{"id":6128,"date":"2025-07-14T10:15:35","date_gmt":"2025-07-14T08:15:35","guid":{"rendered":"http:\/\/inprosec.com\/active-directory-as-user-data-source-for-sap-grc-2\/"},"modified":"2025-07-16T12:54:55","modified_gmt":"2025-07-16T10:54:55","slug":"integrate-active-directory-sap-grc","status":"publish","type":"post","link":"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/","title":{"rendered":"How to Integrate Active Directory as a User Data Source in SAP\u00ae GRC"},"content":{"rendered":"<p><strong>Active Directory (AD)<\/strong> is often the main source of user information within a company. Therefore, its integration with <strong>SAP\u00ae GRC<\/strong> should be an essential practice to ensure centralized, secure, and efficient user data management in enterprise environments. By establishing <strong>Active Directory<\/strong> as the main user data source for <strong>SAP\u00ae<\/strong>, organizations can reduce manual errors, automate provisioning processes, and ensure that the information is always synchronized and up-to-date.<\/p>\n<p>In this <strong>step-by-step guide<\/strong>, we will explore how to properly configure the communication between <strong>Active Directory<\/strong> and <strong>SAP\u00ae GRC<\/strong>, from defining <strong>RFC connections<\/strong> and <strong>LDAP configuration<\/strong>, to executing full <strong>user synchronization<\/strong>. You will also learn how to set <strong>AD<\/strong> as the <strong>master data source<\/strong> and prevent unwanted manual modifications in the <strong>SAP<\/strong> system.<\/p>\n\n<h2>Steps to Connect Active Directory with SAP\u00ae GRC<\/h2>\n<ol>\n<li>RFC communication.<\/li>\n<li>LDAP configuration.<\/li>\n<li>GRC synchronization.<\/li>\n<\/ol>\n<h2>RFC Communication<\/h2>\n<p>Communication between <strong>Active Directory<\/strong> and <strong>SAP\u00ae GRC<\/strong> requires the definition of a <strong>TCP\/IP Connection<\/strong>. The key fields of this connection are:<\/p>\n<ul>\n<li><strong>Gateway Host<\/strong><\/li>\n<li><strong>Gateway Service<\/strong><\/li>\n<li><strong>Registered Program ID<\/strong><\/li>\n<\/ul>\n<p>Both <strong>Gateway Host<\/strong> and <strong>Gateway Service<\/strong> are exclusively related to the <strong>GRC<\/strong> system. The <strong>Registered Program ID<\/strong> must have the same name as the <strong>RFC<\/strong> connection. It is important to note that there may be issues when registering the <strong>Program ID<\/strong> if the <strong>gateway<\/strong> has registration restrictions.<\/p>\n<h2>LDAP Configuration<\/h2>\n<p>The next step is to connect to the <strong>LDAP server<\/strong>, which is configured through the <strong>LDAP transaction<\/strong> in <strong>SAP\u00ae<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"size-medium wp-image-13429 aligncenter\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-1-300x61.png\" alt=\"\" width=\"300\" height=\"61\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-1-300x61.png 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-1-1024x208.png 1024w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-1-600x122.png 600w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-1.png 1070w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p><strong>Key fields:<\/strong><\/p>\n<ul>\n<li><strong>Host Name<\/strong><\/li>\n<li><strong>Port Number<\/strong><\/li>\n<li><strong>Base Entry<\/strong><\/li>\n<li><strong>System Logon<\/strong><\/li>\n<\/ul>\n<p><strong>SAP\u00ae<\/strong> provides a default mapping for <strong>Active Directory<\/strong>, which can be applied by pressing <strong>\u201cF8\u201d<\/strong>. Contact your <strong>System Administration<\/strong> team to confirm that the <strong>Active Directory mapping<\/strong> is correct. In addition, a user that already exists in <strong>Active Directory<\/strong> must be defined for the connection. This configuration is done under the <strong>\u201cSystem Users\u201d<\/strong> option.<\/p>\n<p><img decoding=\"async\" class=\"size-medium wp-image-13431 aligncenter\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-2-300x64.png\" alt=\"\" width=\"300\" height=\"64\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-2-300x64.png 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-2-1024x218.png 1024w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-2-600x128.png 600w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-2.png 1072w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>Remember to include the <strong>Base Entry<\/strong> to locate the <strong>System User<\/strong> within <strong>Active Directory<\/strong>.