new model, you can use this as an opportunity to create a more modern identity management and governance capability, right?
So, for instance, what we used to do in the old days is we'd have JML functions in something like SAP IDM, and then it would do basic JML, you know, user functions into whatever platform it was connected to. In a lot of cases, environments have that, they might have another tool set for other functions in their environment.
This is a great opportunity for you to reconcile all those functions and see if you could create a more comprehensive governance strategy, not only around your SAP identities, but also your other platforms that may be in play that augment SAP or work aside from it in some way. So, what I wanted to point out from a one identity perspective is that we recognize those capabilities, and we absolutely tailor our products to to adhere to that type of flexibility, particularly in large enterprises or enterprises where they have line of business applications.
And we've been very successful in doing that, and you can see from some of the rankings we've got from Carpenter. But, you know, what I wanted to also point out is I mentioned earlier the platform of choice, and that's something that a lot of organizations struggle with. I've seen it many times where they start an initiative to go pure cloud, and then they realize that their IoT systems, their line of business systems, even their networking equipment is still relying on on-prem architecture for authentication, user management, governance.
So, when you're looking at moving from a product like SAP IDM, or you're going to RISE as a comprehensive strategy, the thing that's most important from a practical perspective is where is that stuff going to live, and will it be able to talk back to our on-premise applications and the things we have that we can't move. Obviously, you can't move all your networking equipment to the cloud, right? That's got to stay there. In most cases, your IoT systems, in a lot of cases, your SAP environment is very difficult to move to RISE wholesale.
You have to move it in pieces, and so understanding where the governance platform is going to reside and how it's going to call back to all these different components is very important. So, SAP IDM was an on-prem product, and now you have the opportunity to move it somewhere. Do you move it to another on-prem product? Do you move it to a hybrid model or a private cloud, or do you put it in a full Azure AWS environment?
So, we as a vendor recognize that, and our IJ solution is actually provided in all those different formats so that you have choice, as well as we can provide privileged access management as an integrated component or as a separate component to provide firefighter access, session management, that sort of thing. So, you can uplift or augment your governance environment with privilege.
And then, of course, we also have the ability to add a lot more robust active directory governance to the environment. We can actually aggregate multiple domains.
So, in the past, say with SAP IDM, you'd have a single, you'd have an AD connector per domain, and then you'd have to aggregate it and script it. We can provide a solution that will allow you to connect to intra-multiple ADs, feed that into IGA, and then use that as your repository for different SAP products for authentication, as well as other things.
So, why identity? We recognize that SAP is going to essentially be the core line of business suite for your organization, and we build out solutions that help you support that suite.
And then, you know, I wanted to open this up for a little discussion, Nitesh, and maybe comments from the chat if they have any. But, you know, you mentioned a 12 to 24-month migration strategy.
You know, I added a little bit extra time in there, but obviously, the clock is ticking. Do you, I mean, if you think about it from an organizational perspective, do you think that SAP IDM is something that is still integral to a lot of businesses today, or do you think they've forgotten about it, or do you think they've already migrated off with an honest opinion from you, the analyst?
And also, in the chat, if anybody has any comments around, you know, whether they've already migrated off SAP IDM, or they're still struggling with it, I'd like to know, because it's kind of a black box mystery to me at this point. Yeah, definitely. I think we have some response, as well, for that poll question which we asked earlier right now, is that, where is the organization in its SAP IDM transition journey? And the option which got the most votes, 30%, is they're actively migrating. Second most option is they're evaluating options.
Third option, that is, the tool choice has been completed, and now they're preparing to migrate. And only 13% have responded, saying that they have not yet started.
So, if you look at this pattern, I think we are definitely in the right direction from what we're also expecting, is that this needs to be addressed, and this is being addressed. So, yeah, I mean, it's a right phase, as well, yeah.
Well, that's encouraging. I'm glad to see that everybody's at least on a track to evaluation or migration.
