{"id":66755,"date":"2026-08-06T10:40:09","date_gmt":"2026-08-06T08:40:09","guid":{"rendered":"https:\/\/xiting.com\/?post_type=sap-knowledge&#038;p=66755"},"modified":"2026-08-17T17:57:40","modified_gmt":"2026-08-17T15:57:40","slug":"identity-governance-and-administration-in-hybriden-sap-landschaften","status":"publish","type":"sap-knowledge","link":"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/","title":{"rendered":"Identity Governance and Administration in hybriden SAP-Landschaften"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"66755\" class=\"elementor elementor-66755 elementor-64644\" data-elementor-post-type=\"sap-knowledge\">\n\t\t\t\t<div class=\"elementor-element elementor-element-78cda3bc e-flex e-con-boxed e-con e-parent\" data-id=\"78cda3bc\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-285bc8d1 elementor-hidden-mobile e-flex e-con-boxed e-con e-child\" data-id=\"285bc8d1\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-62f53443 elementor-widget-mobile__width-initial elementor-widget elementor-widget-button\" data-id=\"62f53443\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-xs\" href=\"https:\/\/xiting.com\/de\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-home\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7c9afc04 elementor-widget elementor-widget-text-editor\" data-id=\"7c9afc04\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>\/<\/p>\n<p><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-276a08d0 elementor-widget-mobile__width-initial elementor-widget elementor-widget-button\" data-id=\"276a08d0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-xs\" href=\"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-iga\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Identity Governance and Administration (IGA) erkl\u00e4rt<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a97fd20 elementor-widget elementor-widget-text-editor\" data-id=\"a97fd20\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>\/<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f1d49e3 elementor-widget-mobile__width-initial elementor-widget elementor-widget-button\" data-id=\"f1d49e3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-xs\" href=\"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">IGA in hybriden SAP-Landschaften <\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-66c73a67 animated-fast e-flex e-con-boxed elementor-invisible e-con e-parent\" data-id=\"66c73a67\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;animation&quot;:&quot;fadeInUp&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-10e0d5b8 elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"10e0d5b8\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">Identity Governance and Administration in SAP-Landschaften <\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-8898818 e-con-full e-flex e-con e-child\" data-id=\"8898818\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-b2ba191 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"b2ba191\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"far fa-calendar-alt\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">06. August, 2026<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2baf62d elementor-widget__width-auto elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"2baf62d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-equals\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Identity Governance and Administration (IGA)<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-428d442 elementor-widget__width-auto elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"428d442\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"far fa-user\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Alessandro Banzer<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-22febaa9 e-con-full e-flex e-con e-child\" data-id=\"22febaa9\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2d3430d0 elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"2d3430d0\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Von Access Governance zu agentischen Security Operations <\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-39a4ba55 elementor-widget elementor-widget-text-editor\" data-id=\"39a4ba55\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"ewa-rteLine\"><p><span data-contrast=\"auto\">2026 zeigt sich bei SAP-Kunden branchen\u00fcbergreifend\u00a0ein klares\u00a0Muster: <strong>SAP-Landschaften werden\u00a0hybrider<\/strong> und\u00a0umfassen On-Premise-Systeme, Cloud-Umgebungen und mehrere SaaS-L\u00f6sungen.\u00a0Gleichzeitig steigen\u00a0<\/span><a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/sap-compliance\/\"><span data-contrast=\"none\">Compliance<\/span><\/a><span data-contrast=\"auto\">-Anforderungen\u00a0und\u00a0Bedrohungsdruck. Dennoch\u00a0werden Identit\u00e4tsdaten, Zugriffsrisiken und\u00a0<\/span><a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/sap-security-monitoring\/\"><span data-contrast=\"none\">Security Monitoring<\/span><\/a><span data-contrast=\"auto\">\u00a0h\u00e4ufig\u00a0weiterhin\u00a0in getrennten Silos verwaltet.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Genau deshalb ist\u00a0<\/span><a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-iga\/\"><span data-contrast=\"none\">Identity\u00a0Governance\u00a0and Administration (IGA)<\/span><\/a><span data-contrast=\"auto\">\u00a0heute keine Option mehr, sondern eine <strong>Voraussetzung<\/strong>. IGA stellt sicher, dass die richtigen\u00a0<\/span><a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/identity-access-management\/\"><span data-contrast=\"none\">Identit\u00e4ten<\/span><\/a><span data-contrast=\"auto\">\u00a0den richtigen <a href=\"https:\/\/xiting.com\/en\/sap-knowledge\/sap-authorizations-explained\/\">Zugriff<\/a> haben \u2013 aus den richtigen Gr\u00fcnden, unter den richtigen Kontrollen. Und es liefert die Nachweise, die Pr\u00fcfer und\u00a0Incident-Response-Teams im Ernstfall einfordern.<\/span><\/p><p><strong>Einen allgemeinen Einstieg in das Thema bietet unser \u00dcbersichtsartikel zu den <a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-iga\/\">Grundlagen von IGA.<\/a><\/strong><\/p><p><strong>Dieser Artikel geht tiefer:<\/strong><span data-contrast=\"auto\">\u00a0Er erkl\u00e4rt, was Identity\u00a0Governance\u00a0konkret im SAP-Kontext bedeutet \u2013 und wie Sie ein operatives IGA-Programm aufbauen, das langfristig funktioniert.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\"><strong>Xiting\u00a0geht dabei von der SAP-Realit\u00e4t aus:<\/strong> Berechtigungen sind gesch\u00e4ftskritisch, leistungsstark und komplex. Das Ziel ist keine\u00a0Governance\u00a0auf dem Papier, sondern operative\u00a0Governance\u00a0\u2013 system\u00fcbergreifend und dauerhaft wirksam.<\/span><\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9f5a2db hs-popup-btn elementor-widget elementor-widget-button\" data-id=\"9f5a2db\" data-element_type=\"widget\" data-e-type=\"widget\" data-portal=\"25088517\" data-form=\"ff252bfb-c4f8-4db5-8993-e6ecb87579a0\" data-region=\"eu1\" data-title=\"Kontaktieren Sie unsere Experten.\" data-success-close=\"1500\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/xiting.com\/de\/demo-anfragen\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-angle-double-right\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Jetzt Demo anfragen und Ihre SAP-Landschaft sichern!<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-66ec91ce elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"66ec91ce\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Was bedeutet Identity Governance and Administration im SAP-Kontext? <\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6c338b18 elementor-widget elementor-widget-text-editor\" data-id=\"6c338b18\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"ewa-rteLine\"><p><strong><span class=\"TextRun SCXW201790437 BCX8\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW201790437 BCX8\">In der Theorie klingt das \u00fcberschaubar. In SAP-Landschaften wird IGA greifbar, sobald Sie diese Fragen zuverl\u00e4ssig beantworten k\u00f6nnen:<\/span><\/span><span class=\"EOP Selected SCXW201790437 BCX8\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/strong><\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-46d6081b elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"46d6081b\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">IGA-Reifegrad: Diese Fragen m\u00fcssen Sie beantworten k\u00f6nnen <\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9ab44e0 elementor-widget elementor-widget-text-editor\" data-id=\"9ab44e0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"ewa-rteLine\"><p><span class=\"TextRun SCXW15339136 BCX8\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW15339136 BCX8\">IGA bezeichnet die <strong>Gesamtheit der Richtlinien, Prozesse und Technologien<\/strong>, die <strong>Identit\u00e4ten kontinuierlich verwalten<\/strong> und den Zugriff auf Systeme und Daten steuern \u2013 typischerweise mit <strong>Automatisierung<\/strong> f\u00fcr Access Reviews,\u00a0<\/span><\/span><a class=\"Hyperlink SCXW15339136 BCX8\" href=\"https:\/\/xiting.com\/de\/sap-knowledge\/identity-access-management\/ips\/\" target=\"_blank\" rel=\"noreferrer noopener\"><span class=\"TextRun Underlined SCXW15339136 BCX8\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW15339136 BCX8\" data-ccp-charstyle=\"Hyperlink\">Provisioning<\/span><\/span><\/a><span class=\"TextRun SCXW15339136 BCX8\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW15339136 BCX8\">\u00a0und\u00a0<\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW15339136 BCX8\">Deprovisioning<\/span><span class=\"NormalTextRun SCXW15339136 BCX8\">\u00a0sowie Compliance-Durchsetzung.<\/span><\/span><span class=\"EOP Selected SCXW15339136 BCX8\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a3c4473 elementor-widget elementor-widget-text-editor\" data-id=\"a3c4473\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<section class=\"xtn-check-section\">\n\n<ul class=\"xtn-check-list\">\n<li><span class=\"xtn-check-icon\">&#10003;<\/span>Wer steckt hinter mehreren Accounts \u2013 system\u00fcbergreifend in SAP und <a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/sap-s4hana\/cloud-connector\/\">Cloud<\/a>-Anwendungen?<\/li>\n<li><span class=\"xtn-check-icon\">&#10003;<\/span>Welche <a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/sap-berechtigungen\/\">Berechtigungen<\/a> \u2013 Rollen, Gruppen, Kataloge \u2013 hat eine Person, und wie wurden sie vergeben?<\/li>\n<li><span class=\"xtn-check-icon\">&#10003;<\/span>Ist dieser Zugriff noch gerechtfertigt \u2013 gemessen an Funktion, Unternehmenszugeh\u00f6rigkeit und Risikoprofil?<\/li>\n<li><span class=\"xtn-check-icon\">&#10003;<\/span>Bestehen SoD-Konflikte oder kritische Berechtigungen, die <a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/governance-risk-compliance\">Governance<\/a>-Aufmerksamkeit erfordern?<\/li>\n<li><span class=\"xtn-check-icon\">&#10003;<\/span>Was \u00e4ndert sich automatisch, wenn jemand eintritt, die Rolle wechselt oder das Unternehmen verl\u00e4sst?<\/li>\n<\/ul>\n\n<\/section>\n\n<style>\n  .xtn-check-section{\n    --xtn-red:#cd1316;\n    --xtn-ink:#1a1a1a;\n    font-family:\"Open Sans\",-apple-system,BlinkMacSystemFont,\"Segoe UI\",sans-serif;\n    box-sizing:border-box;\n  }\n  .xtn-check-section *{box-sizing:border-box;}\n\n  .xtn-check-p{\n    font-size:16px;\n    line-height:1.7;\n    color:var(--xtn-ink);\n    margin:0 0 18px;\n  }\n  .xtn-check-p-last{margin-bottom:0;}\n  .xtn-check-p-bold{font-weight:700;}\n\n  .xtn-check-list{\n    list-style:none;\n    margin:0 0 28px;\n    padding:0;\n    display:flex;\n    flex-direction:column;\n    gap:14px;\n  }\n\n  .xtn-check-list li{\n    display:flex;\n    align-items:flex-start;\n    gap:14px;\n    font-size:16px;\n    line-height:1.6;\n    color:var(--xtn-ink);\n  }\n\n  .xtn-check-icon{\n    flex-shrink:0;\n    width:24px;\n    height:24px;\n    border-radius:50%;\n    background:var(--xtn-red);\n    color:#ffffff;\n    font-size:12px;\n    font-weight:700;\n    display:flex;\n    align-items:center;\n    justify-content:center;\n    margin-top:1px;\n  }\n\n  .xtn-check-section a{\n    color:var(--xtn-red);\n    text-decoration:none;\n  }\n  .xtn-check-section a:hover{\n    text-decoration:underline;\n  }\n<\/style>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a7674a4 elementor-widget elementor-widget-text-editor\" data-id=\"a7674a4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"ewa-rteLine\"><br \/><br \/><strong><span class=\"TextRun SCXW213498645 BCX8\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW213498645 BCX8\">Wenn Ihr Unternehmen diese Fragen nicht zuverl\u00e4ssig und system\u00fcbergreifend beantworten kann, besteht eine Identity-<\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW213498645 BCX8\">Governance<\/span><span class=\"NormalTextRun SCXW213498645 BCX8\">-L\u00fccke \u2013 auch wenn einzelne Tools technisch vorhanden sind.<\/span><\/span><span class=\"EOP Selected SCXW213498645 BCX8\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/strong><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-59684e2 elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"59684e2\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Warum ist SAP-fokussierte Identity Governance besonders anspruchsvoll? <\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-237ce9d elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-text-editor\" data-id=\"237ce9d\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"ewa-rteLine\"><p><span class=\"TextRun SCXW215007375 BCX8\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW215007375 BCX8\">SAP ist keine einzelne Anwendung. In den meisten Unternehmen steuert es die gesch\u00e4ftskritischsten Prozesse \u2013 von Finanzen und Einkauf bis hin zu HR und Logistik. <\/span><\/span><\/p><p><strong>Die Herausforderung bei Identity\u00a0<\/strong><strong><span class=\"NormalTextRun SpellingErrorV2Themed SCXW215007375 BCX8\">Governance<\/span><span class=\"NormalTextRun SCXW215007375 BCX8\">\u00a0in SAP liegt nicht allein im Umfang, sondern im Zusammenspiel mehrerer sich gegenseitig verst\u00e4rkender Faktoren:<\/span><\/strong><strong><span class=\"EOP Selected SCXW215007375 BCX8\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/strong><\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c4c4d7f elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-text-editor\" data-id=\"c4c4d7f\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<section class=\"xtn-issue-section\">\n<div class=\"xtn-issue-grid\">\n\n<div class=\"xtn-issue-card\">\n<svg class=\"xtn-issue-icon\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<rect x=\"2\" y=\"5\" width=\"20\" height=\"14\" rx=\"2\" stroke=\"currentColor\" stroke-width=\"1.6\"\/>\n<circle cx=\"8\" cy=\"11\" r=\"1.8\" stroke=\"currentColor\" stroke-width=\"1.6\"\/>\n<path d=\"M5 15.5c.6-1.3 1.8-2 3-2s2.4.7 3 2\" stroke=\"currentColor\" stroke-width=\"1.6\" stroke-linecap=\"round\"\/>\n<path d=\"M14 9h5M14 12h5M14 15h3\" stroke=\"currentColor\" stroke-width=\"1.6\" stroke-linecap=\"round\"\/>\n<\/svg>\n<h3 class=\"xtn-issue-title\">Fragmentierte Identit\u00e4ten \u00fcber Systeme hinweg<\/h3>\n<p class=\"xtn-issue-text\"><span class=\"xtn-issue-arrow\">&rarr;<\/span>Nutzer haben oft unterschiedliche IDs, Namenskonventionen und Attributwerte \u2013 in SAP On-Premise, <a href=\"https:\/\/xiting.com\/de\/identity-and-access-management\/btp-security-id-lifecycle-management\/\">SAP BTP<\/a>, Cloud-Anwendungen und Drittsystemen. Ohne Konsolidierung ist system\u00fcbergreifende Governance nicht m\u00f6glich.<\/p>\n<\/div>\n\n<div class=\"xtn-issue-card\">\n<svg class=\"xtn-issue-icon\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<circle cx=\"12\" cy=\"7.5\" r=\"3.3\" stroke=\"currentColor\" stroke-width=\"1.6\"\/>\n<path d=\"M5.5 20c.9-3.6 3.7-6 6.5-6s5.6 2.4 6.5 6\" stroke=\"currentColor\" stroke-width=\"1.6\" stroke-linecap=\"round\"\/>\n<\/svg>\n<h3 class=\"xtn-issue-title\">Rollenkomplexit\u00e4t und vererbte Berechtigungen<\/h3>\n<p class=\"xtn-issue-text\"><span class=\"xtn-issue-arrow\">&rarr;<\/span><a class=\"xtn-issue-hl\" href=\"https:\/\/xiting.com\/de\/sap-knowledge\/sap-berechtigungen\/berechtigungskonzepte\/\">SAP-Berechtigungskonzepte<\/a> \u2013 mit Einzelrollen, Sammelrollen, abgeleiteten Rollen und <span class=\"xtn-issue-hl\">Fiori-Katalogen<\/span> \u2013 erzeugen Zugriffsschichten, die schwer nachzuverfolgen, zu reviewen und dauerhaft zu steuern sind.<\/p>\n<\/div>\n\n<div class=\"xtn-issue-card\">\n<svg class=\"xtn-issue-icon\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<circle cx=\"12\" cy=\"12\" r=\"9\" stroke=\"currentColor\" stroke-width=\"1.6\"\/>\n<ellipse cx=\"12\" cy=\"12\" rx=\"4\" ry=\"9\" stroke=\"currentColor\" stroke-width=\"1.6\"\/>\n<path d=\"M3 12h18M4.5 7.5h15M4.5 16.5h15\" stroke=\"currentColor\" stroke-width=\"1.6\"\/>\n<\/svg>\n<h3 class=\"xtn-issue-title\">Der Content-Lifecycle von Regelwerken<\/h3>\n<p class=\"xtn-issue-text\"><span class=\"xtn-issue-arrow\">&rarr;<\/span><a class=\"xtn-issue-hl\" href=\"https:\/\/xiting.com\/de\/sap-knowledge\/sod\/\">SoD<\/a>-Regeln, Definitionen kritischer Berechtigungen und Erkennungsmuster m\u00fcssen aktuell bleiben. Wenn SaaS- und Cloud-Anwendungen h\u00e4ufig aktualisiert werden, veralten statische Regelwerke schnell \u2013 und erzeugen blinde Flecken in der Risikoanalyse.<\/p>\n<\/div>\n\n<div class=\"xtn-issue-card\">\n<svg class=\"xtn-issue-icon\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M12 3l7 3v5.2c0 4.6-3 8.4-7 9.8-4-1.4-7-5.2-7-9.8V6l7-3z\" stroke=\"currentColor\" stroke-width=\"1.6\" stroke-linejoin=\"round\"\/>\n<path d=\"M9 12l2.1 2.1L15.5 9.5\" stroke=\"currentColor\" stroke-width=\"1.6\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\n<\/svg>\n<h3 class=\"xtn-issue-title\">Die L\u00fccke zwischen Governance und Monitoring<\/h3>\n<p class=\"xtn-issue-text\"><span class=\"xtn-issue-arrow\">&rarr;<\/span>Viele Unternehmen haben Governance-Prozesse wie Access Reviews und Genehmigungsworkflows, die in einem Quartalszyklus laufen \u2013 w\u00e4hrend <span class=\"xtn-issue-hl\">Bedrohungen und Richtlinienverst\u00f6\u00dfe<\/span> in Echtzeit auftreten. Ohne Br\u00fccke zwischen diesen Welten bleibt Governance reaktiv.