Sei sulla pagina 1di 61

SAP and Mobility

Mederic Leborgne/SAP HANA Cloud Platform and Mobility presales


October, 2016

CUSTOMER
Agenda
Big Pictures
Mobility on SAP HANA Cloud Platform
SAP HANA Cloud Platform, mobile services
Elements of an Enterprise Mobility Management (EMM) Solution
• Mobile App Lifecycle Management
• Mobile Device Management
• Mobile Content Management
• Mobile Identity

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Customer 2


The Big Picture
Mobility in Digital Transformation
Digital Transformation
The Next Revolution

Value creation in the digital economy


begins with ubiquitous mobility
Digitization of data and interactions increasing at an
exponential pace.

Mobile Hyper In-Memory Mobile, Internet of Things and Hyper-connectivity


Connectivity Computing enabling immediate access to every “thing”

In-Memory changing the speed of computing and


delivering the vision of real time

Internet Big Data Machine Big Data and Machine learning technologies
of Things Learning changing how data is being analyzed with predictive
analytics

Cloud enabling digitization with commodity storage,


and on-demand computing at scale
Social Cloud

This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 4
Transforming key Processes with Mobile
Mobile allows digital transformation to impact the ‘Moment of Truth’

Customer
IoT & Big Data Experience

Digital Core

Workforce Supplier
Engagement & Business Networks

SAP HANA PLATFORM

 Leverage Mobile Apps to allow convenient access to Digital Core


 Leverage Mobile Apps to streamline or even reinvent digital E2E Processes…
This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 5
The Mobility Journey
Many Starting Points, Many Paths
Outsourced Internal

Organizations embark on their


mobility journey from different
starting points. Cloud On-Premise

Line of Business
Organizational
Priorities
IT
Business
Drivers Enterprise
Mobile App
Mobility
Development
Skill Sets Management

Business
Process Expert Developer
This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 6
SAP Mobile Strategy – Focus Areas
Helping customers establish Mobility as key pillar of their transformation

Key focus areas shaping mobile platform strategy,


investment and technologies at SAP.

Mobility on SAP Mobile


User Experience Mobile Platform
HANA Cloud On-Premise Developer
and Fiori
Platform Experience

This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including
particular purpose, or non-infringement
but notislimited
This the to,current
the impliedstate
warranties
of ofplanning
merchantability,
and fitness
may for abe changed by SAP at any time. 7
Customer
Unlocking the Power of SAP HANA Cloud Platform for mobile

Mobile Services Reusable Integration


e.g. authentication, to SAP and non-SAP
push, location, off-line back-ends (HCI)

Business Services API Management


leveraging HCP Services, API catalogues,
e.g. gamification, loyalty API governance

SAP HANA Cloud Platform


Custom Business Analytics
Logic and Storage Advanced analytics
Leveraging HANA, Java, services and visualization.
Node.js, etc.
S/4 SAP 3rd
HANA other Party

This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 8
Wide support for mobile devices

iOS Android Windows Phone OSX


• iPhone • Android phones & • Windows Phone 8.1 • Support for self-
• iPad tablets & 10 service configuration
• Apple Watch • Android 4.0.x-6.0.x file distribution for
• iOS 6.0.x - 9.X • Android for Work BYOC
• Samsung KNOX • Mac 10.X+
Standard
• LG Gate

See help.sap.com/mobilesecure system requirements for the current supported devices


This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 9
Everything starts in the Cloud
Controls for managing users, devices, apps and data

• Easy to trial and manage from the HCP Cockpit


• Role based administration and reporting on
devices, apps, users, and security events
• Enterprise integration & connectivity to HCP
services and on premise systems
• Leverages standard HCP administrative controls

This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 10
Mobility on SAP HANA Cloud Platform
SAP: The Cloud Company Powered by SAP HANA

SAP HANA Enterprise Cloud SAP HANA Cloud Platform SAP Cloud Apps
(HEC) Private Managed Cloud (PaaS) (SaaS)

Build
New Digital Apps

Extend
Run mission critical SAP On-premise &
applications in the cloud Digital Apps

Integrate
Everything

SAP Cloud Infrastructure


This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 12
SAP HANA Cloud Platform
The Enterprise Capabilities You Need to Succeed in the Cloud

Collaboration User Experience Integration Internet of Things Analytics

Security Mobile Data & Storage Business Services Dev & Ops

This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 13
Platform Services: Mobility
Value Proposition
App Logic
 UX Development focus is on delivering
 Screen Flow business value-- application logic and
 Interactivity
user experience.