You know, I think that, you know, there's still quite a few footprints of that product out there that, you know, folks need to evaluate, whether or not they need to keep it running for a little bit longer, or they can wholesale move off of it. But the discussions I've had, most people are in the evaluation phase, particularly for a larger organization, because they have a lot going on. I don't know, Natasha, if you've noticed, but our industry seems to have a more with less methodology these days.
So, there's a lot of identity teams that are trying to do day-to-day operational things, as well as worry about migrations and longer-term things. But I probably am not alone in realizing that we're halfway through 2026 already, and I'm quite shocked.
So, it's one of those things where you need to take action very quickly, and that's an encouraging statistic. So, also, you know, back to the Entra thing, I've been through the documentation, and I've looked at what is provided as part of that strategy, and it can solve some use cases. But I'd be curious, and I know this wasn't a poll, but I'd be curious if there's any commentary on, you know, whether folks have adopted the Microsoft strategy for moving off SAP IEM and whether or not it's worked for them.
Because I feel that it could in some scenarios, but the AD lifecycle and hybrid environments and the overall IGA governance capabilities of that solution are not as robust as they could be. So, I'd be curious to see if they're using Entra as the entry point, no pun intended, and then they're going to a deeper level IGA solution for the other use cases.
So, that might be something we could ask in post or if anybody wants to comment in the questions area. Yeah, if you can use the chat option as well to provide your response or the questions as well, and we would love to know how are you addressing this.
Yeah, and I'd be curious, Nitesh, what your opinion is on that. Yeah, it's a thing.
It should, I think, address most of the use cases, but there are, there will be some specific use cases which cannot be addressed completely entirely, and that's what I guess we're also trying to understand is that how are then these gaps being addressed? What is being done for that?
Right, because what I've seen is in the IGA world, you have the Entra connector, and then we're connecting to Entra to manipulate those identities. So, from what I've seen from implementations with Entra, they're not doing SAP directly to Entra. They're using the IGA solution and then going back to Entra or using Entra as another connected system source. They're not necessarily using it as a gateway to uplift because, you know, from my perspective, if you connect SAP to Entra, you're going to get x use cases satisfied, but then what about the others?
Do you then connect an IGA solution to that environment, and then now you're manipulating SAP through the cloud environment to an IGA solution where you could have SOD and attestation centralized? It seems kind of backwards to me, but you know, I could be wrong, right? I don't know all the, you know, what people are going to utilize that connectivity for.
And then, you know, from a technical user, which is the SAP terminology perspective, the governance risk is absolutely not going to be addressed with the Entra solution as it sits today. Now, I know Microsoft's building capabilities for some agentic use cases, but I'd like to know, you know, if you're considering those service accounts, technical users, agentic AI accounts as part of your migration, or you're simply focusing on one-for-one use case migration from the old platform, that would be an interesting talking point.
I don't know, Ditesh, have you seen any, in your discussions with clients, have you talked to them about how their SAP technical users are coming into play with the overall NHI agentic AI governance push, or are they keeping them separate? The NHI agentic topic has been quite, has picked up quite rapidly in the last 12 months. It has been coming up in several discussions around this. First of all is that they are trying to now understand how many NHIs they have in the system, and then they're trying to understand how to then govern these kind of systems on these identities.
So, that's the next challenge. So, it would be interesting to see if how our attendees are also responding to this, and what is their approach as well to this is concerned. You can definitely put it in the chat, and we would love to hear that.
Yeah, so, you know, from my perspective, I see an offshoot of your, if you're doing evaluation now and moving off of SAP IDM, I see, obviously, you have some sort of committee where you're just reviewing the code, you're reviewing the processes, you're understanding how it fits in the overall IAM and security ecosystem that you have in your organization.
I think that's something that needs to be considered as we move further down the timeline, how you're integrating at minimum NHI management into that strategy, but now agentic AI, because I see a lot of under-the-desk agentic AI usage in my encounters with clients, and not a lot of governance. So, I think that maybe setting up some sort of NHI governing body inside that discovery process would probably be of use to you.
