on 2025 May 13 9:00 PM
Hi Experts,
We are planning to implement Multi-Factor Authentication (MFA) for logging into our SAP PO/PI systems. We have around 230+ partner systems connected to our SAP backend via SAP PO/PI. Could you please let me know if there are any risks associated with this, particularly regarding potential impacts on connectivity with these partner systems?
Regards,
Ramu.
Request clarification before answering.
Hi Ramu
in my security understanding the MFA is nowadays state of the art if you have websites for user interaction that can be reached in the cloud (e.g. cloud integration). As I assume your PI/PO system is hosted on premise and monitoring and admin URLs are only reached if you are connected via VPN - you have already reached 1st factor (you have VPN credentials) - so basic authentication on PI/PO is okey. However, it can be easily connected via SSO that you use your Active Directory Certificate that gives extra security.
When talking about integrated services - if they are from outside you need somewhere a reverse proxy or API-M. If you have already integration suite, i would recommend to use API-M to make all security checks. Otherwise install as a reverse proxy but also include a WAF (web application firewall) that is checking and filtering un-wished requests.
BR Helmut
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
User | Count |
---|---|
30 | |
22 | |
16 | |
8 | |
7 | |
7 | |
5 | |
4 | |
4 | |
4 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.