SAP license costs are one of the largest IT budget items in many organizations – and at the same time, one of the areas with with significant potential for optimization . While infrastructure, cloud, and hardware are regularly reviewed, historically grown role and authorization concepts often go unchanged for years.
According to the current SAP S/4HANA licensing metrics, license classification is based on the assigned authorizations and roles to a user, rather than on their actual usage of transactions or authorizations.
As SAP S/4HANA migrations and hybrid SAP landscapes become more common, a modern SAP authorization concept is becoming increasingly important. With the Xiting Authorizations Management Suite (XAMS), existing roles can be analyzed and evaluated directly against the current SAP S/4HANA license rule set from the very first step.
But this is exactly where the challenge begins:
What comes after the license analysis?
An analysis alone does not reduce license costs. Sustainable savings require targeted optimization, controlled testing, and a secure rollout of license-optimized roles.
A key principle of modern SAP license metrics is that the authorizations assigned to a user can have a significant impact on their license type.
As a result, even a small number of critical authorizations can cause a user to be classified as an SAP Professional User – even if those authorizations are never used in production.
A typical example:
An employee exclusively uses display transactions in the Purchasing module. However, due to a historically grown composite role, their role also contains individual critical change or administration authorizations.
The result:
The user may be classified as an SAP Professional User, even though the additional functions are never used.
Within SAP licensing, various SAP license types play a central role. They generally reflect the scope of a user's authorizations and the corresponding activities.
The most important SAP S/4HANA user license types are:
| ID | SAP User License Type | Usage |
|---|---|---|
| HA | S/4HANA Developer Access | Development, debugging, technical administration |
| HB | S/4HANA Professional Use | Extensive operational and functional activities |
| HC | S/4HANA Functional Use | Operational activities with limited change rights |
| HD | S/4HANA Productivity Use | Basic operational activities and self-services |
The most important user license types for SAP S/4HANA Cloud, private edition (RISE with SAP) are:
| ID | SAP User License Type | Usage |
|---|---|---|
| GA | SAP RISE S/4HANA Developer Access | Development, debugging, technical administration |
| GB | SAP RISE S/4HANA Advanced Use | Extensive operational and functional activities |
| GC | SAP RISE S/4HANA Core Use | Operational activities with limited change rights |
| GD | SAP RISE S/4HANA Self-Service User | Basic operational activities and self-services |
Operating hybrid SAP landscapes – combining SAP ECC, SAP S/4HANA, SAP BTP, and cloud and on-premise systems – makes a consolidated view of existing authorization concepts increasingly important.
Particularly worth noting: even individual license-relevant authorizations can shift a user into a higher license type. Additionally, license-relevant authorizations no longer arise in isolation within a single system, but through the combination of various roles, applications, and access rights across hybrid SAP landscapes. It is also important to consider that contractual terms determine whether systems and clients are evaluated separately or in a consolidated view.
In practice, high SAP license costs rarely stem from individual users. More often, they arise from structural problems in the SAP role concept.
Typical root causes include:
In large SAP landscapes, these factors can quickly add up to significant license costs. Composite roles are a common example. By bundling numerous single roles, they can unintentionally accumulate broad license-relevant authorizations. It is exactly this lack of transparency that often prevents potential opportunities for optimization in SAP license management from being identified.
A classic SAP license measurement using SAP USMM and SAP LAW provides organizations with an important baseline for evaluating current license types and user classifications. It creates transparency about which SAP Named Users exist in the system and how they are currently classified.
However, license measurement alone shows who holds which license – but does not reliably answer why a user was assigned to a particular license type.
With the Xiting Authorizations Management Suite (XAMS), existing roles are analyzed and license-relevant authorizations are identified. This makes it immediately visible which roles are contributing to higher license types. It also shows which authorization objects have a direct impact on license costs and where specific optimization potential exists in the authorization concept.
This transforms a simple license overview into a concrete technical basis for decision-making on SAP license optimization.
After completing the license analysis using XAMS, two fundamental approaches are available:
The existing role concept remains intact and is optimized selectively. Individual license-relevant authorizations are identified, removed, or adjusted where appropriate.
Suitable for: stable role structures with limited optimization needsWhen many roles are affected, or the existing concept has grown organically and become inconsistent, a complete redesign is required. Roles are rebuilt based on job functions – following the least-privilege and need-to-know principles, with a clear separation of display vs. change authorizations, master data vs. transactional data, and license-critical authorizations isolated into separate, SoD-compliant roles.
