Вы находитесь на странице: 1из 4

factsheet_Active 21.08.

2002 11:31 Uhr Seite 1

TECHNICAL FACT SHEET

Active Directory Integration and


mySAP.com™
The Active Directory™ Service is a central component of the Windows® 2000
operating system platform. Today, networked computing is more important
than ever for businesses to remain competitive. As a result, modern operating
systems require mechanisms for managing the identities and relationships of
the distributed resources that make up network environments. A directory
service provides a place to store information about network-based entities,
such as applications, files, printers, and people. It provides a consistent way
to name, describe, locate, access, manage, and secure information about
these individual resources.

Further, a directory service acts as the 1. Simplifies management tasks: Integration Highlights
main switchboard of the network operating
system. It is the central authority that The mySAP.com system can use directory ■ Using SAP Central User Account
manages the identities and brokers the services to detect SAP R/3 systems and Management in conjunction with
relationships between these distributed their services such as the application Active Directory enhances security
resources, enabling them to work together. servers, message servers, database, concepts
Because a directory service supplies these gateway service, and ITS instances. This
fundamental network operating system enables enterprise-wide information about ■ Active Directory for both the
functions, it must be tightly coupled with installed systems to be viewed and "Corporate" and the "Portal"
the management and security mechanisms accessed at a single central location. directory server saves management
of the operating system to ensure the The SAP R/3 Version 4.6 C MMC snap-in and implementation costs
integrity and privacy of the network. It also is the first component to use information
plays a critical role in an organization's provided by directory services. In addition ■ SAP systems can share information
ability to define and maintain the network to providing a central view of all SAP with other systems by using the SAP
infrastructure, perform system administra- systems in your landscape, the MMC LDAP connector
tion, and control the overall user experience snap-in provides interfaces to stop/start
of a company's information systems. and monitor the systems. SAPGUI for ■ SAP LDAP connector enabled SAP
Windows can use the Active Directory programs can read information from
Active Directory integration with server to obtain a list of SAP systems. This and write information to Active
mySAP.com offers customers many advan- saves the trouble of having to manually Directory
tages. maintain SAP destinations and files like
■ Simplifies management tasks SAPLogon.ini.
■ Strengthens network security
■ Makes use of existing systems through Using the Active Directory group policy
interoperability feature, administrators can update and
deploy the SAPGUI and other SAP appli-
cations to user desktops. For organizations
wishing to use Single sign on with SAP
GUI, a special MSI package is delivered
Single Sign on SAP System by SAP. This package can be automatically
Management
deployed to all relevant users automatically.
SAP Central user SAP Portal roles
Administration and context

Microsoft Active Directory

SAPGUI for LDAP connector


Windows
SAP.NET
connector
factsheet_Active 21.08.2002 11:31 Uhr Seite 2

TECHNICAL FACT SHEET

Using Active Directory with Central Using the Active Directory with
User Administration 6.10 SAPGUI

SAP Central User Administration (with SAPGUI (version 4.6D and above) can be
Web Application Server 6.10) allows the configured to find SAP R/3 systems and
administration of the whole system land- its message servers from the directory
scape from one single central system. All instead of using a fixed list of systems
user data is maintained centrally although and message servers in the sapmsg.ini
Active Directory Manageability local maintenance is still possible. configuration file. If SAPGUI is configured
to use the LDAP directory, it will query
■ Active Directory centrally manages the directory each time Server or Group
Windows users, clients and servers Central User Microsoft Active
selection is used to get up to date infor-
through a single consistent Administration Directory Services mation about SAP R/3 systems.
management interface, reducing
redundancy and maintenance 2. Strengthens Network security:
LDAP
costs synchronization
One of the most important architectural
■ Group Policy allows administrators advantages of Windows 2000 Server is
to define and control the policies the integration of Active Directory and its
governing groups of computers advanced security features that enable a
and users within their organization new level of data protection.

