PRODUCT NEWS | Xiting Authorization Management Suite (XAMS)
Discover the key innovations of the Xiting Authorization Management Suite (XAMS) SP21 – with a clear focus on license optimization, FUE integration, and targeted enhancements in Role Management and CRAF.
SAP licenses are among the biggest cost drivers in modern IT landscapes – and at the same time one of the most frequently underestimated optimization opportunities.
With the new Service Pack 21 of the Xiting Authorization Management Suite (XAMS), Xiting addresses this challenge head-on: SP21 delivers well-designed tools for license analysis, automation, and transparency – specifically for SAP S/4HANA and RISE environments.
The result: less manual effort, clearer decision-making and active cost control built directly into the role-building process.
SP20 laid the foundation: initial analysis functions in the Role Designer, Role Profiler, and the integration of CRAF into PFCG.
SP21 builds on this – and expands license optimization across the suite.
Okay, Alex. So let's start with our SP twenty one update features, which I'm very looking forward to. Absolutely, yeah, you want to do a quick introduction for everyone in case we have any newcomers for the session here? Yes, of course. So to all of you who have recently joined some minutes ago, welcome to our second webinar session today, which focuses on our EXIM SP21 update features. If you've missed the license analysis and license optimization webinar, which was the first session today, you're very welcome to get a look on this topic by our recordings. And whenever you have questions, feel free to address them to our company. We are very happy to answer your questions. Yeah. And within our exam SP21 features, we tried to cover lots of expectations and problems or challenges we're facing at during our S4HANA migration and license analysis work. So there are quite some handy tools also concerning Fiori, which Alexander and Melina will be showing today. Also concerning our exciting security platform, which is the third session after this one. So please keep tuned, stay here, and, yeah, have a time. Thank you, Eli. Absolutely. And, thanks again, everyone, that maybe recently joined or or stayed from the previous session. And so, in this hour session here, we'll be talking about the exciting authorization management suite and service pack twenty one that was released this year and some of the new updates and features that are associated with it. And before I, oops, before I, dive into the presentation quick agenda, we'll provide a high level overview about s p twenty one. We'll talk about some of the new license optimization features. If you're coming from the previous presentation, it's been a little bit of a repeat. But for newcomers, we wanna make sure we cover this, information, relating to s p twenty one. I'll be talking about some some new features relating to s p twenty one, as well as giving us some time hopefully at the end, for a q and a, from individuals that are present today. And before I even really talk about s p twenty one and and show some things in the system, one of the new capabilities or new offerings that we're offering to our customers as well as our partners is something we're calling the customer portal. And so I wanna switch over to the customer portal here and show this, and let me just kinda minimize my thumbnail for Zoom. So here, I'm logged into the customer portal, and the customer portal is going to be something that anyone that is a customer of Xciting will have access to, whether you are a customer for the XCiting's, maybe some of our other solutions like the exciting security platform, the Lanera solution that we're actually going to be showcasing on July sixteenth, any of those solutions as well as, the exciting central workflow tool, the XCW. So as long as you are a customer of one of our solutions, ultimately, you will be provided access to this portal as well as partners. Partners will be provided access to this portal, and this is meant to be sort of like a a one stop shop for anyone, whether you're customer or partner related. And within this portal, we offer a lot of information, whether it be relating to our knowledge base. So as we talk about some of those different solutions I mentioned within this portal, we provide access to the documentation associated with those solutions. You're able to, as a customer or a partner, dive in and get more information. In this case, if we look at the xAMS, is there a particular module or capability that I have a question about? I'm able to really dive into those modules and that documentation and able to get more information about it. Not just online here, but we also offer the capability as you see here at the bottom to download this into an offline version, and this is something that's important for our customers to be able to give them insights into the tools and the capabilities that these tools provide them that they have access to. The customer portal as well, if you're an existing customer, in the past when we upgraded to a new service pack, in this case, SP twenty one, if you plan on going to SP twenty one, or I should say when you go to SP twenty one, in the past, you may have contacted our exciting support team. They would have made the transports available in our online portal, and you would have downloaded those transports from that online portal. And not just the transports relating to new service packs, but also if you ever had a call with us and we provided a recording from the