Top Banner
HA240 SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security Requirements . . COURSE OUTLINE . Course Version: 15 Course Duration:
47

SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Oct 15, 2021

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

HA240SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security Requirements

..

COURSE OUTLINE.

Course Version: 15Course Duration:

Page 2: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...
Page 3: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

SAP Copyrights, Trademarks and Disclaimers

© 2019 SAP SE or an SAP affiliate company. All rights reserved.

No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP SE or an SAP affiliate company.

SAP and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP SE (or an SAP affiliate company) in Germany and other countries. Please see http://global12.sap.com/corporate-en/legal/copyright/index.epx for additional trademark information and notices.

Some software products marketed by SAP SE and its distributors contain proprietary software components of other software vendors.

National product specifications may vary.

This course may have been machine translated and may contain grammatical errors or inaccuracies.

These materials are provided by SAP SE or an SAP affiliate company for informational purposes only, without representation or warranty of any kind, and SAP SE or its affiliated companies shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP SE or SAP affiliate company products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty.

In particular, SAP SE or its affiliated companies have no obligation to pursue any course of business outlined in this document or any related presentation, or to develop or release any functionality mentioned therein. This document, or any related presentation, and SAP SE’s or its affiliated companies’ strategy and possible future developments, products, and/or platform directions and functionality are all subject to change and may be changed by SAP SE or its affiliated companies at any time for any reason without notice. The information in this document is not a commitment, promise, or legal obligation to deliver any material, code, or functionality. All forward-looking statements are subject to various risks and uncertainties that could cause actual results to differ materially from expectations. Readers are cautioned not to place undue reliance on these forward-looking statements, which speak only as of their dates, and they should not be relied upon in making purchasing decisions.

© Copyright. All rights reserved. iii

Page 4: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Typographic Conventions

American English is the standard used in this handbook.

The following typographic conventions are also used.

This information is displayed in the instructor’s presentation

Demonstration

Procedure

Warning or Caution

Hint

Related or Additional Information

Facilitated Discussion

User interface control Example text

Window title Example text

iv © Copyright. All rights reserved.

Page 5: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Contents

ix Course Overview

1 Unit 1: SAP HANA Overview

1 Lesson: Introducing SAP HANA1 Lesson: Understanding SAP HANA Implementation Scenarios1 Lesson: Outlining Security Functions1 Lesson: Describing Security Administration Tools

3 Unit 2: Network and Communication Security

3 Lesson: Describing Communication Channels3 Lesson: Securing Data Communications

5 Unit 3: Certificate Management

5 Lesson: Describing Certificate Management in SAP HANA

7 Unit 4: Data Storage Security

7 Lesson: Describing Data-at-Rest Encryption

9 Unit 5: Object Ownership

9 Lesson: Understanding Object Ownership

11 Unit 6: User Management

11 Lesson: Comparing User Types11 Lesson: Describing User Administration Tools11 Lesson: Understanding User Groups

13 Unit 7: Authentication and Single Sign-On

13 Lesson: Understanding Authentication and Single Sign-On Mechanisms

15 Unit 8: Elements of Application Development in XS Advanced

15 Lesson: Introducing Application Development Tools15 Lesson: Describing the Multi-Target Application15 Lesson: Using the CDS Entity

17 Unit 9: Elements of Application Development in XS Classic (optional)

17 Lesson: Introducing SAP HANA Repository (optional)

© Copyright. All rights reserved. v

Page 6: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

19 Unit 10: Authorizations

19 Lesson: Describing Authorization in SAP HANA19 Lesson: Describing Privileges19 Lesson: Managing Roles19 Lesson: Describing Analytic Privileges in XS Classic (optional)19 Lesson: Understanding Cross-Database Authorizations in Tenant

Databases19 Lesson: Describing Data Masking20 Lesson: Describing Anonymization20 Lesson: Describing LDAP Group Authorization20 Lesson: Setting up and Analyzing an Authorization Trace

