
Meet the Authors
F5 Distributed Cloud Bot Defense screens SAP Customer Data Cloud login traffic in observation mode, then blocks fraudulent requests in mitigation mode.
SAP Customer Data Cloud hosts more than 1.4 billion consumer identities and processes about 18 billion API calls a month, making its login surface a standing target.
Bot defense sits outside SAP configuration at the application edge, so credential-stuffing protection needs a clear owner across security, customer experience, and platform teams.
F5 has placed its Distributed Cloud Bot Defense in front of SAP Customer Data Cloud, the multi-tenant SaaS that stores and governs consumer identities for business-to-consumer sellers. The move extends a partnership that predates the cloud era. F5 is a charter member of SAP’s Enterprise Services Community and a founding member of the Network Advisory Group within it, and the two companies have collaborated on availability, performance, and security for SAP web and portal technologies for years. F5’s broader business in application delivery and security spans hybrid and multicloud estates, and the current work moves that alliance toward customer identity and access management, where automated attack traffic now concentrates against the login page itself.
How the Bot Defense Reads and Blocks Login Traffic
SAP Customer Data Cloud runs at a scale that makes its login surface a standing target. The platform hosts more than 1.4 billion consumer identities across roughly 700 customers, records 1.6 billion consent transactions each month, and processes about 18 billion API calls monthly. Its Customer Identity function supplies registration-as-a-service, social login, and identity federation with single sign-on, while its consent and profile functions handle GDPR, CCPA, and LGPD obligations such as export and deletion of consumer data. Each of those authentication endpoints is a place where a valid credential can be tested.
F5 addresses that surface in two stages. Distributed Cloud Bot Defense first runs in observation mode, analyzing the logs of incoming requests to fingerprint threats and shape a tailored response before it touches production traffic. Once F5 and the customer confirm that legitimate users will not be caught, the deployment moves to mitigation mode, and requests judged fraudulent in real time are blocked at the source. The system sorts traffic into attack campaigns and continues to recognize a campaign even when it retools with new software or proxies, drawing on hundreds of signals rather than a single fingerprint. Blocking happens without CAPTCHA or a forced multi-factor step, so human users see no added friction.
The mechanism counters credential stuffing, in which cheap bots cycle stolen username and password pairs against a login endpoint hoping a fraction succeed. F5 reports that in the documented deployment, monitoring found 90 percent of login traffic was bot-driven, and mitigation cut it by the same margin. Every one of those attempts also drains bandwidth and server capacity, so removing them returns headroom to the identity platform.
Where Fraud Protection Sits in the Sap Customer Experience Stack
SAP Customer Data Cloud is often deployed as part of SAP Customer Experience Solutions alongside SAP Commerce Cloud, which puts the identity layer directly in the transaction path. That placement raises the stakes on the login page. A successful account takeover reaches stored profiles, consent records, and any commerce entitlements tied to the account, and F5 frames its bot defense as a way to protect that investment while keeping the sign-in experience clean. The company situates the problem against online fraud losses it projects to surpass $48 billion, and it notes that blocked web attacks tend to migrate to mobile, so coverage has to span channels.
The division of labor is worth naming for SAP teams evaluating the pair. SAP Customer Data Cloud does the identity, consent, and profile governance, converting anonymous visitors into known, consented customers. F5 works ahead of that flow, filtering automated and fraudulent traffic before it reaches the authentication logic. For an SAP customer, the practical result is a security control that lives outside the SAP configuration and falls to whoever governs the application edge.
What This Means for SAPinsiders
- Bot traffic is now a CIAM capacity question. When most login attempts are automated, filtering them ahead of SAP Customer Data Cloud returns API and server headroom to the identity platform. Teams sizing the platform should account for attack volume, not only legitimate users.
- Account takeover reaches more than the login screen. A compromised account can expose stored profiles, consent records, and linked commerce entitlements. Security and customer experience owners should map that blast radius before treating login protection as a standalone control.
- Edge defense needs a named owner. F5’s bot defense sits outside SAP configuration, so responsibility falls to whoever governs the application edge. Buyers pairing the platform with third-party protection should settle accountability across security, customer experience, and platform teams early.