But this represents a fraction of the


effort involved in enterprise mobility:

 Authentication &  Push notifications


Enterprise
authorization  High availability & fault
 Backend integration tolerance
 Governance  Security – devices, data,  Scalability
 Security
 Integration
communications  User onboarding and
 Manageability  Disconnected access & support
 Supportability synchronization
This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 14
Platform Services: Mobility
Developer Choice – Use the right tool for the job

Hybrid/Fiori Native
 Apache Cordova  OS Vendor IDE
 SAP Web IDE  SAP SDK
 SAP SDK plugins

Web/Fiori Metadata
 SAPUI5 Driven Apps
 OpenUI5  Codeless
 3rd party modifications
frameworks  Non-developer
user

This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 15
Mobile App Development
Immersive End-to-End DevOps Tool Chain

Discover Prototype Develop Test Package Deploy Extend

SAP Web IDE


SAP Fiori Device Test
Mobile SDK
Cloud

Cloud Build
Fiori
Designer Coder Extensibility

Business
Expert
This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 16
SAP HANA Cloud Platform, mobile services
SAP HANA Cloud Platform, mobile service for development and operations

SAP HANA Cloud Platform, mobile service for app and device management

SAP HANA Cloud Platform, mobile service for SAP Fiori

Other relevant SAP HANA Cloud Platform services


Platform Services: Mobility
SAP HANA Cloud Platform mobile service for development and operations

This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 18
Platform Services: Mobility
SAP HANA Cloud Platform, mobile service for app and device management

This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 19
SAP HANA Cloud Platform,
mobile service for app and device management

An integrated Enterprise Mobility Management (EMM) solution running on SAP HANA Cloud Platform,
leveraging the real-time processing power of SAP HANA.
App & Device Management
• Analysis
Key capabilities • Compliance
• Remediation
• Branded, multi-channel, self-service enterprise app store • Reporting
• Serve employees, partners and contractors
• Mobile app and device lifecycle management
• Streamline publishing, analysis and management of
apps/services
• Support for iOS, Android and Windows mobile platforms

Benefits SAP HANA Cloud Platform


• Increase mobile app adoption
• Lower the overall cost of supporting enterprise mobility
• Improve enterprise compliance and security
Read more: SAP HANA Cloud Platform, mobile service for app and device management

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 20


SAP HANA Cloud Platform
The Quickest Path to Innovative Mobile Apps & Digital Transformation

Build Extend Integrate


New Mobile & Mobile, Digital & Everything
Digital Apps On-premise Apps

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 21


Platform Services: UX
SAP Fiori

This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 22
Platform Services: UX
SAP HCP mobile service for SAP Fiori

Purpose-built to optimize SAP Fiori use


cases for mobile:
 Provide end users with the best possible mobile
experience Monitor
Develop/
Extend
 Simplify supporting use cases that go beyond
accessing Fiori apps from a web browser
HCP
 Provide secure and seamless integration with Run & mobile Build &
complex Fiori deployment scenarios Enjoy service for Test
SAP Fiori
 Provide a simple way for administrators to
manage, secure, enable and test Fiori apps and Discover Package
& &
their lifecycle Install Distribute

This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 23
Platform Services: Integration
SAP HANA Cloud Connector

The SAP HANA Cloud Connector allows a secure integration with on-premise systems. This enables easy integration of
the on-premise data with the SAP HANA Cloud Platform.

