(SM-2502) Azure Data Lake Gen2
This article describes a process required to establish a connection from SAP to Azure Data Lake Storage Gen2.
Prerequisites
SAP NetWeaver 7.01 SP-level 015
HTTPS service enabled
SSFLIB Version 1.850.40 ; CommonCryptoLib (SAPCRYPTOLIB) Version 8.5.20 (+MT)
Azure storage configuration
This section describes the steps needed for the preparation of the landing area on the Azure side.
Storage Account and ADLS container
To create the MS Azure storage account, follow the official documentation Create a storage account to use with Azure Data Lake Storage Gen2.
Landing area (container/directory)
Create a container or a directory within the container where all files extracted from the SAP system will be stored.
In Microsoft Azure Storage Explorer, select the container/directory that will be used and set appropriate permissions depending on the authentication method chosen.
Authentication
Authentication to ADLS can be delivered by two methods:
SAS Token: Recommended for Proof of Concepts, faster setup, but provides fewer security management options.
OAuth 2.0: Recommended for production deployment, fully manageable, but requires application registration and detailed permission setup.
SAS Token
If you use the SAS token, please ignore the OAuth 2.0 Authentication steps. Similarly, you can skip steps related to the OAuth profile in the SAP configuration section.
To generate the SAS token, go to the Azure portal.
The SAS token should grant permission to Create, Read, Write, Delete and List.
Click Generate SAS token and URL.
Copy Blob SAS token string and store it for configuration on the SAP side.
OAuth 2.0 Authentication
OAuth 2.0 required application registration. To create a new registration, follow these steps:
Go to Azure Active Directory > App registrations > New application registration.
2. Fill in the required fields and click Create.
3. Write down Application ID and Directory ID, as it will be required later during the Storage management configuration.
4. Click Certificates & secrets and generate a New client secret. Write down the secret, which will be used later during the configuration.
5. Allow access to the registered application (Client ID) to the landing area.
6. The registered application also needs to execute permission on ALL parent directories and filesystem (enabling directory structure traversal).
SAP system configuration
After preparation is complete on the Azure side, fill in the required information on the SAP side to establish a connection.
STRUST
This step only applies when SAP ICM mode is used, except when OAuth is used for authentication. This functionality becomes deprecated from 2502 release.
To enable verification of server authenticity and encrypted communication (HTTPS), SSL certificates need to be added to the SAP system's STRUST.
To download relevant certificates, open a web browser in private mode and navigate to storage account FQDN in the format: https://<container>.dfs.core.windows.net
The browser will return an InvalidUri error, but will offer an interface to download the certificates:
Please make sure to download all three certificates to have a full certificate chain:
In STRUST, import these certificates into SSL Client (Anonymous) PSE. After the import, click Save.
If OAuth authentication is to be used, repeat the same steps for certificate management with the address https://login.microsoftonline.com.
The address uses the following certificate chain:
When the PSE is updated, run the transaction SMICM and restart the ICM services.
Storage RFC
SAP ICM RFC destination
This step only applies when SAP ICM mode is used. This functionality becomes deprecated from 2502 release.
Create RFC type G for Azure Data Lake Gen2 primary endpoint.
Set Target Host to your ADLS address (e.g. dvdadls2.dfs.core.windows.net).
Set Path Prefix to ADLS container.
Set SSL to Active and Certificate list to ANONYM SSL Client (Anonymous).
Set HTTP Version to 1.1 and Compression to Inactive.
OAuth 2.0 Authentication RFC destination
This step is required only if OAuth authentication is chosen.
Create RFC of the type G for the Microsoft Active directory. This RFC represents a connection to the authority server that grants an authentication token for ADLS.
Set Target Host to: login.microsoftonline.com.
Set SSL to Active and Certificate list to ANONYM SSL Client (Anonymous).