Reducing SAP License Costs

From Role Cleanup to Role Redesign

SAP license costs are one of the largest IT budget items in many organizations – and at the same time, one of the areas with  with significant potential for optimization . While infrastructure, cloud, and hardware are regularly reviewed, historically grown role and authorization concepts often go unchanged for years. 

Why Your Role Concept Determines Your SAP License Costs

According to the current SAP S/4HANA licensing metrics, license classification is based on the assigned authorizations and roles to a user, rather than on their actual usage of transactions or authorizations.  

As SAP S/4HANA migrations and hybrid SAP landscapes become more common, a modern SAP authorization concept is  becoming increasingly important. With the Xiting Authorizations Management Suite (XAMS), existing roles can be analyzed and evaluated directly against the current SAP S/4HANA license rule set from the very first step. 

But this is exactly where the challenge begins: 

What comes after the license analysis? 

An analysis alone does not reduce license costs. Sustainable savings require targeted optimization, controlled testing, and a secure rollout of license-optimized roles.  

Why Role Design and SAP License Costs Are Directly Linked

A key principle of modern SAP license metrics is that the authorizations assigned to a user can have a significant impact on their license type.

As a result, even  a small number of critical authorizations can cause a
user to be classified as an SAP Professional User – even if those authorizations are never used in production.

A typical example: 

An employee exclusively uses display transactions in the Purchasing module. However, due to a historically grown composite role, their role also contains individual critical change or administration authorizations. 

The result: 

The user may be  classified as an SAP Professional User, even though the  additional functions are never used. 

SAP License Types and User Types at a Glance

Within SAP licensing, various SAP license types play a central role. They generally reflect the scope of a user's authorizations and the corresponding activities.

The most important SAP S/4HANA user license types are:

ID SAP User License Type Usage
HA S/4HANA Developer Access Development, debugging, technical administration
HB S/4HANA Professional Use Extensive operational and functional activities
HC S/4HANA Functional Use Operational activities with limited change rights
HD S/4HANA Productivity Use Basic operational activities and self-services

The most important user license types for SAP S/4HANA Cloud, private edition (RISE with SAP) are:

ID SAP User License Type Usage
GA SAP RISE S/4HANA Developer Access Development, debugging, technical administration
GB SAP RISE S/4HANA Advanced Use Extensive operational and functional activities
GC SAP RISE S/4HANA Core Use Operational activities with limited change rights
GD SAP RISE S/4HANA Self-Service User Basic operational activities and self-services

Operating hybrid SAP landscapes – combining SAP ECC, SAP S/4HANA, SAP BTP, and cloud and on-premise systems – makes a consolidated view of existing authorization concepts increasingly important.

Particularly worth noting: even individual license-relevant authorizations can shift a user into a higher license type. Additionally, license-relevant authorizations no longer arise in isolation within a single system, but through the combination of various roles, applications, and access rights across hybrid SAP landscapes. It is also important to consider that contractual terms determine whether systems and clients are evaluated separately or in a consolidated view.

Typical License Drivers in Existing SAP Authorization Concepts

In practice, high SAP license costs rarely stem from individual users. More often, they arise from structural problems in the SAP role concept. 

Typical root causes include: 

  • Complex, overly broad, and unmanageable composite roles 
  • Lack of standardization in the role concept 
  • Historically grown role structures 

In large SAP landscapes, these factors can quickly add up to significant license costs. Composite roles are a common example. By bundling numerous single roles, they can unintentionally accumulate broad license-relevant authorizations. It is exactly this lack of transparency that often prevents potential opportunities for optimization in SAP license management from being identified. 

SAP License Measurement as the Starting Point for Optimization

A classic SAP license measurement using SAP USMM and SAP LAW  provides organizations with an important baseline for evaluating  current license types and user classifications. It creates transparency about which SAP Named Users exist in the system and how they are currently classified. 

However, license measurement alone shows who holds which license – but does not reliably answer why a user was assigned to a particular license type. 

With the Xiting Authorizations Management Suite (XAMS), existing roles are analyzed and license-relevant authorizations are identified. This makes it immediately visible which roles are  contributing to higher license types. It also shows which authorization objects have a direct impact on license costs and where specific optimization potential exists in the authorization concept. 

This transforms a simple license overview into a concrete technical basis for decision-making on SAP license optimization. 

Two Paths after the SAP License Analysis

After completing the license analysis using XAMS, two fundamental approaches are available:

Most Sustainable Short-Term Solution

Role Cleanup

The existing role concept remains intact and is optimized selectively. Individual license-relevant authorizations are identified, removed, or adjusted where appropriate.