Customer
Key capabilities
 On-premise agent establishes secure SSL VPN connection HTTPS Internet
between the SAP HANA Cloud Platform and on-premise

Cloud Platform
systems Applications on
SAP HANA

Customer SAP HANA


 Supports pre-configured “Destination API” and certificate Cloud Platform
inspection to safeguard against forgeries Firewall
 Supports multiple protocols (HTTP, RFC, JDBC), high SSL Tunnel Internet
availability and principal propagation Firewall
SAP HANA
Benefits Cloud Connector
 Complementary to SAP Gateway, HANA Cloud Integration
and 3rd party integration suites both on-premise and in the
cloud ECC CRM HCM
On-Premise Network
Read more: SAP HANA Cloud Connector
This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 24
Platform Services: Integration
SAP API Management

SAP API Management on HANA Cloud Platform provides simple, scalable and secure access to digital assets and
enables engagement of employees and developers.

Key capabilities
 Unified standards based API access of REST/OData or
SOAP services
 Enterprise Grade Security for the APIs against attacks like
DoS, CSRF, XSS etc.
 Real-time insights & analytics on the APIs traffic, usage,
error reporting and monitoring

Benefits
 Platform for engaging with and enabling employees and
developers - internal and external

Read more: SAP API Management


This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 25
SAP HANA® Cloud Platform, integration service
Lowers cost, increases speed, and enhances simplicity for our customers

SAP Cloud Applications  Cloud-to-cloud and


cloud-to-on-premise

 Prepackaged integration content hub:


Engineered Prepackaged “Discover, Configure, Manage”
for the Cloud Integration Flows
 Multi-tenancy, rolling software
updates, horizontal scalability,
subscription-based
Multi-level Community and
Security Marketplace  Strong focus on security including
data isolation

 Complements SAP Process


Orchestration

 Open to partners – projects, content,


SAP 3rd Party 3rd
Party and connectivity adapters
On Premise On Premise Cloud Solutions
This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 26
Apple & SAP Partnership Announcement

A strategic partnership between Apple and SAP to transform the mobile work experience for
enterprise customers of all sizes.

SAP will create Industry lighthouse


SAP will create an iOS SDK for HCP
Apps, with an initial focus on Asset
that enables SAP development, SAP and Apple will jointly develop
Industries, Retail, Healthcare and
customers, and partners to build, and iOS/SAP Academy
Professional Services, supported by
extend and run apps
Apple’s Innovation Labs

This presentation and SAP‘s strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice.
© 2016 SAP SE or an SAP affiliate company. All rights reserved. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a
particular purpose, or non-infringement
Customer 27
Mobile App Lifecycle Management
The administrative user experience
Mobile App Management

Branded, multi-channel, localized, self-service app store experience to


serve employees, partners and consumers

Publishing, analysis and ongoing management of apps and services – to


both managed and unmanaged devices

App discovery through categorization, ratings and reviews and end user
personalization

Automatically direct out of compliance users to download the appropriate


MDM solution before downloading apps and services

Advanced app level security capabilities, remote app configuration and


policy deployment

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 29


Mobile App Management
Mobile app types supported

Enterprise Apps Commercial App Store Apps Web Clips


• Publish apps developed by an • Apple App Store, Google Play, • Publish managed Web based
enterprise or software vendor Windows Phone Store apps resources
supported
• SAP Fiori mobile apps • Support for end user supplied
• Commercial Volume Purchase documents, screenshots, videos
• Support for end user supplied Programs supported.
documents, screenshots, videos • iOS MDM devices: option to provide
• Supports videos, documents, resource as iOS Webclip
• Android for Work, Samsung SAFE
screenshots as supported material
and iOS: MDM deployment via MDM • “My Websites” used for organization
server, other Oss OTA via direct • App Name, App Icon, sample within Mobile Place
download screenshots and App Description
retrieved automatically.

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 30


Manage the lifecycle of mobile apps

Add Apps
• Volume purchase and centrally
deploy / reconcile
• Publish enterprise apps, app store
apps, web apps, SAP Fiori apps to
Mobile Place

Deploy Apps
Retire Apps • Make apps required/available
• Force upgrade or removal of •Automatically install/manage
app to be retired apps based on user and
current device state

Protect Apps Configure Apps


• Automate server/app connection
•Set copy/paste controls, data details and policy deployment
sharing controls, • Support AppConfig Community
compromise tests, or wrap for iOS and AFW apps (support
apps* managed app config)