21 Unit 11: Analyzing Users and Authorizations

21 Lesson: Viewing Information about Users and Authorizations

23 Unit 12: Auditing

23 Lesson: Using Audit Logging

25 Unit 13: Security for SAP HANA Extended Application Services, Classic Model (optional)

25 Lesson: Describing SAP HANA Extended Application Services Security and Application Privileges (optional)

27 Unit 14: Security for SAP HANA Extended Application Services, Advanced Model

27 Lesson: Describing SAP HANA Extended Application Services, Advanced Model Security

29 Unit 15: SAP BW Models in SAP HANA

29 Lesson: Understanding SAP BW Models in SAP HANA

31 Unit 16: Integration with SAP BusinessObjects BI (optional)

31 Lesson: Understanding Authentication Options and User Management Implications for the Integration of SAP BusinessObjects BI 4.X and SAP HANA (optional)

33 Unit 17: SAP HANA with ERP or S/4HANA and the Analytics Authorization Assistant (optional)

33 Lesson: Describing SAP HANA with ERP or SAP S/4HANA and the Analytics Authorization Assistant (optional)

vi © Copyright. All rights reserved.

Page 7: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

35 Unit 18: Integration with SAP GRC (optional)

35 Lesson: Outlining SAP GRC Integration for Governance, Risk and Compliance (optional)

37 Unit 19: Integration with SAP Identity Management (optional)

37 Lesson: Understanding SAP Identity Management Integration (optional)

© Copyright. All rights reserved. vii

Page 8: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

viii © Copyright. All rights reserved.

Page 9: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Course Overview

TARGET AUDIENCEThis course is intended for the following audiences:

● Systems Architect

● Application Consultant

● Development Consultant

● Technology Consultant

● Support Consultant

● Data Consultant

● Database Administrator

● Technology Consultant

© Copyright. All rights reserved. ix

Page 10: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

x © Copyright. All rights reserved.

Page 11: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 1 SAP HANA Overview

Lesson 1: Introducing SAP HANALesson ObjectivesAfter completing this lesson, you will be able to:

● Describe SAP HANA

Lesson 2: Understanding SAP HANA Implementation ScenariosLesson ObjectivesAfter completing this lesson, you will be able to:

● Understand SAP HANA implementation scenarios

Lesson 3: Outlining Security FunctionsLesson ObjectivesAfter completing this lesson, you will be able to:

● Outline the security functions in SAP HANA

Lesson 4: Describing Security Administration ToolsLesson ObjectivesAfter completing this lesson, you will be able to:

● Describe the security administration tools

© Copyright. All rights reserved. 1

Page 12: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 1: SAP HANA Overview

2 © Copyright. All rights reserved.

Page 13: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 2 Network and Communication Security

Lesson 1: Describing Communication ChannelsLesson ObjectivesAfter completing this lesson, you will be able to:

● Describe SAP HANA communication channels

Lesson 2: Securing Data CommunicationsLesson ObjectivesAfter completing this lesson, you will be able to:

● Recognize the options to secure data communications in SAP HANA

© Copyright. All rights reserved. 3

Page 14: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 2: Network and Communication Security

4 © Copyright. All rights reserved.

Page 15: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 3 Certificate Management

Lesson 1: Describing Certificate Management in SAP HANALesson ObjectivesAfter completing this lesson, you will be able to:

● Describe in-database certificate management workflow

● Manage client certificates and certificate collections in SAP HANA

© Copyright. All rights reserved. 5

Page 16: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 3: Certificate Management

6 © Copyright. All rights reserved.

Page 17: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 4 Data Storage Security

Lesson 1: Describing Data-at-Rest EncryptionLesson ObjectivesAfter completing this lesson, you will be able to:

● Describe data-at-rest encryption options in SAP HANA

● Manage data-at-rest encryption

© Copyright. All rights reserved. 7

Page 18: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 4: Data Storage Security

8 © Copyright. All rights reserved.