call, Typically, there was some form of website you would have to go to to download the recordings, but we wanted to try and provide all of this information from a central location. So not only will future service packs be available to download via the customer portal, but also any recordings such as webinar recordings or such as actual individual meetings that we have over Teams, those all will become available via the download section. So if you are a particular customer and we have a meeting, we'll upload that recording into the download section, and that will be where you go to access that particular download. Some of the other additional features that I'll mention here relating to kind of what's new with our tools or product road map type, capabilities. We wanna be able to provide that transparency to our existing clients so they understand, you know, what is new within our solutions, maybe not just our solutions, but also within our customer portal. We also wanna be able to provide a a road map to our customers so they can understand what are some of the things that we plan on introducing into our tools, whether we're looking at all of our different products here, whether you want to filter on specific products that are particular to your organization that you've purchased, and so this is something where we're trying to be more transparent with our customers and and give them those insights that today may be, more difficult for them to get. And to me, think one of the the coolest new features about this portal, relating to the knowledge base, and even if you are a x AMS customer and you have the documentation offline in a PDF, Well, if you've ever looked at some of this documentation, there may be hundreds of pages, maybe sixty pages long, and so it's difficult sometimes to scroll through this long documentation and really find and pinpoint what you're looking for, whether it's a particular functionality, a particular transaction code that you need to execute to perform particular functionality, and so we wanted to think about how can we provide organizations with a way to quickly analyze the document and understand what they need to accomplish that particular task that they're working on. And so within the customer portal, we also have introduced a AI assistant where we can actually go out and ask the AI assistant questions about our solutions, whether it be, hey. I need to, I need to create mitigating controls within the XAMS. Where do I go to do that? And so the AI assistant will provide the individual with information relating to their question and give them maybe hyperlinks to specific documentation associated with that. So if we have different sources within our documentation, this will actually allow me now to jump out to those specific sections within the documentation, as well as in some cases the zoom bar is locking my tab. Maybe I just need to know what's the transaction code I need to go to. So I could say what is the transaction code I run to scan to I run to perform ad hoc risk scans. And so this is a quick way that, individuals that leverage our tool can go out now and actually get that specific information, and they don't have to spend time in, I'll say, researching through the documentation and the various pages to actually go out and just get the pinpointed information they need they can go out and perform that analysis. And so that's one of the cooler solutions that we're offering organizations and existing customers within our customer portal that I wanted to mention, and not just that, but you know maybe to talk a little bit about partners as well. We also have a partner section within our tool here, if we have any partners on the call today, where we offer different onboarding material, marketing material, education relating to our tools, and as I talk about education it's not just for partners, also for our clients. We have different on demand videos that are available for our clients to watch relating to different maybe use cases, maybe new solutions that we're coming out with. So it's a really great solution that we're providing to our customers and partners to really try and advance us into a more modern age and provide that kind of one stop shop and one stop solution for them. We also have an idea section on our customer portal. So as we work with our clients, you know, in the past, someone may have suggested an idea, and a lot of these tools have been built based off of ideas from our clients that we've added to, our suite of capabilities that we provide. And so we wanted to have a central location where you could go as a customer or a partner and provide your ideas. And not just provide your ideas, but also understand where that idea stands. Have we actually reviewed that idea and want to say, hey. Yeah. We want to move forward with that, and we like that idea, and we're gonna work on getting that added to our tool, And we're gonna add that to our product road map that you can actually visualize now to see when that solution will become available. And so I wanted to just take a few minutes to talk about this because this is something new that we're providing to our existing customers as well as our partners, I think it's a great step in the right direction. But with that being said, I'll go ahead and jump over to the system itself, and I'll talk a little bit about some of the new capabilities that come with the XAMS SP twenty one that was released this year. And as always, if you're not familiar with how to access some of these new features that come