The Privileged Access Management service of the SAP Cloud Identity Access Governance lets end-users create self-service requests for emergency access to connected systems and applications and also access request for others.
The end-to-end process consists of several stages with various stakeholders, such as approvers, reviewers, and security teams, to ensure that requests for privileged access sessions can be reviewed and granted properly. Compliance persons can perform periodic audits of usage and logs to monitor compliance with the respective and required company policies.
The Privileged Access Management service covers the following four major categories:
- Administration of privileged user accounts
- Temporary use of privileged access with elevated permissions
- Integrated session tracking and log collection of privileged access sessions
- Workflow-based review of privileged access sessions and the executed activities
Information about Privileged Access Management service and general recommendations can be found on the SAP Help Portal: https://help.sap.com/docs/SAP_CLOUD_IDENTITY_ACCESS_GOVERNANCE/37bacb728d75468c92b1f1e20d5afbe2/1c40793e042a480aa00a95038d7b3839.html?locale=en-US
To understand the Privileged Access Management service and its concept, it is crucial to get familiar with the following roles and terminology:
- PAM user: the end user who requires emergency access
- PAM ID: the user ID with elevated privileges
- Approver: the user responsible for a PAM ID and the assignment of reviewers and PAM users
- Reviewer: the user who reviews and approves (if required) the log files generated from PAM activities
- Direct Privileged Access: PAM users can directly logon to the plug-in systems to make critical changes
Information about the PAM terminology can be found also on official SAP Help page, see: https://help.sap.com/docs/SAP_CLOUD_IDENTITY_ACCESS_GOVERNANCE/37bacb728d75468c92b1f1e20d5afbe2/be4d37827f7741a9bcf6260686bd4eb3.html?locale=en-US
Stages and Roles in of SAP Cloud Identity Access Governance - Privileged Access Management

As already described, there are several stages and stakeholders involved in setting up the Privileged Access Management service. These stages and stakeholders are shown in the figure, Stages and Roles in of SAP Cloud Identity Access Governance - Privileged Access Management, and will be explained in the following rough overview:
- First, you have to create specific backend roles and authorizations that represent the foundation of every created PAM ID in SAP Cloud Identity Access Governance. These roles specify what actions and activities can be executed during the privileged access session.
- Those backend roles will be synchronized to the SAP Cloud Identity Access Governance for further usage.
- The backend roles cannot be directly assigned to a newly created PAM ID, and thus, they have to be included in a business role that will be assigned to the PAM ID.
- After a business role is created, the PAM approver (or at least a SAP Cloud Identity Access Governance administrator) can create a PAM ID, assign the necessary business role and provision the new created ID to the target system.
If an end-user (PAM) needs a temporary privileged access on the target system, it has to be requested by creating an access request in the respective app of SAP Cloud Identity Access Governance Fiori Launchpad. The PAM user can request the access for himself or or a different user can create an access request for him. If this request is approved by the PAM approver, who is responsible for a specific PAM ID, the requested PAM ID is provisioned and will be available in the PAM launchpad of the target system.
- The PAM user logs on directly in the target system and is navigated to the PAM launchpad.
- On the PAM launchpad, the PAM user selects the requested PAM ID and enters the privileged access session. A new user session starts under the PAM ID, parallel to the PAM end user session. The PAM user switches temporarily to the PAM ID and perform all necessary activities, which are released for this PAM ID.
Note
It is based on the backend roles and authorizations included in the assigned business role of PAM ID.It is important to note that the same PAM ID can be assigned to multiple users but only one PAM user can access the system at a time (when it is in usage, it will be locked for other PAM users).
- During the session, all activities will be logged and can be synchronized afterward to SAP Cloud Identity Access Governance for monitoring purposes and triggering the automated log review process.
