This blog is part of a series exploring SAP’s UI Data Protection (UIDP) solution for S/4HANA. UIDP provides a robust framework for managing access to sensitive data across S/4HANA applications, offering features that cater to diverse business requirements.
Overview
In this article, we will cover the business need for such a solution, its architecture, key features, and a practical example of setting up data masking for a specific use case to enhance data security.
Future posts in this series will delve into advanced scenarios and detailed implementations of UIDP features. If you’re eager to explore these topics, feel free to jump to the relevant sections.
The Business Need for a Data Masking Solution
Data is an organization’s most valuable asset, and protecting sensitive information has become a top priority, especially for regulated industries like Aerospace and Defense which deal with hypersensitive data on a regular basis. Data breaches can jeopardize critical operations, lead to financial losses, damage reputations, and incur legal consequences.
SAP’s UIDP add-on addresses these critical challenges around data security by:
- Safeguarding sensitive information and preventing misuse by internal employees.
- Providing visibility into data access activities to monitor user behavior and detect malicious intentions.
With UIDP, businesses can ensure that all users accessing data on S/4HANA systems are subject to data protection measures, controlling visibility based on their authorization or data security clearance.
Architecture Overview: Maximizing Data Security in SAP S/4HANA
SAP UIDP operates between the UI and application logic layers. Its core lies in the authorization layer, where access decisions are made before transmitting original or obfuscated data to the UI. This ensures that users only view information permitted by their authorization level.

Image Credits: SAP
Key Features of SAP UI Data Protection Solution
Here are the key features that ensure high data security across SAP S/4HANA systems, helping prevent unauthorized user access:
- Data Masking: Sensitive information in the system can be masked at the UI layer based on user authorization or data protection policies.
- Data Blocking: This feature allows you to block specific data records on the UI. For instance, a table with multiple records in your SAP application will display only those records the user is authorized to access.
- Attribute-Based Authorization Checks: This core feature sets the solution apart from traditional SAP authorizations. At runtime, the solution dynamically determines whether a user is authorized to access information, based on the context of the request. Complex business rules can be configured in the system, either through setup or ABAP code, to support these authorization decisions. These rules are then applied consistently across the organization.
- Reveal on Demand: Certain sensitive information can be configured to be temporarily revealed on demand, with or without workflow approval.
- Application Blocking: This feature blocks access to specific applications using Attribute-Based Authorization Checks. For instance, access to business-critical applications can be restricted based on geolocation, time of access, or other business requirements.
- GUI Button Blocking: Specific function codes or buttons on SAP GUI screens can be disabled for unauthorized users.
- Sensitive Field Access Trace: This feature enables a trace to track when a user attempts to access sensitive information, recording whether the information was revealed or not.
Example Use Case: Masking Material Numbers in SAP S/4HANA
Let’s explore a straightforward use case where we set up data masking for the material number field:
Define Logical Attribute: Assign a logical attribute to the material number field to determine its data protection behavior.

Link Logical Attribute to UI Field: Map the attribute to the material number field on the sales contract screen (This example is for SAP GUI but the solution supports other SAP UI technologies as well that will be discussed in upcoming blogs, including how to identify the screen address for a UI field.)

Configure Authorization Checks: Choose between:
-
-
- Role-Based Authorization: Use SAP business roles to grant access.
- Attribute-Based Authorization: Implement data protection policies for context-driven access control.
-
For this setup, I have used a data protection policy. We will cover the steps to create a policy in a different blog.

Masked Value Display: Users without necessary permissions will see a masked value instead of the actual field value.

Conclusion
SAP’s UI Data Protection solution offers unparalleled flexibility for managing access to sensitive data in S/4HANA systems. Its rich feature set enables seamless integration into both standard SAP applications and custom interfaces, providing businesses with a reliable framework to address complex data security needs.
At Cognitus, we take it a step further with our CIS-GovCon for A&D solution tailored for the Aerospace and Defense industry. Leveraging SAP’s UIDP framework, our Contract Data Protection solution empowers A&D customers to implement data masking, blocking, application control, and reveal-on-demand features across diverse interfaces like SAP GUI, UI5 applications, and PDFs.
Cognitus’ expertise ensures that businesses can harness the full potential of SAP’s data protection capabilities, delivering industry-specific solutions to meet the highest security standards.
Want to learn more about how CIS-GovCon for A&D ensures compliance while enhancing data security for regulated industries? Get in touch with our experts today!