with SP twenty one, when you go to our main landing page, that slash end slash exciting slash all transaction code, it will bring you to this main kind of landing page screen here. And from this screen at the top left, there is a service pack infos button, and so when you install the latest service pack from Exciting, you can go back and you can select, in this case service pack twenty one, and it will actually provide me with a PDF that I can download, but also the document within the GUI window here that I can scroll through, and it will give me the specific details associated just with the new features of SP twenty one and the specific features for specific modules that have come out in SP twenty one. So sometimes you may ask, okay. Well, what's new with SP twenty one? I just installed it on my landscape, but I don't really know what are some of the new features or capabilities. So whether you're going out to our customer portal now to get that information or you're actually just staying in the GUI, you can go to that service pack infos button, and you can scroll through the information provided to understand what are some of those new capabilities and functionalities. You also can download this into a PDF so you have it as an offline version so that you could store it, you know, somewhere on your company's portal or website such as SharePoint. But this is a great way to get that new information and to answer some of your questions about those new capabilities. Jump back to the presentation. And so in regards to some of the new capabilities relating to SP twenty one, if organizations, our clients that are on the call here today are leveraging SP twenty, you are familiar with some of the existing license tools that we offer to organizations as it relates to the role designer. So in the role designer SP twenty, you have that capability to import users, their roles, their usage data, scan those users and that usage data to determine what the ratio is or what the license type is for the particular roles and the users assigned to those roles, as well as what it should be based off of their usage within the system. Same thing with the role profiler in SP twenty. You had the capability to scan users, to scan roles, to determine what their license type is in the live production system. In the craft tool, we have the capability to integrate that license scanning into the actual generation of a profile, so whenever you generate a profile, we're able to actually initiate that scan and determine what a particular role is flagging for as it relates to licenses. And so these are kind of the capabilities from the last service pack, and so what we introduced with service pack twenty one, so that we can be, more in alignment with what our customers need, we introduced the user licensing summary feature. Now, technically, it was also available in SP twenty as well, but what we added to the user licensing summary feature and and right now, I'm in role designer, where I went and added some users to a project. I added their roles. I added their usage, and I can see what the license type would be based off of the roles they have assigned as well as based off of their usage. But with SP twenty one, what we've added now in the user licensing summary is we've added this FUE ratio as well as the FUE total. If you're on the previous presentation, I talked about FUEs a little bit, but just to talk more to them, when an organization purchases user licenses from SAP, they're ultimately purchasing a set amount of FUEs, and so those FUEs have a corresponding breakdown or ratio to actual user license types. So for example and right now I have the system set up for our RISE license types, but the same ratio is applicable for the on premise license types. They're just called a different name, but ultimately for our advanced use licenses, it's a one to one ratio. For our cloud core use licenses, it's a five to one ratio, and with our self-service licenses, it is a thirty to one ratio. And so we wanted to be able to provide this type of FUE breakdown for organizations, where in the past service pack on SP twenty one, we just had kind of like this section here where we told you how many users were flagging and how many license types were available, and then offline organizations would have to do that ratio conversion. And so we wanted to provide that in the tool going forward, and that's one of the features with Service Pack twenty one, not only in the role designer as you see here, but if I were to also switch over to the role profiler, as we look at the role profiler, and if you were on the last call, you know, this is one of our reports that we deliver out of the box that you may be familiar with associated with calculating user licenses or licenses at the user level, I should say, whether we look at the licenses they have based off of s u zero one or whether it's the license that they should have based off of the access assigned. You know, just like in service pack twenty, you know, we can select a user, and we can transfer that correct license type to that user based off of the access assigned. But what we've enhanced in this is once again that user licensing summary, where we actually now have that FUE ratio breakdown. And once again, we're just trying to give organizations that insight that they were looking for because when we reported to upper management that we had seventy seven advanced, two core, three self-service, that didn't necessarily mean much because, you know, management is thinking about