<\/p>\n<p>Once the <strong>LDAP server<\/strong> is configured, you must define an <strong>LDAP connector<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"size-medium wp-image-13433 aligncenter\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-3-300x63.png\" alt=\"\" width=\"300\" height=\"63\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-3-300x63.png 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-3-1024x216.png 1024w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-3-600x127.png 600w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-3.png 1066w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>The name of the connector <strong>MUST<\/strong> match the <strong>RFC connector<\/strong> name.<\/p>\n<p><strong>The naming convention for the LDAP connector is:<\/strong><\/p>\n<p><strong>Gateway Host_SID of the GRC system_Gateway Service Instance Number<\/strong><\/p>\n<p>Example: SAPGRC00_GRP_00<\/p>\n<p>Then, this <strong>LDAP connector<\/strong> must be <strong>activated<\/strong>.<\/p>\n<p><strong>Common issues when activating the LDAP connector:<\/strong><\/p>\n<ul>\n<li>The <strong>Registered Program ID<\/strong> in transaction <strong>SM59<\/strong> was not registered.<\/li>\n<li>The <strong>Gateway Host<\/strong> and <strong>Gateway Service<\/strong> in <strong>SM59<\/strong> are incorrect.<\/li>\n<li>The <strong>LDAP library<\/strong> is missing in the <strong>SAP\u00ae GRC<\/strong> system and must be installed.<\/li>\n<\/ul>\n<p>Once the <strong>LDAP connector<\/strong> is active, you can run the <strong>\u201cConnection Test\u201d<\/strong> for the <strong>TCP\/IP Connection<\/strong> in the <strong>SM59<\/strong> transaction:<\/p>\n<p><img decoding=\"async\" class=\"size-medium wp-image-13435 aligncenter\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-4-300x36.png\" alt=\"\" width=\"300\" height=\"36\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-4-300x36.png 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-4-600x72.png 600w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-4.png 932w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<h2>GRC Synchronization<\/h2>\n<p>After completing the above tasks, a synchronization operation is required to establish <strong>Active Directory<\/strong> as a <strong>User Data Source<\/strong>.<\/p>\n<p><strong>Steps:<\/strong><\/p>\n<p>1 Verify that all previous configurations are correct.<\/p>\n<p>2 Execute the <strong>LDAP<\/strong> transaction and press <strong>\u201cLog On\u201d:<\/strong><\/p>\n<p><img decoding=\"async\" class=\"size-medium wp-image-13421 aligncenter\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-5-300x86.png\" alt=\"\" width=\"300\" height=\"86\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-5-300x86.png 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-5-1024x292.png 1024w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-5-600x171.png 600w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-5.png 1061w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>3 Once connected, press the <strong>\u201cFind\u201d<\/strong> button:<\/p>\n<p><img decoding=\"async\" class=\"size-medium wp-image-13423 aligncenter\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-6-300x85.png\" alt=\"\" width=\"300\" height=\"85\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-6-300x85.png 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-6-1024x290.png 1024w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-6-600x170.png 600w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-6.png 1061w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>Use the following expressions to find the <strong>SAP User ID<\/strong>:<\/p>\n<p>(&amp;(samaccountname=SAP_USER_ID))<\/p>\n<p>(&amp;(mail=mail_address))<\/p>\n<p>On the <strong>GRC<\/strong> side, do the following:<\/p>\n<ul>\n<li>Define the <strong>LDAP Connector Group<\/strong> using the <strong>SPRO<\/strong> transaction:<br \/>\n<strong>Maintain Connectors and Connection Types<\/strong><\/li>\n<li>Assign the <strong>LDAP Connector<\/strong> to the <strong>\u201cPROV\u201d<\/strong> and <strong>\u201cAUTH\u201d<\/strong> scenarios using <strong>SPRO<\/strong>:<br \/>\n<strong>Maintain Connection Settings<\/strong><\/li>\n<\/ul>\n<p>Then, run the <strong>SAP RSLDAPSYNC_USER<\/strong> program using transaction <strong>SE38<\/strong>, including the previously defined <strong>LDAP Server<\/strong> and <strong>Connector<\/strong>. You can search for a specific user, but it is recommended to test the <strong>full search<\/strong>.