SAP ERP & S/4HANA
Nova provisions SAP users and roles directly through BAPI calls: it creates, locks, and deletes accounts and assigns roles with native validity dates, with no agent or middleware inside the SAP system.
What Nova does with SAP ERP & S/4HANA
- Creates SAP user accounts via BAPI, optionally without an initial password for SSO-only setups
- Assigns single and composite roles with validity dates: time limits are written as FROM_DAT/TO_DAT into the SAP role assignment itself, not just recorded in Nova
- Reads the actual role assignments back from SAP, including the children of composite roles, and reconciles them against the target state in Nova
- Imports the SAP role catalog with German and English role descriptions for use in access requests
- Locks and unlocks accounts, sets passwords, and updates user attributes; every change is checked against the SAP return code and written to the audit log
- Detects dormant SAP accounts using the last logon date read from USR02
Technical integration
Connectivity is plain RFC via the SAP NetWeaver RFC SDK: direct connection, message server with logon group, or SAProuter, authenticated with a technical SAP user. Every write is validated against the BAPI return code and finalized with BAPI_TRANSACTION_COMMIT.
In the identity lifecycle
In the joiner/mover/leaver process, Nova creates SAP accounts automatically, adjusts roles on transfers, and locks accounts at exit; approved requests are provisioned straight into SAP, and recertification reviews the actual state read back from SAP rather than Nova's records alone.
All product names, logos and brands mentioned are property of their respective owners. They are referenced solely to describe compatibility and do not imply any partnership or endorsement.