# Keep DLP-enabled Windows clients away from SAP application shares

> Why can a Windows client's Endpoint DLP configuration matter to a SAP server share?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:34+00:00
- Modified: 2026-09-10T02:14:31+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Briefing
- DSE priority: Information
- Topics: Business Continuity, Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Why can a Windows client's Endpoint DLP configuration matter to a SAP server share?

## Potentially affected

SAP applications on Windows Server and Windows clients with Endpoint DLP accessing their application shares.

## DSE recommendation

Review SAP application-share access from client devices as well as the protection configuration on the SAP servers.

## Article

## Source facts

Microsoft’s SAP guidance warns that, depending on policy, an Endpoint DLP-enabled Windows client can write DLP attributes onto a network share. It prohibits such clients from accessing shares used by SAP applications and advises against activating Endpoint DLP on Windows servers running SAP software. The caution identifies possible corruption or access-denied errors for rapid document or archive writes to affected shares. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/mde-sap-windows-server).

## Applicability

Review the actual SAP file paths and the clients that can access them. This is the source’s Endpoint DLP compatibility boundary, not a recommendation to turn off antivirus or endpoint detection across the environment. Coordinate interpretation with the SAP Basis and security owners.

## DSE recommendation

Review SAP application-share access from client devices as well as the protection configuration on the SAP servers. Identify document, archive, and interface-file workflows that currently cross that boundary. Propose a supported separation of client-facing file exchange from SAP application storage, with named owners for transfer and validation. Do not solve the issue by broadly disabling unrelated endpoint protections.

## Verification

Inspect permissions, access paths, and applicable client policies without deliberately recreating corruption in production. Validate an approved replacement transfer path with representative nonproduction documents and the SAP application owner. Check the resulting files and application behavior, retaining any access error for investigation. Close the review only when both server configuration and client access match the agreed boundary; a server-only policy inventory is incomplete for this question.

## Official references

[Microsoft Learn: Microsoft Defender for Endpoint on Windows Server with SAP](https://learn.microsoft.com/en-us/defender-endpoint/mde-sap-windows-server). Source reviewed September 9, 2026.

## Primary reference

- Name: Microsoft Defender Endpoint on Windows Server with SAP - Microsoft Defender for Endpoint | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-endpoint/mde-sap-windows-server
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Keep DLP-enabled Windows clients away from SAP application shares,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-562-keep-dlp-enabled-windows-clients-away-from-sap-application-shares/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
