Feature · archived
Microsoft
Microsoft retires the containerized data connector agent for the Microsoft Sentinel solution for SAP applications; the SAP agentless data connector is the replacement
left 14 Sept 2026
Quick answers
- Is it true that Microsoft Sentinel retires the containerized SAP data connector agent?
- Yes — and the date has already passed (14 Sept 2026). If you feed SAP logs into Microsoft Sentinel through the containerized data connector agent, that pipeline stops on 14 September 2026.
- When did it take effect?
- 14 Sept 2026 (already passed). Verified against the vendor's own announcement.
- What should I use instead?
- Migrate to the Microsoft Sentinel SAP agentless data connector before 14 September 2026.
What this means for you
If you feed SAP logs into Microsoft Sentinel through the containerized data connector agent, that pipeline stops on 14 September 2026. Microsoft says the agent is permanently disabled after that date and stops sending SAP logs to Sentinel, so any analytics rules, workbooks, hunting queries, and playbooks that depend on SAP data go dark for the affected systems — a real gap in SIEM and threat-detection coverage for your SAP estate. Creation of new containerized agents is already disabled. Customers who already use the newer SAP agentless data connector are not affected, and there is no change to Sentinel pricing or billing meters.
Where to go
Migrate to the Microsoft Sentinel SAP agentless data connector before 14 September 2026. Microsoft describes a side-by-side cutover with no gap in coverage: deploy the agentless connector alongside your existing containerized agent, validate that SAP logs are being ingested, then decommission the agent. Existing analytics rules, workbooks, and playbooks keep working throughout because the data keeps flowing.
- Microsoft Sentinel SAP agentless data connector — generally available, the Microsoft-named replacement
Microsoft is retiring a piece of the plumbing that gets SAP logs into Microsoft Sentinel. In an Azure Updates retirement notice, Microsoft says that on 14 September 2026 it will retire the containerized data connector agent for the Microsoft Sentinel solution for SAP applications. After that date the agent is “permanently disabled” and stops sending SAP logs to Sentinel. Creating new containerized agents is already switched off.
The replacement already exists and is generally available: the SAP agentless data connector. This is a forced migration rather than a feature that simply vanishes — Sentinel keeps ingesting SAP data, but through the agentless connector instead of the container.
Who this affects
Anyone still collecting SAP telemetry via the containerized agent. When it goes dark, the downstream content goes with it: analytics rules, workbooks, hunting queries, and playbooks that rely on SAP data stop returning results for the affected SAP systems. For a security team, that is a blind spot in threat detection over the SAP estate until the connector is replaced. Two groups can relax: teams already on the agentless connector are unaffected, and there is no change to pricing or billing meters.
What to do
Move to the SAP agentless data connector before 14 September 2026. Microsoft’s stated path is a side-by-side cutover with no coverage gap:
- Deploy the agentless connector alongside the existing containerized agent.
- Validate that SAP logs are being ingested through it.
- Decommission the containerized agent.
Because the two run in parallel during the switch, existing analytics rules, workbooks, and playbooks keep working the whole time — the data source underneath them changes, the detections on top do not.
Entry changelog
- — last reviewed.
- — Retirement date reached. Microsoft's stated retirement date (14 September 2026) came due today; status moved to passed. Re-confirmed against the Microsoft release-communications API backing the Azure Updates notice (id 568457), which states retirement "On September 14, 2026"; no facts changed.
- — Entry created from Microsoft's official Azure Updates retirement notice (id 568457, published 12 August 2026), verified against the Microsoft release-communications API backing that page. Retirement date 14 September 2026, replacement (SAP agentless data connector), the side-by-side migration steps, and "no change to pricing or billing" all quoted directly from Microsoft.
Put this countdown in your README
Building on Microsoft? Drop this badge into a project’s README or docs — it shows the days left and
refreshes on its own every night from this page.
[](https://lastcall.dev/entries/microsoft-sentinel-sap-connector-agent-retirement) Spot an error or a changed date? Tell us and it’s corrected the same night.