<\/p>\n<p>If you want to <strong>create all Active Directory records inside SAP\u00ae<\/strong>, make sure to enable that option.<\/p>\n<p><img decoding=\"async\" class=\"size-medium wp-image-13425 aligncenter\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-7-300x105.png\" alt=\"\" width=\"300\" height=\"105\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-7-300x105.png 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-7-1024x358.png 1024w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-7-600x210.png 600w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-7.png 1068w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>Finally, execute the <strong>GRAC_REPOSITORY_OBJECT_SYNC<\/strong> program to perform the <strong>Full Synchronization (Full Sync Mode)<\/strong> using the <strong>LDAP Connector<\/strong>.<\/p>\n<h2>Set Active Directory as the Main User Data Source<\/h2>\n<p>After the integration, it is essential to configure <strong>Active Directory<\/strong> as the <strong>Main User Data Source<\/strong> in <strong>SAP\u00ae GRC<\/strong> using the <strong>SPRO<\/strong> transaction:<\/p>\n<ul>\n<li><strong>Maintain Data Sources Configuration<\/strong><\/li>\n<\/ul>\n<p>Then, include <strong>Active Directory<\/strong> as:<\/p>\n<ul>\n<li><strong>User Search Data Source<\/strong><\/li>\n<li><strong>User Detail Data Source<\/strong><\/li>\n<\/ul>\n<p>Next, the field mapping between <strong>Active Directory<\/strong> and <strong>SAP\u00ae<\/strong> fields must be done using:<\/p>\n<ul>\n<li><strong>Maintain Mapping for Actions and Connector Groups<\/strong><\/li>\n<\/ul>\n<p>It is suggested to map as many relevant fields as possible, especially those used in the <strong>SU01<\/strong> transaction, such as:<\/p>\n<p><img decoding=\"async\" class=\"size-medium wp-image-13427 aligncenter\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-8-189x300.png\" alt=\"\" width=\"189\" height=\"300\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-8-189x300.png 189w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-8-379x600.png 379w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2019\/11\/IMG-8.png 522w\" sizes=\"(max-width: 189px) 100vw, 189px\" \/><\/p>\n<ul>\n<li>USERID \u2192 SAMACCOUNTNAME<\/li>\n<li>LASTNAME \u2192 SN<\/li>\n<li>FIRSTNAME \u2192 givenName<\/li>\n<li>FUNCTION \u2192 title<\/li>\n<li>DEPARTMENT \u2192 Department<\/li>\n<li>TELEPHONE \u2192 telephoneNumber<\/li>\n<li>TELNUMBER \u2192 mobile<\/li>\n<li>EMAIL \u2192 MAIL<\/li>\n<li>PERSONNEL_NUMBER \u2192 employeeID<\/li>\n<li>MANAGERID \u2192 manager<\/li>\n<li>LOCATION \u2192 country<\/li>\n<li>COMPANY \u2192 company<\/li>\n<\/ul>\n<p>These fields can also be used for the definition of <strong>User Defaults<\/strong>, such as:<\/p>\n<ul>\n<li><strong>Logon Language<\/strong><\/li>\n<li><strong>Decimal Notation<\/strong><\/li>\n<li><strong>Date Format<\/strong><\/li>\n<\/ul>\n<p>If there is a requirement to use a specific field from <strong>Active Directory<\/strong> within <strong>SAP\u00ae GRC<\/strong>, you can create a <strong>Custom Field<\/strong> and map it also using:<\/p>\n<ul>\n<li><strong>Maintain Mapping for Actions and Connector Groups<\/strong><\/li>\n<\/ul>\n<h2>Restrict Manual Changes<\/h2>\n<p>To avoid undesired modifications, it is recommended to <strong>restrict manual changes<\/strong> in the fields that are pulled from <strong>Active Directory<\/strong>. This configuration is done via the <strong>SPRO<\/strong> transaction:<\/p>\n<ul>\n<li><strong>Maintain End User Personalization<\/strong><\/li>\n<\/ul>\n<p>This option allows all fields that are populated from <strong>Active Directory<\/strong> to be set as <strong>non-editable<\/strong> by end users.<\/p>\n<h2>Need Help with Active Directory and SAP\u00ae Integration?<\/h2>\n<p>If you found this article helpful or are considering implementing <strong>Active Directory<\/strong> as a <strong>User Data Source<\/strong> in <strong>SAP\u00ae GRC<\/strong>, we are here to support you. Our team of experts can guide you throughout the process, from initial setup to optimizing synchronization and access control.