The End of SAP IDM: Future-Proof Identity Management with SailPoint

Why Xiting Chooses on SailPoint as the Successor to SAP IDM

For many years, SAP NetWeaver Identity Management (SAP IDM) was the backbone of identity management strategies in SAP-centric enterprises. But with the announced end of SAP Identity Management in 2027 and 2030, the time has come to rethink identity governance and elevate it to the next level with modern cloud technologies. 

At Xiting, we have embraced this opportunity and confidently partnered with a new strategic leader: SailPoint. 

SailPoint is a global leader in Identity Security. With its Identity Security Cloud (ISC), SailPoint delivers a comprehensive platform that meets current and future requirements extending well beyond traditional SAP systems. 

Why “Light IGA” Is Not Enough for SAP-Driven Enterprises

The market for Identity Governance solutions is diverse: modular add-ons, service-oriented tools, and ITSM-integrated platforms. Microsoft is also present with Entra ID Governance. While these solutions address basic needs, Gartner highlights that they often fall short when it comes to managing complex enterprise landscapes. 

Common limitations appear in areas such as SoD checks, role-based provisioning, recertifications, or identity analytics. While suitable for simple lifecycle scenarios, they reach their limits with multi-stage approval workflows, heterogeneous integrations (e.g., SAP ERP, HCM, BTP), or the depth required for compliance with standards like ISO 27001, BSI C5, or SOC 2. 

Migration projects often expose these gaps. Critical aspects such as multi-tenancy, on-premises integration, RFC and HR connectors for SAP, or architectural scalability become key. Missing functions frequently force enterprises to add third-party tools, increasing complexity and fragmenting the IAM landscape.

SailPoint solves this with a holistic, cloud-native platform that provides comprehensive governance and the flexibility needed to handle even the most complex SAP IDM replacement scenarios. For organizations planning the migration away from SAP IDM, this means not only feature coverage, but also the foundation for a sustainable, future-proof governance architecture. 

Why Microsoft Entra ID Is Not a Complete SAP IDM Replacement Today

As SAP phases out IDM, Microsoft Entra ID is often mentioned as an alternative. But a closer look shows: Entra ID is primarily a directory service with authentication features, not a full-fledged identity governance system. Even with Entra ID Governance, the focus remains on the Microsoft ecosystem. 

Features like access packages, approval workflows, and recertifications exist, but they are designed mainly for Microsoft environments. For SAP systems, hybrid IT, on-premises integrations, or legacy applications, Entra ID lacks the necessary depth of connectivity. 

Microsoft Entra ID will remain essential for strategies tied to O365, Teams, and Azure. However, identity governance goes beyond authentication and user management – it requires consistent control across all identities, roles, and access rights, regardless of the system landscape. 

Additionally: Entra ID’s advanced governance functions require premium license add-ons per user, which significantly increases costs in enterprise scenarios. For organizations that want to retire SAP IDM and implement a long-term, strategic IAM solution, Entra ID alone is insufficient. SailPoint’s Identity Security Cloud provides true enterprise-grade governance – across SAP, hybrid landscapes, and with a clear focus on scalability and compliance. 

SailPoint vs. Entra ID – Advantages for SAP Enterprises

A holistic identity governance approach – covering compliance, SoD checks, lifecycle management, and hybrid system integration – requires more than Microsoft Entra.
This is where SailPoint delivers key advantages for SAP-driven businesses:
 

 
Cloud-Native Architecture: Identity Security Cloud is built for the cloud,
with microservices, continuous updates, and zero-downtime deployments.
 
 
Maximum Flexibility with Virtual Appliances (VA): Outbound-only communication, encrypted and scalable, controlled by the customer. On-premises SAP systems integrate seamlessly without infrastructure changes. 
 
Strong Governance & AI-Powered Recommendations: Central identity model, automated recertifications, lifecycle workflows, and role assignments optimized by AI/ML. 
 
 
True Identity Governance: Deep SAP connectivity, consolidated view of all identities, and reduced audit risks – going far beyond basic account
and access management.
 

How to Successfully Replace SAP IDM with Xiting

Our customers are now entering a critical phase: migrating from SAP IDM to a future-ready identity platform.

SAP IDM Migration - Roadmap with Xiting and Sailpoint

What Xiting Delivers:

Your Advantage: Tailored Identity Security - Beyond SAP

SailPoint’s approach to identity security goes beyond SAP while ensuring deep SAP integration. The platform is purpose-built for complex, hybrid IT landscapes and stands out with its open architecture and capabilities: 

  • Token-based SaaS connectors with granular control 
  • Low-code workflow automation 
  • Self-service access, recertifications, and privileged task automation 
  • Non-employee identity management (NERM) for external users 

 

A Strategic IAM Partnership for the Future

The partnership with SailPoint is more than a product shift – it marks a new era of identity governance. Together with our customers, and in close collaboration with SailPoint, we are shaping the future of identity and access management – secure, scalable, and cloud-ready.

Xiting Security Platform (XSP) & SailPoint Identity Security Cloud – Identity Governance without Limits

With SailPoint as the new strategic IAM solution, enterprises face growing requirements – especially in SAP environments with hybrid landscapes (SAP on-prem, SAP cloud, non-SAP apps, and diverse user groups). This is where the Xiting Security Platform (XSP) comes in. 
XSP is a central cybersecurity and compliance solution designed for hybrid scenarios, complementing SailPoint ISC and SAP Access Control. Standardized connectors enable automated SoD checks, risk analysis, and license assessments across systems. 

Key Benefits of XSP:

  • Seamless SailPoint Integration: SAP-specific risk analysis, SoD checks, and license classification directly inside SailPoint. 
  • Access Intelligence Service: Unified role, risk, and authorization analysis across SAP BTP, SuccessFactors, and S/4HANA on-prem. 
  • Enhancement, Not Replacement: Existing IAM workflows in SAP Access Control remain intact and are intelligently extended by XSP. 
  • Full Transparency: Dashboards consolidate compliance, audit, and licensing data with drill-downs to the transaction level. 
  • Cloud-Ready: No extra infrastructure, direct SAP BTP integration, continuous updates, and self-service onboarding. 
XSP bridges the gap between traditional SAP GRC Access Control and modern SailPoint-driven identity governance. Enterprises can protect their existing investments while moving toward a future-proof, automated, and compliant governance architecture. 

FAQ

Yes - SailPoint offers significantly more advanced capabilities, especially in the areas of governance, automation, and hybrid integration.

Xiting supports the transition with a structured migration strategy, proven best practices, and seamless technical integration into existing SAP systems.

Yes - SailPoint integrates smoothly with SAP NetWeaver via virtual appliances and standardized connectors. Existing RFC connections (e.g., to HR systems) remain fully usable - without major infrastructure changes.
Additionally, the Xiting Security Platform (XSP) supports role and risk analysis in classic NetWeaver modules. (Link to XSP)

Stay up to date.

Sign up for the newsletter to receive more information.

Follow @Xiting and @xiting.global on social media.

Melden Sie sich jetzt an!

Contact our experts

Kontaktieren sie unsere experten