For IT executives currently using SAP IdM, this means it’s time to systematically address the changeover and find a successor. Don’t rush it, but don’t put it off indefinitely either. After all, migrating to a new identity & access management system isn’t a project that companies can complete casually in a few months.
SAP will end mainstream maintenance for SAP Identity Management (IdM) on December 31, 2027; there will be no successor product.
Extended maintenance, which is subject to a fee, will be available until the end of 2030, but it does not offer any functional enhancements and is intended only as a temporary solution.
As a successor architecture, SAP recommends a combination of Microsoft Entra ID and SAP Cloud Identity Services; alternative IGA platforms such as Omada, One Identity, or SailPoint are also options.
Instead of the usual 18 to 36 months, the migration can be completed in about 9 months using the Migration Package for SAP IdM Replacement from IBsolution – IT managers should start now by conducting an assessment of their own IAM landscape.
In February 2024, SAP officially confirmed that SAP Identity Management 8.0 is the final version of the software. There will be no SAP IdM 9.0. Mainstream maintenance expires on December 31, 2027. This means that, as of that date, there will be no more bug fixes, no security patches, and no support for new operating system versions or browsers.
Those who need more time can opt for extended maintenance through the end of 2030. This service is subject to a fee but also does not include any further functional enhancements. Therefore, it is strongly recommended to carefully evaluate the costs. In general, however, extended maintenance is more of a contingency plan than a long-term solution.
The technical background: SAP IdM is based on the NetWeaver Java platform, which itself will reach end-of-support in 2027. This means that, in the long term, the technical foundation for operating SAP IdM will no longer be available.
SAP announced a strategic partnership with Microsoft some time ago. For the period after 2027, SAP envisions, among other things, a combination of Microsoft Entra ID and SAP Cloud Identity Services as the successor solution to SAP IdM. Specifically, this means that Microsoft Entra ID will assume the role of the central identity provider for enterprise-wide identity management. SAP Cloud Identity Services – primarily SAP Identity Authentication Service (IAS) and SAP Identity Provisioning Service (IPS) – ensure connectivity to the SAP system landscape.
Especially for companies that already use Microsoft technologies, this collaboration sounds so promising that Microsoft Entra ID seems like the next logical step. And indeed, Microsoft Entra ID is known for its powerful features for single sign-on, multi-factor authentication, and conditional access. Furthermore, the relevant user lifecycle processes can generally be mapped out-of-the-box.
However, Microsoft Entra ID is not necessarily the automatic answer in every case. Companies with highly customized SAP IdM processes, complex role models, or specific requirements for SAP authorizations should carefully evaluate whether and how these can be mapped within the new architecture. In addition, there are other proven alternatives on the market – such as Omada, One Identity, and SailPoint—that may also be suitable as successor solutions for SAP IdM.
Migrating an IGA system is not a simple product switch. It’s not just a matter of replacing one tool with another. It involves analyzing existing processes, rethinking them, and mapping them to a new architecture. Until now, the typical duration for such a project has been 18 to 36 months.
With IBsolution’s Migration Package for SAP IdM Replacement, it is now possible to complete the replacement of SAP IdM in just nine months. This is a fixed-price package with a clearly defined scope of services and flexible customization options that ensures the future-readiness of the IAM landscape. In the reference architecture, Microsoft Entra ID serves as the leading identity system, while SAP Cloud Identity Services provide the distribution layer within the SAP landscape. The Entra Connector and SAP Cloud Identity Services Extensions – developed by IBsolution – are designed to close any remaining functional gaps.
However, the Migration Package for SAP IdM Replacement not only delivers significant time savings during the SAP IdM replacement process. At the same time, it enables companies to align their IAM architecture in such a way that it remains migration-ready for years to come. Changing licensing models and pricing metrics are making system changes necessary in significantly shorter cycles (3 to 5 years) than before if companies want to avoid vendor lock-in. To remain flexible in this regard, the migration readiness of the IAM landscape becomes an indispensable prerequisite.
The first step is to gain a clear understanding of the current situation. How many systems are connected to SAP IdM? Which processes are business-critical? Where are there customizations that require special attention during a migration?
Based on this analysis, an informed decision can be made regarding the successor solution. Whether it’s Microsoft Entra ID, Omada, One Identity, or another platform – the choice depends on the existing IT infrastructure, the requirements for SAP integration, and the available resources
It’s important not to view the migration as a purely technical IT project. Identity and Access Management (IAM) has a direct impact on security, compliance, and business processes. Management must be involved early on, while budget planning should reflect the actual effort required.
The migration is also an opportunity. Those who need to rebuild their IAM system anyway can use this opportunity to achieve cloud readiness, introduce zero-trust concepts, and modernize authorization management as a whole. The result will then be not just a new tool, but a future-proof IAM architecture.
With the end of SAP IdM support approaching, there is still enough time for a thorough transition. But the window of opportunity is closing fast. Those who are at least in the analysis phase by 2026 are in a good position. Those who don’t start until 2027, on the other hand, will be under pressure.
The first step isn’t selecting a new tool, but conducting an honest assessment of your IAM landscape. Everything else follows from there: timeline, tool selection, budget, and implementation strategy.