I introduced myself before. I work for Fressnapf. These are actually my two real dogs that I would have really, really liked to bring. Thank you. Applause And, well, oh yeah, let people change some seats. That's fine. Laughter So we actually come to a real-life example how an SAP customer, in this case, Fressnapf Maxizoo, this is my colleague Tobias Zügel, also my personal Microsoft Enter ID guru, as you will see later on, how we are dealing with this. And the title, Who Let The Dogs Out, is not chosen just by random, just because it sounds cute and we care about dogs.
Because what we are presenting, or the way that we are choosing, a lot of people actually thought, like, are you sure you really want to do this? You want to pursue this? We'll show you.
But first, let me introduce very short management slides. Because what is our corporate mission? We do everything we can to make the lives of pets and pet parents easier, better, and happier. Happier pets, happier people. That's our motto. So where we want to go is actually, of course, we want to stay market leader, but we also want to become the best omnichannel pet retailer. Everywhere where you want to get something for your pets, you want to do this with us, because we are the best retailer for you. Apart from the market part, I do have somewhere I want to go with this.
Because if you look at how Fressnapf Maxizoo is centered in Europe, you can see that we have over 2,600 stores. Stores where you can actually walk into, not only an online store, but something where you can go, you can actually bring your pet there as well and buy things. And all this, all this infrastructure is carried by over 20,000 employees.
Employees, workforce, I make this quick because I only have a couple of slides here. These are managed in SAP IDM. What a surprise today. And the important part is that if you look at how these employees are actually, so what sort of employees we have, we have those coming from our SAP HR system, SuccessFactors slash HCM. I'm not going to go into detail with that, which are brought into our SAP IDM. And we also have a big franchise business, especially in Germany. And that actually means that we have a lot of, for us, more or less external employees in our IDM as well. Everyone knows that.
That is quite important. And if we take a closer look what that means, then you see that actually the blue and the gray part here are our store users. Those are the people who earn our salary because they are in the stores. And if you go to one of our stores, they just don't only point you to the dog food or the fish food or whatever. They will tell you which food is good for your dog. They will look at your dog. They can tell you things about it. They can actually really have a benefit there. And for that, those are actually our main focus group when it comes to the employees at Fresno.
And that means they are also the main IAM focus group, because they should not think about how to log onto a system when they're in the store. They should think about how can I best serve our customers. And from here, I will hand over to Tobias, who is going to show us a bit more how our landscape looks today around SAP IDM.
So, hi, folks. So, I'm Tobias. And as Lisa said, I'm the intra-guru at Fresno. And the guru is nothing bad. It's more like bringing light into the darkness.
So, let me bring some light into the darkness of what we're actually doing. So, this is maybe a complex picture, but it's actually not that difficult and maybe also standard with other companies.
So, we have HR on the right-hand side. And it's like HR user data comes into SAP IDM.
So, as a kind of provisioning. On the other side, we already feed data from HR into cloud identity services, because SuccessFactors requires that.
So, also into SAP BTP. So, as we explained, it's like we have the SAP and Microsoft as basic environment. And this is for employees only.
So, as usual, it's like for franchises, they are not in the HR store. So, we manage them directly in the IDM field, in the SAP IDM.
So, from the SAP IDM, we provision to various subsystems, also like in the portal, in Active Directory for employees. But also, data flows back from SAP systems.
So, additional data that is owned and originates from the ERP systems and stuff. So, from the Entra side, we also already provision directly from Entra other systems like ServiceNow, for example.
So, this is just the identity flow. So, how we distribute identities. We have also a difference between different user personas.
So, on the one-hand side, we have information workers, which are more like IT personnel, where they need more IT equipment. And also, a larger group is like the store employees, which are like in the store, they don't need fully equipped workplaces and stuff like that. They are more frontline workers.
So, special devices and stuff. So, we differentiate between those two user personas on the one-hand side and between employees and franchise partners on the other side.
So, it's these four different areas. If we look at that, this is kind of like just the synchronization and provisioning part of it. The authentication part is a bit more different.
So, on the authentication part, we have, well, a large space already in the Entra side. So, modern applications primarily, which is good if you look at that from the transition from SAP IDM, because we have already parts in Entra ID. On the left-hand side, it's like with the conditional access on the Entra side. We're already quite developed using stuff that is already there, like device coupling with device management, also with our rugged devices that are in the stores. On the other side, we have the private access, the network integration with Microsoft already for the employees.
And we have some app proxy stuff for remote access scenarios. So, we're in this space quite far ahead. On the other side, on the right-hand side, it gets a bit more difficult.
So, because we have the Cloud Identity Services on the right-hand side, which needs to be interconnected. So, it's like single sign-on and sign-on with the Entra ID and SAP Identity Services needs to be interconnected. Which is a bit like, can be very difficult, because you do not want to lose the application that the user authenticates to for the conditional access part.
