Executive Summary: Part 1 of our 4-series blog explained how modern SAP environments are moving toward distributed, API-driven architectures and why that shift creates a rapid rise in non-human identities (NHIs). Part 2 showed why traditional SAP tools and human-centric IAM models fail to govern these identities at scale.
Part 3 of this blog aims to go deeper into how exposures happen in real SAP landscapes, the patterns behind these failures, and where governance gaps consistently emerge.
Non-human identities now drive a large share of activity across SAP BTP, S/4HANA, and connected applications. Yet most organizations still treat them as background components rather than high-risk access points. This part breaks down how these identities actually get exposed, why the weaknesses keep repeating, and what attackers typically exploit inside real SAP environments.
Why Long-Lived SAP Non-Human Identities Become Easy Targets
Modern SAP BTP and S/4HANA landscapes rely heavily on NHIs such as service keys, OAuth clients, API tokens, certificates, technical users, and now AI agents. These identities often operate quietly in the background, supporting integrations, workflows, extensions, and automation.
They also create an attractive target surface because they often:
- Stay active for long periods
- Carry broader permissions than intended
- Remain in the landscape after projects end
- Operate outside of MFA, password resets, and HR-driven offboarding
And examples of commonly exposed NHIs in SAP environments include:
- BTP service keys used in integration flows or CI/CD jobs
- OAuth client credentials created for testing and not retired
- Certificates used across multiple environments
- AI agents or autonomous automation components that generate new identities as part of workflows
Hence, just one exposed key or token with broad permissions can open doors to multiple subaccounts or connected systems.
How Non-Human Credentials Fail in Practice
Exposures involving non-human identities (NHIs) are increasingly common in cloud applications, and SAP environments are no exception. Many of these failures stem from gaps in the credential lifecycle, creating predictable patterns that attackers can exploit.
API Token Exposure
Long-lived tokens stored in code, logs, or configuration files can be accidentally exposed. Public repositories occasionally contain committed secrets, and automated tools make it easy for attackers to discover them.
Certificate Expiry and Workarounds
Certificates used for destinations or communication users may expire unexpectedly. Emergency workarounds often introduce temporary broad access, which can remain unaddressed if not properly revisited.
OAuth Credential Reuse
OAuth clients created during testing phases often stay active long after their intended use. When assigned broad scopes, these credentials can grant access far beyond what was originally intended.
AI Agent Credential Use
As AI-driven automation grows within SAP BTP, some agents dynamically create or use new credentials. If one of these is exposed, it may allow unauthorized actions across downstream workflows or automated processes.
Accumulation of Residual Credentials
Over time, old keys, unused accounts, expired certificates, and orphaned tokens accumulate. This residual credential footprint is often overlooked, leaving hidden entry points that teams do not actively track.
Common Attack Paths in SAP Landscapes
Below are realistic scenarios showing how NHI exposures can enable unauthorized access in SAP environments:

These examples reflect common patterns in cloud identity misuse and can also apply in SAP landscapes depending on configuration and governance practices.
Additionally, mappings to common MITRE ATT&CK techniques (credentials in files, cloud credential theft, valid accounts) provide a helpful reference for security teams.
Blast Radius and Environment Drift
Non-human identities often span multiple layers of SAP environments, creating broad exposure risks:
- A single service key can access S/4 APIs, Event Mesh, and SAP HANA Cloud.
- Credentials may migrate across Dev, QA, and Prod during testing or deployment cycles.
- Certificates are sometimes reused across multiple destinations.
- AI agents can trigger processes across several connected systems.
These horizontal access pattern means that a single exposed or outdated credential can ripple across multiple services, amplifying the potential impact of a security incident.
Industry Case References
Broader research across cloud environments highlights a consistent pattern: unmanaged non-human identities create significant exposure risks.
- Cloud security studies frequently report that service principals and long-lived secrets are often overprivileged.
- Incident response teams note that attackers commonly target machine credentials.
- Public repository scans continue to reveal exposed API keys and tokens across multiple platforms.
In SAP BTP landscapes, the same identity types and practices exist, making proactive governance essential to reduce exposure and prevent potential breaches.
Lifecycle Weak Points: Where SAP NHIs Go Wrong
Most NHI risk in SAP environments comes from lifecycle inconsistencies rather than a single major issue. Common gaps include:

Each stage contributes to the accumulation of residual credentials and increases audit fatigue and operational risk.
Closing the Gap: Securing Non-Human Identities in SAP BTP
Non-human identities now dominate SAP environments. Operating behind the scenes and often bypassing lifecycle checks applied to human accounts, they can accumulate across projects, pipelines, and automation layers.
As SAP landscapes grow with BTP services, integrations, and AI-driven workflows, these gaps become increasingly visible. Managing the full lifecycle of NHIs — from creation and usage to rotation and retirement — is critical to minimize credential drift and maintain a strong security posture.
The next part of this series will show a practical governance model, guiding SAP teams on establishing clarity, ownership, and lifecycle control for NHIs across their BTP landscape.
Frequently Asked Questions
What are non-human identities (NHIs) in SAP environments?
Non-human identities include service keys, API tokens, certificates, OAuth clients, technical users, and AI agents. They support integrations, workflows, and automation but operate behind the scenes, making them high-risk access points if unmanaged.
Why are NHIs in SAP landscapes considered high-risk?
NHIs often bypass standard lifecycle checks, carry broad permissions, remain active after projects end, and are excluded from MFA or HR-driven offboarding. This creates opportunities for exposure, lateral movement, and unauthorized access across systems.
How do non-human credentials typically fail in SAP environments?
Common failures include exposed API tokens, reused or misconfigured OAuth credentials, expired or broadly shared certificates, AI agent credentials being logged or duplicated, and the accumulation of residual keys and tokens across environments.
What is “blast radius” in the context of SAP NHIs?
Blast radius refers to the extent of exposure when a single credential is compromised. Because NHIs often span multiple environments and systems, one exposed key, token, or certificate can impact several services, subaccounts, or workflows.
How can SAP teams reduce risks associated with non-human identities?
Proactive lifecycle management—covering creation, usage, rotation, and retirement—is essential. Establishing clarity, ownership, and governance for NHIs helps prevent credential drift, minimize audit fatigue, and strengthen the overall security posture.