* Some app protection capabilities may require additional licensing


© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 31
App Catalog Administration

• Role based Administration:


• App Catalog Admin
• App Catalog Publisher
• Reporting Admin
• Mobile Place User
• Support for mobile app:
• Private trials & betas
• Social and IT/Dev feedback
• App version management: updates,
multiple versions, retire/expire
• Support for adding additional security to
‘enterprise apps’ prior to publishing to
production
• Support for pre-production app testing
on real devices on real networks

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 32


App Catalog Administration
Settings Management

• Define app publishing meta data


• Details – including name,
description, language, featured
app, MDM versus Non or both,
• Groups – who gets the app
• Multimedia – supporting
graphics media for app
• Support for private trials & betas
with feedback loops for IT and App
Developers
• Support for adding additional
security to ‘enterprise apps’ prior to
publishing to production
• Support for pre-production app
testing on real devices on real
networks

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 33


App Catalog Administration
Test the app on real devices

Select action on app


to initiate testing
workflow

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 34


App Catalog Management
Create a catalog experience to meet your requirements

Rich customization capabilities:


• Override default text
• Upload new languages
• Custom support text and EULA settings
• Use custom logo
• Set background Image
• Use custom stylesheet
• Set favorite/default App/Webclip icon
• Set default access to Managed or
Unmanaged device
• Configure authentication mechanism -
Cloud/Enterprise, SAML
• Allow app store “Preview” for managed
devices not under MDM
© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 35
Mobile Device Management
Controls for Managing Users, Devices and Data
Device Management
Secure, Configure, and Monitor

Secure Configure Monitor


• Enforce PIN/passcode • Group policies • Corporate or end user driven
requirements • Corporate email access enrollment
• Detect jailbreak & root • Device ID • Detailed asset tracking
compromises • WiFi settings • Device location and activity
• Locate, lock, wipe, and • VPN and per-app VPN • Enforce policy compliance
password reset for lost devices • Enterprise SSO • Event logs
• Install and manage digital • Device restrictions and usage • Pre-built and custom reports
certificates control • HCP–based administrative
• Enforce device data protection • Apple AirPlay console
• Require encrypted backups • Android for Work enterprise
• Restrict copy and paste containers
between apps • Cellular roaming controls
• Browser proxies
• Device APN

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 37


Device Management
Manage Android

Standard Android
• Manufacturer-independent settings to control passcodes,
configure Wi-Fi, block Bluetooth, block camera, force encryption
and more on devices running Android 4.0 and above

Android for Work


• Google’s secure enterprise solution for app and device
management
• Provides managed Chrome, managed email/calendar/contacts
• Offered on 70 enterprise-class devices from 13 OEMs including
HP, HTC, LG, Samsung, Sony, Motorola, Fujitsu, Blackberry,
Google

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 38


Device Management
Manage Android

LG Gate
 Control roaming, USB, email & Microsoft Exchange accounts,
browser, apps and remote data wipe options

Samsung KNOX Standard


 Manage browser, APN, applications, OTA updates, device resets,
roaming, SD card, Wi-Fi, email and Exchange, USB, microphone,
camera, clipboard, NFC, GPS, firewall, app whitelist/blacklist,
access to Play, YouTube, voice dialer and more

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 39


Device Management
Manage iOS

Manage and secure iPhones and iPads in the enterprise


• Volume Purchase Program
• Apple Device Enrollment Program (DEP)
• Supervised device settings
• SSO for enterprise apps
• App configuration
• Certificate management
• Per app VPN

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 40


Device Management
Manage Windows Phone

Device policies to manage Windows Phones


• App Restrictions – maintain app whitelist/blacklists - by app and by app publisher
• Device Restrictions – Wi-Fi, NFC, Bluetooth, roaming, storage card, location,
telemetry, disable reset by user, disable copy/paste, disable user un-enrollment,
block Windows Store,
• Certificates – deploy, track and revoke device and user certificates
• Exchange Active Sync – manage email account settings
• Passcode – set passcode quality and remediation options
• VPN – configure VPN access
• Wi-Fi – configure access to corporate Wi-Fi
• Assigned Access – enable kiosk / specialized use scenarios
• Distribute enterprise and Windows Store apps