Page 19: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 5 Object Ownership

Lesson 1: Understanding Object OwnershipLesson ObjectivesAfter completing this lesson, you will be able to:

● Understand object ownership effects

© Copyright. All rights reserved. 9

Page 20: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 5: Object Ownership

10 © Copyright. All rights reserved.

Page 21: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 6 User Management

Lesson 1: Comparing User TypesLesson ObjectivesAfter completing this lesson, you will be able to:

● Compare the different user types in SAP HANA

Lesson 2: Describing User Administration ToolsLesson ObjectivesAfter completing this lesson, you will be able to:

● Understand which tools are available for user management tasks

Lesson 3: Understanding User GroupsLesson ObjectivesAfter completing this lesson, you will be able to:

● Understand user groups in SAP HANA

© Copyright. All rights reserved. 11

Page 22: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 6: User Management

12 © Copyright. All rights reserved.

Page 23: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 7 Authentication and Single Sign-On

Lesson 1: Understanding Authentication and Single Sign-On MechanismsLesson ObjectivesAfter completing this lesson, you will be able to:

● Recognize the different authentication mechanisms available in SAP HANA

© Copyright. All rights reserved. 13

Page 24: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 7: Authentication and Single Sign-On

14 © Copyright. All rights reserved.

Page 25: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 8 Elements of Application Development in XS Advanced

Lesson 1: Introducing Application Development ToolsLesson ObjectivesAfter completing this lesson, you will be able to:

● Explain application development tools for SAP HANA XS advanced

Lesson 2: Describing the Multi-Target ApplicationLesson ObjectivesAfter completing this lesson, you will be able to:

● Explain what a multi-target application is

Lesson 3: Using the CDS EntityLesson ObjectivesAfter completing this lesson, you will be able to:

● Create a CDS entity that is a table in the database

© Copyright. All rights reserved. 15

Page 26: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 8: Elements of Application Development in XS Advanced

16 © Copyright. All rights reserved.

Page 27: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 9 Elements of Application Development in XS Classic (optional)

Lesson 1: Introducing SAP HANA Repository (optional)Lesson ObjectivesAfter completing this lesson, you will be able to:

● Describe the SAP HANA Repository

© Copyright. All rights reserved. 17

Page 28: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 9: Elements of Application Development in XS Classic (optional)

18 © Copyright. All rights reserved.

Page 29: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 10 Authorizations

Lesson 1: Describing Authorization in SAP HANALesson ObjectivesAfter completing this lesson, you will be able to:

● Describe the basic authorization entities in SAP HANA

Lesson 2: Describing PrivilegesLesson ObjectivesAfter completing this lesson, you will be able to:

● Understand the different type of privileges and their usage

Lesson 3: Managing RolesLesson ObjectivesAfter completing this lesson, you will be able to:

● Define, create, and manage roles

Lesson 4: Describing Analytic Privileges in XS Classic (optional)Lesson ObjectivesAfter completing this lesson, you will be able to:

● Understand the Analytic Privileges

Lesson 5: Understanding Cross-Database Authorizations in Tenant DatabasesLesson ObjectivesAfter completing this lesson, you will be able to:

● Understand cross-database authorization between tenant databases

Lesson 6: Describing Data Masking

© Copyright. All rights reserved. 19

Page 30: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Lesson ObjectivesAfter completing this lesson, you will be able to:

● Describe how dynamic data masking works in SAP HANA

Lesson 7: Describing AnonymizationLesson ObjectivesAfter completing this lesson, you will be able to:

● Explain what anonymization is

Lesson 8: Describing LDAP Group AuthorizationLesson ObjectivesAfter completing this lesson, you will be able to:

● Decribe LDAP Group authorization functionality in SAP HANA

Lesson 9: Setting up and Analyzing an Authorization TraceLesson ObjectivesAfter completing this lesson, you will be able to:

● Set up and analyze authorization traces

Unit 10: Authorizations

20 © Copyright. All rights reserved.