<\/p>\n<\/div>\n\n<\/div>\n<\/section>\n\n<style>\n  .xtn-issue-section{\n    --xtn-red:#cd1316;\n    --xtn-ink:#1a1a1a;\n    --xtn-muted:#4a4f56;\n    font-family:\"Open Sans\",-apple-system,BlinkMacSystemFont,\"Segoe UI\",sans-serif;\n    background:transparent;\n    padding:32px;\n    box-sizing:border-box;\n  }\n  .xtn-issue-section *{box-sizing:border-box;}\n\n  .xtn-issue-grid{\n    display:grid;\n    grid-template-columns:repeat(2, 1fr);\n    gap:24px;\n  }\n\n  .xtn-issue-card{\n    background:#ffffff;\n    border-radius:18px;\n    padding:32px 30px;\n    box-shadow:0 10px 24px rgba(20,20,20,.06);\n  }\n\n  .xtn-issue-icon{\n    width:30px;\n    height:30px;\n    color:var(--xtn-red);\n    margin-bottom:18px;\n    display:block;\n  }\n\n  .xtn-issue-title{\n    font-size:20px;\n    line-height:1.3;\n    font-weight:700;\n    color:var(--xtn-ink);\n    margin:0 0 14px;\n  }\n\n  .xtn-issue-text{\n    font-size:16px;\n    line-height:1.65;\n    color:var(--xtn-muted);\n    margin:0;\n  }\n\n  .xtn-issue-arrow{\n    color:var(--xtn-muted);\n    margin-right:6px;\n  }\n\n  .xtn-issue-hl{\n    color:var(--xtn-red);\n    font-weight:400;\n    text-decoration:none;\n  }\n  a.xtn-issue-hl:hover{\n    text-decoration:underline;\n  }\n\n  @media (max-width:700px){\n    .xtn-issue-grid{\n      grid-template-columns:1fr;\n    }\n    .xtn-issue-section{padding:20px;}\n    .xtn-issue-card{padding:26px 22px;}\n  }\n<\/style>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bdb6abd elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-text-editor\" data-id=\"bdb6abd\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"ewa-rteLine\"><p><span data-contrast=\"auto\">Ein\u00a0weiterer Katalysator\u00a0ist das bevorstehende\u00a0<\/span><a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/ende-von-sap-idm\/\"><span data-contrast=\"none\">Wartungsende von SAP Identity Management (SAP IDM)<\/span><\/a><span data-contrast=\"auto\">:<strong>\u00a0Ende 2027\u00a0endet der regul\u00e4re\u00a0Wartungszyklus<\/strong> \u2013 ohne direkten Nachfolger. F\u00fcr Unternehmen, die noch auf SAP IDM setzen,\u00a0steigt damit der\u00a0Handlungsdruck\u00a0deutlich. Statt lediglich ein einzelnes Tool zu ersetzen, sollten sie\u00a0<strong>Identity\u00a0Governance\u00a0ganzheitlich\u00a0neu denken<\/strong>.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><p><strong>Hier\u00a0setzt\u00a0Xiting\u00a0mit der\u00a0<a href=\"https:\/\/xiting.com\/de\/xiting-security-platform\/\">Xiting\u00a0Security\u00a0Platform\u00a0(XSP)<\/a><\/strong><span data-contrast=\"auto\"><strong>\u00a0an<\/strong>:\u00a0Sie unterst\u00fctzt User- und\u00a0<\/span><a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/sap-lizenzen\/lizenzverwaltung\/\"><span data-contrast=\"none\">Berechtigungsmanagement<\/span><\/a><span data-contrast=\"auto\">, Compliance Management\u00a0sowie\u00a0system\u00fcbergreifende\u00a0Risikoanalysen\u00a0\u2013 erg\u00e4nzt durch\u00a0Real-Time-Monitoring mit SIEM-Integration \u00fcber\u00a0<\/span><a href=\"https:\/\/xiting.com\/de\/falcora\/\"><span data-contrast=\"none\">Xiting\u00a0Falcora<\/span><\/a><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><p><span data-contrast=\"none\">Die\u00a0<strong>Xiting\u00a0Security Platform\u00a0entwickelt\u00a0sich\u00a0zu\u00a0einer\u00a0integrierten\u00a0Identity Governance Platform<\/strong>. Moderne Identity-Lifecycle-Prozesse, Access Requests und Provisioning werden k\u00fcnftig direkt innerhalb von <strong>XSP Identity Managemen<\/strong>t\u00a0bereitgestellt,\u00a0w\u00e4hrend\u00a0<strong><a href=\"https:\/\/xiting.com\/en\/xiting-central-workflows\/\">Xiting\u00a0Central Workflows\u00a0<\/a><\/strong>insbesondere\u00a0bestehende\u00a0SAP-zentrierte\u00a0Szenarien\u00a0optimal\u00a0unterst\u00fctzt.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ec1bb53 elementor-widget elementor-widget-button\" data-id=\"ec1bb53\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/xiting.com\/de\/sap-knowledge\/ende-von-sap-idm\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-angle-double-right\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">SAP IDM  mit Xiting strategisch neu ausrichten<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-10e6327e elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"10e6327e\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">IGA vs. IAM vs. PAM \u2013 Was ist der Unterschied? <\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bf1423e elementor-widget elementor-widget-text-editor\" data-id=\"bf1423e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"ewa-rteLine\"><p><span class=\"TextRun SCXW117878661 BCX8\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW117878661 BCX8\" data-ccp-parastyle=\"Standard1\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;747f99d7-bd73-5996-86db-241716b17f98|1&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[469777841,&quot;Arial&quot;,469777842,&quot;Arial&quot;,469777843,&quot;Arial&quot;,469777844,&quot;Arial&quot;,469769226,&quot;Arial&quot;,335559740,&quot;240&quot;,201341983,&quot;0&quot;,335559739,&quot;0&quot;,201342446,&quot;1&quot;,201342447,&quot;5&quot;,201342448,&quot;1&quot;,201342449,&quot;1&quot;,201341986,&quot;1&quot;,268442635,&quot;24&quot;,469775450,&quot;Standard1&quot;,201340122,&quot;2&quot;,134233614,&quot;true&quot;,469778129,&quot;Standard1&quot;,335572020,&quot;1&quot;,469778324,&quot;Normal&quot;]}\">I<\/span><span class=\"NormalTextRun SCXW117878661 BCX8\" data-ccp-parastyle=\"Standard1\">m<\/span><span class=\"NormalTextRun SCXW117878661 BCX8\" data-ccp-parastyle=\"Standard1\">\u00a0SAP-Security-<\/span><span class=\"NormalTextRun SCXW117878661 BCX8\" data-ccp-parastyle=\"Standard1\">Kontext\u00a0<\/span><span class=\"NormalTextRun SCXW117878661 BCX8\" data-ccp-parastyle=\"Standard1\">werden IAM, IGA und PAM<\/span><span class=\"NormalTextRun SCXW117878661 BCX8\" data-ccp-parastyle=\"Standard1\">\u00a0oft gleichgesetzt. Dabei<\/span><span class=\"NormalTextRun SCXW117878661 BCX8\" data-ccp-parastyle=\"Standard1\"><strong>\u00a0\u00fcberschneiden<\/strong>\u00a0<\/span><span class=\"NormalTextRun SCXW117878661 BCX8\" data-ccp-parastyle=\"Standard1\">sie\u00a0<\/span><span class=\"NormalTextRun SCXW117878661 BCX8\" data-ccp-parastyle=\"Standard1\">sich<\/span><span class=\"NormalTextRun SCXW117878661 BCX8\" data-ccp-parastyle=\"Standard1\">\u00a0zwar, adressieren<\/span><span class=\"NormalTextRun SCXW117878661 BCX8\" data-ccp-parastyle=\"Standard1\">\u00a0aber u<strong>nterschiedliche\u00a0<\/strong><\/span><span class=\"NormalTextRun SCXW117878661 BCX8\" data-ccp-parastyle=\"Standard1\"><strong>Aufgaben<\/strong>. Wer diese Unterschiede nicht sauber trennt, riskiert<\/span><span class=\"NormalTextRun SCXW117878661 BCX8\" data-ccp-parastyle=\"Standard1\">\u00a0ein unvollst\u00e4ndiges\u00a0<\/span><span class=\"NormalTextRun SCXW117878661 BCX8\" data-ccp-parastyle=\"Standard1\">Sicherheitsprogramm<\/span><span class=\"NormalTextRun SCXW117878661 BCX8\" data-ccp-parastyle=\"Standard1\">.<\/span><\/span><span class=\"EOP Selected SCXW117878661 BCX8\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-78cc52d1 elementor-widget elementor-widget-text-editor\" data-id=\"78cc52d1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<section class=\"xtn-table-section\">\n<div class=\"xtn-table-wrap\">\n<table class=\"xtn-table\">\n<thead>\n<tr>\n<th><\/th>\n<th>IAM<\/th>\n<th>IGA<\/th>\n<th>PAM<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"xtn-td-label\" data-label=\"\">Kernfrage<\/td>\n<td data-label=\"IAM\">Wer sind Sie?<\/td>\n<td data-label=\"IGA\">Sollten Sie diesen Zugriff haben \u2013 und warum?<\/td>\n<td data-label=\"PAM\">Wer kontrolliert die sensibelsten Privilegien?<\/td>\n<\/tr>\n<tr>\n<td class=\"xtn-td-label\" data-label=\"\">SAP-Fokus<\/td>\n<td data-label=\"IAM\">SSO, MFA, Verzeichnisse, grundlegende Zugriffsvergabe<\/td>\n<td data-label=\"IGA\">SoD, Access Reviews, Lifecycle-Automatisierung, Audit-Nachweise<\/td>\n<td data-label=\"PAM\">Firefighter-Zugriff, Notfallzugang, Session Controls<\/td>\n<\/tr>\n<tr>\n<td class=\"xtn-td-label\" data-label=\"\">Scope<\/td>\n<td data-label=\"IAM\">Authentifizierung und Zugriffsfreigabe<\/td>\n<td data-label=\"IGA\">Governance, Compliance und kontinuierliche Durchsetzung<\/td>\n<td data-label=\"PAM\">Hochriskanter, hochwirkungsvoller Zugriff<\/td>\n<\/tr>\n<tr>\n<td class=\"xtn-td-label\" data-label=\"\">Risiko bei isoliertem Einsatz<\/td>\n<td data-label=\"IAM\">Nutzer authentifiziert, aber Zugriff nicht dauerhaft gerechtfertigt<\/td>\n<td data-label=\"IGA\">Richtlinien vorhanden, aber kein Bezug zur tats\u00e4chlichen Nutzung<\/td>\n<td data-label=\"PAM\">Privilegiertes Risiko reduziert, Standardrollen aber weiterhin ungesteuert<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/section>\n\n<style>\n  .xtn-table-section{\n    --xtn-red:#cd1316;\n    --xtn-ink:#33373b;\n    --xtn-muted:#6a6f76;\n    --xtn-border:#ededed;\n    --xtn-bg:#ffffff;\n    --xtn-row-alt:#f9f9fa;\n    font-family:\"Open Sans\",-apple-system,BlinkMacSystemFont,\"Segoe UI\",sans-serif;\n    background:#ffffff;\n    padding:40px 20px;\n    box-sizing:border-box;\n  }\n  .xtn-table-section *{box-sizing:border-box;}\n\n  .xtn-table-wrap{\n    max-width:1200px;\n    margin:0;\n    border-radius:18px;\n    overflow:hidden;\n    box-shadow:0 8px 28px rgba(20,20,20,.05);\n    border:1px solid var(--xtn-border);\n  }\n\n  .xtn-table{\n    width:100%;\n    border-collapse:collapse;\n    background:var(--xtn-bg);\n  }\n\n  .xtn-table thead th{\n    background:var(--xtn-red);\n    color:#ffffff;\n    font-size:15px;\n    font-weight:700;\n    text-align:left;\n    padding:16px 22px;\n  }\n\n  .xtn-table tbody td{\n    font-size:14.5px;\n    line-height:1.6;\n    color:var(--xtn-muted);\n    padding:16px 22px;\n    border-bottom:1px solid var(--xtn-border);\n    vertical-align:top;\n  }\n\n  .xtn-table tbody tr:last-child td{\n    border-bottom:none;\n  }\n\n  .xtn-table tbody tr:nth-child(even){\n    background:var(--xtn-row-alt);\n  }\n\n  .xtn-td-label{\n    font-weight:700;\n    color:var(--xtn-ink);\n  }\n\n  .xtn-table tbody td a{\n    color:var(--xtn-red);\n    text-decoration:none;\n  }\n  .xtn-table tbody td a:hover{\n    text-decoration:underline;\n  }\n\n  \/* ---------- Responsive fine-tuning ---------- *\/\n  @media (max-width:767px){\n    .xtn-table-section{padding:32px 16px;}\n  }\n\n  \/* ---------- Mobile: Tabelle wird zu gestapelten Karten ---------- *\/\n  @media (max-width:600px){\n    .xtn-table-wrap{overflow-x:visible !important;border:none !important;box-shadow:none !important;border-radius:0 !important;}\n    .xtn-table{display:block !important;width:100% !important;table-layout:auto !important;}\n    .xtn-table thead{display:none !important;}\n    .xtn-table tbody{display:block !important;}\n    .xtn-table tbody tr{\n      display:block !important;\n      width:100% !important;\n      height:auto !important;\n      margin-bottom:16px;\n      border:1px solid var(--xtn-border);\n      border-radius:14px;\n      overflow:visible !important;\n      box-shadow:0 6px 20px rgba(20,20,20,.05);\n    }\n    .xtn-table tbody tr:nth-child(even){background:var(--xtn-bg);}\n    .xtn-table tbody td{\n      display:block !important;\n      width:100% !important;\n      height:auto !important;\n      max-width:none !important;\n      padding:12px 16px;\n      border-bottom:1px solid var(--xtn-border);\n      white-space:normal !important;\n      overflow:visible !important;\n    }\n    .xtn-table tbody tr:last-child td:last-child,\n    .xtn-table tbody td:last-child{border-bottom:none;}\n    .xtn-table tbody td.xtn-td-label{\n      background:var(--xtn-red);\n      color:#ffffff;\n      font-size:15px;\n    }\n    .xtn-table tbody td:not(.xtn-td-label)::before{\n      content:attr(data-label);\n      display:block !important;\n      font-size:11px;\n      font-weight:700;\n      text-transform:uppercase;\n      letter-spacing:.03em;\n      color:var(--xtn-red);\n      margin-bottom:4px;\n    }\n  }\n<\/style>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-620f630e elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"620f630e\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Typische Stolpersteine bei SAP-Kunden <\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5e7f293a elementor-widget elementor-widget-text-editor\" data-id=\"5e7f293a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"ewa-rteLine\"><p><span data-contrast=\"auto\"><strong>In der Praxis zeigt sich h\u00e4ufig dasselbe Muster:<\/strong> Unternehmen f\u00fchren eine einzelne Schicht ein und nehmen an, dass die \u00fcbrigen Anforderungen damit automatisch erf\u00fcllt sind.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><ul><li aria-setsize=\"-1\" data-leveltext=\"\u2022\" data-font=\"\" data-listid=\"9\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"10\" data-aria-level=\"1\"><strong>IAM ohne IGA und PAM:<\/strong><span data-contrast=\"auto\"><strong>\u00a0<\/strong>Nutzer k\u00f6nnen sich sicher authentifizieren \u2013 aber Zugriffsrechtfertigung,\u00a0SoD-Kontrolle und auditf\u00e4hige Nachweise fehlen.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:60,&quot;335559739&quot;:60,&quot;335559740&quot;:360}\">\u00a0<\/span><\/li><\/ul><ul><li aria-setsize=\"-1\" data-leveltext=\"\u2022\" data-font=\"\" data-listid=\"9\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"11\" data-aria-level=\"1\"><strong>PAM ohne IGA:<\/strong><span data-contrast=\"auto\"><strong>\u00a0<\/strong>Das Risiko privilegierter Zugriffe sinkt \u2013 aber Access Creep und\u00a0Governance-L\u00fccken in Standardgesch\u00e4ftsrollen bleiben bestehen.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:60,&quot;335559739&quot;:60,&quot;335559740&quot;:360}\">\u00a0<\/span><\/li><\/ul><ul><li aria-setsize=\"-1\" data-leveltext=\"\u2022\" data-font=\"\" data-listid=\"9\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"12\" data-aria-level=\"1\"><strong>IGA ohne operative Integration:<\/strong><span data-contrast=\"auto\"><strong>\u00a0<\/strong>Richtlinien und Workflows existieren \u2013 aber\u00a0Governance-Entscheidungen sind nicht mit tats\u00e4chlicher Nutzung und Security Monitoring verkn\u00fcpft.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:60,&quot;335559739&quot;:60,&quot;335559740&quot;:360}\">\u00a0<\/span><\/li><\/ul><p><span data-contrast=\"auto\"><strong>Das Ziel ist nicht, sich f\u00fcr eine\u00a0einzelne\u00a0Disziplin zu entscheiden, sondern IAM, IGA und PAM\u00a0SAP-zentrisch zu verbinden:<\/strong><br \/><br \/><strong>\u2192 <\/strong>IAM schafft starke Identit\u00e4t und Authentifizierung, IGA liefert den Nachweis angemessener Zugriffe und PAM sch\u00fctzt\u00a0die sensibelsten Privilegien.<br \/><br \/>Erst in Verbindung mit Monitoring wird daraus eine <strong>Governance<\/strong>, die nicht nur im Quartalszyklus wirkt, sondern <strong>laufend auf reale Risiken<\/strong> reagiert.<\/span><\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2e96324f elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"2e96324f\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Identity Governance Solutions und Frameworks <\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a71ff1c elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"a71ff1c\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Die \"Vier A\u2032s\" f\u00fcr ein Identity-Governance-Framework <\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-39392ba4 elementor-widget elementor-widget-text-editor\" data-id=\"39392ba4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"ewa-rteLine\"><p><span data-contrast=\"auto\">Wenn es darum geht, Identity\u00a0Governance\u00a0and Administration gegen\u00fcber Entscheidern zu erkl\u00e4ren, funktionieren einfache Frameworks am besten \u2013 vorausgesetzt, sie bilden die SAP-Realit\u00e4t weiterhin ab.\u00a0<\/span>\u00a0<\/p><p><strong>Ein\u00a0praktisches\u00a0Modell\u00a0sind\u00a0die &#8222;Vier A\u2032s&#8220;:\u00a0<\/strong><\/p><ul><li aria-setsize=\"-1\" data-leveltext=\"\u2022\" data-font=\"\" data-listid=\"9\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"13\" data-aria-level=\"1\"><span data-contrast=\"auto\"><strong>Authenticate<\/strong>\u00a0\u2013 die Eingangst\u00fcr: Wie Identit\u00e4ten durch SSO, MFA und starke Authentifizierung nachweisen, wer sie sind.\u00a0<\/span><span data-contrast=\"auto\">Ist\u00a0die\u00a0Authentifizierung\u00a0schwach,\u00a0wird\u00a0alles\u00a0Nachgelagerte\u00a0reaktiv.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:60,&quot;335559739&quot;:60,&quot;335559740&quot;:360}\">\u00a0<\/span><\/li><\/ul><ul><li aria-setsize=\"-1\" data-leveltext=\"\u2022\" data-font=\"\" data-listid=\"9\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"14\" data-aria-level=\"1\"><span data-contrast=\"auto\"><strong>Authorize\u00a0<\/strong>\u2013 wo SAP lebt: Rollen, abgeleitete und Sammelrollen, Kataloge, Gruppen und die Disziplin der Least Privilege. Hier m\u00fcssen\u00a0SoD\u00a0und kritische Berechtigungen nicht nur dokumentiert, sondern aktiv durchgesetzt werden.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:60,&quot;335559739&quot;:60,&quot;335559740&quot;:360}\">\u00a0<\/span><\/li><\/ul><ul><li aria-setsize=\"-1\" data-leveltext=\"\u2022\" data-font=\"\" data-listid=\"9\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"15\" data-aria-level=\"1\"><span data-contrast=\"auto\"><strong>Administer\u00a0<\/strong>\u2013 der operative Herzschlag: Joiner\/Mover\/Leaver-Prozesse, Zugriffsantr\u00e4ge, Genehmigungen sowie\u00a0Provisioning\u00a0und\u00a0Deprovisioning\u00a0\u2013 idealerweise automatisiert und standardisiert, damit\u00a0Governance\u00a0das Unternehmen nicht verlangsamt.