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 41


Mobile Identity
User Management
Mobile Identity and Access

User authentication secures User identity forms policies Access control regulates mobile
access • User directories - Microsoft Active device access
• SAML 2.0 compliant services Directory and LDAP – user • Email – Microsoft Exchange and
(Azure AD, OKTA, PING, context data for groups and Microsoft Office 365
Centrify, etc.) variables • Network Access Control – Aruba,
• SAP Cloud Identity Service • Certificates - full management Checkpoint, Cisco, Forescout
through certificate lifecycle for
Microsoft and Entrust certificate
authorities

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 43


SAP HANA Cloud Platform Identity Authentication
In the SAP security portfolio

SAP Cloud SAP Cloud Identity


Applications Manage access,
SAP HANA Cloud SAP HANA Cloud Access
users and
compliance in the Platform Identity Platform Identity Governance,
cloud Authentication Provisioning access analysis
service
SAP
S/4HANA

Add-On for Code


SAP Single SAP Identity SAP Access SAP Enterprise
SAP Vulnerability
Sign-On Management Control Threat Detection
Business Analysis
Suite
Ensure corporate Find and correct
Make it simple for users to do Know your users and what Counter possible threats and
compliance to vulnerabilities in customer
what they are allowed to do they can do identify attacks
regulatory requirements code

3 rd Party
Systems SAP HANA Cloud SAP NetWeaver
Platform Make sure that SAP
SAP HANA
solutions run securely Platform Application Server
Security

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 44


Product overview
Introduction

SAP HANA Cloud Platform Identity Authentication provides secure access to web
applications. It is a software as a service (SaaS) offering by SAP

Access protection
 Identity federation based on SAML 2.0
 Web single sign-on and desktop SSO
 Secure on-premise integration with existing authentication system
 Social and strong authentication
 Risk-based authentication

Manage users and access to applications


 User administration and integration with on-premise user stores
 User groups and application access management
 User self-services
 Password and privacy policies

Enterprise features for integration


 Branding of end user UIs Identity Authentication
 Programmatic integration via SCIM standard Service

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 45


Integrating SAP – and 3rd party applications
Introduction

HR & Collaboration ERP, CRM Planning & Analytics 3rd party

SF Employee Microsoft:
S4HANA IBP
Central Office365, Azure

C4C Travel, …
Jam Cloud Analytics
Cloud for Customer

Authentication, SSO

SAP HANA Cloud Platform Social Platforms


Delegate
Identity Authentication authentication Facebook, Google,
Cloud
Service Twitter

Authentication, Provisioning
On-premise
HCM Identity Management

HR IDM IdP

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 46


Configurable access levels
Identity access management

Access protection on user level and on application level

Public access
Self registration is allowed
Social authentication [optional]

Internal access
User status Only users already registered
new, active, are entitled to access
inactive, locked
Private access
Only users registered for the
application can access

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 47


Risk-based authentication
Identity access management

Define authentication rules to control application access

Allow

User Group Membership

and/or
******
****** Logon

Logon

Two-factor-authentication
Network IP Ranges Deny

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 48


Identity authentication service as a proxy to a corporate IdP
Delegated authentication

IdP proxy via the SAML standard – easy to establish

Identity provider proxy


SAML  Authentication is delegated to
Identity Authentication
Service corporate identity provider login
 Reuse of existing single sign-on
Applications SAML infrastructure
 Easy and secure authentication for
****** business-to-employee (B2E) scenarios
Logon

 Federation based on the SAML 2.0


standard
3rd party Cloud Corporate
Identity
Provider

Corporate Network

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 49


Authentication with on-premise user store
Delegated authentication

Integrate with an on-premise user store via a secure tunnel

******
On-premise user store
Logon
 Users credentials from:
Identity Authentication  Active Directory
Service
 3rd party user store
Applications
 No user replication to the cloud required
Cloud Connector  Internal network ports do not need to be
exposed to the Internet
 In addition usual product features can
be used: UI configuration, policies, two-
SAP
LDAP NW JAVA factor-authentication
+ SAP SSO AS ABAP
SAP NetWeaver
Corporate Network