FUEs because that's what they've purchased from SAP. So this is just another enhancement that we've provided to our existing license tools to give organizations insight into that FUE ratio and that FUE counts that they have within the environments. Switch back here. Jump ahead. One of the other areas that we have oops. Come back to that. One of the other whoops. Actually, I'll go back to that. Sorry. One of the other areas within the role profiler, and I'll jump back to that screen in a moment, that we've enhanced relating to licenses, is an ability to perform a trace against a user. So if you're familiar with our tools and our capabilities, we have the exciting times productive test simulation process where we're able to monitor what users are doing within the production system. And so within the role profiler and within that particular user licensing report, we actually have the ability to turn on a specific license trace for a user, and we can go through and analyze that license trace to determine based off of usage, what should this user be classified as if we were to have access designed based off of that principle of least access or least privilege. And I'll just kinda quickly show this from the profiler. And so here within the role profiler report that we're looking at a few moments ago, we have an additional column that we've added associated with that license trace where we can go ahead and we can select a user, we could select multiple users, and we can go out and activate that particular trace for those selected users. And then as that trace is running and collecting that data, we can go out and evaluate that data to determine what their license type would be based off of the authorizations that they're using. If you're familiar with the PTS, or their productive test simulation process, in SP twenty, we didn't really have a capability to restrict the trace just to license relevant objects. You know, we only could really trace all of the authorization checks that they were calling, not just the license relevant ones. And so we wanted to provide a capability to organizations to really just run that PTS process or or run that trace just against licensed relevant objects, so you can have a more pointed and a more focused, section of information to look at and review relating to licenses. And I can jump back to the slide deck here, Kind of show this from this perspective. So ultimately as we turn that trace on where we ultimately have the ability to go to a report that allows us to look at a particular user, look at a particular date range, and really change our source of data to be that license trace. Whereas before in our PTS or our coverage analyzer report, we had our sources limited to, like, s u fifty three simulation comparison mode, but now we have this additional capability to change the source to be that license trace where we get an overview of what the user has listed in s u zero one and what they should have based off of the trace data. And just like any of our tools, wherever we see numbers, typically, we can dive in and get more information. So I could dive into these particular boxes here and get an understanding of, you know, what are the apps that the user is using, what license types are those apps associated with, and so this is just a great opportunity to really have a pinpointed trace, relating to that license topic because it is such an important topic for clients, whether they're on the on premise environments or whether they are on the rise environments. The other license optimization capability that we provided was the integration into the coverage analyzer report that I mentioned a moment ago. So if you're familiar with the coverage analyzer report, and I'll switch screens here, So in the coverage analyzer report now in SP twenty one, when we are analyzing the PTS logs that we've collected for a user or a particular user, we're now able to, if we scroll down here, actually check an additional box relating to licensing. So as we're looking at that trace data that's being collected, we can determine what license type that trace data is associated with. So for the coverage analyzer report here, I've gone ahead and selected a date range, I've selected a user, a role, the simulation mode from PTS, and I've also elected to select that license processing. And so as we execute this and we look at the results, the screen will look very similar if you're familiar with the coverage analyzer, but now what we've added by selecting that box, if we scroll over, we've added the license glass column here. And so if I go ahead and just filter this on relevant objects related to the license classification, Yeah. Let's do it like this. Just trying to copy it, but it wouldn't let me. And so here now we've we've added color coding that will give us a high level kind of quick feedback as we're looking at the logs to help us understand what these particular entries are associated with as it comes to licensing. So for these light blue entries, these are the lowest costing license type self-service, So that gives me quick instant feedback that as I'm working on updating my new role that I'm, creating maybe as a part of a role redesign project, or maybe if I'm going through and I wanna update existing roles based off of usage, this will let me know that this particular set of entries is associated with the lowest costing license type, so I'm kind of safe to add these without impacting my license type. But as we scroll through here, we'll see that as we look at other entries