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:60,&quot;335559739&quot;:60,&quot;335559740&quot;:360}\">\u00a0<\/span><\/li><\/ul><ul><li aria-setsize=\"-1\" data-leveltext=\"\u2022\" data-font=\"\" data-listid=\"9\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\u2022&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" data-aria-posinset=\"16\" data-aria-level=\"1\"><span data-contrast=\"auto\"><strong>Audit \u2013<\/strong> wo\u00a0Governance\u00a0real wird: Nachweise, Nachvollziehbarkeit, Review-Historie und Monitoring-Signale, die belegen, dass Kontrollen funktionieren \u2013 und Abweichungen fr\u00fchzeitig sichtbar machen.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:60,&quot;335559739&quot;:60,&quot;335559740&quot;:360}\">\u00a0<\/span><\/li><\/ul><p><span data-contrast=\"auto\">Diese Struktur ist f\u00fcr die Gesch\u00e4ftsf\u00fchrung verst\u00e4ndlich und f\u00fcr SAP-Teams direkt anwendbar. Sie zeigt sofort, welche Schicht stark ist, welche fehlt \u2013 und wo\u00a0<strong>Xiting-L\u00f6sungen (Governance, Workflows, Content, Monitoring)<\/strong> die L\u00fccken schlie\u00dfen.<\/span><\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3412826 elementor-widget__width-initial elementor-widget elementor-widget-html\" data-id=\"3412826\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<script src=\"https:\/\/fast.wistia.com\/player.js\" async><\/script><script src=\"https:\/\/fast.wistia.com\/embed\/e15uh4ltoa.js\" async type=\"module\"><\/script><style>wistia-player[media-id='e15uh4ltoa']:not(:defined) { background: center \/ contain no-repeat url('https:\/\/fast.wistia.com\/embed\/medias\/e15uh4ltoa\/swatch'); display: block; filter: blur(5px); padding-top:64.79%; }<\/style> <wistia-player media-id=\"e15uh4ltoa\" aspect=\"1.5434083601286173\"><div class=\"wistia_preload_transcript_outer_wrapper\" style=\"width: 100%; height: 100%; display:flex; justify-content:center; align-items: center; margin-top:-64.79%;\"><div class=\"wistia_preload_transcript_inner_wrapper\" style=\" overflow: auto;\"><p class=\"wistia_preload_transcript_text\" aria-hidden=\"true\" tabindex=\"-1\" style=\"text-align: justify; font-size: 5px !important;\">And I'd like to thank everyone and I'd like to thank everyone for joining us today. But before we begin the webinar, just a few quick housekeeping items. Recording of the webinar will be provided after the session here today for any participants that have signed up or or joined or if you need to leave halfway through. We will provide a copy of the webinar recording to you after the call has been completed. Participants' webcams and microphones have been turned off to ensure audio quality. If you have any questions throughout the presentation, please feel free to submit them in the chat. We will reserve time at the end of the session to review and address as many of those questions as possible. But with that, let's go ahead and get started. My name is Alex Manning, and I am the managing con managing consultant, for the Americas here at Xciting. And joining me on the call today is Alessandra Banzer, who is the CEO of the Americas. I'll be moderating today's webinar titled the SAP centric IGA blueprint for hybrid landscapes. And this session really marks the first webinar in our security madness two thousand twenty six series, which is our March themed program inspired by the excitement and competitive spirit of the well known college basketball tournament, March Madness. And then we can see here them repping the Kentucky team here. But, anyway, this session marks the first web or whoops. Much like our tournament itself, success in SAP security comes down to preparation, structure, and strong fundamentals. The organizations that advance are the ones that build on a solid foundation and execute with discipline. Across this series, we'll break down the key building blocks of a resilient SAP security strategy starting with today's presentation, which is defining the IGA blueprint. The following webinars that follow will talk about redesigning roles and authorizations, implementing SOD and risk analysis, modernizing the identity life cycle management, as well as ultimately advancing toward an AI driven security monitoring for SAP environments. And each of these sessions ultimately build on the last just like progressing through a bracket. And today, we tip-off with the blueprints. Today's session focuses on something every organization talks about, but not every organization truly designs, an SAP centric IGA blueprint. Hybrid landscapes are now the norm, which include s four HANA environments, ECC remnants, cloud applications, BTP services, third party integrations, and now even AI driven tools and autonomous agents operating together. The challenge isn't simply governing identity. It's governing its consistency across that complexity, managing both human and nonhuman identities within a unified framework. Without a blueprint, IGA really becomes reactive. But with a blueprint, we can become strategic. Today's discussion really sets that architectural vision for everything that follows with the security madness series that we have for March. And with that, I'll go ahead and turn the webinar over to Alessandro to begin the presentation portion. Thank you, Alex, and welcome, everyone. My name is Alessandro Benser. Like Alex said, I I head up the Americas for exciting. I've been in SAP security and GSE for, I think, almost twenty years now. I'm getting old, that means. And, yeah, I'm very excited to to be here today to talk about the IGA and the IGA blueprint. And as Alex pointed out, it's, like, a high level overview that goes into certain details and recovering a lot of of the aspects that are then also laid out in in the in the following sessions. So what do I have on the agenda for today? At first, a little bit about exciting. Just for those of you that are new and that have maybe haven't had interaction with us yet, just a little bit couple minutes about about us, what we do, why we're here, why we're talking to you. And then we wanna, dive into the topics. I wanna talk about that ITA, identity governance and administration. What does that mean? What's what is a modern ITA? Why is it important? Especially, why is it important now? What changes with AI, with the AI, with all those LLM new things that are that are coming out and are probably already in your environment? How do we, you know, guard that? How do we protect that? How do we, you know, talk governance and all the aspects around? And also a little bit, you know, why you have to adjust your IGA or why your traditional IGA will fail, and, you how we have to then really incorporate these new things into into your IGA blueprint. With that, let me get started. Let's start over with just, like I said, a couple minutes about Xighting. We've been around for, quite a while since two thousand eight. Originally founded in in Switzerland. We're an SAP solution provider in in in particular in sub security. We have a lot of solutions. So we're a solution provider. We also do consulting services, and all our solutions, they are SAP certified. So we are fully certified for S4HANA, S4HANA Cloud, and and different other certifications that we hold as well. We're also, obviously, SAP partners, and like I said, very heavily focused on on SAP security. We have offices throughout the world, I would say. Like I said, originally, we're from Switzerland, but we have offices in in Germany, in Romania, in the UK. Also here in United States, we have, sales locations in Argentina and Colombia, and we have, obviously, a global presence through our partners. So we work with over over eighty global partners that, use our tools, our services, and, you know, distribute our knowledge and our experience and, obviously, the solutions as well to a global audience. We very heavily focus on four pillars, I would say. The first one, that's also where we originally come from. That's particularly our authorizations management. So we typically or traditionally come from, yeah, ABAP authorizations or ABAP authorization concepts, redesigns, S4HANA migrations, Fiori security implementations. Anything around roles and authorizations management, that's where we originally come from. That's also where we have our flagship solution, the exciting authorizations management suite that really enables and accelerates anything, authorizations related. So when it comes to role building, role testing, role design implementation, fallback, go live scenarios, anything and everything around the authorizations management, that's, you know, what we do. That's our bread and butter. Then we also moved into different areas over the years. One big area is obviously also the entity access management, I'm more than also now more the ITA portion of it where we talk about and and, obviously, have solutions when it comes to user management. So the workflow driven approach for self-service capabilities, integrations into HR applications. We'll talk about that a little bit later. But then also anything when it when when when when it comes to the entities in general with the cloud and the services, we do a lot of consulting in that area as well, b two p security, implementing security concepts for those, and making sure we have a holistic approach and and, you know, a governed and secure environment also when it goes beyond just a traditional app up on prem. Then we also do a lot of things in regards of cybersecurity and security monitoring. We have a very exciting session coming up. That's I think it's the fifth session where we talk about our AI driven security operation centers over the end of the month, the end of of March, we're releasing a new a new solution that fully automates the security operations centers or the SOC level. We'll talk about that briefly today as well. But, obviously, we also have other capabilities when it comes to security monitoring, cybersecurity monitoring, especially in regards to anything SAP, up up on prem or or on prem application in general, but then also cloud logs, making sure that, you know, everything that we've implemented stays compliant, stays secure, and, you know, therefore, we also have different capabilities around there. We also have a lot of integrations in general. We'll better it in in a in just a minute. And so we also integrate with, you know, standard solutions like Centimeters applications for event and information monitoring solutions and so on, different integration capabilities. And then last but not least, we also talk about governance risk compliance. That's where I originally come from. I've been doing sub g o c or access control in IHE for almost fifteen plus years, almost eighteen or nineteen years. That's how old I am. And, obviously, there we talk about, you know, emergency and and privilege access, obviously, the rule set topic, which is very important. We have a specific session on that topic as well because, you know, rule sets are important, especially with all the governance and and, you know, comp compliance requirements we have. And that's obviously also important in a hybrid landscape, especially also when we move towards cloud and get more and more solutions covered. Cross system risk analysis, simulations, you know, mitigation scenarios, all those things come together, and we have solutions for all of that. And that's ultimately what we do. With the solutions, we're not just a solution provider. We also do consulting services. So if you're interested in any kind of of of, you know, consulting, whether it's managed services or more like package services that we can deliver or then also project or sales consulting, so when it really means to implement, redesign, migrate, any any type of guidance and consulting support you need, we we provide that as well with our consulting units throughout the globe. With that, let's go a little deeper just for another minute. We have an entire portfolio, obviously, of services and solutions. And what's important for us is we live and we have our our, yeah, our saying is get connected, run secure. So what does that mean? We have a lot of solutions, lot of solutions that have been around for many, many years, and a lot of solutions that are used by various customers around the globe in any industry, any size and regulation that they have to follow. But we don't reinvent the wheel. So we want to make sure that we, you know, get connected and run secure, which means, you know, instead of reinventing the wheel, we also connect. So lot of our solutions, they're also available to integrate with existing solutions. So if there's something already in place, it's very likely that we offer interfaces connectivity to those applications. So in in you know, that that goes from, obviously, the classical authorizations and user management, whether you do those through our tools or if you're using, let's say, like, an IEM solution, like a SailPoint or Nomada or even a sub access control to your c or sub IDM. We can connect to those and then provide additional functionality like your risk risk simulation, risk analysis, license analysis, anything that we provide with solutions, we can also offer in an integrative way with those applications. We connect to Centimeters applications. We connect to licensing solutions for proper license management, and then, obviously, anything and everything within the SAP ecosystem that we support and and connect to. With that, enough about what we do. Let's talk about the topic. The IGA or entity governance and administration is a very, very important aspect. The entity governance administration talks about life cycle, excess governance or governance in general, and then, obviously, the entire administration aspect of how do we maintain, how do we, you know, handle all that. So I have a couple slides prepared. First and foremost, I just wanted to get started with, like, what is IGA? You know? Because maybe not everyone of you is familiar with IGA or has not really heard the term. Oftentimes, we, you know, use one term and mean another. But IGA is basically a framework, and that's that ultimately answers your most critical security questions. And ICA is more than just for SAP. Today, we're talking very specifically on SAP, so I wanna be SAP focused. But ICA is a broader topic. It's a framework, And it's a framework that ensures that the right people have the right access to the right resources at the right time and that you can prove it. That's the ultimately what it comes down to. So what does that mean? That means it handles all your entities, human, nonhuman. We'll get to it in a second, especially with AI, with the bots, with the agents. Very, very important. But IT ultimately really follows that approach. Like, it will it it it needs to tell you who has access to what, should they have it from a GRC perspective, SOTs, critical authorizations, or other governance aspects, who approved it, and when. So it's the entire audit trail that's important, and that's ultimately also what your what your what your auditors will ask you. They will ask you those those four questions. Who has access to what? Who approved it? And when was it granted? That's ultimately what an IHA solution needs to provide you. What needs to prove you is that you have a proper implementation, a proper life cycle that, you know, has governance aspects, and then the entire audit trail for visibility, all the analytics capabilities that are audit ready for any type of reviews. That's very, very important. So I chase a framework. It's not necessarily a a tool, you could say. It's more a framework, more an approach where we have to follow and consider many, many many, many different points that that that that that go towards that. So when we look at modern identity and governance and administration framework or a solution that provides those IGA capabilities? What are the most important features that we have? We have that in three silos, as I like to call them. We have the life cycle. We have the governance aspect and then the entire intelligence. On the life cycle, and that's obviously very, very important. The life cycle and and also governance, knows intelligence needs to handle and needs to be available and and around for not just your human entities, also for your nonhuman entities, like your AI agents, your bots, your service users, your interfaces, pretty much anything. So we need to establish life cycle processes for anything and everything that's that's that's accessing your applications. Very, very often, obviously, we we start with with human interaction, and there we have typical, like, join and mover lever processes where, you know, we have provisioning, deprovisioning, and all those good things, we won't have triggered automatically if possible. So if you have a, like, an HR application in place, like SuccessFactors or Workday, we wanna make sure that when our HR department enters a joiner, that a process gets triggered automatically. Or if you have someone that leaves the organization, that we deprovision the access automatically. That's very, very important. And, obviously, also in between, so the entire life cycle from hire to retire, as we also call it, job changes, organizational changes, all those things need to be reflected, and we always have to live the the process. Again, I think there, one of the most important things is that we automatically trigger it. That makes it that makes it, yeah, that makes it much more efficient and helps along the way also to, you know, prove compliance down the road. In the life cycle, obviously, we also wanna include the governance aspect. So for example, the SOD controls, cross system SODs, critical authorizations, you know, checking for critical transaction codes, Fiori access. We shouldn't leave Fiori out now because Fiori becomes very popular. But then also not just the for on prem. It also needs to be for cloud applications, for your S4HANA public cloud, but also for others like