SAP

ConnectorStandard

SAP ERP & S/4HANA

Nova provisions SAP users and roles directly through BAPI calls: it creates, locks, and deletes accounts and assigns roles with native validity dates, with no agent or middleware inside the SAP system.

Capabilities

What Nova does with SAP ERP & S/4HANA

  • Accounts via BAPI

    Creates SAP user accounts via BAPI, optionally without an initial password for SSO-only setups.

  • Roles with validity dates

    Assigns single and composite roles with validity dates: time limits are written as FROM_DAT/TO_DAT into the SAP role assignment itself, not just recorded in Nova.

  • Role reconciliation

    Reads the actual role assignments back from SAP, including the children of composite roles, and reconciles them against the target state in Nova.

  • Role catalog import

    Imports the SAP role catalog with German and English role descriptions for use in access requests.

  • Locking and passwords

    Locks and unlocks accounts, sets passwords, and updates user attributes; every change is checked against the SAP return code and written to the audit log.

  • Inactive accounts

    Detects dormant SAP accounts using the last logon date read from USR02.

Technology and process

Integration and identity lifecycle

Technical integration

Connectivity is plain RFC via the SAP NetWeaver RFC SDK: direct connection, message server with logon group, or SAProuter, authenticated with a technical SAP user. Every write is validated against the BAPI return code and finalized with BAPI_TRANSACTION_COMMIT.

In the identity lifecycle

In the joiner/mover/leaver process, Nova creates SAP accounts automatically, adjusts roles on transfers, and locks accounts at exit; approved requests are provisioned straight into SAP, and recertification reviews the actual state read back from SAP rather than Nova's records alone.

More in the catalog

Related integrations

All product names, logos and brands mentioned are property of their respective owners. They are referenced solely to describe compatibility and do not imply any partnership or endorsement.

Next step

Ask your questions live on the system.

30 minutes via video call on the demo system: you name your use cases, we show the relevant functions.

Request a demo

What happens next

  1. ReplyWe usually get back to you on the same working day and agree a date with you.
  2. PreparationWe prepare the demo around the topics you name.
  3. 30 minutes via video callLive on the demo system with fictitious data: you ask, we show the relevant views.