Suitable for: stable role structures with limited optimization needs
Suitable for: Long-Term Governance and License Optimization

Role Redesign

When many roles are affected, or the existing concept has grown organically and become inconsistent, a complete redesign is required. Roles are rebuilt based on job functions – following the least-privilege and need-to-know principles, with a clear separation of display vs. change authorizations, master data vs. transactional data, and license-critical authorizations isolated into separate, SoD-compliant roles.

Reducing SAP License Costs through Targeted Role Cleanup

Role cleanup is often the fastest path to reducing SAP license costs. The goal is to optimize existing roles in a targeted way without immediately rebuilding the entire authorization concept. 

Typical measures include: 

  • Removing license-relevant authorizations 
  • Reducing unnecessary transactions 
  • Cleaning up outdated role components 
  •  Adjusting over-classified users 

The advantage of this approach is its speed: it requires minimal changes to existing system structures while delivering noticeable, short-term effects on license costs. 

With XAMS, initial optimization results can be achieved quickly. The XAMS Role Designer allows the specific authorization objects responsible for higher SAP license types to be analyzed – both at the level of roles assigned to a user and at the level of individual roles. On this basis, authorizations can be precisely adjusted or removed. 

Table titled "Licenses for selected users (4)" showing SAP usernames X_CO, X_COCO, X_CONSTANTIN, and X_CORA with role ratio, license based on roles, license based on usage (S/4HANA EM Professional, Productivity, and Functional Use), license ratio, and license object counts.
Figure 1 –SAP license overview for selected users

The XAMS Role Profiler also enables a detailed comparison between user and role information and the authorizations that are actually assigned. For example, license types stored for users in SU01 can be compared directly with the authorizations effectively assigned to them. 

Xiting Role Profiler "User classification overview" report displaying four SAP users (X_CO, X_COCO, X_CONSTANTIN, X_CORA) with SU01 license, match status, authorization license, role license, and profile license columns, plus transfer and trace icons.
Figure 2 – Xiting Role Profiler – User Classification Overview Screen

It is also possible to compare the license classifications stored in roles directly with the authorizations they contain. This makes it visible whether a role leads to a higher license tier than originally intended, based on its authorization structure. 

Xiting Role Profiler "Role classification overview" report listing five SAP roles (ZWCHXIT_SU24_00, _01, _02, _05, _07) with user count, PFCG license, match status, authorization license, object counts, and transfer icons.
Figure 3 – Xiting Role Profiler Role Classification Overview

Additionally, the XAMS License Trace provides a targeted optimization capability.  For users already identified as potentially over-licensed, XAMS License Trace combines authorization analysis with usage information to identify the license-relevant authorizations that contribute to the license classification. . 

Together, these capabilities allow license-driving authorizations to be cleaned up  – sustainably reducing SAP license costs without requiring a complete redesign of the role model. 

Role Redesign for Long-Term SAP License Optimization

If a  role cleanup is not sufficient, a fundamental redesign of the role concept is often the next step. A  poorly structured role concept not only increases the risk of unnecessary license costs, but also complicates governance, auditability, and system maintenance. 

A modern role design is therefore built around a clear structure based on job functions. 

With the XAMS Role Designer, new role models can be built  based on  the user’s usage history. The focus is on building lean single roles, a clear separation between business roles and IT roles, the definition of standardized role models, and the deliberate isolation of license-relevant authorizations. 

This approach  results in a structured, maintainable, and  sustainable authorization concept. At the same time, controllability of license types is significantly improved, and unnecessary over-licensing is sustainably reduced. 

 

Implementing and Securing SAP License Optimization with XAMS

When making major changes to roles, the question often arises of how new or optimized roles can be safely transitioned into the production environment. Especially in a full role redeisgn, a structured and risk-free transition is crucial to avoid disrupting business processes. 

XAMS addresses this through two sequential phases: the Productive Test Simulation (PTS) and the Protected Go-Live (PGL). 

 

Productive Test Simulation and Protected Go-Live

In a  role redesign, the Productive Test Simulation (PTS) enables the validation of new roles using real production data, before end users actively work with them. Roles are technically validated and the required authorization objects are identified and maintained.  

An additional benefit is direct transparency into license impacts at the level of authorization objects. 

The PTS reveals which authorization objects and field values map to a specific license type under SAP’s license rule set. The PTS does not show the final license classification of a user. Instead, it makes visible which authorization objects and field values contribute to a specific license assessment. This allows you to understand which role components are license-relevant and what influence they have on the potential license type assignment. On this basis, the required authorizations can be specifically adjusted.

