From SAP to Entra ID: accounts and roles in one lifecycle
Nova provisions accounts, roles and groups directly in your systems, through native connectors and open protocols. 13 integrations as standard, SAP BTP in beta, and further systems as project integrations on the connector SDK. Guideline per new integration: 1–2 weeks, depending on the API and the test system.
All integrations with protocol and status
25 systems
| System | Protocol | Status | Scope | Detail page |
|---|---|---|---|---|
| SAP | ||||
| Nova connects SAP ERP and S/4HANA directly via RFC/BAPI, with no middleware in between, and also reads the organizational structure from SAP HCM via RFC. Nova connects SAP BTP via SCIM as a beta, and SuccessFactors as a project integration. | ||||
| SAP ERP & S/4HANA | RFC/BAPI (SAP NetWeaver RFC SDK) | Standard | User lifecycle directly via RFC/BAPI: create and lock accounts, passwords, single and composite roles with native validity dates. Role import including hierarchy straight from the system. | Details on SAP ERP & S/4HANA |
| SAP BTP | SCIM 2.0 via SAP Cloud Identity Services; WebSocket RFC in trial | Beta | SAP systems on the Business Technology Platform via SCIM against SAP Cloud Identity Services. Direct RFC connectivity via WebSocket RFC is in trial. | Details on SAP BTP |
| SAP HCM & Organisational Management HR source | RFC (Organizational Management, read-only); personnel data via LDAP or a staging table | Standard | SAP HR master data and org tree as a source: infotypes with validity periods, org units, positions. Drives joiner, mover and leaver processes. | Details on SAP HCM & Organisational Management |
| SAP SuccessFactors HR source | OData | Project integration | Employee Central as an HR source via OData: hires, transfers and departures flow into the identity lifecycle with their validity dates. | Details on SAP SuccessFactors |
| Directories & Identity Providers | ||||
| Active Directory | LDAP/LDAPS | Standard | Accounts, groups and passwords in AD: creation with naming rules, disabling, nested groups, LDAPS password management. Changes are journaled and individually revertible. | Details on Active Directory |
| OpenLDAP & generic LDAP | LDAP/LDAPS | Standard | Dedicated directory profiles for OpenLDAP (posixGroups, ppolicy) and generic LDAP servers (groupOfNames). Active Directory uses the same connector with its own profile. | Details on OpenLDAP & generic LDAP |
| Microsoft Entra ID | Microsoft Graph API, OAuth2 | Standard | Cloud identities via the Graph API: accounts, group memberships including nested groups, account status and sign-in activity. | Details on Microsoft Entra ID |
| Keycloak | Keycloak Admin REST API | Standard | Users, groups and roles via the admin API, current Keycloak versions included. Keycloak is the only target system where Nova also provisions AI agents as dedicated service accounts. | Details on Keycloak |
| SCIM 2.0 | SCIM 2.0 | Standard | Any SCIM-capable system as a target: create accounts, assign groups, control active status. No dedicated connector is needed per application. | Details on SCIM 2.0 |
| HR Sources & Data Import | ||||
| Personio HR source | Personio REST API | Project integration | Personio as an HR source: master data, hires and departures via the Personio API feed the lifecycle sync. Delivered as a project integration. | Details on Personio |
| CSV & File Import (AI-assisted) | File upload: CSV, Excel, XML, JSON | Standard | HR and legacy data from CSV, Excel, XML or JSON: the migration workbench generates the parser function with AI assistance; every import is logged and can be rolled back. | Details on CSV & File Import (AI-assisted) |
| User Import from Target Systems | Native connectors: LDAP, Graph API, Keycloak, RFC | Standard | Collect existing accounts from AD, LDAP, Entra, SAP or Keycloak and reconcile them with Nova identities: as a job, matched by email or identifier. | Details on User Import from Target Systems |
| Microsoft 365 & Collaboration | ||||
| Microsoft Teams | Microsoft Graph API via the Entra ID connector | Standard | Manage team memberships through roles: assigning the role adds the membership, revoking the role ends it. Runs on the Entra groups behind each team. | Details on Microsoft Teams |
