Skip to content

Commit db9b99e

Browse files
committed
clarify
1 parent a7a86ea commit db9b99e

1 file changed

Lines changed: 6 additions & 4 deletions

File tree

articles/sentinel/sap/sap-agent-migrate.md

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -51,13 +51,13 @@ Your existing investment in the Microsoft Sentinel Solution for SAP analytic rul
5151
1. **Monitor**: Run both the containerized agent and the agentless data connector in parallel for a defined period to ensure stability and completeness of log collection.
5252
1. **Decommission**: Once you have validated that the agentless data connector is functioning correctly, proceed to decommission the containerized SAP agent. See the "[Stop SAP data collection](stop-collection.md)" article for details.
5353
54-
## Feature parity
55-
56-
The agentless data connector provides built-in feature parity with the containerized SAP agent for most important use cases regarding analytic rules and workbooks. See the [content reference](sap-solution-security-content.md) for details. Less relevant features are being covered through the extension patterns available for the agentless data connector. Watchlists and Playbooks remain fully functional without any changes. You may consider using the capabilities of SAP Integration Suite however to further simplify your SOAR workflows. See [this integration flow](https://github.com/Azure-Samples/Sentinel-For-SAP-Community/tree/main/integration-artifacts) for SAP user blocking.
57-
5854
> [!IMPORTANT]
5955
> Review the authorizations of the Sentinel user and role on your SAP systems used with the containerized agent. The agentless data connector requires less but different authorizations compared to the containerized SAP agent. Refer to the [configuration guide](/azure/sentinel/sap/preparing-sap?pivots=connection-agentless#configure-the-microsoft-sentinel-role) for details and SAP role sample for minimum authorizations.
6056
57+
## Feature parity
58+
59+
The agentless data connector provides built-in feature parity with the containerized SAP agent for most important use cases regarding analytic rules and workbooks. See the [content reference](sap-solution-security-content.md) for details.
60+
6161
All analytics rules and workbooks built on the underlying SAP sources mentioned on the [table reference](./sap-solution-log-reference.md#logs-collected-by-the-agentless-data-connector) remain functional without any changes.
6262
6363
These sources include but are not limited to the following [logs](sap-solution-security-content.md#built-in-analytics-rules):
@@ -66,6 +66,8 @@ These sources include but are not limited to the following [logs](sap-solution-s
6666
- SAPcon - Change Documents Log
6767
- User and User Authorization Details
6868
69+
The solution scope can be extended through [extensions patterns](https://github.com/Azure-Samples/Sentinel-For-SAP-Community) available for the agentless data connector. Watchlists and Playbooks remain fully functional without any changes.
70+
6971
SAP HANA database or OS-level detections are out of scope for the comparison because they are covered by their own connectors in Microsoft Sentinel.
7072
7173
## Next steps

0 commit comments

Comments
 (0)