What's changed: Created AZ-120 Chapter 1 (Domain 1: target requirements & sizing (SAPS/HANA memory, SAP-certified VMs, supported scenarios, quota, licensing, cost), migration strategy (lift-and-shift/lift-shift-migrate/lift-shift-migrate to HANA, Azure Migrate); Azure environment (Azure RBAC, Entra ID auth, Azure Policy governance, management hierarchy, SAP landing zone); SAP RISE integration (managed-service, VNet peering/private endpoints/ExpressRoute, data archiving, Entra ID integration)).
1.3Integration with SAP RISE
Understand integrating RISE with SAP (managed-service SAP) with Azure: networking, compute/network/storage, data archiving, and identity/security design and implementation.
RISE with SAP is a managed-service SAP offering where SAP holds operational responsibility. Under the covers it is SAP S/4HANA Cloud Private Edition run by SAP on a hyperscaler — not true multi-tenant SaaS (that is SAP S/4HANA Cloud Public Edition) — which is why it has a customer-dedicated tenant that must be network-integrated with the surrounding Azure resources. Unlike self-managed SAP, the focus is integrating the SAP tenant (often a separate Azure subscription/tenant) with the customer’s Azure environment.
1.3.1RISE networking integration
Because the RISE SAP environment lives in an SAP-managed subscription, design private connectivity to the customer’s VNet. Connect via VNet peering and private endpoints, with ExpressRoute for hybrid, to integrate app tiers, surrounding services, and on-prem at low latency in a closed network. Clarify the boundary and responsibility split between RISE and the customer’s surrounding Azure services (compute/network/storage).
1.3.2Data, identity, and security integration
Integrate data management services (e.g., data archiving to Azure storage) to optimize long-term retention and cost. For identity integration, apply SSO/Conditional Access to RISE apps via Microsoft Entra ID, and fold security service integration (monitoring, threat protection) into the customer’s governance. Design around the split where SAP operates and the customer integrates plus runs surrounding services.
Cues: "RISE is a managed-service SAP operated by SAP." Connect SAP tenant and customer VNet "privately" = VNet peering/private endpoints; hybrid = ExpressRoute. "long-term retention/cost" = data archiving to Azure storage. Identity = Entra ID SSO/Conditional Access.
Watch the mix-ups: (1) RISE (SAP-managed) vs self-managed SAP (customer-operated). (2) The RISE SAP environment is in a separate subscription/tenant—design private connectivity. (3) Do not blur the responsibility boundary (SAP vs customer). (4) Avoid connecting over the public internet.
1.3.3Section summary
- RISE with SAP = managed-service operated by SAP; the customer handles integration and surrounding services
- Privately connect the SAP tenant and customer VNet (VNet peering/private endpoints, ExpressRoute)
- Archive data to Azure; integrate identity via Entra ID SSO/Conditional Access
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. You want low-latency, closed-network connectivity between the RISE with SAP environment (separate subscription) and the customer’s Azure VNet. Best?
Q2. Which is correct about operational responsibility in RISE with SAP?
Q3. You want to offload long-term SAP data to Azure to optimize cost and performance. Best?
Q4. You want to apply SSO and Conditional Access to RISE apps. Best?
Q5. Which correctly distinguishes RISE with SAP from self-managed SAP?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