So, it shouldn't be hidden behind the Cloud Identity Services. It shouldn't be hidden with that.
So, you need the real application the user logs onto in order to be able to make an access decision. And also, we have the NetWeaver portals, a bit more older stuff, legacy stuff, which is also like that.
So, it's like there. So, with the Entra stuff, we have some stuff already with new components inter-incorporated. But the question is, well, how do we evolve that more to replace the access decisions, to replace approval flows and stuff like that?
That, well, usually in the past was not really the strength of Entra ID. So, this is where we are right now. And I'll hand back to Lisa. Thank you.
Thank you, Tobias, for giving us some insight how today our IDM, what is its main goal? What do we use it for? And you can see from everything that he told us that we are very Microsoft invested already. We are also very SAP invested. And the Cloud Identity Systems that were there in the first talk here are very important for us as well. And this kind of means that we are having all the parts that we need that lead us into a certain direction. Our main focus group are our store employees. You can see that from before as well.
And all this leads us to the question, well, with SAP IDM end of life 27, where do we go? And what about Entra ID? Our management does not tell us that this is the only way. But we are all aware and we are very sure about this that we have to look at Entra ID much, much closer. And this is what we are doing. And this is why I will now hand over to Martin Repler from Microsoft because with him in the last year, we've looked at a lot of our scenarios and talked about how it would be possible for us with where Entra ID today is as an IIM system. What you could actually do with that.
And he will give you an overview over a couple of best practice cases that kind of fit into our direction. There's a bit in there. And after that, I will try to just make some conclusion about how this might actually fit together for our environment. Disclaimer. What we are doing here is not something that we have decided. We have no contract or something. We have our Microsoft investment. This is a collaboration to really bring the whole topic forward.
Also with the DSAG thought behind this to actually give the customers what we learn back, even if at the end of the day we are not using Entra ID. We'll see about that.
Martin, I hand over to you. Thanks a lot, Lisa. Yeah.
Also, welcome. More welcome from my side. Yeah. Martin Repler from Microsoft. As Lisa said, we worked closely throughout the last year, but not only with Fresnap, also with other customers who are basically in the same situation as you are, right? Not exactly sure what will happen in the next year and how to progress with the SAP IDM migration.
So, I would quickly like to talk a little bit about that partnership that has been announced last year at the DSAG event at the Technologie Tag in 2024. Which actually was not something that has happened or this close partnership between SAP and Microsoft on the identity space. It is more like a continuation of what has been done already for the last 20 or even more years. I can tell that because before I joined Microsoft five years ago, I worked 15 years for SAP, where I worked also very closely with Microsoft on many of the security and identity interoperability topics.
So, it's nothing new, but I think it's a further intensification of the already existing collaboration between both companies. One of the key results or early results from that partnership is what we see here. A reference architecture that I think we've also seen in a slightly different format or form in the previous talks. It basically puts Microsoft Entra and the SAP Cloud Identity Services in the center of this reference architecture.
Basically, Entra being the place to integrate, for example, with HR success factors. Certainly, also other HR sources or other SaaS applications synchronizing with Active Directory, which I think is the case for many of Entra customers.
Then, when it comes to provisioning into the SAP world, Cloud Identity Services is the key component that orchestrates everything towards S4, be it on-prem, be it native on any of the cloud providers or also as part of the RISE offering from SAP. But it certainly also takes care for provisioning into other SAP SaaS solutions.
However, such reference architectures are typically not that – are a little bit abstract. That's why in the collaboration with Wesnaf and with other customers, we try to figure out certain patterns in terms of concrete scenarios that allows us to understand much better the actual requirements. I want to quickly go through a few of those patterns that we identified. One of them certainly being the inclusion of any SAP BTP application. BTP stands for the Business Technology Platform of SAP, where more and more applications we see on the SAP side are built on.
The integration here is quite, let's say, quite simple to build, because you can simply make use of the so-called identity proxying or identity federation within the Identity Authentication Service and Cloud Identity Services to either use OIDC or the semi-proxying capabilities in IAS to federate with an enterprise application registered in Entra.ID. That can provide certain claims, for example, in terms of group claims to federate with the application that resides on the BTP side in order to authenticate and authorize the user to BTP applications.
However, as we know, when it comes to S4 and the ERP solutions on the SAP side, we always need to have a local user in the user store of the S4 system. This is where it gets a little more heavy in terms of the requirements. We need to provision users from Entra to S4, and that can be accomplished also with the Identity Provisioning Service on the SAP side in Cloud Identity Services.
Typically, what you do is you pair that with the connectivity service in BTP that is connected to the SAP Cloud Connector that establishes a secure connection to BTP and the Identity Provisioning Service on the Cloud Identity Services side. And then you leverage the SCIM protocol from Entra, from the ready-to-use SCIM connector, in order to provision users from Entra to S4. We also saw quite often that in the context of workflows, approval workflows for access governance, the context of the user is quite important. And by context, I mean context in SAP of the user.
