↳ GitHub sourceSolution

SAP BTP

Description

SAP Business Technology Platform (BTP) is SAP's platform-as-a-service for building, extending, and integrating SAP and third-party applications. It brings together services such as Cloud Integration (CPI), Cloud Identity Services, Business Application Studio, and Build Work Zone that organizations rely on to run business-critical processes. The SAP BTP Solution for Microsoft Sentinel ingests audit and activity events from the SAP BTP Audit Log Service across multiple subaccounts using a codeless data connector, and ships detections, hunting content, and a workbook to help security teams monitor BTP for identity abuse (privileged role changes, mass user deletion, IdP/trust tampering), integration threats (Cloud Integration artifact deployment, security-material and access-policy tampering, JDBC data source changes), developer-workspace risks (malware in BAS dev spaces, failed cross-tenant access), and audit coverage gaps (unaudited custom apps, audit log service unavailability).
Version
3.1.1
Declared author / publisher
Microsoft - support@microsoft.com
Support tier
Microsoft

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
sap_btp_sentinel_solution
Additional source files 2Solutions/SAP BTP/Data/Solution_SAPBTP.jsonsolution-manifest ↗Solutions/SAP BTP/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.