Analytics Legends The knowledge platform for SAP Analytics
Academy module

Security for SAP AI — Prompt Injection, Data Exfiltration and Authorisations

Security for SAP AI — Prompt Injection, Data Exfiltration and Authorisations — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-09-25

Expert-level security module for SAP generative AI and agentic solutions, built on the orchestration service's documented content-filtering and data-masking modules and the authorisation architecture underneath every SAP AI Core workload. Covers the precise, documented behaviour of Azure Content Safety (harm classification with severity levels, PromptShield prompt-attack detection and its system/developer-message exclusion, Protected Material Detection) and Llama Guard 3; the distinction between anonymization and pseudonymization with SAP's own entity catalog, including SAP-specific staff- and public-user-ID categories a generic masking product would miss; documented data-exfiltration risks and controls for agents (MCP tool whitelisting, SAP API Management, Allowed Tools List, no-retention contractual commitments); a four-layer authorisation model (resource-group/XSUAA isolation, principal propagation, scoped OAuth tokens, human approval gates); SAP AI Core's audit-log security events and four greppable authentication-failure messages; and Inference Observability's own documented security caution, which this module treats as a design requirement rather than an afterthought. Closes with a governance split — what SAP's platform runs versus what the implementer configures — defensible in a go-live risk review.

What you will learn

  • State SAP's documented definition of a prompt attack and configure the orchestration service's content filtering module (Azure Content Safety harm classification, PromptShield, Llama Guard 3) correctly, including the system/developer-message exclusion and multi-filter billing
  • Distinguish anonymization from pseudonymization and select the right SAP Data Privacy Integration entity categories for an SAP data use case, including SAP-specific IDs
  • Explain the documented data-exfiltration risks for AI agents (tool misuse, knowledge poisoning) and the corresponding SAP controls (MCP whitelisting, API Management, Allowed Tools List, no-retention commitments)
  • Design a four-layer authorisation model for an SAP AI agent: resource-group isolation, principal propagation, scoped OAuth tokens, and human approval gates
  • Read SAP AI Core's audit log for security events and authentication-failure messages, and wire them into alerting
  • State precisely what SAP's platform provides versus what the implementer must configure, for every control covered in this module

Module overview

Who this is for. You are being asked to sign off a generative AI or agentic solution on SAP data, and "the vendor handles security" is not an answer your risk/control stakeholders will accept. This module builds the threat model and the concrete SAP controls for the three failure modes that actually get an AI project rejected at go-live review: prompt injection, data exfiltration through tools or logs, and authorisation gaps. It assumes M325, M333 and, for the agent-building side, M369.

Prerequisites

  • M333 (AI & LLM Fundamentals for SAP Consultants) and M325 (SAP Generative AI Hub hands-on)
  • M369 (SAP Build Process Automation with Agents) recommended if the go-live under review includes an agent, not only a single-turn assistant
  • Working understanding of SAP AI Core's resource-group and multitenancy model
  • Comfort reading API documentation and REST headers; no coding required for the exercises

Outcomes

  • Chair a go-live security review for an SAP generative AI or agentic solution using named, documented controls rather than vendor assurances.
  • Produce a content-filtering and data-masking configuration for a real SAP use case, with SAP-specific entity categories included.
  • Threat-model an agent's tool access and produce an Allowed Tools List with scopes and human-approval gates.
  • Explain to a risk committee, control by control, what SAP's platform provides and what the implementer is responsible for configuring.

Full module available to members. The full module adds: the decision framework · the end-to-end scenario walkthrough · the KPI scorecard · the anti-patterns · the code blocks · the knowledge check · the diagrams.

Open in the app →