SuccessFactors, Ariba, Fidelis. There's a lot of things in there that are also critical that lead to SOD conflicts, and those need to be established as part of the life cycle as well. With the life cycle, obviously, as well, and that's also in the context of IHE, very, very important, is your back end authorization. So your classical ABAP authorization concept, obviously, needs to needs to be adjusted or needs to follow certain principles. So if we wanna remediate SOD findings, we have to start in the authorizations. Because if we have roles and authorizations built in PFCG that are, you know, totally overloaded with authorizations, it's very difficult to remediate that on a user level. So we also have to consider the overarching ITA framework also down to the authorization, not just in your ABAP on prem. That's typically the core application. That's where we have the most authorizations and the most the the the most reasons to to separate and and then have a close eye on those. But also for other applications like your SuccessFactors, your Fieldglass, and all the others need to follow that as well. It's ultimately important because when we do the life cycle, when we have, let's say, a joiner or a mover or a lever process, oftentimes, we also wanna automate those entirely. So when we have someone joining the organization, we wanna provision the user. Provision the user doesn't just mean we're creating a user ID and and and create the account. We maybe also wanna provide certain access, and that's one something we call birthright access. So they get that access when they're born, basically. So the identity is born, and then we provide certain access along with it that can be based on on the job, that can be based on the position, on the organization. And if we do those type of life cycles, which ultimately then will make our process much more efficient and automated and also from their perspective more compliant because we have certain guardrails in place, that goes back down to a proper authorization concept. So if I have proper authorizations controlled, then I also control the the change, There's a proper change controls on my authorizations and including all those governance aspects, then I can also automate the life cycle for, like I said, typically for joiners, providing access for movers, deprovisioning old access, granting new access, all the way to a lever when someone retires to taking all the access away, locking users and invalid users as well. So the life cycle is very important, but the life cycle alone is not everything. We also need the governance So we have, obviously, certain things, like we said, we can automate, but others we cannot. So certain things need to be provided in addition to what is automatically provided. Like, for example, then we talk about self-service capabilities, you know, giving the users or manager, whoever, the ability to request additional access, but also those additional access that is not automatically provided needs to be governed. We have to have policy enforcement, SOT checks, critical authorizations, mitigation strategies, and so on. Very, very important. Again, not just for your human identities, also for your nonhuman identities. So for your bots, for your RFC interfaces, for your technical users, for the agents, and so on. And that all goes for everything, for the life cycle, for the governance, and then also the intelligence. In the governance aspect, we also wanna make sure we orchestrate workflows. We have a lot of different workflows that concern IGA, typically your typically your user provisioning workflows where we have, you know, multistage approval processes, manager approvals, role on approval, risk owner approvals, maybe an admin that needs to interfere. Maybe we have license implications where license costs like, a user might you know, new authorization might lead to to a higher license cost. Maybe we have an additional approval for that or someone that reviews that. So a lot of things need to be orchestrated, need to come together. Not just the access request where we provide access and deprovision access, also the entire review when we talk about access certification, user access reviews, but also reviews of role content and other things that need to be reviewed. That's very often done in campaigns and also can be prioritized by by risk level, by criticality. Sometimes also certain thing need to be done by calendar date, not exclusively, but some need to be done once a year and so on. But that's also very important that they feed into that. So if we do user access reviews and we deprovision access, we have to make sure that, you know, that's governed through an ITA approach and properly documented audit trails and so on. So even we take something away, we always have to be able to document why and who decided when and what. That's very, very important. The last pillar is the intelligence aspect. That's all about reporting analytics. So different dashboards, obviously, evidence packages that need to be put together. And that's obviously very, very important as well, and the audit will come one way or the other. And it's important that we have that always available, not just when the auditor asks for it. So we shouldn't put the evidence packs together when the auditor asks. The application needs to support that. And, obviously, modern applications, that's a hundred percent mandatory, and we always have to be able to answer the who, what, why, when, and that that's important. We also talk about the entire entitlements, obviously, from on prem to cloud. You know, different applications have different authorization concepts. Insights into those is is critical, but then also understanding and, you know, building rules around that. And like I said, for the nonhuman entities and the entire AI agents, and they're booming right now, we'll we'll get to that in just a minute, we also have to ensure that all these processes, the life cycle, the governance aspects, but then also the intelligence needs to also exist now for all those technical or nonhuman identities. That's very, very important. Because even there, if something happens, in order to will ask who approved when and why and what, and that's why we also have to include that into our, IGA approach. I'm not sure. Kati, do we have a a quick poll on that? I think we have a quick poll just to yeah. There we go. Just a just a quick poll just out of out of curiosity that we wanted to see. We have, like, two two quick question. The first one is, you know, what's the the biggest thing of slowing down your IGA in today's landscape? And then the second one will be around the AI agents. So if you wanna answer those, that would be fantastic. Then we can also, I mean, a little bit look at, you know, what the what the answers are. But let me continue. So IGA is obviously, yeah, a big a big topic for many organizations, and it's also becoming a board level topic. So more executives and more, you know, higher ups are now talking about IGA, and it's important that we address that and also look at that very, very briefly. So first and foremost, identity is the number one attack vector for most organizations. What does that mean? We have insider threat. We have, you know, obviously, externals like hackers or in you know, criminals that try to exploit and and get access to this. But also the insider threat where we know the human, the the people, they are ultimately a risk to our organization. So identity is the number one attack vector. That means, especially for SAP applications, that's a hundred percent true because SAP especially how they it holds all our sensitive business data. You know? That's basically our secret sauce. That is in SAP. We have the financial records, all the payroll, HR, all the like I said, the secret sauce is in SAP. And that's why whenever there's a breach in SAP, it's not just an I c IT incident, it's really a business crisis. That's why it's very important that we address identity, that we live a proper workflow, a proper life cycle, govern that, and have the ability to administrate and get intelligence on it to always report who, what, when, and why. AI agents, like I mentioned, we'll have have a slide just the next slide, we'll talk a little bit more about AI agents and what that means. But AI agents and AI in general is becoming overly popular. I mean, I think you guys have all all seen and heard and and and have your experience with AI. It's incredibly powerful already, and it's it's only going, you know, gonna be more and more. And SAP is pushing it hard as well. We have tool. We have b two p automations. We have other AI tools around that are integrated. And also those, we now have to address because, ultimately, what we see a lot is now, you know, organizations are adopting AI because it's it's fancy. It's interesting. It it solves problems, creates others, but it's also very interested in learning more or trying out, and we're we're we're we're trying to automate and, you know, lower headcounts and save money and all those good things. But, ultimately, it also has an inherent risk that we have to also manage those entities. We see it many times where, you know, we start with, like, a POC. We, you know, let let an AI agent operate with my authorizations, and then we go to production, and it still has my authorizations. And that should not be the case. We don't know who approved the access. We don't have specific roles for it. We don't know anything about it. And so that's why it's important that we also, you know, talk about AI, and that's also why IT now is becoming a board level topic because we have to address and also answer questions on the AI side. Then, obviously, there are a couple of things also impacting the the the board. That's obviously the sub IDM. Many of you probably have sub IDM in place. It's going out of maintenance in end of twenty twenty seven, so there needs to be a replacement solution one way or the other because it's all going out of maintenance. A lot of organizations are shopping around. There's different applications or different solutions out there that can help with that, and that's obviously also one driving factor into really talking ITA and talking ITA strategy, you know, more than just probably more than just just on the SAP side. Then we have a lot of a huge a huge gain or a huge drive towards the hybrid landscape. So we have more and more applications that come into picture and not just our on prem ECC like it used to be in the days. Now it's s four, s four on prem, s four cloud, public cloud. We have BTP. We have all kind of cloud apps, SuccessFactors, Ariba, you name it. And then also non SAP or third party apps that are now all of a sudden hosted on BTP that have identities, two things. We have the we have bots, you know, the the RPAs and so on. And there's a lot of identities that are that are that are now, you know, coming around and not just in one application, cross application in the entire landscape. And that's the hybrid landscape makes it more more complex, more more difficult to to govern, and that's also one thing where we need a a full fledged ITA approach. Also, obviously, on the regulation side, I mean, you know, SOX and GDPR and ISO and all those frameworks, they're more and more there's more and more requirements from stock market, from regulators that that we follow and and adhere to different policies, and that makes this very important. And if you break it down, obviously, a a a big push towards or because of the end of maintenance, also, ECC is going out of maintenance that is driving that. And then, obviously, the AI is a big driver in talking ITA. There's a lot of studies out there. Gartner has a couple. I found here one from, or not just found one. I know one from, Rubik's Rubik's Zero Labs that are saying, today, there are already forty five nonhuman entities for every human identity. So, basically, that means for every person that has a user, there's forty five nonhuman identities. It could be a bot, an and whatever, and that's only going to grow. Gartner is predicting that to grow even faster. So that means there will be a big shift towards the technical, the nonhuman users, and that's why we need really need to start addressing that and start looking into what that means. Not as much. Switch. Here we go. Specifically, I I spoke a lot about AI agents and AI in general. I mean, we all know AI is becoming overly popular, and AI agents are or AI in general is fantastic. I use it every every single day. It's it's my companion. It's my copilot for many things. I do a lot of things. I I I build my own agents that are fantastic to do a lot of work for me or or not just a lot of work, but they help me to be more efficient or review things or do things for me. And that's also obviously becoming now popular or not just popular, becoming reality in your productive environment. So in your ECC, in your s four, in your cloud applications, AI is coming. Whether you like it or not, it's adopting. And from an AI perspective, there's different ways of how AI or the agentic AIs interact with your environment. Sometimes you start out with a Copilot. That's like your your your chatbot. Like, you know, you you ask questions and answers and, you know, gives you drafts your request and summarizes certain things and explains the context. But then from a chatbot, it might go into more like an assistant where it gives you recommendations, what you could do, all the way to an agent where all of a sudden, it acts on behalf of you or it acts by itself. So the chatbot, you know, is not just answering your your questions, like, you know, you know, explain me why someone got or explain an SOD conflict. It's now maybe also going towards, okay. Let me let me clean it up. Let's do a deprovisioning request, or let's change authorizations. So as soon as a chatbot also evolves into more, like, the doing side, it becomes an agent. Agent has a different meaning as well, but we see that very often, where it progresses. We start somewhere, then it progresses into more like an an agent where it executes tasks directly and, you know, sometimes with approval, sometimes without approvals. And that's what we really need to consider now as well. So whenever we talk AI, we talk agents, we have to establish guardrails. For me, they're nonnegotiable. We have to talk about that. We have to talk about different action tiers, you know, what what what you know, which agent or which AI application does certain recommendations, you know, who can do you know, which which agent or which which app can execute, you know, who approves access, you know, how do we how do we ensure that we review what an AI agent does, who can even review what an AI AI agent does, and then ultimately also down to the road when we have an audit. Because if an AI agent does something, someone will be or has to be accountable and responsible for what the AI agent does. So then there must be clear ownership. We have to be always able to explain what was the rationale behind an AI decision, especially when they when they act autonomously. So if they're just, you know, doing things, which that's the future. That's where it's going for certain things. It's fantastic. But we have to be able to explain and document and and and ultimately answer to the auditors if something happened, whether good or bad, but someone will ask, and we have to be able to document. It also goes back to the identity. We have a lot of AI agents. They they connect from left to right. They have a lot of authorizations very often, and that's why it's very important that we govern it properly. We run them through the the life cycle because also AI agents, eventually, they it's like hire and fire. Right? We hire an AI agent. We fire it eventually. And and and during the life cycle, it might change positions or or maybe capabilities. You know, it starts as a chatbot, but eventually, it's an AI it's it's an fully automated agent. And that's why it's important that we also control the access the agent gets. Whenever we have agents, whenever we have AI, we have to make sure we have kill switches and human override because we don't want them just, you know, autonomously do whatever and and and go, you know, go in loops and do. So we have to make sure there's the kill switch is in there. It should never, you know, operate without any escalation path. It should always be, you know, under clear ownership, and someone needs to be accountable and responsible for what the AI agent for for does. And I'm pretty sure we had it in the poll. I'm not sure how many AI or how many AI agents you're already using in your in your application. I mean, we all talked about we all heard of Chewel and other automations. It's become more and more. And I think they're already in your landscape for for most of you at least, and it's important that, again, we define ownership. We define review cycles. We define the guardrails. That that that's a must. It must change today because, ultimately, that's where the world is going, towards, and that's why it's important that we really think about that and also think about it in the context of of of IGA of the entire life cycle. When we look at traditional IGAs, mean, IGA is not nothing entirely new. IGA has been around, and, you know, you could say with sub IDM or others, you already have, like, an IGA in place. You know, you might have your your access controls, your GSEs connected for risk and as a simulation and so on. So certain things are already there. But why do traditional ITAs fail in a hybrid scenario, especially now when we also look into AI and we're now in a area of of of of AI? And I was kinda trying to show it in in in sense of, like, a like an iceberg. And the tip of the iceberg, that's like our static design and our human only lens that we're focusing on. And when we think about, like, our traditional sub IDM or even if you sub access control g or c or other, let's call it, more older applications, they were built for on prem lives for on prem