within the file, such as this entry in red, well, if I were to add this entry in red to that new role or the existing role that I'm working on updating, well, that entry in red is associated with an advanced license type, and so if that were to get added to that role, that role is now an advanced license type, and any user that receives that role is going to be considered an advanced license type. So this is just another feature that we wanted to add relating to licensing to help organizations kind of quickly get insights as they're looking at the logs relating to the coverage analyzer report and working on updating those roles. And just to mention the last license type here as we scroll down, we can see we have some line items showing up in orange, and, ultimately, these light items are going to be associated with that second highest costing license type, that core license type. So just giving us some instant feedback as we're looking at the logs, as we're updating the roles, Maybe we wanna take a stance of, hey. Anything that shows up in red with the highest costing license type, we wanna hold off on adding that until we maybe get some further approval, or we review that with the business that they understand that if we were to add this access, it's going to cause this particular user to flag for that highest costing license type. Switch back to the presentation here. Some new additional features as well. I'll talk about four different specific modules, that we provide, that is going to allow organizations to have more capabilities as it relates to to Fiori, as it relates to really monitoring their environment. And one of the first ones that I'll talk about is the exciting times capability that we've added for a central location to review, all of the open exciting time sessions, not just in a particular system, but from across multiple systems. So if you're using the exciting times module in the PTS process, the protective go live feature, the firefighter emergency access management feature, and you're using that in multiple SAP systems in the s a p s p twenty world, you'd have to log in to each of those systems to monitor what sessions are running. Do I have workflows that are pending? Do I have people still in the checkout process for Protective Go Live. And so what we've added in s p twenty one now is a Fiori app that allows you to, from a central location, ultimately monitor all of those sessions across your SAP landscape. And so this was important to us because this is going to allow our customers to be more flexible and save them time and allow them to perform that monitoring in a much more efficient manner. So I just have a few pictures here on what it looks like, what the Fiori app is called. It's the exciting time session cross system analysis app. We have an overview down there at the bottom about what it looks like. It allows us to see what systems these sessions are associated with, what is the reference user associated with these sessions, is it a reference user associated with PTS, is it associated with firefighter? Is it a protective go live? Are these self-service sessions? Are they workflow based sessions? Who are the owner for these different sessions? So all of that information that you would have to log in to the individual system before, we now offer that solution from a central location to do that monitoring. For the role replicator, this is one of the also, I know I say this I've said this a couple times already, but I really enjoy this feature with the role replicator. If anyone here on the call is, familiar with Fiori adaptation, and so for Fiori adaptation, this is when we talk about adjusting the predelivered tiles from SAP. And so when I talk about adjusting a tile, what I mean is the title of a tile, the subtitle of a tile, the keyword of a title. And so all of these things you would have to do what I'll call manually on a one by one by one basis in the, functionality that SAP provides out of the box. And so at Exciting, you know, one of our key philosophies is trying to offer accelerators to our clients. And so we've added a new functionality in the role replicator that it's going to allow you to do that Fiori adaptation process en masse now. And so I wanna go ahead and show this in the system. Jump out to the role replicator. And so within the Fiori objects tab of the role replicator, which we had available in SP twenty, in SP twenty one, you'll have a new button down here towards the middle called mass adaptation of UI AD tile text, and this is that Fiori adaptation exercise that I was just mentioning, where you now have the ability to go out and look at particular tiles, their keywords, the information, the tile icons, and work on adjusting those en masse with the organization. So if I were to whoops. Let me go back and close out of this pop up. So here now I can put in a particular catalog, I can put in a tile ID, an app ID, I can put in a t code or Fiori ID, and I can go out. I can display the details associated with that app. And so prior to this call here, I went ahead and, did some adaptation myself. We can see for this particular app, f zero seven one eight, I've gone ahead and added a subtitle called Alex. I've added a tile information called exciting. And if I were to actually show that in the Fiori space, We can see here in my Fiori lunch pad, I have the title. Just gonna let me sign back in. I'm just gonna stop the share for a second so no one sees my password. And let me kick the share back off. Okay. Sorry about that. So here I have