And again, I was trying to allude to this earlier, but this, the SAP evaluation of migration, SAP IDM evaluation of migration, and potentially the RISE initiative, if you have that in place, would be a great opportunity if you evaluate how you're managing NHIs as a comprehensive whole, and does it have parity with managing and governing your human identities, because in my world, I see them as, they should be parallel as far as capabilities and what you're doing with them. So, again, another thing to address as part of your migration would be how those NHIs are being managed.
And then, finally, the last couple things are pretty, I think, a pretty common sense. Make sure you're evaluating your platform on how all this stuff ties together as part of your migration strategy instead of, I think, going one-to-one functionality is a good short-term strategy if you're under a time crunch, but if you can take the opportunity to evaluate the overall lifecycle governance big picture from AD, Entra, PAM, SAP, line of business applications in general, I think this is a great opportunity to do that.
And then, finally, I'd encourage you to look at the different modern capabilities that are out there today from clean core or clean core guidance from SAP and certification, things like behavior-driven governance and UABA, and so you can create an environment where you're quickly manipulating the risk posture of identities, because as these agenic AIs and machine learning technical users come online, even Juul, I'm sorry, I'm pointing ahead of the screen, but Juul with their autonomous, you're going to have to figure out how to manage that thing, because you don't want to go out of control.
So understanding the SOD environment for agenic AIs as well as humans, understanding the table stakes when it comes to your requirements, that should be a serious consideration if you have the opportunity to do it. And I don't know, Nateshi, if you have any other recommendations. I know you have a lot in your surveys, particularly the line of business one, but that's my take as a vendor. I think that, you know, absolutely you could use this opportunity to move away from SAP IEM to uplift your governance and identity management capabilities.
Yeah, I think I completely agree with you, Robert. So just starting with the basics, I guess, and then moving on towards the more complex stuff.
Right, especially when it comes to cloud environments and how you're doing credit operations in those or more deep level integrations to things like SuccessFactors or ServiceNow or any of those big cloud environments, making sure that you have the capabilities to support those as part of your migration would be a great value add. And with that, I think that's all the content I have. I'd like to open this up for any questions. I see there's some questions that Tan has posted, and I know we have the poll results. I don't know if you want to cover those.
Yeah, definitely. I'll first share my screen quickly. There we go.
Oh, it can always be challenging. Hopefully, I'm showing the right screen.
Yeah, so I think we discussed the first poll already, is that where is your organization in its SAP IEM journey? But I think now that we have got more votes for actively migrating, so that option is the top with 44% votes. 22% votes are for evaluating options. Another 22% votes for tool stress complete and preparing to migrate.
Oh, yeah, another change. Actually, my rating is not 50%. So this is a good pattern to observe here is that this is in line with what you also presented, Robert, is based on your timeline, where you should be right now. So I think this is a good reflection of that. So do you have maybe any comment on that?
No, it's great that I guessed right. No, I think that our industry, we have a lot of very smart people in our industry. And I think people recognize that you don't want that albatross hanging over your neck when it comes to an old, deprecated identity management environment. You want to make sure that you're evaluating that and where you can take the opportunity to uplift those capabilities in a more modern environment. So I think this tracks with what I'm seeing in the field.
And I think it's, it's encouraging that I didn't get 100% not started yet, because that would that would very much concern me. That would be a little stressful. That would stress me out. And I'm not part of those programs.
So yeah, yes, definitely. So I think that that summarizes the first poll. The second poll was what is the biggest challenge you expect in moving away from SAP IDM and 78% of the votes have gone to migrating identities, roles and workflows, while 22% has gone to maintaining compliance and audit readiness. The other two options about maintaining active directory and prior lifecycle process and limited internal resource and expertise has not received any votes. But with 80% of the votes now for migrating identities, and that seems to be the biggest challenge as well.