Xiting Role Builder Trace Coverage Analyzer table for user X_FI, transaction FB03, listing authorization objects (F_BKPF_BUK, F_BKPF_FKB, F_BKPF_KOA, K_TP_VALU) with fields, values, hide and organization-level controls, reference user X_FI_PTS, and license class /XITING/LIC_HD_PROD.
Figure 4 – Xiting Role Builder Trace Coverage Analyzer

Following successful validation in the PTS,  a controlled rollout to the production environment takes place via the Protected Go-Live (PGL). 

The Protected Go-Live serves as a safeguard mechanism during live operations. If users encounter restrictions with the new roles, they can reactivate their previous authorizations at any time through a self-service mechanism. This ensures that business units remain fully operational throughout the transition. 

While a  role optimization often requires only the Protected Go-Live as a safeguard, in a comprehensive role redesign, the Productive Test Simulation acts as the upstream validation stage. Together they create a seamless, low-risk transition from the existing role model to an optimized role structure.

PFCG Integration for Continuous License and Risk Analysis after Optimization and Redesign

After a successful role cleanup or  role redesign, the goal is to keep the newly built role structures stable over the long term, and to make SAP license costs transparent and controllable in ongoing operations. 

The PFCG Integration in XAMS automatically evaluates role changes directly within the standard SAP process, with respect to both licensing and compliance. 

Whenever a role is modified in PFCG and the profile is generated, XAMS automatically analyzes the impact. Changes to license types and any potential SoD conflicts are immediately displayed. 

Figure 5 – XAMS CRAF Integration – License and Critical Authorization Checks

This ensures that the optimized role model remains stable even in day-to-day operations. 

SAP License Management in Hybrid System Landscapes

Modern SAP landscapes increasingly consist of hybrid systems such as SAP ECC, SAP S/4HANA, SAP BTP, and additional SAP cloud solutions or complementary SaaS components. 

In such landscapes in particular, SAP Digital Access is growing in importance. Business processes today often run across system boundaries. License-relevant effects therefore arise not only from direct user access, but also from interfaces, external applications, and integrated platforms. 

Against this backdrop, a consolidated view of roles, authorizations, and license structures across the central systems is critical – provided this is covered by the applicable contractual terms. This allows potential license risks to be identified early and managed proactively.

Centrally Analyzing and Optimizing Hybrid SAP Landscapes

With the Xiting Security Platform (XSP), SAP S/4HANA systems and clients can be analyzed centrally and – where a consolidated view has been agreed contractually – evaluated together. This creates cross-system transparency across users, roles, authorizations, and license types within the connected S/4HANA landscape. 

Especially in hybrid scenarios with multiple systems, this centralized approach provides the foundation for assessing license and authorization structures consistently and detecting cross-system discrepancies early. 

This transforms a fragmented system view into a consolidated governance perspective – critical for both license optimization and compliance and audit requirements. 

Conclusion

The SAP license analysis is only the starting point into a broader optimization topic.

What matters most are the steps that follow:

  • Targeted role cleanup
  • Structured role redesign
  • Continuous monitoring
  • Centralized analysis of hybrid landscapes

With XAMS and XSP, a seamless end-to-end approach emerges for sustainably reducing SAP license costs and optimizing the SAP authorization concept over the long term.

 

FAQ

What causes high SAP license costs?

Historically grown role models, over-authorized users, and incorrectly classified SAP Named Users are typically the main causes of unnecessarily high license costs.

Modern SAP license metrics primarily evaluate the authorizations that are present, not solely the actual usage of functions.

SAP USMM measures users within individual systems, while SAP LAW consolidates the results across systems. 

New technologies such as SAP Fiori and the underlying OData services, as well as hybrid system landscapes, significantly change the requirements for roles and license classifications. 

XAMS analyzes users, roles, and authorizations based on current SAP license rule sets and makes license-relevant changes immediately visible. In addition, the PFCG Integration enables continuous monitoring of license types after each role adjustment. 

SAP Digital Access is an SAP licensing model for capturing indirect system access. Unlike classic Named User licensing, the focus is not on the individual user but on the business documents generated in SAP by external systems. 

Currently, the Xiting Security Platform’s license analysis focuses on SAP S/4HANA landscapes. XSP provides a central, consolidated view of users, roles, authorizations, and license types across the connected S/4HANA systems. Other SAP solutions are not currently part of the analysis, though an expansion of supported systems is planned for the future. 

Get in touch now!

Melden Sie sich jetzt an!

Nehmen Sie jetzt Kontakt auf!