the post general journal entries app, and we can see that I've adapted it to add Alex as a title or and added exciting at the bottom as a subtitle. And if we dive into the app, it still takes me to post journal entries. But one of the key things and why this is potentially important for organizations as we transition to s four our end users aren't familiar with app IDs. You know, if I were to say the app ID give us a second to load. I'll show this from the GUI. You know, if I were to say to a user, hey, I need you to go out and execute F0718, well, it doesn't really mean much to them because they're used to maybe executing a particular transaction code. And so this transition to Fiori for the user base may be challenging, and one of the ways that you could alleviate that challenge is by updating the predelivered subtitles and tile information for these tiles to make the navigation experience more meaningful for our users. And so if I were to back out here now and actually, do this adaptation here, I'll just do it for a single tile, but, ultimately, you can do this en masse. So you could simply put in your selection of Fiori IDs that you're looking to update. You can download the details associated with those Fiori IDs that we were just displaying. I'll go ahead and open the file. And so here now we have the output, and I'll go ahead and do my text to columns. And so here were those two fields that I had mentioned I had updated prior to the webinar here today just to show that those tiles were adapted from SAP standard. Obviously, SAP standard isn't delivering a tile that says Alex versus exciting at the bottom. But, ultimately, now for my Excel file, if I downloaded multiple apps, those apps would be listed here. And what I can go through doing now and what I can do now is go through this file and update these tile information, the keywords, the subtitles to be more in aligned with what makes sense to our user base. So if I were to put in maybe Melina here now and change this exciting to be exciting demo, we can go ahead and save this or maybe Melina doesn't make sense. Maybe we want to put in a particular transaction code. Off the top of my head, I don't remember the transaction code for this particular app, but I'll just put in, like, f b zero one, for example. We can save this, and we'll go back to the role replicator. And so just like we have a download option, we also have a upload option. So I'll go ahead and upload my file. Let me do a different download. I apologize. I clicked the wrong option. Okay. Now we have the right download. How to do the text to columns. I'll update this again to be f p zero one. We'll change this to be exciting demo. Save. Now the upload should work as intended. There we go. Now it's asking me for that workbench transport. So whenever we did that theory adaptation exercise via the traditional method from SAP, you know, it's always gonna ask us for a workbench. Go ahead and save this, and it's let me know now that those texts have been adjusted. Now even though the the text has been adjusted for the Fiori app, if I were to go back and refresh, we'll notice that the change hasn't occurred yet. We still see Alex. We still see exciting listed on the Fiori tile. And so what we have to do is we have to make sure that we are synchronizing the cache associated with their users in Fiori. So I'll go ahead and start the synchronization process, which we offer via kind of a hyperlink button there. And so this does take a little while to run, but, ultimately, as it's running, it's going through the system and syncing the cache for each different user. And so I'm just gonna go back to my Fiori page here and just refresh this. And, hopefully, as the job is going, eventually, this will update here in a moment. We'll give it a a second. And I I didn't mention it, but as this is going, maybe I'll come in here just to show it. The traditional Fiori adaptation exercise, that's done via the Launchpad application manager where you need to go out and you need to select the technical catalog, that is associated with the app that you're trying to adapt. And within here at the top, once this loads whoops. Okay. Didn't like that. Okay. Perfect. As I was going in there and wanting to show that, you'll see here that my tile has now updated. So we see that Alex was switched to f b zero one, and we see that the bottom section of the tile now has been updated to be exciting demo. And so this is important because, as I mentioned previously, the out of the box method delivered by SAP is something that you have to do on a manual basis where you have to ultimately select your particular technical catalog. We have to select the particular transaction or apps that we're looking to adapt. We have to go into edit mode. It's gonna ask for a package. It's going to ask for a transport request. We then have to switch to adaptation mode, and then eventually I can adapt that particular line item. But if we're trying to adapt ten, twenty, fifty different tiles, it's a very cumbersome process because you have to go through each individual line one at a time and perform that adaptation. And so with SP twenty one, we wanted to offer that functionality to be able to do that exercise in mass because it is a great way to enhance the user experience as it relates to Fiori at the organization as you maybe migrate to s four or even if you're already on s four and you're thinking about ways how we can drive adoption and make the experience more meaningful for the users, Fiori adaptation is a great