life cycles and not so much for SaaS. So very often, they're lacking the SaaS support for your success factors, Naribas, and so on, and BTP itself. And but also AI and all those new things are not really considered from ground up. That means that all the machine identities and AI, since they're scaling so fast and and, again, without ownership, our our IDM cannot really keep up with that. That's why we, you know, we have to really rethink that. And that's why I think this the the traditional ITA, it's kinda failing because we're only looking at the tip of the iceberg, and we kinda forget what's underneath, which is very, very important. And I think one big topic is the entitlement sprawl, especially with the cloud adoption, with the hybrid landscapes, and also just historically. Because I've I've been to many, many customers that tell me, hey. You know, we used to have grid authorizations in the nineties, but, you know, the business evolved. We acquired companies. We had, you know, sell offs and so on, and a lot of things changed. It changed it changed hands. It changed, you know, over and over. And a lot of times, we have hundreds and thousands, and we've got tens of thousands of roles and authorizations laying around. Some are used, some are not. Now we add more applications to it, cloud applications to it. There's new authorizations, new roles. We don't know exactly. We don't have a concept. We don't have a clear concept. We have nothing that governs the entire hybrid landscape from left to right in the context of IGA. Why is that so important? Because, ultimately, we have to authorize users, whether the users are a human being or a nonhuman identity. We have to authorize someone, and that's why we have to make sure that the the authorizations within the systems is properly properly built. And especially also when we review older organizations that have been around for years and had, you know, ECC for for decades, some of the users still have roles that were built in the in the nineties. And I don't mean they're negative. It's just reality. The roles are still working. They were always added there were always authorizations added on. They're fully functioning, oftentimes way, way more than what the user needs, and it was always added on. It's accumulation of excess, and it's very, very difficult to provision, but also very difficult to review. And that's ultimately why we talk, redesign, getting up, following a proper, you know, authorization concept across the board, not just in one system, but across in the entire hybrid landscape. Because, again, sometimes also business processes, they start in one application, continue another, and might end in a third application. And the entire process needs to be obviously documented, but also properly authorized from start to finish, and that's cross system. That's why we always talk cross system SODs and cross system risks, but also cross system authorization concept are very, very important. Then we also have, obviously, a lot of silos nowadays. Very often, we have we have maybe an IEM solution. You know, we have a GRC solution. We have our firefighting solution. We have Centimeters applications. We have our SOC teams that do certain things, and it's all in silos. They're not talking to one another. It's not integrated. And that's one thing also where we have to be, you know, more cautious and more you know, we have to address that more going forward is to bring those closer together. That's also the the fifth session where we also talk about our new SOC tool where we also consolidate different application into one. That's ultimately what we also try to do with our get connected run secure approach is connecting all those applications, whether it's your I'm application, your tier c application, your, obviously, your back end applications, get them together, connect signals, locks, and, you know, correlate and, you know, you know, build out or get actionable insight and results out of it. Last but not least, obviously, also a lot of times, you know, we have manual ticket driven approaches, manual processes. You know, very difficult to match the speed of business as especially now with AI. I mean, if we're still following a paper trail or even manual workflows, it's very difficult. That's why we talk with the life cycle. We have to make sure that we, you know, automate it more and more so that we're more efficient going forward and always obviously, keep keep the governance aspect in scope there as well. So when we look at, again, the iQIYI blueprint, so if we just go a little bit deeper now. We have the three blocks. We have identity life cycle, access governance, and then the access intelligence, I mentioned already. On identity life cycle and I have one slide each just to go a little bit deeper. On the identity life cycle, obviously, again, we talk about the mover lever. Obviously, best will be automatically triggered by a SuccessFactors or Workday or any other HR system you have, which are to avoid manual approaches. The more automation, the better. Additional access can always be provided. That's the more the access governance side where we have self-service capabilities, you know, to to access more. But we wanna integrate more. So the life cycle, very important Access governance, that's typically our SODs, critical authorization checks, cross system checks, but also identity in general, making sure we have consistent entities across all kind of mitigations, remediation capabilities, and simulation capabilities within the the entire life cycle. So we'd wanna make sure we address issues before they happen. We don't wanna provision. And then at the end of the year, the order says, hey. Alessandra has an SOD conflict. We wanna see that before it happens. And then, again, on the intelligence side, we wanna get full visibility. We wanna also on the identity side because it is the number one attack vector from from cyber security perspective. We wanna make sure we have everything visible, documented, full audit stamp, and, you know, we get all those anomalies and anything detection wise that's possible to detect into connect applications. We'll talk about that also in a second. Again, whenever we talk about any of these silos, whether it's identity life cycle, access governance, or access intelligence, it's very important that we always talk about it from a nonhuman perspective as well. So all the machine entities, the AI agents, your RFC interfaces, all those need to be included as well. That's very important. They need clear ownership. They need clear policies and and and, frameworks that they follow and, also the continuous monitoring to get the intelligence into other applications wherever needed. The ended life cycle here, obviously, oversimplified. The joiner mover lever should be your automated control system that's triggered by HR. That's ultimately where where it comes down to. Like I said, automation is good because the automation is is helps to standardize and, you know, build more robust, yeah, processes. In the life cycle, again, we wanna use alternative sources like your HR for key identifiers that could be your HR, your intra, others as well. We have the cloud and the services with the IES portion. That's your identity backbone. That's from where we trigger it. And we wanna make sure everything goes through that. So if you have the cloud and the services, we always wanna use that as the a single source where we that we use. Then we have different triggers for the life cycle that can be the hire, the fire, the transfer, termination events. But also in between, you know, maybe when there's a transfer change of organizational levels or position, trigger review workflows, the you know, trigger deprovisioning or retention of access for thirty days and then deprovision, There's a lot of automations that we can incorporate into those life cycles. Clear ownership, obviously, for every role that's being provisioned, whether it's a technical role or business role, it's cross, application, needs clear ownership. Should always be business use and not IT. It's not that the IT admin decides what the business needs. It needs to be business a business ownership. It's it's a business responsibility that needs to be very clearly marked. And it also then goes back down to the authorization concept. So even if we build authorization concepts, you have to ensure that in both business, there's clear ownership, what goes into role, what's being authorized in the role. It's it's it's an overarching approach. Obviously, there's also a lot of SLAs, service level agreements that we have to define, you know, for especially for deprovisioning. Orders are always looking for that that, know, we have same date deprovisioning. So if a user accounts, you know, terminates the end of March, we have to ensure the end of March, it was a terminate. You know, it should not be that still open on April fifth. Right? That will not be good. So there not needs to be needs to be clear SLAs as well to monitor and also report if that's, properly working. We always have, removal with time frame windows or, like, a defined window. Like I said, grace period, fifteen, twenty, thirty days. Someone keeps access when they do positional changes. That's obviously needs to be fully customizable as well. But also there, we wanna SLAs, wanna report on it, and making sure that that's that's that's clear. For the entire identity life cycle, lot of evidence is needed. That's where I mentioned earlier with the audit log. We always have to define we always have to answer those those w questions we say in German, the who, what, when, why. That's very, very important. So any action within the workflow needs to be documented, time stamped. We always need to know who and and and and and when and what and why. So even for for automated stuff. So if there's automation, it's, you know, it's we documented as well. When there's, like, human interaction, like an approval or someone forwarding or approving on behalf. All those steps, all those decisions along the way need to be properly documented. Then, obviously, also about deprovisioning, we have to make sure it's everything is timely deprovisioned. It shouldn't, you know, you know, be a delay. That's why time stamps are important. Anything that's exceptional needs to be properly documented, whether that's, you know, you know, temporary access, privileged access, always there. And then also that we have the the reconciliation, so checking between, like, what was approved versus what is authorized. That's a big problem for a lot of organizations. We have an IDM applications or IEM application in place. We provision access to that, but then we have the admins or site and shadow processes that still do manual s s zero one where someone assigns access or remove access. That should not be the case because that's very difficult from an audit perspective to explain why that happened. So that's why it's important to also reconcile, making sure that only the user only has what what actually was approved and was, you know, going through an entire process. That's very, very important from an identity life cycle. That's also one of the things where, Fabian, my colleague, I think in in session three, he will very specifically talk about identity life cycle in the context of ITA, where really a full a full hour will be spent on how do we, you know, ensure identity life cycle with different tools and how we have to relook into the more detailed aspect of of how that can be done and and what that what that means in in general. The life cycle alone, that's your IDM process, your IEM processes in the aspect of IGA of identity governance. We also have the access governance silo where we typically have our SOD scanning, the entire obviously, the the audit the the audit log is is part of access governance. But that, again, is something that needs to happen ad hoc. It's not like something that happens post provisioning. So when we do SOD scanning, SOD simulation, SOD, you know, risk analysis that needs to happen throughout the workflow. So that's it's a workflow. And here, I'm just showing one. That's not a obviously, not a complete workflow. There's no detouring and no escalation path. But what what what I wanna show here is basically that in the workflow, there needs to be risk checks, need to be simulation. What if scenarios? So what if I assign this role to user? What happens from an SSD perspective? What happens from a critical authorization's perspective? What happens from a license perspective? So even license governance is a big topic as well. So we're not not, you know, triggering higher license costs or changing license things. That's very, very important. Also, from an access governance perspective, we have a lot of alignments with different frameworks and standards. I mean, NIST is definitely one that's that's that's very important. Two aspects of NIST, the govern and the protect in in particular. That means that policies need need to be established. It's not like you can or cannot. It needs to be established. It's a must. And we also have to always protect. So that means we have to follow least privilege principles for an authorizations and and identity perspective. We only grant what users need. We don't overauthorize. And then, obviously, again, we have to with the government, we have to make sure that we're living those processes along the way. So every request, anything that's provisioned needs to go through the rule engine, check for compliance, check check for any, any issues in regards of of any concept or or or, framework we're we're checking against. Access review is a big topic as well, recertification. So once access is provided, it was obviously initially approved. Eventual needs to be revisited. Someone needs to review if the if the access is still accurate and timely. So that means if I if I've gotten access two years ago, we have to revisit whether that's still possible because maybe my my job change workflow that automatically triggers didn't fully work, or maybe I haven't had it two years ago. So that's why review of access is very important. Review of access or access reviews in general can be in different form and shape. It could be straight up user access reviews where we just review what users have authorized, but it could also be that we have more like a risk driven review looking into what risky access a user has, like like, what leads to SOD conflicts or critical authorizations. So access reviews can be in different form and shape, and that's also one important aspect of of the IGA is that we obviously govern and make sure that access is continuously checked. So it's not and that's that's an ongoing continuous, event. Very, very important. Ultimately, every access decision must, produce evidence at any moment in time, and it should never be reconstructed later. So, you know, you like I said earlier, if you have an audit end of the year, we cannot reconstruct audit and evidence. It needs to be always an ongoing event. Whenever something happens, whenever an approval is given, it needs to follow that. Can I say it one more time? Nonhuman entities are all also in scope. Okay? That means for SOD conflicts and so on because it doesn't help if we reduce SOD conflicts on a on a on a human level. If Alessandro doesn't have an SOD conflict, but my AI agent I'm using has, and I can do the same thing as I would have the access myself. So we also have to consider that. We will eventually also have to talk about SOD violations between AI agent that I have in control and what I have. Because if an SOD conflict where we have two a separation of two functions and I do the one and my AI agent does the other, I technically don't have the SOD conflict. But in combination, because I can access my authorizations and the AI agent performs certain functions when I tell them to, if that leads to an SOD conflict, we also have to address that. So we also have to think about our, let's call it, or our governance aspect or governance controls and policies that we have to also include that. In the past, we looked into firefighter access because I have a firefighter available that I can use. But going forward, we also have to think about all those new nonhuman entities like an AI agent that can work on my behalf or if I tell them to. Right? If I say, hey. Do this and does it, it needs to consider that I have the access or that the AI needs to check that I'm not doing something that leads to fraud or anything that I'm not supposed to do, but that's another, aspect that we have to, definitely consider. So access governance, they have a specific session about that as well. I think it's session four with Eric that will talk about the access governance aspect, especially in hybrid landscapes and what that means, and how do we also ensure and build those rules, make sure that the rules stay, you know, stay in sync, stay up to date because it's an ever changing environment, especially with this AI and with cloud adoption and the the, you know, the entire speed. We also have to make sure that our rule sets, our controls, our policies, they stay up to date. They're they're they're current. They're they're, yeah, they're they're they're specific enough for the cases and for the business scenarios that we have in front of us, and that's that's changing faster than it has ever. And that's why it's important that we also specifically address the access governance side, and Eric will talk about that, in in session four. Last but not least from the IHA perspective, you have the access intelligence, so that's the third, silo. And access intelligence really means that we're turning the raw entitlement into insight. So that means, basically, again, also things, like I mentioned earlier, with the attack vector. So identity being the number one attack vector, we also have a lot of events and a lot of raw data locks and things that are happening on the identity side, whether those are role changes, whether those are user