{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares/",
        "slug": "dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares/"
        },
        "title": "Keep DLP-enabled Windows clients away from SAP application shares",
        "summary": "Why can a Windows client's Endpoint DLP configuration matter to a SAP server share?",
        "format": {
            "slug": "briefing",
            "name": "Briefing"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "managed-it",
            "label": "Managed IT operations",
            "alt": "A controlled technology lifecycle progressing from assessment to approved production.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/managed-it-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/managed-it-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:22:34+00:00",
        "modified_at": "2026-09-10T02:14:31+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 252,
        "potentially_affected": "SAP applications on Windows Server and Windows clients with Endpoint DLP accessing their application shares.",
        "dse_recommendation": "Review SAP application-share access from client devices as well as the protection configuration on the SAP servers.",
        "primary_source": {
            "name": "Microsoft Defender Endpoint on Windows Server with SAP - Microsoft Defender for Endpoint | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-endpoint/mde-sap-windows-server",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft&#8217;s SAP guidance warns that, depending on policy, an Endpoint DLP-enabled Windows client can write DLP attributes onto a network share. It prohibits such clients from accessing shares used by SAP applications and advises against activating Endpoint DLP on Windows servers running SAP software. The caution identifies possible corruption or access-denied errors for rapid document or archive writes to affected shares. <a href=\"https://learn.microsoft.com/en-us/defender-endpoint/mde-sap-windows-server\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review the actual SAP file paths and the clients that can access them. This is the source&#8217;s Endpoint DLP compatibility boundary, not a recommendation to turn off antivirus or endpoint detection across the environment. Coordinate interpretation with the SAP Basis and security owners.</p>\n<h2>DSE recommendation</h2>\n<p>Review SAP application-share access from client devices as well as the protection configuration on the SAP servers. Identify document, archive, and interface-file workflows that currently cross that boundary. Propose a supported separation of client-facing file exchange from SAP application storage, with named owners for transfer and validation. Do not solve the issue by broadly disabling unrelated endpoint protections.</p>\n<h2>Verification</h2>\n<p>Inspect permissions, access paths, and applicable client policies without deliberately recreating corruption in production. Validate an approved replacement transfer path with representative nonproduction documents and the SAP application owner. Check the resulting files and application behavior, retaining any access error for investigation. Close the review only when both server configuration and client access match the agreed boundary; a server-only policy inventory is incomplete for this question.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-endpoint/mde-sap-windows-server\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Microsoft Defender for Endpoint on Windows Server with SAP</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nMicrosoft’s SAP guidance warns that, depending on policy, an Endpoint DLP-enabled Windows client can write DLP attributes onto a network share. It prohibits such clients from accessing shares used by SAP applications and advises against activating Endpoint DLP on Windows servers running SAP software. The caution identifies possible corruption or access-denied errors for rapid document or archive writes to affected shares. Microsoft Learn.\nApplicability\nReview the actual SAP file paths and the clients that can access them. This is the source’s Endpoint DLP compatibility boundary, not a recommendation to turn off antivirus or endpoint detection across the environment. Coordinate interpretation with the SAP Basis and security owners.\nDSE recommendation\nReview SAP application-share access from client devices as well as the protection configuration on the SAP servers. Identify document, archive, and interface-file workflows that currently cross that boundary. Propose a supported separation of client-facing file exchange from SAP application storage, with named owners for transfer and validation. Do not solve the issue by broadly disabling unrelated endpoint protections.\nVerification\nInspect permissions, access paths, and applicable client policies without deliberately recreating corruption in production. Validate an approved replacement transfer path with representative nonproduction documents and the SAP application owner. Check the resulting files and application behavior, retaining any access error for investigation. Close the review only when both server configuration and client access match the agreed boundary; a server-only policy inventory is incomplete for this question.\nOfficial references\nMicrosoft Learn: Microsoft Defender for Endpoint on Windows Server with SAP. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft’s SAP guidance warns that, depending on policy, an Endpoint DLP-enabled Windows client can write DLP attributes onto a network share. It prohibits such clients from accessing shares used by SAP applications and advises against activating Endpoint DLP on Windows servers running SAP software. The caution identifies possible corruption or access-denied errors for rapid document or archive writes to affected shares. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/mde-sap-windows-server).\n\n## Applicability\n\nReview the actual SAP file paths and the clients that can access them. This is the source’s Endpoint DLP compatibility boundary, not a recommendation to turn off antivirus or endpoint detection across the environment. Coordinate interpretation with the SAP Basis and security owners.\n\n## DSE recommendation\n\nReview SAP application-share access from client devices as well as the protection configuration on the SAP servers. Identify document, archive, and interface-file workflows that currently cross that boundary. Propose a supported separation of client-facing file exchange from SAP application storage, with named owners for transfer and validation. Do not solve the issue by broadly disabling unrelated endpoint protections.\n\n## Verification\n\nInspect permissions, access paths, and applicable client policies without deliberately recreating corruption in production. Validate an approved replacement transfer path with representative nonproduction documents and the SAP application owner. Check the resulting files and application behavior, retaining any access error for investigation. Close the review only when both server configuration and client access match the agreed boundary; a server-only policy inventory is incomplete for this question.\n\n## Official references\n\n[Microsoft Learn: Microsoft Defender for Endpoint on Windows Server with SAP](https://learn.microsoft.com/en-us/defender-endpoint/mde-sap-windows-server). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Keep DLP-enabled Windows clients away from SAP application shares",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares/",
                "headline": "Keep DLP-enabled Windows clients away from SAP application shares",
                "description": "Why can a Windows client's Endpoint DLP configuration matter to a SAP server share?",
                "abstract": "Why can a Windows client's Endpoint DLP configuration matter to a SAP server share?",
                "articleBody": "Source facts\nMicrosoft’s SAP guidance warns that, depending on policy, an Endpoint DLP-enabled Windows client can write DLP attributes onto a network share. It prohibits such clients from accessing shares used by SAP applications and advises against activating Endpoint DLP on Windows servers running SAP software. The caution identifies possible corruption or access-denied errors for rapid document or archive writes to affected shares. Microsoft Learn.\nApplicability\nReview the actual SAP file paths and the clients that can access them. This is the source’s Endpoint DLP compatibility boundary, not a recommendation to turn off antivirus or endpoint detection across the environment. Coordinate interpretation with the SAP Basis and security owners.\nDSE recommendation\nReview SAP application-share access from client devices as well as the protection configuration on the SAP servers. Identify document, archive, and interface-file workflows that currently cross that boundary. Propose a supported separation of client-facing file exchange from SAP application storage, with named owners for transfer and validation. Do not solve the issue by broadly disabling unrelated endpoint protections.\nVerification\nInspect permissions, access paths, and applicable client policies without deliberately recreating corruption in production. Validate an approved replacement transfer path with representative nonproduction documents and the SAP application owner. Check the resulting files and application behavior, retaining any access error for investigation. Close the review only when both server configuration and client access match the agreed boundary; a server-only policy inventory is incomplete for this question.\nOfficial references\nMicrosoft Learn: Microsoft Defender for Endpoint on Windows Server with SAP. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:22:34+00:00",
                "dateModified": "2026-09-10T02:14:31+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Keep DLP-enabled Windows clients away from SAP application shares"
                },
                "articleSection": [
                    "Business Continuity",
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "Cybersecurity",
                    "IT",
                    "Briefing",
                    "Information priority"
                ],
                "genre": "Briefing",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 252,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Microsoft Defender Endpoint on Windows Server with SAP - Microsoft Defender for Endpoint | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-endpoint/mde-sap-windows-server"
                }
            }
        ]
    }
}