A hybrid SAP landscape combines on-premise systems such as SAP S/4HANA with cloud services like SAP BTP, SuccessFactors, Ariba, and SAP Identity Services. Governing user access consistently across both environments has become one of the central challenges for SAP security and compliance teams.
In this article, you will learn how SAP Access Control can be extended into hybrid and cloud landscapes without replacing your existing governance setup.
The SAP landscape has changed dramatically over the last decade. What was once a predominantly on-premise environment has evolved into a complex ecosystem consisting of SAP S/4HANA, SAP Business Technology Platform (BTP), SuccessFactors, Ariba, Identity Services, and an increasing number of non-SAP cloud applications.
As organizations continue to adopt cloud services, identity and access management processes are becoming more distributed, while governance and compliance requirements remain as important as ever. For SAP security and compliance teams, this transformation creates a fundamental challenge.
Access governance processes are expected to remain centralized and auditable, while access provisioning is increasingly executed across multiple technologies, platforms, and service providers. The result is a growing disconnect between governance decisions and technical execution.
Historically, SAP Access Control has served as the central platform for access governance activities such as Access Request Management, Segregation of Duties analysis, compliance reporting, and audit support. In traditional SAP environments, these processes were closely integrated with backend systems through established SAP connectors and RFC-based communication. Governance, risk analysis, approval workflows, and provisioning were all part of a largely unified process.
Cloud applications follow a different architectural model. Many modern solutions rely on REST-based interfaces and SCIM standards, while provisioning is often executed through SAP Identity Provisioning Service (IPS) rather than directly from SAP Access Control.
Although this approach aligns with modern cloud principles, it can lead to fragmented operating models in which governance activities are performed in one solution while provisioning is executed in another. As landscapes continue to expand, maintaining transparency, traceability, and audit readiness becomes increasingly difficult.
Organizations often attempt to bridge these gaps through custom integrations or manual provisioning processes. While such approaches may address immediate project requirements, they frequently introduce additional complexity and create long-term maintenance challenges.
More importantly, they can undermine one of the key principles of effective access governance: maintaining a centralized point of control for access decisions, risk assessments, and compliance monitoring.
From an audit perspective, fragmented processes increase the effort required to demonstrate who approved access, when provisioning occurred, and whether governance controls were consistently applied.
As a result, many organizations are looking for ways to extend the reach of SAP Access Control beyond traditional SAP systems without fundamentally redesigning their governance model. Some organizations extend their governance model by adopting a separate, cloud-native governance service designed primarily for SAP BTP and cloud applications.
The Xiting Security Platform (XSP) takes a different approach: it keeps the established, on-premise governance model of SAP Access Control at the center and extends it into hybrid and non-SAP environments through the XSP Access Control Connector, without introducing an additional governance platform.
Xiting’s XSP Access Control Connector was developed to address exactly this challenge. Rather than introducing another governance solution, it extends the capabilities of SAP Access Control into cloud and non-SAP environments while preserving established governance processes.
This allows organizations to continue leveraging SAP Access Control as their central system for access requests, approval workflows, risk analysis, and compliance reporting, regardless of where users and authorizations are ultimately provisioned.
Governance remains centralized while provisioning can be executed through modern cloud-native technologies and interfaces.
By integrating SAP cloud applications, SAP BTP environments, identity services, and even non-SAP platforms into a unified process framework, organizations can maintain a consistent governance model across their entire landscape. Security teams benefit from greater transparency, compliance teams retain a complete audit trail, and users experience a standardized access request process independent of the target system.
The XSP Access Control Connector does not replace SAP Access Control. It extends the existing governance processes, access requests, approvals, and risk analysis, to systems that communicate via REST or SCIM instead of RFC.
The XSP Access Control Connector runs within the Xiting Security Platform (XSP) and extends SAP Access Control’s existing governance processes, such as access requests, approvals, and risk analysis, into cloud and non-SAP systems without replacing the current SAP Access Control setup.
Identity Provisioning Service (IPS) provisions users in a hybrid landscape by receiving approved requests from SAP Access Control through the XSP Access Control Connector and executing the corresponding actions on the target cloud or non-SAP system.