<\/p>\n<p><strong>Contact us <\/strong><a href=\"https:\/\/www.inprosec.com\/en\/contact\/\"><strong>here<\/strong><\/a>, or visit our <a href=\"https:\/\/www.inprosec.com\/en\/sap-security\/\"><strong>SAP\u00ae Security<\/strong><\/a> and <a href=\"https:\/\/www.inprosec.com\/en\/services\/sap-grc\/\"><strong>SAP\u00ae GRC<\/strong><\/a><strong> Services<\/strong> section to discover how we can help you improve the efficiency and security of your SAP system.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Active Directory (AD) is often the main source of user information within a company. Therefore, its integration with SAP\u00ae GRC should be an essential practice to ensure centralized, secure, and efficient user data management in enterprise environments. By establishing Active Directory as the main user data source for SAP\u00ae, organizations can reduce manual errors, automate&#8230;<\/p>\n","protected":false},"author":6,"featured_media":13453,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[60,61],"tags":[151],"class_list":["post-6128","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sap-grc-en","category-sap-security-en-2","tag-sap-grc-en"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.3 (Yoast SEO v27.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>How to Integrate Active Directory as a User Data Source in SAP\u00ae GRC - Inprosec<\/title>\n<meta name=\"description\" content=\"Learn how to integrate Active Directory as the main user data source in SAP\u00ae GRC. Step-by-step guide including RFC setup, LDAP configuration, and full synchronization.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Integrate Active Directory as a User Data Source in SAP\u00ae GRC\" \/>\n<meta property=\"og:description\" content=\"Learn how to integrate Active Directory as the main user data source in SAP\u00ae GRC. Step-by-step guide including RFC setup, LDAP configuration, and full synchronization.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/\" \/>\n<meta property=\"og:site_name\" content=\"Inprosec\" \/>\n<meta property=\"article:published_time\" content=\"2025-07-14T08:15:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-16T10:54:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/07\/2.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Fernando Mosquera\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Fernando Mosquera\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/integrate-active-directory-sap-grc\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/integrate-active-directory-sap-grc\\\/\"},\"author\":{\"name\":\"Fernando Mosquera\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"headline\":\"How to Integrate Active Directory as a User Data Source in SAP\u00ae GRC\",\"datePublished\":\"2025-07-14T08:15:35+00:00\",\"dateModified\":\"2025-07-16T10:54:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/integrate-active-directory-sap-grc\\\/\"},\"wordCount\":913,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/integrate-active-directory-sap-grc\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/2.png\",\"keywords\":[\"SAP GRC\"],\"articleSection\":[\"SAP GRC\",\"SAP Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/integrate-active-directory-sap-grc\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/integrate-active-directory-sap-grc\\\/\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/integrate-active-directory-sap-grc\\\/\",\"name\":\"How to Integrate Active Directory as a User Data Source in SAP\u00ae GRC - Inprosec\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/integrate-active-directory-sap-grc\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/integrate-active-directory-sap-grc\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/2.png\",\"datePublished\":\"2025-07-14T08:15:35+00:00\",\"dateModified\":\"2025-07-16T10:54:55+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"description\":\"Learn how to integrate Active Directory as the main user data source in SAP\u00ae GRC. Step-by-step guide including RFC setup, LDAP configuration, and full synchronization.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/integrate-active-directory-sap-grc\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/integrate-active-directory-sap-grc\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/integrate-active-directory-sap-grc\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/2.png\",\"contentUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/2.png\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/integrate-active-directory-sap-grc\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Integrate Active Directory as a User Data Source in SAP\u00ae GRC\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\",\"name\":\"Inprosec\",\"description\":\"Information security is our priority.