Page 31: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 11 Analyzing Users and Authorizations

Lesson 1: Viewing Information about Users and AuthorizationsLesson ObjectivesAfter completing this lesson, you will be able to:

● View information about users and authorizations

© Copyright. All rights reserved. 21

Page 32: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 11: Analyzing Users and Authorizations

22 © Copyright. All rights reserved.

Page 33: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 12 Auditing

Lesson 1: Using Audit LoggingLesson ObjectivesAfter completing this lesson, you will be able to:

● Use audit logging

© Copyright. All rights reserved. 23

Page 34: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 12: Auditing

24 © Copyright. All rights reserved.

Page 35: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 13 Security for SAP HANA Extended Application Services, Classic Model (optional)

Lesson 1: Describing SAP HANA Extended Application Services Security and Application Privileges (optional)Lesson ObjectivesAfter completing this lesson, you will be able to:

● Describe SAP HANA extended application services security aspects and use application privileges

© Copyright. All rights reserved. 25

Page 36: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 13: Security for SAP HANA Extended Application Services, Classic Model (optional)

26 © Copyright. All rights reserved.

Page 37: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 14 Security for SAP HANA Extended Application Services, Advanced Model

Lesson 1: Describing SAP HANA Extended Application Services, Advanced Model SecurityLesson ObjectivesAfter completing this lesson, you will be able to:

● Describe SAP HANA extended application services, advanced model (XSA)

© Copyright. All rights reserved. 27

Page 38: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 14: Security for SAP HANA Extended Application Services, Advanced Model

28 © Copyright. All rights reserved.

Page 39: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 15 SAP BW Models in SAP HANA

Lesson 1: Understanding SAP BW Models in SAP HANALesson ObjectivesAfter completing this lesson, you will be able to:

● Understand the basics of SAP BW model generation in SAP HANA

© Copyright. All rights reserved. 29

Page 40: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 15: SAP BW Models in SAP HANA

30 © Copyright. All rights reserved.

Page 41: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 16 Integration with SAP BusinessObjects BI (optional)

Lesson 1: Understanding Authentication Options and User Management Implications for the Integration of SAP BusinessObjects BI 4.X and SAP HANA (optional)Lesson ObjectivesAfter completing this lesson, you will be able to:

● Understand authentication options and user management implications for the integration of SAP BusinessObjects BI 4.X and SAP HANA

© Copyright. All rights reserved. 31

Page 42: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 16: Integration with SAP BusinessObjects BI (optional)

32 © Copyright. All rights reserved.

Page 43: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 17 SAP HANA with ERP or S/4HANA and the Analytics Authorization Assistant (optional)

Lesson 1: Describing SAP HANA with ERP or SAP S/4HANA and the Analytics Authorization Assistant (optional)Lesson ObjectivesAfter completing this lesson, you will be able to:

● Describe different scenarios for SAP HANA with ERP or SAP S/4HANA

● Describe the Analytics Authorization Assistant (AAA)

© Copyright. All rights reserved. 33

Page 44: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 17: SAP HANA with ERP or S/4HANA and the Analytics Authorization Assistant (optional)

34 © Copyright. All rights reserved.

Page 45: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 18 Integration with SAP GRC (optional)

Lesson 1: Outlining SAP GRC Integration for Governance, Risk and Compliance (optional)Lesson ObjectivesAfter completing this lesson, you will be able to:

● Outline the integration options with SAP Access Control

© Copyright. All rights reserved. 35

Page 46: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

Unit 18: Integration with SAP GRC (optional)

36 © Copyright. All rights reserved.

Page 47: SAP HANA 2.0 SPS03 - Authorizations, Scenarios & Security ...

UNIT 19 Integration with SAP Identity Management (optional)

Lesson 1: Understanding SAP Identity Management Integration (optional)Lesson ObjectivesAfter completing this lesson, you will be able to:

● Understand possible integrations with SAP Identity Management

© Copyright. All rights reserved. 37