■ Active Directory lets administrators Single Sign-On for seamless and secure
automatically distribute applications network authentication
to users based on their role in the SAP supports various single sign-on
company mySAP.com Applications:
options for the Microsoft platform includ-
R/3, CRM, BW ing Kerberos, NTLM and X.509 certificates.
■ Active Directory Service Interfaces These single sign on options are
greatly simplifies the development supported by the SAPGUI for Windows,
of directory-enabled applications, In Central user administration, the SAP the mySAP™ Enterprise Portal, SAP
as well as the administration of HR system can use directory services to Internet Transaction Server and the new
distributed systems make personnel data in the mySAP.com SAP.NET Connector.
components available to other appli-
cations. Employee information that may The following are some of the ways in
Active Directory Security be of interest can be stored on the which Active Directory strengthens security
directory server and retrieved by other in an SAP environment:
■ Supports logon via smart cards for applications as necessary. For example, ■ It improves password security and
strong authentication to sensitive the HR application stores employee data management – SAP systems can take
resources (name and position) on the directory advantage of the built-in Kerberos
server. A different application such as integration in Active Directory. Not only
■ Full support for Kerberos 5 protocol project management can access this is the need for a separate SAP pass-
provides fast, single sign-on to information for its own purposes. word eliminated but the data channel
Windows 2000-based resources, between the SAP client and application
as well as to other environments Microsoft Active Directory is SAP server is encrypted.
that support this protocol BC-LDAP-USR certified ■ It speeds e-business deployment –

SAP certification indicates that the third- Both SAP and Microsoft are committed
■ Support for x.509 certificates and party interface has been tested for to providing built-in support for secure
public key infrastructure (PKI) Internet-standard protocols and
quality and approved at one of SAP’s
ensures interoperability with and authentication mechanism such as
Integration and Certification Centers (ICC).
deployment of extranet and Kerberos, public key infrastructure
e-commerce applications. Customers are assured to get: (PKI) and lightweight directory access
■ A product technically verified to work protocol (LDAP) over secure sockets
with SAP Business integrations, layer (SSL).
■ An interface that is ready to use and
release-stable,
■ Proof of verification with full documen-
tation and a corresponding certifica-
tion test procedure.
factsheet_Active 21.08.2002 11:31 Uhr Seite 3

TECHNICAL FACT SHEET

3. Makes use of existing systems Active Directory as the Portal LDAP


through interoperability: The Portal LDAP will extend the schema
of Active directory by adding several new
Using the SAP LDAP connector, SAP object classes. Before you can begin you
ABAP/4 programs can read and write must configure Active Directory to allow
information in Microsoft Active Directory schema modifications. This is done within
for example to retrieve address, user or the Active Directory Schema MMC snap- Active Directory Interoperability
system data such as email addresses, in.
fax numbers, addresses or printers. Many
SAP applications now ship with built in Using Active Directory with LDAP ■ Active Directory is implemented as
directory integration including Central Connector a native LDAP server that doesn't
User Administration version 6.10 and the require request translation to
mySAP Enterprise Portal version 5.0. With mySAP.com, applications that support ensure interoperability in extranet
the standard Internet protocol LDAP can environments and e-commerce
Using Active Directory with mySAP access directory services and use them applications
Enterprise Portal for their storage needs. For example,
mySAP Enterprise portal version 5.0 various systems on different platforms ■ Active Directory lets developers
uses Active Directory to store user can access information using a common and administrators extend the
mapping information, role-to-user assign- directory service. Likely candidates for directory schema and create new
ments and other customization attributes. application scenarios include: properties and objects. Using the
Microsoft encourages SAP customers to directory as a data store, devel-
use Active Directory for all of their mySAP ■ Personnel information opers can use this feature to
Enterprise Portal directory requirements. (name, department, organization) create their own data structures
■ User and security information (user for applications
mySAP Enterprise Portal uses a directory account, authorizations, public-key
in two capacities. These are referred to certificates)
as the Corporate Directory Server and ■ System resource and service informa-
the Dedicated (or Portal) Directory Server. tion (system identifier, application
These directories are independent. Using configuration, printer configuration).
Microsoft Active Directory for both the
"Corporate” and the "Portal” directory Each SAP system is an LDAP client and
server will save management and can take advantage of the LDAP directory
implementation costs. server concept. Information that is shared
between mySAP.com and other
Active Directory as the Corporate LDAP components can be stored on an LDAP
mySAP Enterprise Portal makes use of directory server and accessed by the
users and groups stored in the corporate various applications. As an LDAP client,
LDAP directory. No changes are required the SAP applications have both read and
to Active directory as the configuration write access to the LDAP directory server.
and mapping is done within the mySAP Therefore, information from other
Enterprise Portal User administration tool. systems is available to the SAP system,
and SAP system data is available to other
systems.

Portal
Directory
R/3
System 1

Single
Authentication Sign on

R/3
System 2

Windows 2000
Domain others
Datacenter

Corporate
Directory
factsheet_Active 21.08.2002 11:31 Uhr Seite 4

Microsoft SAP Competence Center


in Walldorf, Germany:
Email: mssapcc@microsoft.com
Phone: +49 (0) 6227 73 17 10
http://www.microsoft-sap.com

Вам также может понравиться