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\",\"name\":\"Fernando Mosquera\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"caption\":\"Fernando Mosquera\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"How to Integrate Active Directory as a User Data Source in SAP\u00ae GRC - Inprosec","description":"Learn how to integrate Active Directory as the main user data source in SAP\u00ae GRC. Step-by-step guide including RFC setup, LDAP configuration, and full synchronization.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/","og_locale":"en_US","og_type":"article","og_title":"How to Integrate Active Directory as a User Data Source in SAP\u00ae GRC","og_description":"Learn how to integrate Active Directory as the main user data source in SAP\u00ae GRC. Step-by-step guide including RFC setup, LDAP configuration, and full synchronization.","og_url":"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/","og_site_name":"Inprosec","article_published_time":"2025-07-14T08:15:35+00:00","article_modified_time":"2025-07-16T10:54:55+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/07\/2.png","type":"image\/png"}],"author":"Fernando Mosquera","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Fernando Mosquera","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/#article","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/"},"author":{"name":"Fernando Mosquera","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"headline":"How to Integrate Active Directory as a User Data Source in SAP\u00ae GRC","datePublished":"2025-07-14T08:15:35+00:00","dateModified":"2025-07-16T10:54:55+00:00","mainEntityOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/"},"wordCount":913,"commentCount":0,"image":{"@id":"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/07\/2.png","keywords":["SAP GRC"],"articleSection":["SAP GRC","SAP Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/","url":"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/","name":"How to Integrate Active Directory as a User Data Source in SAP\u00ae GRC - Inprosec","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/#primaryimage"},"image":{"@id":"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/07\/2.png","datePublished":"2025-07-14T08:15:35+00:00","dateModified":"2025-07-16T10:54:55+00:00","author":{"@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"description":"Learn how to integrate Active Directory as the main user data source in SAP\u00ae GRC. Step-by-step guide including RFC setup, LDAP configuration, and full synchronization.","breadcrumb":{"@id":"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/#primaryimage","url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/07\/2.png","contentUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2025\/07\/2.png","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/www.inprosec.com\/en\/integrate-active-directory-sap-grc\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.inprosec.com\/en\/"},{"@type":"ListItem","position":2,"name":"How to Integrate Active Directory as a User Data Source in SAP\u00ae GRC"}]},{"@type":"WebSite","@id":"https:\/\/www.inprosec.com\/en\/#website","url":"https:\/\/www.inprosec.com\/en\/","name":"Inprosec","description":"Information security is our priority.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.inprosec.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2","name":"Fernando Mosquera","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","caption":"Fernando Mosquera"}}]}},"_links":{"self":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/6128","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/comments?post=6128"}],"version-history":[{"count":2,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/6128\/revisions"}],"predecessor-version":[{"id":13438,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/6128\/revisions\/13438"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media\/13453"}],"wp:attachment":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media?parent=6128"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/categories?post=6128"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/tags?post=6128"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}