| Microsoft OneDrive | Microsoft Graph API, OAuth2 | Project integration | Access via Entra groups and account status, which the Entra connector already manages. OneDrive-specific scope such as license assignment is added as part of the project. | Details on Microsoft OneDrive |
| Webex | SCIM or REST API, decided in the project | Project integration | Account lifecycle for Cisco Webex via the identity API: creation, deactivation and group assignment in step with the central lifecycle. | Details on Webex |
| ITSM & Help Desk | ||||
| With a project integration, provisioning actions and approvals create tickets in your ITSM system, so changes are traceable where your operations team works. | ||||
| Jira | Jira REST API, as a plugin | Project integration | Ticket bridge to Atlassian Jira: requests, approvals and provisioning results as issues in the project of your choice. | Details on Jira |
| TOPdesk | TOPdesk REST API, as a plugin | Project integration | Incident and change integration for TOPdesk: IAM operations feed into your existing incident and change processes. | Details on TOPdesk |
| ServiceDesk Plus | REST API, as a plugin | Project integration | Integration with ManageEngine ServiceDesk Plus via its REST API: tickets from Nova workflows, status fed back into the history. | Details on ServiceDesk Plus |
| Infrastructure & Databases | ||||
| Microsoft SQL Server | T-SQL via the standard database interface | Project integration | Logins, database users and roles on SQL Server: database access becomes part of the same request and recertification process as everything else. | Details on Microsoft SQL Server |
| Linux & Unix (SSH) | SSH, typically with key pairs | Project integration | Manage local accounts and groups on servers via SSH: creation, locking and group assignment, auditable like any other provisioning action. | Details on Linux & Unix (SSH) |
| Windows (PowerShell) | PowerShell remoting over WinRM | Project integration | PowerShell remoting as a provisioning path for Windows environments and anything manageable via cmdlet. | Details on Windows (PowerShell) |
| macmon NAC | macmon REST API | Project integration | Identity synchronization with macmon Network Access Control via its REST API: network access follows identity status. | Details on macmon NAC |
| Platform Interfaces | ||||
| REST-API | HTTP with JSON | Standard | Nova’s entire surface is a JSON API: systems, identities, requests, provisioning, jobs. The UI uses the same endpoints. | Details on REST-API |
| Email Notifications | SMTP with STARTTLS or SSL | Standard | Built-in SMTP channel for approvals, escalations and lifecycle events: credentials stored encrypted, TLS, no additional service required. | Details on Email Notifications |
| File & Data Export | Export jobs, retrieved via API | Standard | Export identity and entitlement data as files, such as CSV, Excel or PDF, via API call. Recurring handovers to downstream systems are set up as part of the project. | Details on File & Data Export |
No system found. Yours is missing? Talk to us.
Extensible through the connector SDK and plugins
If a system is missing from the catalog, the integration is built on the same SDK as the standard connectors.
Connector-SDK
Every connector implements the same lean base interface: accounts, roles, passwords, status, jobs. A new connector is a Python module and inherits change journaling and audit automatically.
Plugin System
Feature modules with their own UIs and hooks: MFA, SoD checks, Teams control and GRC analytics are built this way. The same mechanism is open for customer requirements.
Open Standards First
Where a standard exists, we use it: LDAP, SCIM 2.0, OAuth2, REST. That keeps integrations maintainable and keeps you independent of proprietary gateways.
Your system isn’t listed?
New connectors are built on the connector SDK as part of your project. Guideline per new integration: 1–2 weeks, depending on the API and the test system. Tell us which system you want to connect, and we will work out the interface and effort with you.
Request a demoAll product names, logos and brands mentioned are property of their respective owners. They are referenced solely to describe compatibility and do not imply any partnership or endorsement.