Extending SAP Access Control

Governance for Hybrid SAP Landscapes with the XSP Access Control Connector

A hybrid SAP landscape combines on-premise systems such as SAP S/4HANA with cloud services like SAP BTP, SuccessFactors, Ariba, and SAP Identity Services. Governing user access consistently across both environments has become one of the central challenges for SAP security and compliance teams. 

In this article, you will learn how SAP Access Control can be extended into hybrid and cloud landscapes without replacing your existing governance setup.

Key Takeaways

  • A hybrid SAP landscape combines on-premise systems (e.g., SAP S/4HANA) with SAP cloud services and non-SAP cloud applications.
  • SAP Access Control remains the central governance system for access requests, SoD analysis, and audit reporting.
  • SAP Identity Provisioning Service (IPS) handles provisioning to cloud and non-SAP targets.
  • The XSP Access Control Connector extends existing governance processes into hybrid landscapes without replacing SAP Access Control.
  • SAP Access Control 12.0 is supported until 2027 (mainstream) / 2030 (extended); SAP GRC for HANA is the announced long-term successor.

The Evolution of SAP Access Governance

The SAP landscape has changed dramatically over the last decade.  What was once a predominantly on-premise environment has evolved into a complex ecosystem consisting of SAP S/4HANA, SAP Business Technology Platform (BTP), SuccessFactors, Ariba, Identity Services, and an increasing number of non-SAP cloud applications.

As organizations continue to adopt cloud services, identity and access management processes are becoming more distributed, while governance and compliance requirements remain as important as ever.
 For SAP security and compliance teams, this transformation creates a fundamental challenge

Access governance processes are expected to remain centralized and auditable, while access provisioning is increasingly executed across multiple technologies, platforms, and service providers. The result is a growing disconnect between governance decisions and technical execution.
 

Historically, SAP Access Control has served as the central platform for access governance activities such as Access Request Management, Segregation of Duties analysis, compliance reporting, and audit support. In traditional SAP environments, these processes were closely integrated with backend systems through established SAP connectors and RFC-based communication. Governance, risk analysis, approval workflows, and provisioning were all part of a largely unified process. 

Cloud applications follow a different architectural model. Many modern solutions rely on REST-based interfaces and SCIM standards, while provisioning is often executed through SAP Identity Provisioning Service (IPS) rather than directly from SAP Access Control.

Although this approach aligns with modern cloud principles, it can lead to fragmented operating models in which governance activities are performed in one solution while provisioning is executed in another. As landscapes continue to expand, maintaining transparency, traceability, and audit readiness becomes increasingly difficult.
 

Note

Common Signs of Fragmented Hybrid Governance

  • !Access approvals happen in SAP Access Control, but provisioning happens separately in a cloud identity tool.
  • !Audit trails are split across multiple systems, making end-to-end traceability difficult.
  • !Manual, ad hoc integrations replace standardized, auditable governance workflows.
  • !SoD analysis covers on-premise systems but not cloud or non-SAP applications.

The Need for a Unified Governance Approach

Organizations often attempt to bridge these gaps through custom integrations or manual provisioning processes. While such approaches may address immediate project requirements, they frequently introduce additional complexity and create long-term maintenance challenges. 

More importantly, they can undermine one of the key principles of effective access governance: 
maintaining a centralized point of control for access decisions, risk assessments, and compliance monitoring.
 

Why SAP Access Control Struggles with Cloud Applications

From an audit perspective, fragmented processes increase the effort required to demonstrate who approved access, when provisioning occurred, and whether governance controls were consistently applied.

As a result, many organizations are looking for ways to extend the reach of SAP Access Control beyond traditional SAP systems without fundamentally redesigning their governance model.
 Some organizations extend their governance model by adopting a separate, cloud-native governance service designed primarily for SAP BTP and cloud applications.

The Xiting Security Platform (XSP) takes a different approach: it keeps the established, on-premise governance model of SAP Access Control at the center and extends it into hybrid and non-SAP environments through the XSP Access Control Connector, without introducing an additional governance platform.

Extending SAP Access Control into Hybrid Landscapes

Xiting’s XSP Access Control Connector was developed to address exactly this challenge. Rather than introducing another governance solution, it extends the capabilities of SAP Access Control into cloud and non-SAP environments while preserving established governance processes. 

This allows organizations to continue leveraging SAP Access Control as their central system for access requests, approval workflows, risk analysis, and compliance reporting, regardless of where users and authorizations are ultimately provisioned.
Governance remains centralized while provisioning can be executed through modern cloud-native technologies and interfaces.
 

By integrating SAP cloud applications, SAP BTP environments, identity services, and even non-SAP platforms into a unified process framework, organizations can maintain a consistent governance model across their entire landscape. Security teams benefit from greater transparency, compliance teams retain a complete audit trail, and users experience a standardized access request process independent of the target system. 

Note!

The XSP Access Control Connector does not replace SAP Access Control. It extends the existing governance processes, access requests, approvals, and risk analysis, to systems that communicate via REST or SCIM instead of RFC.

How does the XSP Access Control Connector work?