changes, provisioning, deprovisioning, all kind of things that might lead into or that that that, you know, is a is an event or a raw data, that may need need to be put into an intelligent way to understand it better to process it also from, like, a like, a security monitoring perspective, let's say. So, basically, also those outputs we have from the life cycle, from from excess governance, that needs to now be fed into the security monitoring. So for example, if we are assigning a firefighting a firefighter someone or if someone gets access to an AI agent, let's think about, like, we have proper life cycle processes, and I'm requesting authorizations for an AI agent that I own. Then we also have to feed that back into security monitoring for events and, you know, making sure we're also putting monitoring around that. And there's a lot of different raw data that are being produced, and that ultimately needs to correlate as well. That's the session the the fifth session with Moritz where we talk about our new product, Fulcora. It's called exciting Fulcora. It's like an AI driven security operation center, so it really handles all kind of events. It it's also AI. It's a lot of AI agents in there that have guardrails and are properly implemented, hopefully. But they they deal with all these signals and interact with the IGE as well. So security monitoring should not be blind an IT perspective. It needs to correlate and work together hand in hand as well. So that could be for enrichment. That could be to to, you know, perform certain actions. So when we have a security operation center and there's, like, an alert and an incident that needs to like, for containment or for corrective actions, that also needs to feed through the IT approach. Also, again, following the life cycle, the workflows, excess governance aspect, and so on. And that's ultimately also where those two words need to come closer together because everything is moving faster. We also have to make sure that our security monitoring stays up to date and, you know, keeps everything in check. And that's where, you know, the intelligence portion of it is very, very important as well to correlate, prioritize, and ultimately, you know, forward into wherever we need it. So yeah. That's that's ultimately what I wanted to show you guys. It's like a high level overview. Like I mentioned, we have a lot of different pillars, a lot of different things we're addressing. We have just a blueprint high level overview. We have a couple interesting sessions coming up. The first one is the is this coming Thursday where we talk about authorizations in S4HANA, those authorizations, and the redesign is a foundation for IGA. Why is that important? Like I mentioned earlier, when we talk about governance or SOD remediation and all those good things, our life cycle and automations, it's important that we have a solid authorization design. So if you have bad roles and you know? I I always say the she show, the **** inch it out. Right? I'm not supposed to say it, but I say it anyways. The if you if you have a solid concept, it makes it much easier to build business roles to do the role mining to, you know, find the correct roles a user needs. So that's why it needs to start in the background, in the back end. That's what we're talking on Thursday. And then we have those three pillars. We have the access governance session. We have the life cycle session, and we have the intelligence session where we talk about our new products and also then in channel in in specifically, like, you know, how do we do the the churn and mover lever, how that interacts, and also how do we do the risk analysis and and keeping SOTs in check and also keep it up to date. With that, let's see. We might have questions. We might have an answer to the poll maybe. Let's quickly see. So I'm not sure if you can can you guys see the or I can read it out? So maybe for you for those of that are interested, we had the the first question was, you know, what is the biggest thing slowing down IGA in your landscape today? And, yeah, a lot of lot of a lot of you say that too many systems and entitlements, so it's the hybrid and SaaS pro. So a lot of more applications, lot of lot of application entitlements that are just too many to handle, then also provisioning deprovisioning delays, which kinda leads to not having a proper churn and mover lever process. I would say, Alex, you just interrupt or feel free to add anything I'm missing. And those are the things we want we will address on that identity lifecycle management session for the children mover lever. And then the second question was in regards to the AI agent. That was more and more for my curiosity, like, how many of you are already operating AI agents and AI bots and any kind of bots in your productive or pilot landscapes. And a third of you guys say we're already using them in business critical productive environments, and that's kinda interesting or not interesting. I'm was kinda expecting that, but that means, like, a third of you guys are already using in production, and that's that's interesting. I think it's growing. And a lot of you are planning it or are using it in in limited scope. So if you look at, like, not planned, there's only one person. So it that I think that's the trend where that we see. It's it's more and more, and it will be very interesting. And I think that's why we need to talk about the the topic of AI, how do we get that into into our, you know, ITA process. With that, Alex, any questions? Let me check. Yeah. Ultimately, thank you for providing this presentation here today to the group, you know, the first part in our webinar series for Security Madness. We do have a minute left. So if there are any questions in the chat, maybe we can use this time to go through and answer them. Yeah. There was a specific question on one application. I'm not familiar with that application, so I can't really answer that question. I'll look into that and just follow-up offline with the person who asked that. Okay. Perfect. But I would say if any other questions I mean, we have four more sessions that go into more detail, and those are the experts for every single I'm just a high level guy, but for every single of those, you know, silos or topics. We'll have a follow-up session and, yeah, looking forward to that. Awesome. Well, thank you so much for providing this presentation today. And as just a reminder, our our next session in our Security March Madness webinar series will be this Thursday, March fifth at twelve PM eastern. So if you're not signed up yet, you know, you can use this time to get signed up for that next event. But, ultimately, thank you so much for joining everyone, and I hope everyone has a great rest of their day and a a great week. Thank you, everyone.<\/p><\/div><\/div><\/wistia-player>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2203e2fa elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"2203e2fa\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Identity Governance Solutions von Xiting <\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3685da9 elementor-widget elementor-widget-text-editor\" data-id=\"3685da9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"ewa-rteLine\"><p><strong>Konkret braucht ein modernes SAP-fokussiertes IGA-Programm sieben Bausteine:\u00a0<\/strong><\/p><ol><li aria-level=\"3\"><strong>Entitlement Management mit gesch\u00e4ftlichem Kontext\u00a0<\/strong><\/li><\/ol><p><span data-contrast=\"auto\">Governance\u00a0scheitert, wenn Berechtigungen nur als technische Labels\u00a0betrachtet\u00a0werden.\u00a0Entscheidend sind\u00a0Ownership\u00a0und <strong>Kontext:<\/strong>\u00a0Welchen\u00a0Gesch\u00e4ftsprozess\u00a0unterst\u00fctzt\u00a0eine Berechtigung, wie kritisch ist sie\u00a0und\u00a0wer tr\u00e4gt\u00a0die\u00a0Verantwortung? Erst\u00a0dann\u00a0lassen sich\u00a0Genehmigungen und Reviews\u00a0klar, konsistent\u00a0und\u00a0nachvollziehbar durchf\u00fchren.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\"><a href=\"https:\/\/xiting.com\/de\/xiting-security-platform\/\"><strong>Die\u00a0Xiting\u00a0Security\u00a0Platform\u00a0(XSP)<\/strong><\/a> unterst\u00fctzt dies durch zentrales SAP-Sicherheitsmanagement, gest\u00fctzt auf system\u00fcbergreifende Risikoanalyse und Compliance-Funktionen \u2013 und bildet damit die Grundlage, um\u00a0Governance-Metadaten an Zugriffsrechte zu kn\u00fcpfen.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<br \/><br \/><\/span><\/p><ol start=\"2\"><li aria-level=\"3\"><strong> Identit\u00e4tskonsolidierung \u00fcber Systeme hinweg<\/strong><\/li><\/ol><p><span data-contrast=\"auto\">Was\u00a0sich\u00a0nicht zusammenf\u00fchren\u00a0l\u00e4sst, l\u00e4sst sich auch\u00a0nicht steuern. Hybride Landschaften\u00a0f\u00fchren fast zwangsl\u00e4ufig zu fragmentierten Identit\u00e4ten: unterschiedliche User-IDs, abweichende Namenskonventionen, mehrere\u00a0Verzeichnisse und\u00a0verschiedene\u00a0<\/span><a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/identity-access-management\/cloud-identity-service\/\"><span data-contrast=\"none\">Cloud-Identit\u00e4ten.<\/span><\/a><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><p><a href=\"https:\/\/xiting.com\/de\/governance-risk-compliance\/zentralisierte-konsolidierung-von-identitaeten\/\"><span data-contrast=\"none\">Identit\u00e4tskonsolidierung<\/span><\/a><span data-contrast=\"auto\">\u00a0ist daher keine Option, sondern eine Voraussetzung. Konsolidierte Identit\u00e4ten bilden das Fundament f\u00fcr system\u00fcbergreifende Analyse, Risikoerkennung und\u00a0Provisioning.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<br \/><br \/><\/span><\/p><ol start=\"3\"><li aria-level=\"3\"><strong> System\u00fcbergreifende Risikoanalyse und SoD<\/strong><\/li><\/ol><p><span data-contrast=\"auto\">SoD-Konflikte\u00a0entstehen selten\u00a0in\u00a0nur\u00a0einem System. Gesch\u00e4ftsprozesse\u00a0laufen\u00a0h\u00e4ufig\u00a0\u00fcber\u00a0mehrere Anwendungen\u00a0hinweg\u00a0\u2013 etwa\u00a0<\/span><a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/sap-s4hana\/cloud-connector\/\"><span data-contrast=\"none\">S\/4HANA<\/span><\/a><span data-contrast=\"auto\">\u00a0und Ariba oder SAP ERP und SuccessFactors. Wirksame\u00a0Governance\u00a0braucht daher\u00a0eine system\u00fcbergreifende Risikoanalyse, die konsolidierte Identit\u00e4ten, aktuelle Regelwerke\u00a0sowie die\u00a0Erkennung\u00a0in\u00a0Provisioning, Zugriffsantr\u00e4gen und Review-Zyklen\u00a0zusammenf\u00fchrt.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Das\u00a0neue<\/span><a href=\"https:\/\/xiting.com\/de\/lynera\/\"><span data-contrast=\"none\">\u00a0<strong>Xiting\u00a0Content Portal\u00a0Lynera<\/strong><\/span><\/a><span data-contrast=\"auto\"> spielt dabei eine zentrale Rolle: Als SaaS-Anwendung vereinfacht es die Pflege von Regelwerken, ausgleichenden Kontrollen und Erkennungsmustern \u2013 unterst\u00fctzt durch Automatisierung und KI-Funktionen.\u00a0Xiting\u00a0Lynera\u00a0liefert Content\u00a0as\u00a0a Service und sorgt daf\u00fcr, dass Regeln aktuell bleiben, auch wenn SaaS-Anwendungen regelm\u00e4\u00dfig aktualisiert werden.<br \/><br \/><\/span><\/p><ol start=\"4\"><li aria-level=\"3\"><strong> Automatisierte Access Reviews und Rezertifizierung<\/strong><\/li><\/ol><p><span data-contrast=\"auto\">IGA muss manuelle Arbeit reduzieren und menschliche Fehler minimieren \u2013 insbesondere bei Access Reviews. Automatisierung ist f\u00fcr skalierbare und konsistente\u00a0Governance\u00a0unverzichtbar.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">In der SAP-Praxis sind die wirksamsten Review-Modelle sowohl periodisch als auch ereignisgesteuert. Sie werden etwa durch Rollenwechsel, Projektenden, Notfallzugriffe, kritische Berechtigungen oder Sicherheitsereignisse ausgel\u00f6st. So finden Reviews nicht nur nach Kalender statt, sondern genau dann, wenn sie relevant sind.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<br \/><br \/><\/span><\/p><ol start=\"5\"><li aria-level=\"3\"><strong> Workflow-gesteuertes Provisioningund User Administration\u00a0<\/strong><\/li><\/ol><p><span data-contrast=\"auto\">Self-Service-Antr\u00e4ge und standardisierte Workflows\u00a0steigern die Produktivit\u00e4t \u2013 vorausgesetzt, sie\u00a0sind mit\u00a0Governance-Regeln und der\u00a0passenden\u00a0Genehmigungslogik verkn\u00fcpft.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><p><span data-contrast=\"none\"><a href=\"https:\/\/xiting.com\/de\/identity-and-access-management\/identity-management-and-workflows\/\"><strong>Xiting\u2018s\u00a0XSP\u00a0Identity Management<\/strong><\/a> liefert genau das<\/span><span data-contrast=\"auto\">: standardisierte Workflows f\u00fcr Benutzerverwaltung, Rollenzuweisung und -entzug, Benutzeranlage und Passwort-Self-Services \u2013 mit flexiblen Szenarien f\u00fcr hybride IT-Landschaften.\u00a0System\u00fcbergreifende Risikoanalyse und Lizenzkostensimulationen sind integriert.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<br \/><br \/><\/span><\/p><ol start=\"6\"><li aria-level=\"3\"><strong>Governance-Content aktuell halten<\/strong><\/li><\/ol><p><span data-contrast=\"auto\">Ein versteckter Kostentreiber bei IGA ist die Regelwerkspflege \u2013\u00a0insbesondere\u00a0wenn sie in Tabellen erfolgt.\u00a0SoD-Regeln, ausgleichende Kontrollen und Erkennungsmuster m\u00fcssen kontinuierlich aktualisiert werden, um organisatorische Ver\u00e4nderungen, neue Anwendungen und ver\u00e4nderte regulatorische Anforderungen abzubilden.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Hier wird\u00a0Lynera\u00a0als Content\u00a0as\u00a0a Service entscheidend.\u00a0Xiting\u00a0und sein Partner\u00f6kosystem stellen sicher, dass\u00a0Governance-Content aktuell bleibt \u2013 eine\u00a0besonders wichtige F\u00e4higkeit, wenn Cloud-Anwendungen regelm\u00e4\u00dfig \u00c4nderungen einf\u00fchren.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<br \/><br \/><\/span><\/p><ol start=\"7\"><li aria-level=\"3\"><strong> SAP-Berechtigungsmanagement schneller und sicherer machen<\/strong><\/li><\/ol><p><span data-contrast=\"auto\">IGA kann nicht gelingen, wenn das\u00a0<\/span><a href=\"https:\/\/xiting.com\/de\/identity-and-access-management\/identity-management-and-workflows\/\"><span data-contrast=\"none\">Rollenmanagement<\/span><\/a><span data-contrast=\"auto\">\u00a0langsam, inkonsistent oder zu stark manuell gepr\u00e4gt ist. Rollendesign und -bereinigung bestimmen, wie sauber die\u00a0Governance-Basis tats\u00e4chlich ist.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Die\u00a0<\/span><strong><a href=\"https:\/\/xiting.com\/de\/xiting-authorizations-management-suite\/\">Xiting\u00a0Authorizations\u00a0Management Suite (XAMS)<\/a><\/strong><span data-contrast=\"auto\">\u00a0folgt einem Least-Privilege-Ansatz nach dem Prinzip &#8222;Get\u00a0clean,\u00a0stay\u00a0clean&#8220;: Rollendesign mit integrierten Pr\u00fcfungen auf kritische Berechtigungen und\u00a0SoD-Konflikte, erhebliche Zeitersparnis gegen\u00fcber manuellen Verfahren und Transparenz \u00fcber Lizenzkosten bei S\/4HANA-Migrationen.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c8fe2d2 elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"c8fe2d2\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Wo IGA auf Security Monitoring trifft \u2013 die Br\u00fccke zur agentischen SOC <\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ecee496 elementor-widget elementor-widget-text-editor\" data-id=\"ecee496\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Klassisches Identity\u00a0Governance\u00a0and Administration beantwortet die Frage: &#8222;<strong>Wer sollte welchen Zugriff haben?<\/strong>&#8220; Security Monitoring beantwortet: &#8222;<strong>Was passiert gerade?<\/strong>&#8222;.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Solange diese beiden Welten getrennt bleiben, sind\u00a0Governance-Entscheidungen immer einen Schritt hinter der tats\u00e4chlichen Systemaktivit\u00e4t.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Xiting\u00a0adressiert diese L\u00fccke gezielt mit<strong>\u00a0<a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/sicherheit\/sap-security-monitoring\/\">Real-Time-SAP-Security-Monitoring<\/a><\/strong> \u2013 einschlie\u00dflich Alert-Forwarding\u00a0an applikationsneutrale SIEM-L\u00f6sungen \u00fcber<strong>\u00a0<a href=\"https:\/\/xiting.com\/de\/falcora\/\">Xiting\u00a0Falcora<\/a>.<\/strong><\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-127b2a1 elementor-widget elementor-widget-button\" data-id=\"127b2a1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/xiting.com\/de\/falcora\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-angle-double-right\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Mehr \u00fcber Xiting Falcora erfahren<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-909fc90 elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"909fc90\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Was \"agentische SOC\" in diesem Kontext bedeutet <\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8a2df75 elementor-widget elementor-widget-text-editor\" data-id=\"8a2df75\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\"><strong>Agentische\u00a0KI stellt die n\u00e4chste Evolutionsstufe der Automatisierung dar: Agenten<\/strong>, die nicht nur Alerts zusammenfassen, sondern Kontext auswerten und unter klaren Leitplanken konsistente Reaktionsschritte ausf\u00fchren.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\"><strong>In SAP liefert IGA\u00a0den entscheidenden\u00a0Kontext:<\/strong> konsolidierte Identit\u00e4ten,\u00a0Rollen-Ownership,\u00a0SoD-Regeln,\u00a0Definitionen kritischer Berechtigungen,\u00a0\u00c4nderungshistorien\u00a0und Genehmigungsnachweise.\u00a0Damit entsteht eine klare Verbindung zwischen\u00a0Governance\u00a0und Security\u00a0Operations: Monitoring-Signale sollten\u00a0Governance-Entscheidungen ausl\u00f6sen, w\u00e4hrend\u00a0Governance-Kontext Security-Untersuchungen schneller,\u00a0fundierter\u00a0und pr\u00e4ziser\u00a0macht.