SAP Identity Management (SAP IDM) is SAP's on-premises identity management product. It manages user and access data centrally, based on roles. You maintain an identity once, and SAP IDM creates, updates and removes the matching accounts in every connected system. The technology came from MaXware, a Norwegian vendor SAP acquired in 2007. It first shipped as SAP NetWeaver Identity Management 7.0 and became SAP Identity Management with release 8.0.
It was never a general-purpose identity governance suite, but for close to two decades it has been the default choice for organizations that wanted SAP user administration driven from one authoritative source, with deep reach into SAP ERP Human Capital Management (SAP HCM), ABAP authorizations and SAP Access Control.
That position, however, is changing. SAP has confirmed that maintenance for SAP Identity Management ends in 2027, with extended maintenance available until 2030. This makes version 8.0 the final functional release.
For most SAP customers, identity strategy is now tied directly to two major transformations: the move from ECC to SAP S/4HANA, and increasingly, the transition to RISE with SAP.
In this guide, we will look at the components SAP IDM is built from, the capabilities you can implement with it and how to migrate to a long-term replacement before support runs out.
Next, let's explore how the components above combine to deliver the capabilities SAP customers actually implement, and what any replacement therefore has to cover.
Access changes are automated from a single authoritative record when someone joins, changes role or leaves.
You can:
HR-driven provisioning makes the HR system the trigger for access changes.
You can:
Role-based access control (RBAC) bundles technical privileges into business roles, so you assign the role rather than individual permissions.
You can:
The approval process is defined from business rules and policies in a web-based workflow engine.
You can:
This section covers both provisioning passwords into target systems and letting users recover access themselves. Although, Password synchronization is no longer a strategic discussion point for SAP transformation buyers.
Segregation of duties (SoD) stops one person holding permissions that let them complete a sensitive transaction end to end. SAP IDM does not evaluate the rules itself, it calls SAP Access Control.
You can:
Attestation is the periodic review in which an owner confirms that access already granted is still appropriate. In SAP IDM it is only partially surfaced.
You can:
One Identity record can drive account creation well beyond the SAP estate.
You can:
The migration itself runs on ASCONSIT FASTlane, an analysis tool and consulting service built specifically for moving from SAP IDM to Identity Manager by One Identity.
Instead of starting with an empty platform and rebuilding everything from documentation, FASTlane pulls your existing configuration out, lets you review it, then loads it into the new environment. The five steps:
ASCONSIT positions FASTlane as a scalable approach suiting large and small organizations alike. The benefits it is built to deliver are:
With mainstream maintenance ending in 2027, the question is not whether to move, but where to move and how.
There is no SAP IDM 9.0, so the target is a different platform with a different data model.
Identity Manager is the strongest fit for organizations replacing SAP IDM: it covers the SAP-specific depth those customers depend on and adds the governance layer SAP IDM lacked. When SAP looked for a partner solution to support customers leaving SAP IDM, it set stringent requirements covering SAML, OIDC, SCIM and X.509, on-premises and cloud workloads, and SAP Fieldglass, SAP SuccessFactors and SAP Cloud Identity Services. Identity Manager met all of them natively, the outcome of years as SAP's development partner around identity governance.
SAP Identity Management is a distributed system whose components can be installed across separate hosts. Below are the main ones and what each does.
The Identity Center is the primary component for identity management. It uses a central repository, the identity store, to present a uniform view of identity data whatever its source. It comprises the Identity Management database, the runtime components and the Developer Studio.
The database holds all information about managed users and their accounts and runs on a supported database management system. Inside it, the identity store is modeled as typed entries: MX_PERSON for people, MX_PRIVILEGE for technical privileges and MX_ROLE for business roles.
The Developer Studio is an Eclipse plug-in and the environment in which the configuration is built. For example, developers use it to maintain identity stores, the identity store schema, packages, repository types, processes, forms and jobs.
The provisioning framework supplies the standard processes and tasks for reading from and writing to connected systems, with connectors delivered as separate packages. SAP ships connectors for on-premises SAP S/4HANA, AS ABAP, AS Java, SAP HANA, SuccessFactors, SAP Cloud Identity Services, Microsoft Active Directory and Exchange, and generic LDAP directories.
End users reach identity store data through the Identity Management user interface, which offers self-service and management functions. Administrators use a separate administration interface. A REST interface, currently at version 2, supports custom front ends.
The Virtual Directory Server (VDS) makes several separate directories, databases and repositories look like a single directory. You control which parts of that data each user and application sees. Running standalone, it accepts incoming LDAP requests. On SAP NetWeaver AS for Java, it accepts Service Provisioning Markup Language (SPML).
Identity Federation is a separate component that handles single sign-on (SSO) for SAP and non-SAP systems. It supplies a SAML 2.0-compliant identity provider for browser logins, and a security token service for SSO between web services.
SAP Identity Management did its job well for a long time: a central identity store, role-based provisioning into ABAP and non-SAP systems, HR-driven lifecycle management from SAP HCM and risk checks through SAP Access Control. That list is the bar any replacement has to clear.
With maintenance ending in 2027, no on-premises successor from SAP and migration timelines running well over a year, the planning window is now.
Identity Manager is the strongest destination: SAP-certified, deeper into SAP authorizations than a general-purpose provisioning service, and equipped with the attestation, certification and SoD controls SAP IDM customers previously had to assemble elsewhere.
Paired with ASCONSIT FASTlane, you extract what you have, clean it up, map it and start working with your own data on day one, while your existing environment keeps running until you are ready to switch it off.