The global and independent platform for the SAP community.

Secure Development With SAP Hana XSA

SAP Hana XSA enables different deployments in one single Hana database. However, companies have to consider various security guidelines to ensure diligent access management.
Thomas Tiede, IBS
April 9, 2020
It Security
avatar

With Hana1.0 SPS11, SAP Hana Extended Application Services, Advanced Model (SAP HanaXSA) was introduced. This model is based on a microservices approach andenables the modulization of software development.

Hana XSAmakes different deployments (separated development environments) in one singleHana database possible. Every application operates in a separate container andin its own environment, meaning that problems in one application do not affect theothers.

Companieshave to consider various security guidelines to ensure diligent accessmanagement. SAP Hana XSA Cockpit orchestrates the solution, managing users,access and security configurations (e.g. tenants or SAML identity providers).

In user management, admins can create new accounts or convert existing Hana users to XSA users. Access is granted by so-called role collections. For example, for user management the role collection XS User Admin is necessary, and for role management users need the role collection XS Authorization Admin. For viewing only, standard role collections XS Authorization Display and XS User Display are available. Accountability is guaranteed by Hana’s auditing.

How SAP Hana XSA works

The basicstructure of SAP Hana XSA consists of organizations and spaces. In spaces, userscan develop applications. Organizations are containers meant to structure thespaces. Developers operate in spaces. After the user master data have beencreated, developers are assigned spaces and access rights. There are three typesof roles: Space Manager (space management as wells as evaluating applications);Space Developer (implementing, activating and deactivating of applications,matching applications to services); and Space Auditor (evaluation ofapplications and role management).

Regarding organizations, the role Organization Manager enables user management andmaintaining the spaces in an organization. Any changesof organizations or spaces are recorded in trace files on the operating systemthat can be analyzed with e.g. Hana Database Explorer.

The central development platform for SAPUI5 applications is SAP WebIDE (integrateddevelopment environment). It supports various programming languages like Java,Java Script, SAPUI5 HTML5, Node.js and more. WebIDE can be used for on-prem applications(Hana XSA) and as central development application for SAP Cloud Platform (CloudFoundry).

To leverageWebIDE, developers have to be assigned corresponding access rights in SAP HanaXSA. Two standard templates already exist for this purpose: WebIDE Developerand WebIDE Administrator. To authorize users for application development, arole has to be created from the template WebIDE Developer.

Toimplement access rights in customized solutions, companies have to define theirown rules. They can also integrate actions into customized solutions that canbe recorded using Hana’s auditing (category application auditing).

Inconclusion, the use of SAP Hana XSA requires following strict securityguidelines and practicing diligent user and access management.

avatar
Thomas Tiede, IBS

Thomas Tiede is managing director of IBS Schreiber.


Working on the SAP basis is crucial for successful S/4 conversion. 

This gives the Competence Center strategic importance for existing SAP customers. Regardless of the S/4 Hana operating model, topics such as Automation, Monitoring, Security, Application Lifecycle Management and Data Management the basis for S/4 operations.

For the second time, E3 magazine is organizing a summit for the SAP community in Salzburg to provide comprehensive information on all aspects of S/4 Hana groundwork.

Venue

FourSide Hotel Salzburg,
Trademark Collection by Wyndham
Am Messezentrum 2, 5020 Salzburg, Austria
+43-66-24355460

Event date

Wednesday, June 10, and
Thursday, June 11, 2026

Early Bird Ticket

Regular ticket

Subscribers to the E3 Magazine Ticket

reduced with promocode CCAbo26

Students*

reduced with promocode CCStud26.
Please send proof of studies by e-mail to office@b4bmedia.net.
*The first 10 tickets are free of charge for students. Try your luck! 🍀
EUR 390 excl. VAT
available until November 30, 2025
EUR 590 excl. VAT
EUR 390 excl. VAT
EUR 290 excl. VAT

Venue

Hotel Hilton Heidelberg
Kurfürstenanlage 1
D-69115 Heidelberg

Event date

Wednesday, April 22 and
Thursday, April 23, 2026

Tickets

Early Bird Ticket
Regular ticket
EUR 390 excl. VAT
available until 30.11.2025
EUR 590 excl. VAT
Subscribers to the E3 magazine
reduced with promocode STAbo26
EUR 390 excl. VAT
Students*
reduced with promocode STStud26.
Please send proof of studies by e-mail to office@b4bmedia.net.
EUR 290 excl. VAT
*The first 10 tickets are free of charge for students. Try your luck! 🍀
The event is organized by the E3 magazine of the publishing house B4Bmedia.net AG. The presentations will be accompanied by an exhibition of selected SAP partners. The ticket price includes attendance at all presentations of the Steampunk and BTP Summit 2026, a visit to the exhibition area, participation in the evening event and catering during the official program. The lecture program and the list of exhibitors and sponsors (SAP partners) will be published on this website in due course.