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2b4684b elementor-widget elementor-widget-image\" data-id=\"2b4684b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"1835\" height=\"598\" src=\"https:\/\/xiting.com\/wp-content\/uploads\/2026\/06\/en_ai-steps_iga-guardrails.svg\" class=\"attachment-full size-full wp-image-66754\" alt=\"\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8f5b6f2 elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"8f5b6f2\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Fazit <\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-27f4cb5 elementor-widget elementor-widget-text-editor\" data-id=\"27f4cb5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"ewa-rteLine\"><p><span data-contrast=\"auto\"><strong>Identity\u00a0Governance\u00a0and Administration in SAP funktioniert nur, wenn sie operativ wird:<\/strong> Identit\u00e4ten konsolidiert, Berechtigungen verstanden, Risiken gemessen, Workflows standardisiert und Reviews automatisiert.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><p><span data-contrast=\"none\">Deshalb positioniert\u00a0Xiting\u00a0die\u00a0<strong><a href=\"https:\/\/xiting.com\/de\/xiting-security-platform\/\">Xiting\u00a0Security\u00a0Platform\u00a0(XSP)<\/a> als zentrale Plattform f\u00fcr <a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-iga\/\">Identity\u00a0Governance\u00a0<\/a>und SAP-Sicherheitsmanagement mit system\u00fcbergreifender Risikoanalyse,\u00a0Provisioning, Real-Time-Monitoring und SIEM-Integration<\/strong>. <br \/><br \/>F\u00fcr SAP-zentrierte User- und Berechtigungsprozesse steht mit<a href=\"https:\/\/xiting.com\/de\/xiting-central-workflows\/\">\u00a0<\/a><\/span><a href=\"https:\/\/xiting.com\/de\/xiting-central-workflows\/\"><strong>Xiting\u00a0Central Workflows<\/strong><\/a><span data-contrast=\"none\"><strong>\u00a0(XCW)<\/strong> eine eigenst\u00e4ndige Workflow-L\u00f6sung zur Verf\u00fcgung, w\u00e4hrend <strong>XSP Identity Management (XSP IM)<\/strong> den unternehmensweiten <a href=\"https:\/\/xiting.com\/de\/identity-and-access-management\/btp-security-id-lifecycle-management\/\"><strong>Identity Lifecycle<\/strong><\/a> und das\u00a0<a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/identity-access-management\/ips\/\"><strong>Provisioning\u00a0<\/strong><\/a>\u00fcber SAP- und Non-SAP-Systeme hinweg abbildet. Erg\u00e4nzt wird das Portfolio durch das\u00a0<strong><a href=\"https:\/\/xiting.com\/de\/lynera\/\">Xiting\u00a0Content Portal\u00a0Lynera<\/a>\u00a0f\u00fcr den Regelwerks- und Kontrolllebenszyklus<\/strong> sowie die\u00a0<strong><a href=\"https:\/\/xiting.com\/de\/xiting-authorizations-management-suite\/\">Xiting\u00a0Authorizations\u00a0Management Suite (XAMS)<\/a><\/strong> f\u00fcr Least-Privilege-Rollenengineering im gro\u00dfen Ma\u00dfstab.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-96df30c elementor-widget elementor-widget-testimonial\" data-id=\"96df30c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"testimonial.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-testimonial-wrapper\">\n\t\t\t\t\t\t\t<div class=\"elementor-testimonial-content\"><p>\"Der n\u00e4chste Schritt \u2013 und der, den ich bei vielen Unternehmen noch vermisse \u2013 ist, diese Governance-Basis mit dem Security-Betrieb zu verbinden. IGA, die nur im Quartalszyklus lebt, kommt zu sp\u00e4t.<\/p>\n<\/div>\n\t\t\t\n\t\t\t\t\t\t<div class=\"elementor-testimonial-meta elementor-has-image elementor-testimonial-image-position-aside\">\n\t\t\t\t<div class=\"elementor-testimonial-meta-inner\">\n\t\t\t\t\t\t\t\t\t\t\t<div class=\"elementor-testimonial-image\">\n\t\t\t\t\t\t\t<img decoding=\"async\" width=\"2560\" height=\"2560\" src=\"https:\/\/xiting.com\/wp-content\/uploads\/2024\/10\/xitingalessandro-banzer-scaled-1.jpg\" class=\"attachment-full size-full wp-image-44493\" alt=\"\" srcset=\"https:\/\/xiting.com\/wp-content\/uploads\/2024\/10\/xitingalessandro-banzer-scaled-1.jpg 2560w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/10\/xitingalessandro-banzer-scaled-1-300x300.jpg 300w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/10\/xitingalessandro-banzer-scaled-1-1024x1024.jpg 1024w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/10\/xitingalessandro-banzer-scaled-1-150x150.jpg 150w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/10\/xitingalessandro-banzer-scaled-1-768x768.jpg 768w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/10\/xitingalessandro-banzer-scaled-1-1536x1536.jpg 1536w, https:\/\/xiting.com\/wp-content\/uploads\/2024\/10\/xitingalessandro-banzer-scaled-1-2048x2048.jpg 2048w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/>\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t<div class=\"elementor-testimonial-details\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"elementor-testimonial-name\">Alessandro Banzer<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"elementor-testimonial-job\">Americas CEO und SAP Security Experte bei Xiting<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-38ec6a2 hs-popup-btn elementor-widget elementor-widget-button\" data-id=\"38ec6a2\" data-element_type=\"widget\" data-e-type=\"widget\" data-portal=\"25088517\" data-form=\"ff252bfb-c4f8-4db5-8993-e6ecb87579a0\" data-region=\"eu1\" data-title=\"Kontaktieren Sie unsere Experten.\" data-success-close=\"1500\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"#elementor-action%3Aaction%3Dpopup%3Aopen%26settings%3DeyJpZCI6NTQzMTYsInRvZ2dsZSI6ZmFsc2V9\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Jetzt unverbindlich beraten lassen!<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-955ebac elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"955ebac\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">FAQ<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c71a10f elementor-widget elementor-widget-n-accordion\" data-id=\"c71a10f\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;max_items_expended&quot;:&quot;multiple&quot;,&quot;default_state&quot;:&quot;expanded&quot;,&quot;n_accordion_animation_duration&quot;:{&quot;unit&quot;:&quot;ms&quot;,&quot;size&quot;:400,&quot;sizes&quot;:[]}}\" data-widget_type=\"nested-accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"e-n-accordion\" aria-label=\"Accordion. Open links with Enter or Space, close with Escape, and navigate with Arrow Keys\">\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-2080\" class=\"e-n-accordion-item\" open>\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"1\" tabindex=\"0\" aria-expanded=\"true\" aria-controls=\"e-n-accordion-item-2080\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> Was ist der Unterschied zwischen IGA, IAM und PAM in SAP?  <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><i aria-hidden=\"true\" class=\"fas fa-angle-up\"><\/i><\/span>\n\t\t\t<span class='e-closed'><i aria-hidden=\"true\" class=\"fas fa-angle-right\"><\/i><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-2080\" class=\"elementor-element elementor-element-5b7f279 e-con-full e-flex e-con e-child\" data-id=\"5b7f279\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-04b6f8e elementor-widget elementor-widget-text-editor\" data-id=\"04b6f8e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<p><span class=\"TextRun SCXW43437640 BCX8\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW43437640 BCX8\">IAM deckt Authentifizierung und grundlegende Zugriffsfreigabe ab (SSO, MFA, Verzeichnisse). IGA erg\u00e4nzt die\u00a0<\/span><span class=\"NormalTextRun SCXW43437640 BCX8\">Governance<\/span><span class=\"NormalTextRun SCXW43437640 BCX8\">-Schicht \u2013 Zugriffsrechtfertigung,\u00a0<\/span><span class=\"NormalTextRun SCXW43437640 BCX8\">SoD<\/span><span class=\"NormalTextRun SCXW43437640 BCX8\">-Durchsetzung, Lifecycle-Automatisierung und Audit-Nachweise. PAM fokussiert speziell auf hochprivilegierte Zugriffe wie SAP-<\/span><span class=\"NormalTextRun SCXW43437640 BCX8\">Firefighter<\/span><span class=\"NormalTextRun SCXW43437640 BCX8\">-Szenarien. Ein vollst\u00e4ndiges SAP-Sicherheitsprogramm verbindet alle drei Disziplinen.<\/span><\/span><span class=\"EOP Selected SCXW43437640 BCX8\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p>\n<\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-2081\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"2\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-2081\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> Warum reicht SAP Access Control allein nicht als IGA-L\u00f6sung aus?  <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><i aria-hidden=\"true\" class=\"fas fa-angle-up\"><\/i><\/span>\n\t\t\t<span class='e-closed'><i aria-hidden=\"true\" class=\"fas fa-angle-right\"><\/i><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-2081\" class=\"elementor-element elementor-element-c89d35c e-con-full e-flex e-con e-child\" data-id=\"c89d35c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-afcddb4 elementor-widget elementor-widget-text-editor\" data-id=\"afcddb4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<p><a class=\"Hyperlink SCXW213784117 BCX8\" href=\"https:\/\/xiting.com\/de\/sap-knowledge\/sap-access-control\/\" target=\"_blank\" rel=\"noreferrer noopener\"><span class=\"TextRun Underlined SCXW213784117 BCX8\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW213784117 BCX8\" data-ccp-charstyle=\"Hyperlink\">SAP Access Control<\/span><\/span><\/a><span class=\"TextRun SCXW213784117 BCX8\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW213784117 BCX8\">\u00a0deckt wichtige\u00a0<\/span><\/span><a class=\"Hyperlink SCXW213784117 BCX8\" href=\"https:\/\/xiting.com\/de\/sap-knowledge\/grc\/\" target=\"_blank\" rel=\"noreferrer noopener\"><span class=\"TextRun Underlined SCXW213784117 BCX8\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW213784117 BCX8\" data-ccp-charstyle=\"Hyperlink\">Governance<\/span><\/span><\/a><span class=\"TextRun SCXW213784117 BCX8\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW213784117 BCX8\">-Funktionen wie\u00a0<\/span><\/span><a class=\"Hyperlink SCXW213784117 BCX8\" href=\"https:\/\/xiting.com\/de\/governance-risk-compliance\/cross-system-risikoanalyse\/\" target=\"_blank\" rel=\"noreferrer noopener\"><span class=\"TextRun Underlined SCXW213784117 BCX8\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW213784117 BCX8\" data-ccp-charstyle=\"Hyperlink\">SoD<\/span><span class=\"NormalTextRun SCXW213784117 BCX8\" data-ccp-charstyle=\"Hyperlink\">-Analyse<\/span><\/span><\/a><span class=\"TextRun SCXW213784117 BCX8\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW213784117 BCX8\">\u00a0und Access Risk Management ab. Ein vollst\u00e4ndiges IGA-Programm erfordert jedoch zus\u00e4tzlich:\u00a0<\/span><span class=\"NormalTextRun SCXW213784117 BCX8\">Identit\u00e4tskonsolidierung<\/span><span class=\"NormalTextRun SCXW213784117 BCX8\">\u00a0\u00fcber SAP und Nicht-SAP-Systeme hinweg, automatisiertes User Lifecycle Management, workflow-gesteuertes\u00a0<\/span><span class=\"NormalTextRun SCXW213784117 BCX8\">Provisioning<\/span><span class=\"NormalTextRun SCXW213784117 BCX8\">\u00a0sowie die Verbindung zwischen\u00a0<\/span><span class=\"NormalTextRun SCXW213784117 BCX8\">Governance<\/span><span class=\"NormalTextRun SCXW213784117 BCX8\">\u00a0und Echtzeit-Monitoring \u2013 F\u00e4higkeiten, die \u00fcber Access Control hinausgehen.<\/span><\/span><span class=\"EOP Selected SCXW213784117 BCX8\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p>\n<\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-2082\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"3\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-2082\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> Welche Rolle spielt das SAP IDM End of Life f\u00fcr die IGA-Strategie?  <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><i aria-hidden=\"true\" class=\"fas fa-angle-up\"><\/i><\/span>\n\t\t\t<span class='e-closed'><i aria-hidden=\"true\" class=\"fas fa-angle-right\"><\/i><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-2082\" class=\"elementor-element elementor-element-296eb78 e-con-full e-flex e-con e-child\" data-id=\"296eb78\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-5f60609 elementor-widget elementor-widget-text-editor\" data-id=\"5f60609\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<p><span class=\"TextRun SCXW256383210 BCX8\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW256383210 BCX8\"><a href=\"https:\/\/xiting.com\/de\/sap-knowledge\/ende-von-sap-idm\/\">SAP Identity Management 8.0 erreicht 2027 das Ende<\/a> des regul\u00e4ren <\/span><span class=\"NormalTextRun SCXW256383210 BCX8\">Wartungszyklusses<\/span><span class=\"NormalTextRun SCXW256383210 BCX8\">\u00a0\u2013 ohne Nachfolgeprodukt. Das zwingt Unternehmen, Identity\u00a0<\/span><span class=\"NormalTextRun SCXW256383210 BCX8\">Governance<\/span><span class=\"NormalTextRun SCXW256383210 BCX8\">\u00a0ganzheitlich neu zu denken, statt lediglich ein Tool zu ersetzen. Es ist eine Chance, ein modernes IGA-Programm aufzubauen, das hybride Landschaften, system\u00fcbergreifende Risikoanalyse und automatisierte Workflows abdeckt.<\/span><\/span><span class=\"EOP Selected SCXW256383210 BCX8\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:80,&quot;335559739&quot;:160,&quot;335559740&quot;:360}\">\u00a0<\/span><\/p>\n<\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-2083\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"4\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-2083\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> Welche IGA-L\u00f6sungen bietet Xiting?  <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><i aria-hidden=\"true\" class=\"fas fa-angle-up\"><\/i><\/span>\n\t\t\t<span class='e-closed'><i aria-hidden=\"true\" class=\"fas fa-angle-right\"><\/i><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-2083\" class=\"elementor-element elementor-element-eb0ccf2 e-con-full e-flex e-con e-child\" data-id=\"eb0ccf2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-59f94da elementor-widget elementor-widget-text-editor\" data-id=\"59f94da\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<div class=\"x_elementToProof\" data-olk-copy-source=\"MessageBody\">\n<p>\u00a0Xiting offers an integrated portfolio:<\/p>\n<ul>\n<li><a href=\"https:\/\/xiting.com\/de\/xiting-security-platform\/\">Xiting Security Platform (XSP)<\/a> for centralized security management and cross-system risk analysis<\/li>\n<li>\u00a0<a href=\"https:\/\/xiting.com\/de\/xiting-authorizations-management-suite\/\">Xiting Authorizations Management Suite (XAMS)<\/a> for least-privilege role engineering<\/li>\n<li><a href=\"https:\/\/xiting.com\/de\/xiting-content-portal\/\">Xiting Content Portal (XCP)<\/a> for governance content maintenance as a service<\/li>\n<li><a href=\"https:\/\/xiting.com\/de\/xiting-security-platform\/\">Xiting Central Workflows (XCW)<\/a> for automated user lifecycle management<\/li>\n<\/ul>\n<p>Combined with <a href=\"https:\/\/xiting.com\/de\/sap-consulting\/\">consulting expertise<\/a> and<a href=\"https:\/\/xiting.com\/en\/sap-security-monitoring\/\"> real-time monitoring<\/a> capabilities, Xiting helps organizations build IGA programs that are operational \u2013 not just documented.<\/p>\n<\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n<p><\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<script type=\"application\/ld+json\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Was ist der Unterschied zwischen IGA, IAM und PAM in SAP?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"IAM deckt Authentifizierung und grundlegende Zugriffsfreigabe ab (SSO, MFA, Verzeichnisse). IGA erg\\u00e4nzt die\\u00a0Governance-Schicht \\u2013 Zugriffsrechtfertigung,\\u00a0SoD-Durchsetzung, Lifecycle-Automatisierung und Audit-Nachweise. PAM fokussiert speziell auf hochprivilegierte Zugriffe wie SAP-Firefighter-Szenarien. Ein vollst\\u00e4ndiges SAP-Sicherheitsprogramm verbindet alle drei Disziplinen.\\u00a0\"}},{\"@type\":\"Question\",\"name\":\"Warum reicht SAP Access Control allein nicht als IGA-L\\u00f6sung aus?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"SAP Access Control\\u00a0deckt wichtige\\u00a0Governance-Funktionen wie\\u00a0SoD-Analyse\\u00a0und Access Risk Management ab. Ein vollst\\u00e4ndiges IGA-Programm erfordert jedoch zus\\u00e4tzlich:\\u00a0Identit\\u00e4tskonsolidierung\\u00a0\\u00fcber SAP und Nicht-SAP-Systeme hinweg, automatisiertes User Lifecycle Management, workflow-gesteuertes\\u00a0Provisioning\\u00a0sowie die Verbindung zwischen\\u00a0Governance\\u00a0und Echtzeit-Monitoring \\u2013 F\\u00e4higkeiten, die \\u00fcber Access Control hinausgehen.\\u00a0\"}},{\"@type\":\"Question\",\"name\":\"Welche Rolle spielt das SAP IDM End of Life f\\u00fcr die IGA-Strategie?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"SAP Identity Management 8.0 erreicht 2027 das Ende des regul\\u00e4ren Wartungszyklusses\\u00a0\\u2013 ohne Nachfolgeprodukt. Das zwingt Unternehmen, Identity\\u00a0Governance\\u00a0ganzheitlich neu zu denken, statt lediglich ein Tool zu ersetzen. Es ist eine Chance, ein modernes IGA-Programm aufzubauen, das hybride Landschaften, system\\u00fcbergreifende Risikoanalyse und automatisierte Workflows abdeckt.\\u00a0\"}},{\"@type\":\"Question\",\"name\":\"Welche IGA-L\\u00f6sungen bietet Xiting?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"\\u00a0Xiting offers an integrated portfolio:\\n\\nXiting Security Platform (XSP) for centralized security management and cross-system risk analysis\\n\\u00a0Xiting Authorizations Management Suite (XAMS) for least-privilege role engineering\\nXiting Content Portal (XCP) for governance content maintenance as a service\\nXiting Central Workflows (XCW) for automated user lifecycle management\\n\\nCombined with consulting expertise and real-time monitoring capabilities, Xiting helps organizations build IGA programs that are operational \\u2013 not just documented.