The XSP Access Control Connector runs within the Xiting Security Platform (XSP) and extends SAP Access Control’s existing governance processes, such as access requests, approvals, and risk analysis, into cloud and non-SAP systems without replacing the current SAP Access Control setup. 

Leveraging SAP IPS for Modern Provisioning

Identity Provisioning Service (IPS) provisions users in a hybrid landscape by receiving approved requests from SAP Access Control through the XSP Access Control Connector and executing the corresponding actions on the target cloud or non-SAP system. 

A key aspect of the solution is its alignment with SAP’s modern identity architecture.   

→ Instead of relying on direct connectivity to cloud systems, approved provisioning requests are routed through the XSP Access Control Connector and orchestrated via SAP Identity Provisioning Service. IPS then executes the required provisioning actions on the respective target platforms and returns the provisioning status to SAP Access Control. 

This approach establishes a clear separation between governance and technical execution while maintaining end-to-end visibility throughout the process. Access decisions continue to be governed by SAP Access Control, while IPS provides the provisioning capabilities required for modern cloud applications. The result is a scalable architecture that supports both current and future landscape requirements without compromising governance standards. 

How to Maintain Compliance in a Cloud-Driven World

For many organizations, the primary objective is not simply automation. The real objective is maintaining a sustainable and auditable control framework as the SAP landscape evolves. Cloud adoption does not reduce compliance requirements. It increases the need for a single, auditable governance framework that spans both SAP and non-SAP systems. 

By extending SAP Access Control into hybrid landscapes, organizations can continue to enforce consistent approval processes, execute centralized Segregation of Duties analyses, and maintain comprehensive audit documentation across both SAP and non-SAP systems. This enables cloud adoption without sacrificing transparency, accountability, or control effectiveness. 

Is SAP Access Control End-of-Life? – A Roadmap Perspective

SAP Access Control 12.0 is not end-of-life. The table below summarizes the key maintenance milestones. 

Milestone Date Status
Mainstream maintenance ends December 31, 2027 SAP Note 3326989
Extended maintenance available until 2030 SAP Note 3326989
Announced successor SAP GRC for HANA (“GRC 2026”) Unified successor to Access Control, Process Control, and Risk Management 12.0

SAP’s designated successor, SAP GRC for HANA, is positioned as a unified successor to SAP Access Control 12.0, SAP Process Control 12.0, and SAP Risk Management 12.0, with its maintenance aligned to the S/4HANA lifecycle.

Organizations extending SAP Access Control today, for example through the XSP Access Control Connector, are building on a currently supported platform while preparing for this longer-term transition. 

Conclusion

The shift toward hybrid SAP landscapes is no longer a temporary phase but a long-term reality for most organizations. As cloud services become increasingly embedded within enterprise architectures, access governance solutions must evolve accordingly. 

The XSP Access Control Connector provides a practical way to bridge the gap between traditional governance processes and modern cloud provisioning models. By extending SAP Access Control beyond its traditional boundaries while preserving centralized governance, it enables organizations to maintain consistent security controls, strengthen auditability, and support future growth without introducing unnecessary complexity. 

„In a world where SAP landscapes continue to diversify, having a single governance framework that spans both on-premise and cloud environments is no longer just beneficial – it is becoming essential.”
Johannes Kastner, Head of GRC at Xiting
Johannes Kastner
Head of GRC at Xiting

FAQ

Do I need to replace SAP Access Control when moving to the Cloud?

SAP Access Control can be extended into cloud and non-SAP environments rather than replaced. A connector, such as the XSP Access Control Connector, routes access requests, approvals, and risk analysis for cloud and non-SAP applications through the existing SAP Access Control setup, while SAP Identity Provisioning Service (IPS) handles the actual provisioning on the target systems. This means organizations can bring cloud applications like SuccessFactors or Ariba under the same governance model they already use for their on-premise SAP systems, without introducing a separate governance platform or migrating existing approval workflows, risk rules, and audit processes.

SAP Access Control was originally designed for on-premise systems connected through RFC. It can be extended to govern cloud applications, such as SuccessFactors or Ariba, by combining it with SAP Identity Provisioning Service (IPS) and the XSP Access Control Connector that routes access requests and provisioning actions between SAP Access Control and the cloud target systems. 

SAP Access Control 12.0 remains in mainstream maintenance until December 31, 2027, with extended maintenance available until 2030. SAP has announced SAP GRC for HANA as its unified successor for Access Control, Process Control, and Risk Management, but existing SAP Access Control implementations remain fully supported during this period. 

Yes SAP Access Control can be extended to non-SAP applications through a combination of SAP Identity Provisioning Service and a governance connector, such as the XSP Access Control Connector. Organizations can route access requests, approvals, and provisioning actions for non-SAP applications through the same governance process used for SAP systems, without duplicating controls in a separate tool. 

Stay up to date.

Sign up for the newsletter to receive more information.

Follow @Xiting and @xiting.global on Social Media.

Get in touch now!

Melden Sie sich jetzt an!

Nehmen Sie jetzt Kontakt auf!