exercise that you can go through. And now with SP twenty one, you have a way to do that in a much more quicker and a much more efficient manner, or you could say an accelerated manner. I'll jump back to the presentation. And so the next particular topic that I wanna talk about as it relates to SP twenty one is the role designer. And so with the role designer, what we've gone ahead and added is the ability to merge different projects together. So in the past, you may have had different projects maybe for different business process areas like finance, SD, MM, security and basis, IT, and you're working in these different projects to design the new roles for the organization. But once the projects are done, you have no central location to do, like, a report out of what it looked like before versus what it looked like after. So now when you go to create a project in the role designer, there is the capability here at the bottom to merge projects into one, and I'll actually jump into the system and show that. Go to my role designer. Back it out of this project. And so when we go to create a new project, as I mentioned, we have the merge projects into one feature. And when I select this feature now, I have an option to select which projects I'm looking to merge into one, and I can select as many projects as I would like ultimately. And so we can go through here now and select multiple projects. This is now going to create a new project based I have to give it a name. Whoops. And so now that projects have been merged together, I can go ahead and launch this new project that I've created. It lets me know that ultimately it's a merged project, and so now I have a single project at the end of the project or maybe even at the beginning of the project as you want to provide a high level overview of what users have, what usage they have, what roles they have assigned. And this may take a second to load for the first time like it always does when we're creating a project for the first time, But that capability is there now, and that's something new with SP twenty one that we didn't have previously. And so now I'm pulled into the project. It lets me know, when we merge the project, it also merges the comments. It merges the users. It merges their usage. It merges the roles that they had in both of the projects. And so this is something new that we wanted to talk about and demonstrate to the individuals on the webinar here today. One of the other new features that we have as well is relating to the role designer and the ability to import Fiori usage data. So if you're familiar with the solutions within the XAMS, one of the solutions that we had in SP twenty that came out was that exciting Fiori app tracker, And we didn't really have a great way at the time to take that Fiori app tracker data that we were collecting in a separate tool essentially and import that into the role designer. And so what we have now is a functionality of as you're monitoring users using that Fiori app tracker data or that Fiori app tracker tool, you can actually now not only import their traditional GUI type usage, whether it be transaction codes, function modules, other menu objects like WebDIMM Prose, but we also now can import that Fiori app tracker data that we've been collecting directly into the role designer project. And so this allows individuals now to have a much clearer picture, especially for clients that are doing a redesign on s four HANA. You know, maybe they're not on ECC still or more of a Fiori first strategy on s four. Well, if that's the case, then we need to understand what Fiori apps people are using. That's going to come from the Fiori app tracker, but we also need a way to get that data into our role designer module so that we can design new roles based off of that information. And so with this new capability that's coming with SP twenty one, this is going to be a great solution for that type of activity to get that usage data into the role designer so that we can start understanding what are people using and still leveraging those capabilities that come with the role designer and perform those different what if scenarios. You know, what if I create a role based off of these apps? Does it provide a hundred percent coverage? Does it cause a particular SOD risk to occur? What's the license type associated with this theoretical role that I've created? So all of those traditional functionalities that we have in role designer, we're now just trying to become or incorporate more of that Fiori data that organizations have as they're on S4HANA or on the Rise environment. We do have some new features associated with CRAF as well that I'll talk to. So within CRAF, if you're utilizing the exciting XAMS and CRAF for your risk analysis scanning and for your mitigating control assignments, We've also added the ability now to, perform, workflow approvals, and this is something important to us because we really want to think about that four eye principle. Whoops, I don't have the slide showing. My apologies. Let me unhide this. Let me just show it from the documentation perspective. Okay. We've added the ability now to also provide workflows for mitigations. So where in the past, if you were mitigating a particular user or you were mitigating a role within the, CRAFT tool, there was no real workflow capability where we could ultimately go to an approver to have that mitigating control assigned. It was something more that the security administrators did individually, and so we wanted to add that approver capability