Keep DLP-enabled Windows clients away from SAP application shares

Why can a Windows client's Endpoint DLP configuration matter to a SAP server share?

A controlled technology lifecycle progressing from assessment to approved production.
DSE visual intelligenceManaged IT operationsBriefing · 2 min read
Executive summary

What you need to know

Why can a Windows client's Endpoint DLP configuration matter to a SAP server share?

Potentially affected

SAP applications on Windows Server and Windows clients with Endpoint DLP accessing their application shares.

DSE recommendation

Review SAP application-share access from client devices as well as the protection configuration on the SAP servers.

Source facts

Microsoft’s SAP guidance warns that, depending on policy, an Endpoint DLP-enabled Windows client can write DLP attributes onto a network share. It prohibits such clients from accessing shares used by SAP applications and advises against activating Endpoint DLP on Windows servers running SAP software. The caution identifies possible corruption or access-denied errors for rapid document or archive writes to affected shares. Microsoft Learn.

Applicability

Review the actual SAP file paths and the clients that can access them. This is the source’s Endpoint DLP compatibility boundary, not a recommendation to turn off antivirus or endpoint detection across the environment. Coordinate interpretation with the SAP Basis and security owners.

DSE recommendation

Review SAP application-share access from client devices as well as the protection configuration on the SAP servers. Identify document, archive, and interface-file workflows that currently cross that boundary. Propose a supported separation of client-facing file exchange from SAP application storage, with named owners for transfer and validation. Do not solve the issue by broadly disabling unrelated endpoint protections.

Verification

Inspect permissions, access paths, and applicable client policies without deliberately recreating corruption in production. Validate an approved replacement transfer path with representative nonproduction documents and the SAP application owner. Check the resulting files and application behavior, retaining any access error for investigation. Close the review only when both server configuration and client access match the agreed boundary; a server-only policy inventory is incomplete for this question.

Official references

Microsoft Learn: Microsoft Defender for Endpoint on Windows Server with SAP. Source reviewed September 9, 2026.

Primary reference

Review the official source

Microsoft Defender Endpoint on Windows Server with SAP - Microsoft Defender for Endpoint | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE