SAP HANA
On-premises, SAP HANA Cloud, SAP BTP.
Access mode: Read-only or read-write
Required information
| Field | Details |
|---|---|
| Host / IP | HANA server FQDN or IP. HANA Cloud: endpoint from SAP BTP cockpit. |
| Instance number | Two-digit instance number (e.g., 00). Determines port: 3<instance>15 for indexserver. |
| Port | Calculated: 3<instance>15 (e.g., 30015 for instance 00). HANA Cloud uses 443 with TLS. |
| Database name | For multi-tenant (MDC): specific tenant database name. Single-container: SYSTEMDB. |
| Schema(s) | HANA schemas to access. |
| Credentials | Username + password. SAML-based SSO if required. |
| Access level | Read-only: SELECT on schemas, EXECUTE on procedures. Minimum roles: PUBLIC, custom read role. |
Network considerations
On-premises (most common): VPN or dedicated circuit. HANA is typically deep inside the corporate network.
HANA Cloud: Connections over HTTPS (443) with TLS. IP allowlisting required in SAP BTP cockpit.
SAP Cloud Connector: If on-prem HANA is exposed via SAP Cloud Connector, provide the virtual host mapping.
Credential and auth management
Standard HANA auth: Username + password. Technical user recommended (not dialog user).
SAML bearer assertion: For SSO environments. Requires IdP configuration.
X.509 certificate: Supported for service-to-service. Provide client cert.
Password policy: HANA enforces password policies at system level. Confirm service account policy allows long-lived or non-expiring passwords, or establish rotation process.
Stored procedure and logic access
HANA stored procedures invoked with CALL. Require EXECUTE privilege. Introspection via SYS.PROCEDURES system view. HANA also has calculation views, table functions, and SQLScript functions. Confirm which are in scope. For ABAP-managed schemas, CDS views may be the primary access pattern instead of direct SQL.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Network reachability | telnet <host> <port> or HTTPS test for HANA Cloud | Connected |
| Authentication | SELECT 1 FROM DUMMY; | Returns 1 |
| Identity | SELECT CURRENT_USER FROM DUMMY; | Expected service account |
| Schema access | SELECT TABLE_NAME FROM TABLES WHERE SCHEMA_NAME = '<schema>' | Lists tables |
| Procedure listing | SELECT PROCEDURE_NAME FROM SYS.PROCEDURES WHERE SCHEMA_NAME = '<schema>' | Lists procedures |
| Execute test | CALL <schema>.<proc>(test_params); | Returns expected result |
| Privilege audit | SELECT * FROM EFFECTIVE_PRIVILEGES WHERE USER_NAME = '<user>' | Matches expected privileges |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.