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 50


SPNEGO authentication
Delegated authentication

SPNEGO: integrate with MS Windows domain authentication

SPNEGO* authentication
SAML  Users authenticated with corporate
Identity Authentication LDAP enjoy single sign-on to cloud
Service
applications without re-authentication
Applications  Reuse of existing corporate identity
SPNEGO infrastructure
 Secure authentication and SSO for
cloud and on-premise web applications
Kerberos  Increase user productivity in B2E
token
scenarios
LDAP
Corporate LDAP
credentials AS AAP
Corporate Network
* Simple and Protected GSSAPI Negotiation Mechanism

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 51


Social IdP integration
Delegated authentication

Enable social login with popular identity providers in the Internet

Social media authentication


SAML
Identity Authentication  Suitable for B2C, B2B scenarios
Service
 Configurable per application
Applications  Linking and unlinking of social
accounts
******
Logon
 Logon credentials
 Social media username & password
OAuth

3rd party Cloud Social Media


IdPs

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 52


IdP initiated SSO
Delegated authentication

Secure your business network and allow partner users to login via their corporate IdP

****** „User Group 1“


SAML IdP 1 Logon
can access via
SAML IdP 1

Identity Authentication
Service
Application
******
SAML IdP 2
Logon „User Group 2“
can access via
SAML IdP 2

SAP HANA Cloud Platform Identity Authentication as a proxy to multiple SAML identity providers
 Authentication is initiated by the SAML identity provider
 Upon successful authentication, a check for correct user group assignment can be configured (optional)

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 53


Administration services
User management & user self-services

Application Configuration User Management

Reporting Branding & Policies

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 54


User management
User management & user self-services

Web-based and programmatic user management capabilities

User administration
 Web based user management
 User search
 Mass user import/export
 Monitor user access

User groups administration


 Define user groups
 Assign users to groups

Integration
 Programmatic integration via
SCIM REST APIs

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 55


Branding and customization
User management & user self-services

User interface, email templates and registration policies can be adjusted to corporate needs

Customization features
 Company Logo
 Application name and logo
 Color style
 Terms of use & privacy policy
 Adjust UI texts via API
 Mail templates (account confirmation,
forgot pwd., et al.)

Product features
 Responsive UIs
 Multilanguage support

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Public 56


Mobile Content Management
Enterprise File Sync & Share
Mobile Content Management with SAP Document Center
Simple access to enterprise content

• Enterprise File Sync and Share (EFSS) solution


• Simple access to content on any device (online &
offline) with native clients for all major platforms
• Files automatically downloaded to mobile devices
• Content can be pushed to devices based on roles
• Documents available even when offline
• Synchronize single documents or complete folder
• Personalized access to on-premise content in
Microsoft SharePoint, SAP S/4 HANA and SAP
Business Suite Applications
• Easy integration with wide range of SAP solutions

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 58


3rd Party Integration Framework
SAP HANA Cloud Platform
Extend Mobile Apps via 3rd Party Integration Framework

Enhance all mobile apps post-development Add advanced capabilities to Fiori mobile apps
3rd Party cloud services are Publicly available Cordova
integrated into the workflows plugins and 3rd party
with SAP HANA Cloud commercial app plugins are
Platform mobile services dynamically built into SAP
App Wrapping Fiori mobile apps
Threat Defend against cyber
Requires: App Testing attacks, report/enforce risk- Requires:
SAP HCP mobile service for Detection based policy management SAP HCP mobile
app and device management service
Create custom Fiori mobile
OR EMM/MAM apps. Deploy them via EMM for SAP Fiori
SAP HCP mobile service solutions
for SAP Fiori
Create custom SAP Fiori
VPN apps and automate
connection to VPN
Leverage publically available
Cordova Plugin Codova plugins

Enterprise mobile apps developed with SAP Fiori mobile apps built with
HCP mobile service for dev & ops HCP mobile service for SAP Fiori

© 2016 SAP SE or an SAP affiliate company. All rights reserved. Internal 60


Thank you
Contact information:

F name L name
Title
Address
Phone number

F name L name
Title
Address
Phone number

Potrebbero piacerti anche