As we enter the last quarter of mainstream support for SAP BusinessObjects BI 4.3, many customers are actively upgrading. Some are finally retiring BI 4.2. Others are updating to one of the final patch levels of BI 4.3 SP5. And still others – those that have paid down their classic UNV universe technical debt – are moving to BI 2025.
I still get pushback from corporate security teams when we ask for antivirus software to be temporarily disabled during a patch cycle. Or to implement the real-time exemptions SAP has carefully described in SAP KB 1497394. Curious, I decided to ask Microsoft Copilot for its opinion.
Q: We always get strange looks from our customer’s security teams. But are there other vendors and products besides SAP BusinessObjects where the best practice is to install patches with antivirus disabled, as described in SAP KB 1497394?
A: Yes. In fact, SAP BusinessObjects is far from unique in this regard.What’s unusual is not that a vendor recommends disabling antivirus during an installation or patch application. What’s unusual is how often security teams assume that no legitimate enterprise software would ever require it. Many large enterprise platforms have documented guidance to temporarily disable antivirus, endpoint protection, or real-time scanning during installation, upgrades, or patching because file-locking and behavioral monitoring can interfere with installers.
Copilot offered Oracle Enterprise Performance Management, Autodesk, and Examsoft as examples from vendors other than SAP. So at least SAP BusinessObjects isn’t a unicorn in this respect. Let’s review best practices for working with SAP BusinessObjects and antivirus software.
Pre-installation Best Practices
There’s a full checklist described in SAP Note 1952120 that the upgrade project team should review prior to an installation or patch.
This is what I wrote the last time regarding antivirus:
During the kickoff meeting for an installation or upgrade project, determine the vendor and version of the antivirus software in use. Next, identify the person who administers the antivirus software who will assist, if necessary, during the installation process. It’s really important to identify this person, even if everyone in the kickoff meeting begins to stare uncomfortably at their shoes when you pose the question. Establish that the software must either be disabled or uninstalled for the duration of the installation process. SAP also provides a list of files and folders that should be permanently exempted from real-time scanning, to improve the day-to-day run-time performance of SAP BusinessObjects.
Over the years, the vendor names have changed, but the issue hasn’t. Today’s environments may be protected by CrowdStrike, SentinelOne, Microsoft Defender, Sophos, Trellix, or some other endpoint security product. But the same principle applies to all: follow the exclusions documented in SAP KB 1497394 and avoid allowing real-time scanning to interfere with SAP BusinessObjects installation and patching activities.
In 2026, I’m still seeing botched installations when its advise isn’t heeded. Download the KB, engage your security team, and get those SAP KB 149739 exemptions in place today.
References
- SAP KB 1497394 remains the definitive article regarding “Which files and directories should be excluded from an antivirus scan for SAP BusinessObjects Business Intelligence Platform products in Windows?”. It was last updated to version 30 on November 3, 2025.
- SAP Note 1602088 – Which version number corresponds to which patch / SP for SAP BusinessObjects BI 4.x / 2025 ?
- SAP KB 1952120 – Best practices & pre-requisites on Windows while Install/Update/Patching BI
Have you upgraded to BI 4.3 or BI 2025 recently? The final patch for BI 4.3 SP5 (Patch 10) will be released soon in December 2026. Share your experience in the comments below.