A key aspect of the solution is its alignment with SAP’s modern identity architecture.
→ Instead of relying on direct connectivity to cloud systems, approved provisioning requests are routed through the XSP Access Control Connector and orchestrated via SAP Identity Provisioning Service. IPS then executes the required provisioning actions on the respective target platforms and returns the provisioning status to SAP Access Control.
This approach establishes a clear separation between governance and technical execution while maintaining end-to-end visibility throughout the process. Access decisions continue to be governed by SAP Access Control, while IPS provides the provisioning capabilities required for modern cloud applications. The result is a scalable architecture that supports both current and future landscape requirements without compromising governance standards.
For many organizations, the primary objective is not simply automation. The real objective is maintaining a sustainable and auditable control framework as the SAP landscape evolves. Cloud adoption does not reduce compliance requirements. It increases the need for a single, auditable governance framework that spans both SAP and non-SAP systems.
By extending SAP Access Control into hybrid landscapes, organizations can continue to enforce consistent approval processes, execute centralized Segregation of Duties analyses, and maintain comprehensive audit documentation across both SAP and non-SAP systems. This enables cloud adoption without sacrificing transparency, accountability, or control effectiveness.
SAP Access Control 12.0 is not end-of-life. The table below summarizes the key maintenance milestones.
| Milestone | Date | Status |
|---|---|---|
| Mainstream maintenance ends | December 31, 2027 | SAP Note 3326989 |
| Extended maintenance available until | 2030 | SAP Note 3326989 |
| Announced successor | SAP GRC for HANA (“GRC 2026”) | Unified successor to Access Control, Process Control, and Risk Management 12.0 |
SAP’s designated successor, SAP GRC for HANA, is positioned as a unified successor to SAP Access Control 12.0, SAP Process Control 12.0, and SAP Risk Management 12.0, with its maintenance aligned to the S/4HANA lifecycle.
Organizations extending SAP Access Control today, for example through the XSP Access Control Connector, are building on a currently supported platform while preparing for this longer-term transition.
The shift toward hybrid SAP landscapes is no longer a temporary phase but a long-term reality for most organizations. As cloud services become increasingly embedded within enterprise architectures, access governance solutions must evolve accordingly.
The XSP Access Control Connector provides a practical way to bridge the gap between traditional governance processes and modern cloud provisioning models. By extending SAP Access Control beyond its traditional boundaries while preserving centralized governance, it enables organizations to maintain consistent security controls, strengthen auditability, and support future growth without introducing unnecessary complexity.
SAP Access Control can be extended into cloud and non-SAP environments rather than replaced. A connector, such as the XSP Access Control Connector, routes access requests, approvals, and risk analysis for cloud and non-SAP applications through the existing SAP Access Control setup, while SAP Identity Provisioning Service (IPS) handles the actual provisioning on the target systems. This means organizations can bring cloud applications like SuccessFactors or Ariba under the same governance model they already use for their on-premise SAP systems, without introducing a separate governance platform or migrating existing approval workflows, risk rules, and audit processes.
SAP Access Control was originally designed for on-premise systems connected through RFC. It can be extended to govern cloud applications, such as SuccessFactors or Ariba, by combining it with SAP Identity Provisioning Service (IPS) and the XSP Access Control Connector that routes access requests and provisioning actions between SAP Access Control and the cloud target systems.
SAP Access Control 12.0 remains in mainstream maintenance until December 31, 2027, with extended maintenance available until 2030. SAP has announced SAP GRC for HANA as its unified successor for Access Control, Process Control, and Risk Management, but existing SAP Access Control implementations remain fully supported during this period.
Yes SAP Access Control can be extended to non-SAP applications through a combination of SAP Identity Provisioning Service and a governance connector, such as the XSP Access Control Connector. Organizations can route access requests, approvals, and provisioning actions for non-SAP applications through the same governance process used for SAP systems, without duplicating controls in a separate tool.
You are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from YouTube. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from hCaptcha to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from Turnstile to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Hubspot Embedded Content. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Hubspot Meetings. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information