where someone in the business is typically going to be the owner or they're going to be responsible for that mitigating control, and we wanna make sure that these users that are flagging for risks or maybe these roles that are flagging for risks have the ability to be reviewed and approved by that mitigating control owner. So having kind of a central location where we can track and document for audit the flow and assignment of mitigating controls is important for visibility purposes. Or in the past with SP twenty, we didn't necessarily have that. Maybe you received an email from the mitigating control owner to say, this user should have access. Go ahead and assign the mitigating control within the XAMS within CRAFT. But now we've set up the capability to have workflows within CRAFT for that mitigation assignment. Not just workflows, but we also have a central location where we can monitor the status of those workflows. So whether or not the, mitigation workflow is pending, whether or not it's been approved, is there a removal action, maybe the requester or the owner has suggested that that mitigation control shouldn't be assigned because that user shouldn't have that access. So this is an enhancement to SP twenty one to give organizations increased insight and increased flexibility as it relates to mitigating control assignments. And relating to SP twenty one, there's a lot of new features that come with SP twenty one. I want to make sure I reserve some time at the end of the presentation here for questions. So I think that's all that I wanted to kind of quickly go over here today as it relates to SP twenty one. So are there any questions, in the chat or, anything that we'd like to see in more detail relating to SP twenty one? Right now, we don't have any questions, but I would also like to point out and encourage all of you, all of our customers who run XMS to really regularly import the support packages our support team delivers as we have lots of improvements, bug fixes, and extensions. It also helps our support team to support you as well. So if you, for example, have an older exam S release in place and have a question that some features do not work as expected, it's mostly or it's very likely linked to the older releases you're running on your system. So it helps us also a lot if you just import the latest support packages, and we promise you you will benefit from the improvement. Alex, thank you very much. Even though this release was a bit smaller than the last ones in the past years, well, we made big steps concerning the license analysis. And also for the next year, we have lots of plans improving the license analysis and license optimization. So I hope we could provide insights to where we're going to, yeah, where our plants are developing to. So thank you very much, Alex. So yeah, if there are no other questions left or no other questions planned here in the chat, I'd suggest us to have a short break of maybe five minutes.
For customers in SAP S/4HANA RISE environments, calculating Full Usage Equivalent (FUE) metrics was previously time-consuming and error-prone.
SP21 solves this: FUE data is now automatically evaluated in the Role Designer and Role Profiler – no manual calculation required.
In the Role Designer, you benefit from:
Do you really know whether every user has been assigned the correct license?
With the new License Trace, you receive an automated evaluation in parallel with the simulation that answers exactly that. The collected data is stored seamlessly within the existing data model – no media disruption, no additional effort.
The most expensive point at which license errors occur is during role building – because that is where they are hardest to detect. SP21 brings license evaluation directly into this process:
In complex system landscapes, requesting sessions across multiple systems was previously cumbersome.
With SP21, sessions can be requested in central mode directly via a Fiori app – cross-system, clearly structured, and with significantly reduced effort. Workflow approvals for these sessions can of course still be handled centrally.
Common challenges in searching, testing, and translating Fiori applications are directly addressed in SP21 through mass adjustment of UIAD objects:
Especially in larger redesign projects spanning multiple systems, structured project management makes a real difference.
SP21 introduces targeted new capabilities:
Compliance requirements are increasing – and with them the need for structured, traceable processes.
SP21 strengthens the CRAF area with purpose-built enhancements:
XAMS SP21 is not a routine update – it is a clear commitment to transparency, automation, and cost control in SAP authorization and license management. Organizations looking to manage their SAP landscape efficiently and future-proof will find in SP21 the tools needed to do exactly that.
Key benefits at a glance:
“Current insights into SAP license optimization, XAMS SP21, and hybrid authorization management”
Our experts will show you live what SP21 can do in your SAP landscape.
Julia Sterr
Marketing Manager
Phone: +49 151 125 710 12
You are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from YouTube. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from hCaptcha to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from Turnstile to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Hubspot Embedded Content. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Hubspot Meetings. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information