Think of, for example, the cost center or the company code or any other sorts of information that actually resides with the user in SAP, but is needed in order to, for example, find the responsible approver in an access governance workflow.
This is also where SAP's technology platform, business technology platform, comes into play by using the so-called integration suite that can be linked to an extended custom logic implemented on the Microsoft side with Azure Logic Apps that is able to integrate using the business technology platform integration suite, again via the cloud connector, providing a secure connectivity to BTP in order to access this data in SAP. And typically there you use the SAP gateway in order to expose, for example, this data as an OData service that is exposed to the integration suite.
When it comes to HR integration, certainly there's also a ready-to-use connector to success factors in Entra that can be customized using the so-called lifecycle workflows and entitlement management in Entra ID governance. And then you can also customize all of that using basically the same approach as shown before, with the logic apps on the Microsoft side in order to, for example, do some sorts of, for example, email notification to a manager of a new employee seven days prior to the hire date, for example, and things like that.
And again, certainly those custom extensions can be integrated using integration suite from the SAP side via cloud connector to any sort of data that resides on the SAP system. All right. And I think last but not least, I also want to mention something that's on the roadmap and that's part of that closer collaboration that we announced jointly a year already ago. And that's already on our making with the collaboration and the development that happens on both sides. And that is all about the integration from Entra to SAP Identity Access Governance or IAG.
This is where you basically can tell or can say from an approval workflow in Entra ID governance and entitlement management when you assign a user to an access package. And I think that's what affects many of the SAP IDM customers.
They will more or less transfer the business roles in SAP IDM to so-called access packages in Entra, associate that with a workflow and the approvals, for example, might need to do SOD checks and the integration with Entra ID or with the entitlement management in Entra ID governance and the solutions, the risk and compliance solutions on the SAP side, including Identity Access Governance.
And I think I can also now talk about this publicly because it has been agreed between SAP and Microsoft just recently, two weeks ago, that also access control, which is part of the GRC platform in SAP, will be also included in the same manner as Identity and Access Governance. All right. And with that, I hand back to Lisa. Thank you very much for this nice deep dive.
Yes, so let me wrap up the whole thing because now you've seen a lot of information about, you've learned a bit about Fesnav and about what Microsoft is doing right now. And if we put this together for us, if you look at what we did with SAP IDM, so we had also there the focus on store employees already. So this is our main group, like I said before. And especially the cash register system for us is very important because if people come into the store and they can't pay, that's not good. And historically, we have as many SAP IDM customers, a lot of customizations.
We also have a lot of manual costs in the UI still. That's also a thing that comes with this toolbox. And it was also a good solution for us, actually, for the franchise partners because we had a possibility to insert externals in there.
Again, the toolbox. It allows for a lot of things.
Now, we want to change things for the future, but looking at Microsoft for us, it was important to see, okay, what matches on what. So access packages for us, for authorization, is what we are looking for in the future. So this is what we're going to try. We are implementing it for a couple of things already, especially for some new systems, to see how this works for us. Hopefully automatically because that's the best way, but there's more stuff to do behind that.
Logic apps for customization allow us a bit of freedom to not stick completely in the Entry ID environment, especially where things might not be capable today in a way that we would actually need it. And we can't wait for it all to be implemented. So logic apps will actually give us a good way. We are very interested in looking at the SCIM connector for the Cloud Identity Services because then we have also our SAP world covered in a good way, also towards the ABAP systems. But this is all still some things that we want to do.
And the lifecycle workflows, together with success vectors, as Martin showed, would be the way for us to go to actually, well, at some point, switch to there. So that's the things that we are looking at. This sounds good.
Now, you heard from the talk before, there are gaps for sure. And for us, there are a couple of open issues, which are mostly important. There's other things, but this is something that we have to look at. The customization of UIs, if we still want to do more and more manual stuff, because we have to, because our processes cannot change fast enough, we will actually talk with Martin probably in the summer with this, maybe looking at power apps or stuff like that. But that's still to be determined. Extended privacy settings for externals. That's a special issue.
If you want to talk about something like this, let me know later on. But actually, well, that is an issue. Android is not so good if you have one tenant and you don't want people who insert user to see other users. It's not so easy to do that. Believe me. And one test for us that will be very important, we're implementing a new cash register system, and that's a non-SAP web app. Yay!
So, with special requirements, because like offline possibilities and stuff like that. So, this together with our store customer employees as the main focus group will definitely be one of the things that this has to work.
Otherwise, if we don't find a solution for this, we cannot do this. So, please stay tuned for what comes next. And I hope that you could take some information back from that. If you have questions about EntroID, for ConfessNAP, and of course also for the DSAG, for all the information that you got from the talk before, the team groups, we didn't put up all 50 or 60 points and stuff like that. You can get that from us. Talk to us. Let us know. And thank you for having us. It was a real pleasure. Good afternoon.