From maybe your point of view, Robert, when you are working with your customers, is this something which comes up quite often? It does. It actually where we're internally, we're working on a an offering that will help facilitate that a lot faster. Because we identify that the mapping of that particular data model is unique, right? And like any migration of identities and roles, it takes a lot of mapping. And so what we're seeing in the field is people understand the problem. They know that there is a problem. They see the announcements all the time.
They have their CISOs and CTOs breathing down their neck to say, hey, when are we getting off this thing? Because it's a ticking time bomb. And what I've heard wholeheartedly from our partners and our clients or customers is, please provide something that will help us do this faster. So I think it's a pretty common theme with a lot of the customers that I work with. Absolutely. Perfect. Thanks. I think now we can take a look at some of the questions that we have from the audience. We have a few questions.
The first one, I think this one has got to upvote as well, is which modernization trends are most relevant for enterprises that are still heavily invested in SAP IDM? Maybe Robert, when you're dealing with such kind of customers, what is the trend that you come across most? I see the folks that I've spoken to that are migrating off of it or are in the planning stages. They're looking at it as an opportunity to adopt a solution that can do cloud application manipulation too. So communicating with things like Dropbox and other little credit operation applications they couldn't do before.
Because a couple of customers that I've spoken to that are migrating, they don't have any modern IGA solution. They have a few, but they're outdated. So they're using this as an opportunity to consolidate. And so they're evaluating solutions that can do on-premise and cloud at the same time and synchronize that data set in a way that can govern. And in a couple of cases, they don't even have more of what you would consider table stakes governance capabilities like attestations and SOD.
So what they're attempting to do is consolidate or find a solution that can provide that as a second phase, as well as integrate their on-premise SAP environment, which they still have, as well as more modern cloud environments like Etra or small things like Box and Dropbox and that sort of thing. That's what I'm seeing. Understood.
Okay, perfect. Thank you. The next question is, what would be your two key recommendations for migration? I think maybe the first one would be is that if you have not started already, start right now. It's already towards the, let's say the late stage, but you have to really start right now. And the next one would be just that when you're doing the migration is like, if I go back to my slide of considerations, you need to take all those considerations into when you're doing the migration. So I think that will definitely be something that I can recommend.
Maybe what would be your two recommendations? Yeah, obviously, I mean, you don't know what you don't know. So you want to absolutely evaluate that environment and understand what you're migrating and what you don't have to migrate, because there may be synchronizations or other scripting in place that is, it goes nowhere, right? I've seen that a few times where they just, you know, the team leaves a script in place that was written by someone a decade ago. And they say, I don't know, we just leave it running. And then you look at it just cyclical, it doesn't do anything.
So evaluating the actual platform and understanding what it does, that's mission critical. And then, you know, without creating a whole project plan for everybody, I would say, prioritize what you have to, what would be nice to move and what you don't have to. And then my other recommendation would be, please don't try and migrate everything at once. That just creates levels of chaos.
Now, as a former consultant, I can say, if you want to migrate everything at once, I'd be more than happy to provide 15 people to do it. But I think, you know, phasing it, understanding your top priorities, and then picking a platform that, like our own identity manager product that could actually accept that data model relatively easily is very important.
Yeah, exactly. I think I agree with you as well on the second one about don't do everything at once. That was also the challenge, which I mentioned earlier is that avoid this single phase migration. So a phase wise migration would definitely be a recommendation. We have a couple of more questions here. Maybe I can take the next one is that for organizations starting their SAP migration journey today, that's okay. What accelerators or capabilities can reduce timelines, preserve internal knowledge and maintain compliance?
I think it's already critical we saw in the poll question as well, this option of not yet started has also received some votes. So there are still organizations and people out there who have still not started. What would be maybe your recommendation for accelerators for catching up on this journey?
Well, I think I'd break it down in a people process technology could actually fit. So from a people perspective, internal knowledge, the only way to preserve that is to make sure you have somebody on staff who still knows the product, right? So if you don't have the internal knowledge, at least document the solution than the scripting and then bring someone in who can interpret what it's doing. So the internal knowledge could be a repository and staff or it could be just staff or just repository, but make sure you're preserving both.