\"}}]}<\/script>\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-24408b92 elementor-section-stretched elementor-section-height-min-height elementor-section-boxed elementor-section-height-default elementor-section-items-middle\" data-id=\"24408b92\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;stretch_section&quot;:&quot;section-stretched&quot;,&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t\t<div class=\"elementor-background-overlay\"><\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5fd7da40\" data-id=\"5fd7da40\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-6bb35d6a elementor-widget elementor-widget-heading\" data-id=\"6bb35d6a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Bleiben Sie auf dem Laufenden<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6be3bbae elementor-widget elementor-widget-heading\" data-id=\"6be3bbae\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Melden Sie Sich zu dem Newsletter an, um weitere Informationen zu erhalten.<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6bcc92e1 elementor-align-center elementor-widget elementor-widget-button\" data-id=\"6bcc92e1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm elementor-animation-grow\" href=\"https:\/\/xiting.com\/de\/anmeldung-zum-xiting-newsletter\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"fas fa-long-arrow-alt-right\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Anmeldung zum Newsletter<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-105b5147 elementor-widget elementor-widget-heading\" data-id=\"105b5147\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Folgen Sie @Xiting und @xiting.global auf den Sozialen Medien.<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-720e5683 e-flex e-con-boxed e-con e-parent\" data-id=\"720e5683\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-391ccf29 elementor-view-default elementor-widget elementor-widget-icon\" data-id=\"391ccf29\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon-wrapper\">\n\t\t\t<a class=\"elementor-icon\" href=\"https:\/\/www.linkedin.com\/company\/xiting\/\">\n\t\t\t<i aria-hidden=\"true\" class=\"fab fa-linkedin-in\"><\/i>\t\t\t<\/a>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4172d9e2 elementor-view-default elementor-widget elementor-widget-icon\" data-id=\"4172d9e2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon-wrapper\">\n\t\t\t<a class=\"elementor-icon\" href=\"https:\/\/www.youtube.com\/@Xiting\">\n\t\t\t<i aria-hidden=\"true\" class=\"fab fa-youtube\"><\/i>\t\t\t<\/a>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2bc52836 elementor-view-default elementor-widget elementor-widget-icon\" data-id=\"2bc52836\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-icon-wrapper\">\n\t\t\t<a class=\"elementor-icon\" href=\"https:\/\/www.instagram.com\/xiting.global\/\">\n\t\t\t<i aria-hidden=\"true\" class=\"fab fa-instagram\"><\/i>\t\t\t<\/a>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Identity Governance and Administration (IGA) in SAP-Landschaften: Prozesse, L\u00f6sungen und Strategie. Erfahren Sie, wie IGA, IAM und PAM zusammenwirken.<\/p>\n","protected":false},"author":7,"featured_media":24408,"parent":0,"menu_order":0,"template":"elementor_header_footer","sap-knowledge-category":[1862],"class_list":["post-66755","sap-knowledge","type-sap-knowledge","status-publish","has-post-thumbnail","hentry","sap-knowledge-category-identity-governance-and-administration-iga"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.5 (Yoast SEO v28.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Identity Governance and Administration in SAP \u2013 IGA-Leitfaden<\/title>\n<meta name=\"description\" content=\"Identity Governance and Administration (IGA) in SAP-Landschaften: Prozesse, L\u00f6sungen und Strategie. Erfahren Sie, wie IGA, IAM und PAM zusammenwirken.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/\" \/>\n<meta property=\"og:locale\" content=\"de_DE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Identity Governance and Administration in hybriden SAP Landschaften\" \/>\n<meta property=\"og:description\" content=\"Identity Governance and Administration in SAP-Landschaften: Prozesse, L\u00f6sungen und Strategie. Erfahren Sie, wie IGA, IAM und PAM zusammenwirken.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/\" \/>\n<meta property=\"og:site_name\" content=\"Xiting\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/XitingAG\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-17T15:57:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/xiting.com\/wp-content\/uploads\/2022\/08\/shutterstock_172003139-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"2467\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Identity Governance and Administration in hybriden SAP-Landschaften\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/sap-knowledge\\\/identity-governance-and-administration-in-hybriden-sap-landschaften\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/sap-knowledge\\\/identity-governance-and-administration-in-hybriden-sap-landschaften\\\/\"},\"author\":{\"name\":\"Alessandro Banzer\",\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/#\\\/schema\\\/person\\\/9f4b7239bdd4d109e5a45c9432779d5e\"},\"headline\":\"Identity Governance and Administration in hybriden SAP-Landschaften\",\"datePublished\":\"2026-08-06T08:40:09+00:00\",\"dateModified\":\"2026-08-17T15:57:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/sap-knowledge\\\/identity-governance-and-administration-in-hybriden-sap-landschaften\\\/\"},\"wordCount\":13147,\"publisher\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/sap-knowledge\\\/identity-governance-and-administration-in-hybriden-sap-landschaften\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/xiting.com\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/shutterstock_172003139-scaled.jpg\",\"inLanguage\":\"de-DE\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/sap-knowledge\\\/identity-governance-and-administration-in-hybriden-sap-landschaften\\\/\",\"url\":\"https:\\\/\\\/xiting.com\\\/de\\\/sap-knowledge\\\/identity-governance-and-administration-in-hybriden-sap-landschaften\\\/\",\"name\":\"Identity Governance and Administration in SAP \u2013 IGA-Leitfaden\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/sap-knowledge\\\/identity-governance-and-administration-in-hybriden-sap-landschaften\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/sap-knowledge\\\/identity-governance-and-administration-in-hybriden-sap-landschaften\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/xiting.com\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/shutterstock_172003139-scaled.jpg\",\"datePublished\":\"2026-08-06T08:40:09+00:00\",\"dateModified\":\"2026-08-17T15:57:40+00:00\",\"description\":\"Identity Governance and Administration (IGA) in SAP-Landschaften: Prozesse, L\u00f6sungen und Strategie. Erfahren Sie, wie IGA, IAM und PAM zusammenwirken.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/sap-knowledge\\\/identity-governance-and-administration-in-hybriden-sap-landschaften\\\/#breadcrumb\"},\"inLanguage\":\"de-DE\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/xiting.com\\\/de\\\/sap-knowledge\\\/identity-governance-and-administration-in-hybriden-sap-landschaften\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"de-DE\",\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/sap-knowledge\\\/identity-governance-and-administration-in-hybriden-sap-landschaften\\\/#primaryimage\",\"url\":\"https:\\\/\\\/xiting.com\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/shutterstock_172003139-scaled.jpg\",\"contentUrl\":\"https:\\\/\\\/xiting.com\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/shutterstock_172003139-scaled.jpg\",\"width\":2560,\"height\":2467},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/sap-knowledge\\\/identity-governance-and-administration-in-hybriden-sap-landschaften\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/xiting.com\\\/de\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Identity Governance and Administration in hybriden SAP-Landschaften\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/xiting.com\\\/de\\\/\",\"name\":\"Xiting\",\"description\":\"Your Expert for SAP Security\",\"publisher\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/xiting.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"de-DE\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/#organization\",\"name\":\"Xiting\",\"url\":\"https:\\\/\\\/xiting.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"de-DE\",\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/xiting.com\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/xiting-logo.png\",\"contentUrl\":\"https:\\\/\\\/xiting.com\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/xiting-logo.png\",\"width\":960,\"height\":504,\"caption\":\"Xiting\"},\"image\":{\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/XitingAG\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/1345129\\\/\",\"https:\\\/\\\/www.instagram.com\\\/xiting.global\\\/\",\"https:\\\/\\\/www.crunchbase.com\\\/organization\\\/xiting\",\"https:\\\/\\\/www.youtube.com\\\/@Xiting\"],\"description\":\"Xiting wurde 2008 von erfahrenen SAP-Beratern in der Schweiz gegr\u00fcndet. Heute besch\u00e4ftigt das Unternehmen 140 Mitarbeitende an mehreren Standorten weltweit. Die SAP Security Consultants von Xiting bringen tiefes Fachwissen aus der Projektpraxis mit und betreuen \u00fcber 700 nationale und internationale Kunden \u2013 remote und vor Ort.\",\"email\":\"info@xiting.ch\",\"telephone\":\"+41 43422 8803\",\"legalName\":\"Xiting AG\",\"foundingDate\":\"2008-06-01\",\"numberOfEmployees\":{\"@type\":\"QuantitativeValue\",\"minValue\":\"51\",\"maxValue\":\"200\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/xiting.com\\\/de\\\/#\\\/schema\\\/person\\\/9f4b7239bdd4d109e5a45c9432779d5e\",\"name\":\"Alessandro Banzer\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"de-DE\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bd69cf75d8008518f801684fb686af7daad3e988b323551989d44fb47d82a240?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bd69cf75d8008518f801684fb686af7daad3e988b323551989d44fb47d82a240?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bd69cf75d8008518f801684fb686af7daad3e988b323551989d44fb47d82a240?s=96&d=mm&r=g\",\"caption\":\"Alessandro Banzer\"},\"description\":\"Alessandro has worked in the field of IT since 2004, specializing in SAP in 2009 and working on global SAP projects in various roles since that date. Alessandro is an active contributor and moderator in the Governance, Risk, and Compliance space on SAP SCN. Alessandro is in charge of Xiting's operations in the United States and a subject matter expert in SAP Access Control, SAP Cloud IAG, and SAP Security.\",\"url\":\"https:\\\/\\\/xiting.com\\\/de\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Identity Governance and Administration in SAP \u2013 IGA-Leitfaden","description":"Identity Governance and Administration (IGA) in SAP-Landschaften: Prozesse, L\u00f6sungen und Strategie. Erfahren Sie, wie IGA, IAM und PAM zusammenwirken.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/","og_locale":"de_DE","og_type":"article","og_title":"Identity Governance and Administration in hybriden SAP Landschaften","og_description":"Identity Governance and Administration in SAP-Landschaften: Prozesse, L\u00f6sungen und Strategie. Erfahren Sie, wie IGA, IAM und PAM zusammenwirken.","og_url":"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/","og_site_name":"Xiting","article_publisher":"https:\/\/www.facebook.com\/XitingAG","article_modified_time":"2026-08-17T15:57:40+00:00","og_image":[{"width":2560,"height":2467,"url":"https:\/\/xiting.com\/wp-content\/uploads\/2022\/08\/shutterstock_172003139-scaled.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_title":"Identity Governance and Administration in hybriden SAP-Landschaften","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/#article","isPartOf":{"@id":"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/"},"author":{"name":"Alessandro Banzer","@id":"https:\/\/xiting.com\/de\/#\/schema\/person\/9f4b7239bdd4d109e5a45c9432779d5e"},"headline":"Identity Governance and Administration in hybriden SAP-Landschaften","datePublished":"2026-08-06T08:40:09+00:00","dateModified":"2026-08-17T15:57:40+00:00","mainEntityOfPage":{"@id":"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/"},"wordCount":13147,"publisher":{"@id":"https:\/\/xiting.com\/de\/#organization"},"image":{"@id":"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/#primaryimage"},"thumbnailUrl":"https:\/\/xiting.com\/wp-content\/uploads\/2022\/08\/shutterstock_172003139-scaled.jpg","inLanguage":"de-DE"},{"@type":"WebPage","@id":"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/","url":"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/","name":"Identity Governance and Administration in SAP \u2013 IGA-Leitfaden","isPartOf":{"@id":"https:\/\/xiting.com\/de\/#website"},"primaryImageOfPage":{"@id":"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/#primaryimage"},"image":{"@id":"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/#primaryimage"},"thumbnailUrl":"https:\/\/xiting.com\/wp-content\/uploads\/2022\/08\/shutterstock_172003139-scaled.jpg","datePublished":"2026-08-06T08:40:09+00:00","dateModified":"2026-08-17T15:57:40+00:00","description":"Identity Governance and Administration (IGA) in SAP-Landschaften: Prozesse, L\u00f6sungen und Strategie. Erfahren Sie, wie IGA, IAM und PAM zusammenwirken.","breadcrumb":{"@id":"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/#breadcrumb"},"inLanguage":"de-DE","potentialAction":[{"@type":"ReadAction","target":["https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/"]}]},{"@type":"ImageObject","inLanguage":"de-DE","@id":"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/#primaryimage","url":"https:\/\/xiting.com\/wp-content\/uploads\/2022\/08\/shutterstock_172003139-scaled.jpg","contentUrl":"https:\/\/xiting.com\/wp-content\/uploads\/2022\/08\/shutterstock_172003139-scaled.jpg","width":2560,"height":2467},{"@type":"BreadcrumbList","@id":"https:\/\/xiting.com\/de\/sap-knowledge\/identity-governance-and-administration-in-hybriden-sap-landschaften\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/xiting.com\/de\/"},{"@type":"ListItem","position":2,"name":"Identity Governance and Administration in hybriden SAP-Landschaften"}]},{"@type":"WebSite","@id":"https:\/\/xiting.com\/de\/#website","url":"https:\/\/xiting.com\/de\/","name":"Xiting","description":"Your Expert for SAP Security","publisher":{"@id":"https:\/\/xiting.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/xiting.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"de-DE"},{"@type":"Organization","@id":"https:\/\/xiting.com\/de\/#organization","name":"Xiting","url":"https:\/\/xiting.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"de-DE","@id":"https:\/\/xiting.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/xiting.com\/wp-content\/uploads\/2025\/08\/xiting-logo.png","contentUrl":"https:\/\/xiting.com\/wp-content\/uploads\/2025\/08\/xiting-logo.png","width":960,"height":504,"caption":"Xiting"},"image":{"@id":"https:\/\/xiting.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/XitingAG","https:\/\/www.linkedin.com\/company\/1345129\/","https:\/\/www.instagram.com\/xiting.global\/","https:\/\/www.crunchbase.com\/organization\/xiting","https:\/\/www.youtube.com\/@Xiting"],"description":"Xiting wurde 2008 von erfahrenen SAP-Beratern in der Schweiz gegr\u00fcndet. Heute besch\u00e4ftigt das Unternehmen 140 Mitarbeitende an mehreren Standorten weltweit. Die SAP Security Consultants von Xiting bringen tiefes Fachwissen aus der Projektpraxis mit und betreuen \u00fcber 700 nationale und internationale Kunden \u2013 remote und vor Ort.","email":"info@xiting.ch","telephone":"+41 43422 8803","legalName":"Xiting AG","foundingDate":"2008-06-01","numberOfEmployees":{"@type":"QuantitativeValue","minValue":"51","maxValue":"200"}},{"@type":"Person","@id":"https:\/\/xiting.com\/de\/#\/schema\/person\/9f4b7239bdd4d109e5a45c9432779d5e","name":"Alessandro Banzer","image":{"@type":"ImageObject","inLanguage":"de-DE","@id":"https:\/\/secure.gravatar.com\/avatar\/bd69cf75d8008518f801684fb686af7daad3e988b323551989d44fb47d82a240?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/bd69cf75d8008518f801684fb686af7daad3e988b323551989d44fb47d82a240?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/bd69cf75d8008518f801684fb686af7daad3e988b323551989d44fb47d82a240?s=96&d=mm&r=g","caption":"Alessandro Banzer"},"description":"Alessandro has worked in the field of IT since 2004, specializing in SAP in 2009 and working on global SAP projects in various roles since that date. Alessandro is an active contributor and moderator in the Governance, Risk, and Compliance space on SAP SCN. Alessandro is in charge of Xiting's operations in the United States and a subject matter expert in SAP Access Control, SAP Cloud IAG, and SAP Security.","url":"https:\/\/xiting.com\/de\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/xiting.com\/de\/wp-json\/wp\/v2\/sap-knowledge\/66755","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xiting.com\/de\/wp-json\/wp\/v2\/sap-knowledge"}],"about":[{"href":"https:\/\/xiting.com\/de\/wp-json\/wp\/v2\/types\/sap-knowledge"}],"author":[{"embeddable":true,"href":"https:\/\/xiting.com\/de\/wp-json\/wp\/v2\/users\/7"}],"version-history":[{"count":28,"href":"https:\/\/xiting.com\/de\/wp-json\/wp\/v2\/sap-knowledge\/66755\/revisions"}],"predecessor-version":[{"id":67224,"href":"https:\/\/xiting.com\/de\/wp-json\/wp\/v2\/sap-knowledge\/66755\/revisions\/67224"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/xiting.com\/de\/wp-json\/wp\/v2\/media\/24408"}],"wp:attachment":[{"href":"https:\/\/xiting.com\/de\/wp-json\/wp\/v2\/media?parent=66755"}],"wp:term":[{"taxonomy":"sap-knowledge-category","embeddable":true,"href":"https:\/\/xiting.com\/de\/wp-json\/wp\/v2\/sap-knowledge-category?post=66755"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}