Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

SAP IDM replacement for manufacturing: what governance must change?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12518
Topic starter  

TL;DR: SAP Identity Management 8.0 mainstream maintenance ends on December 31, 2027, and SAP will not release a successor, leaving manufacturing firms to choose between preserving old gaps or redesigning governance across SAP, contractors, plant systems, and connected apps. The replacement decision is really about lifecycle, SoD, and audit scope, not lift-and-shift software selection.

NHIMG editorial — based on content published by OpenIAM: SAP IDM Replacement Is a Governance Decision, Not a Migration

By the numbers:

Questions worth separating out

Q: What is the biggest failure mode when organisations replace SAP IDM too late?

A: The biggest failure mode is rushed migration that copies legacy custom logic, access exceptions, and incomplete role cleanup into the new platform.

Q: Why is SAP Cloud Identity Services not a full SAP IDM replacement?

A: SAP Cloud Identity Services covers SAP authentication, federation, and provisioning, but it does not natively recreate SAP IDM's broader lifecycle governance across non-SAP systems.

Q: How should manufacturing companies handle contractor identity in an SAP IDM replacement?

A: They should treat contractors as a separate governance population with their own onboarding, approvals, reviews, and revocation rules.

Practitioner guidance

  • Define the governance outcome before selecting a platform Document which controls must be enterprise-wide, which remain SAP-specific, and which must apply to contractors, plant transfers, and service accounts.
  • Separate SoD detection from lifecycle orchestration Preserve SAP GRC risk logic where it already works, but require the replacement design to add preventive SoD validation at request and provisioning time.
  • Model contractor and plant access as distinct lifecycle paths Do not force contractor onboarding and plant transfer events through the same HR-driven workflow used for standard employees.

What's in the full article

OpenIAM's full analysis covers the operational detail this post intentionally leaves for the source:

  • A manufacturing-focused replacement planning model for SAP IDM end-of-maintenance decisions
  • The governance gap analysis across SAP, Microsoft Entra ID, SAP Cloud Identity Services, contractors, and plant operations
  • The migration questions that separate a like-for-like swap from a real identity governance redesign
  • The coexistence model for SAP GRC, lifecycle workflows, and enterprise access evidence

👉 Read OpenIAM's analysis of SAP IDM replacement and manufacturing governance →

SAP IDM replacement for manufacturing: what governance must change?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12102
 

SAP IDM replacement is a governance decision because the old platform already encoded a partial control model. It automated lifecycle tasks, but it never enforced SoD, never fully governed non-SAP systems, and never solved contractor identity at manufacturing scale. Replacing the product without replacing those assumptions simply preserves the same audit exposure under a new interface.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • 71% of NHIs are not rotated within recommended time frames, which means hidden access often persists long after the original business need has changed.

A question worth separating out:

Q: Who should own the SAP IDM replacement decision?

A: Ownership should sit across IAM, SAP architecture, compliance, and the business teams that manage plant operations. This is not just an identity tool choice. It is a decision about control scope, audit evidence, and how access governance will work across SAP, connected systems, and non-human identities over the next decade.

👉 Read our full editorial: SAP IDM replacement is a governance decision, not migration



   
ReplyQuote
Share: