Services

UI Data Protection Masking

Protect Sensitive Data and be compliant with Data Protection requirements

Data Protection is beyond SAP Authorizations

Traditional SAP authorization controls are essential. It focuses on primarily focuses on controlling access to transaction codes, Fiori apps, and the underlying authorizations at activity, field, and organizational levels, but they may not provide the level of data protection required today as per the privacy, regulatory, and data protection requirements.

Consider a procurement user who works with supplier records every day may need to create purchase orders, review invoices, or manage supplier information, but there may be no business reason for them to see the supplier’s complete bank account details. Similarly, a finance user may need to process payments or review financial documents without unrestricted visibility into sensitive banking, tax, or other financial information.

This is where UI Data Protection Masking becomes valuable. Instead of removing a user’s access to the entire business process, sensitive information can be protected at the point where it is displayed, while authorized users retain the access they need to perform their responsibilities.

Expert Guide

Beyond SAP Authorization: Why UI Data Protection Masking Matters

Traditional SAP Security controls who can access applications and what actions they can perform. But what happens when users need access to a business process without needing to see all the sensitive information within it? Explore how UI Data Protection Masking adds another layer of protection by controlling what users can see.

License

ToggleNow helps customers with UI Data Protection Masking licensing and procurement, including applicable licensing requirements and implementation considerations.

Implement

Our SAP Security specialists can design and implement the solution around your SAP landscape, sensitive-data requirements, business processes, and existing authorization model.

Advisory

Our experts help define what data needs protection, who should see it, and how it should be protected based on your business and security requirements. They can bring the pre-defined rulebooks.

Support

ToggleNow provides ongoing support and optimization for configuration changes, new requirements, troubleshooting, and evolving data protection needs.

One Partner for the Complete UI Data Protection Masking Journey

Implementing a data protection solution involves more than installing software.

Organizations need to understand the licensing model, identify sensitive information, determine who should see it, configure the protection rules, test the impact on business processes, and continue managing those rules as the SAP landscape changes.

ToggleNow supports the complete lifecycle.

Sensitive Data Is Everywhere in SAP. Protect it!

UI Data Protection Masking allows organizations to introduce more granular protection around sensitive information without automatically taking away access to the complete business process.

Where Can UI Data Protection Masking Be Used?

UI Data Protection Masking supports multiple SAP user-interface technologies in applicable scenarios.

SAP GUI

Protect sensitive information within established SAP GUI business processes.

SAP Fiori & SAPUI5

Apply data protection controls to modern SAP Fiori and SAPUI5 applications.

Web Dynpro ABAP

Protect sensitive information in applicable Web Dynpro applications.

WebClient UI

Extend data protection to supported WebClient UI scenarios.

A Practical Implementation Approach

01 - Discover

We identify the sensitive information, applications, business processes, users, roles, and existing authorization controls involved.

02 - Assess

We determine where existing SAP authorization is sufficient and where additional protection is required at the field, record, or application level.

03 - Design

We define the sensitive attributes, protection actions, authorization requirements, masking patterns, and business scenarios.

04 - Implement

We configure and deploy the applicable UI Data Protection Masking capabilities across the relevant SAP environment.

05 - Validate

We test both authorized and unauthorized scenarios to make sure sensitive information is protected without unnecessarily disrupting legitimate business activities.

06 - Govern

We help establish a sustainable approach for reviewing, changing, monitoring, and optimizing data protection policies.

Why ToggleNow?

SAP Security Is Our Foundation

UI Data Protection Masking sits at the intersection of SAP Security, authorization, sensitive-data protection and governance.

ToggleNow brings experience across these areas rather than approaching the solution as an isolated technical implementation.

One Partner From License to Support

You do not need one provider for licensing, another for implementation, and another for advisory.

ToggleNow can support the complete journey:

License → Design → Implement → Go-Live → Advise → Support

We Start With the Business Process

The objective is not to mask as many fields as possible.It is to protect the information that actually needs protection without making the business process unnecessarily difficult to use.

Practical SAP Security Experience

Our approach is grounded in real-world SAP Security and authorization challenges, including role design, access governance, audit requirements, and business-process impact.

Built for Long-Term Governance

Our approach is grounded in real-world SAP Security and authorization challenges, including role design, access governance, audit requirements, and business-process impact.

Frequently asked questions

Questions you might have about our solution

Still have questions?

Can’t find the answer you’re looking for? Please contact our SMEs.
SAP UI Data Protection Masking – FAQ
UI Data Protection Masking is a solution for protecting restricted and sensitive data values at field level. Depending on the applicable capability and configuration, fields can be masked, cleared, hidden, or disabled for users who are not authorized to view or edit the information. SAP also documents capabilities such as data blocking, attribute-based authorization, Reveal on Demand, and field access tracing.
No. SAP authorization controls access to applications, transactions, business functions and other protected resources. UI Data Protection Masking provides an additional level of control over sensitive information displayed within supported user interfaces.
Yes. Field-level protection is one of the core capabilities. Depending on configuration, a field can be masked, cleared, hidden, or have editing disabled.
Yes. Data blocking can be used in supported scenarios to suppress rows or block access to sensitive records.
Yes. SAP documents UI Data Protection Masking for SAPUI5 and SAP Fiori applications in applicable scenarios.
Yes. SAP GUI is one of the supported UI channels documented by SAP for UI Data Protection Masking.
Yes. SAP documents support for both role-based access control and attribute-based access control for data protection masking.
Reveal on Demand provides an additional level of protection by keeping sensitive information masked or protected by default and allowing authorized users to explicitly request access. Depending on the configuration, the user may need to provide a reason for viewing the information.
No. UI Data Protection Masking should complement, not replace, appropriate SAP authorization design.
SAP documents recording, authorization tracing, and field access tracing capabilities that can help organizations understand which fields are accessed and which authorizations grant access in applicable scenarios.
Yes. ToggleNow can support customers with UI Data Protection Masking licensing and procurement, subject to applicable SAP commercial terms, product availability, and customer eligibility.
Yes. ToggleNow provides assessment, design, configuration, implementation, testing, deployment, and knowledge-transfer services.
Yes. ToggleNow provides ongoing advisory and support for UI Data Protection Masking, including new use cases, configuration changes, troubleshooting, optimization, governance, and evolving data protection requirements.
UI Data Protection Masking can contribute to an organization’s security, privacy, and compliance control framework. However, the technology itself does not establish regulatory compliance. Compliance depends on the organization’s applicable requirements, policies, technical controls, operating procedures, monitoring, and governance.

Protect Sensitive Data.
Keep Business Moving.

Protect Sensitive Data.
Keep Business Moving.

The objective of data protection is not to make SAP harder to use. It is to make sure that the right people can access the right information for the right business reason.

Learn how we can help you and your enterprise through the GRC transformation journey. Choose the appropriate option and fill out the form. Let’s get started!

Product
Demo

Product Demo

Explore our range of SAP Access Governance products.

Detailed Discussion

Engage with our SMEs regarding any challenges in Access Governance.

Partnership Discussions

Interested to be part of ToggleNow partner network? Let’s discuss!