You have at least this, at least you're preserving and documenting what you think it's doing. And if you have someone on staff or multiple people that know the product, make sure you're documenting it in a comprehensive way. So it'd be easy for either you internally to migrate those processes to a more modern system, or you could take that documentation and provide it to a consultancy so they can tell you what it's doing because there's a good chance that might be happening as well.
And as far as solution accelerators, if you're just starting today, I would look at vendor offerings or services offerings or both that have maybe not necessarily a complete plug and play, but can get you past the initial phase very quickly.
So instead of doing mapping, if you find a vendor, and I know we at One Identity have some stuff we're working on, but that where you can plug in and we can get you that first big picture view and get you an initial outlook that will get you, maybe push you past with your timeline, or push you, you know, accelerate your timeline to the point where you're not feeling as stressed, I think that's a great place to start. You don't, you never want to start from zero if you're, you should be at two. You'd like to start from at least one and a half so you get to two really quick.
So, and then from a compliance perspective, that's where I, in my slide, I put, you know, parallel, you probably want to keep a parallel environment, at least for the first couple phases, until you have the top priority use cases that will affect compliance and audit in place. You never want to shut off compliance-reliant, audit-reliant services with no backup.
That's a, right? I don't know, Nitesh, I'm sure you have a lot of opinions on that, so.
Yeah, definitely. I think that was also one of my points about is that, maintain this historical audit records before you do the decommissioning. You need to have this in place, so do not shut it off completely and then move on.
So, this needs to be in place for a while. But, yeah, perfect. I think that's a good insight from you about one identity, how we can also accelerate. Thank you for that. We have a few, four minutes, but we can still take one more question.
It's, what migration options in IGA are you observing for the SAP roles as transaction models into new IGA hybrid tools? So, maybe Robert, if you want to take this one.
Yeah, so actually, that's a, that's one of my favorite SAP topics, because we have a very, very robust, what we call a connected system module connector. We use the, we use SAP's certified BAPI. We were a certified BAPI connector and we dig deep into the SAP role modeling.
So, we can, we actually have visibility in all the clients. We can see exactly, you know, key code, we can see key codes and all the different unique security model functions of SAP.
Well, when I say SAP, I mean, you know, ERP, ACM, the big, the big solutions. Obviously, SAP, like I said earlier, has like a couple hundred products.
So, we have visibility into what you would consider your strategic line of business SAP solutions at a deep level. So, if you, I know other vendors have similar capabilities, but from our perspective, we have a connector that will dig right into those roles and give you native visibility into all that directly.
So, that's a, that's a unique thing from my perspective, and that gives you the ability to, you know, model your new strategy for IGA relatively quickly, once you have that connector in place. I don't know, Vitesh, you have a broader perspective from your surveys, maybe you have a different outlook on that. I think I agree with you as well, what you mentioned.
So, anything more for me to add as well? We have just, I think, a couple of minutes left.
So, if anyone has any questions, now is the time. Otherwise, I'd say, first of all, thank you, Robert, for your presentation as well, and for joining me for this webinar. Definitely, it's an ongoing topic, an ongoing theme that will go on for at least the next one, two years.
So, let's see how this space evolves and develops, and if there are new challenges that come up, and what happens. But we'll take a look at that from, if you have any final closing statements. The only thing I'll say is, I hope if we do this in 2029, I don't have a lot of poll respondents sitting there evaluating.
Hopefully, by then it's already done. Hopefully, we're not talking about this again, and everybody, you know, gets their system migrated. But I appreciate your time. It's been interesting and fun. Perfect.
Thank you, Robert. Here's some, also, a little bit of research that we have from Tuping and Gold. It's available on our website. You can go there and check it out.
Otherwise, I would like to thank everyone for joining this webinar, and we will see you next time. Thank you.
See All Locations
See All Locations