Role cleanup is often the fastest path to reducing SAP license costs. The goal is to optimize existing roles in a targeted way without immediately rebuilding the entire authorization concept.
Typical measures include:
The advantage of this approach is its speed: it requires minimal changes to existing system structures while delivering noticeable, short-term effects on license costs.
With XAMS, initial optimization results can be achieved quickly. The XAMS Role Designer allows the specific authorization objects responsible for higher SAP license types to be analyzed – both at the level of roles assigned to a user and at the level of individual roles. On this basis, authorizations can be precisely adjusted or removed.
The XAMS Role Profiler also enables a detailed comparison between user and role information and the authorizations that are actually assigned. For example, license types stored for users in SU01 can be compared directly with the authorizations effectively assigned to them.
It is also possible to compare the license classifications stored in roles directly with the authorizations they contain. This makes it visible whether a role leads to a higher license tier than originally intended, based on its authorization structure.
Additionally, the XAMS License Trace provides a targeted optimization capability. For users already identified as potentially over-licensed, XAMS License Trace combines authorization analysis with usage information to identify the license-relevant authorizations that contribute to the license classification. .
Together, these capabilities allow license-driving authorizations to be cleaned up – sustainably reducing SAP license costs without requiring a complete redesign of the role model.
If a role cleanup is not sufficient, a fundamental redesign of the role concept is often the next step. A poorly structured role concept not only increases the risk of unnecessary license costs, but also complicates governance, auditability, and system maintenance.
A modern role design is therefore built around a clear structure based on job functions.
With the XAMS Role Designer, new role models can be built based on the user’s usage history. The focus is on building lean single roles, a clear separation between business roles and IT roles, the definition of standardized role models, and the deliberate isolation of license-relevant authorizations.
This approach results in a structured, maintainable, and sustainable authorization concept. At the same time, controllability of license types is significantly improved, and unnecessary over-licensing is sustainably reduced.
When making major changes to roles, the question often arises of how new or optimized roles can be safely transitioned into the production environment. Especially in a full role redeisgn, a structured and risk-free transition is crucial to avoid disrupting business processes.
XAMS addresses this through two sequential phases: the Productive Test Simulation (PTS) and the Protected Go-Live (PGL).
In a role redesign, the Productive Test Simulation (PTS) enables the validation of new roles using real production data, before end users actively work with them. Roles are technically validated and the required authorization objects are identified and maintained.
An additional benefit is direct transparency into license impacts at the level of authorization objects.
The PTS reveals which authorization objects and field values map to a specific license type under SAP’s license rule set. The PTS does not show the final license classification of a user. Instead, it makes visible which authorization objects and field values contribute to a specific license assessment. This allows you to understand which role components are license-relevant and what influence they have on the potential license type assignment. On this basis, the required authorizations can be specifically adjusted.
Following successful validation in the PTS, a controlled rollout to the production environment takes place via the Protected Go-Live (PGL).
The Protected Go-Live serves as a safeguard mechanism during live operations. If users encounter restrictions with the new roles, they can reactivate their previous authorizations at any time through a self-service mechanism. This ensures that business units remain fully operational throughout the transition.
While a role optimization often requires only the Protected Go-Live as a safeguard, in a comprehensive role redesign, the Productive Test Simulation acts as the upstream validation stage. Together they create a seamless, low-risk transition from the existing role model to an optimized role structure.
After a successful role cleanup or role redesign, the goal is to keep the newly built role structures stable over the long term, and to make SAP license costs transparent and controllable in ongoing operations.
The PFCG Integration in XAMS automatically evaluates role changes directly within the standard SAP process, with respect to both licensing and compliance.
Whenever a role is modified in PFCG and the profile is generated, XAMS automatically analyzes the impact. Changes to license types and any potential SoD conflicts are immediately displayed.
This ensures that the optimized role model remains stable even in day-to-day operations.
Modern SAP landscapes increasingly consist of hybrid systems such as SAP ECC, SAP S/4HANA, SAP BTP, and additional SAP cloud solutions or complementary SaaS components.
In such landscapes in particular, SAP Digital Access is growing in importance. Business processes today often run across system boundaries. License-relevant effects therefore arise not only from direct user access, but also from interfaces, external applications, and integrated platforms.
Against this backdrop, a consolidated view of roles, authorizations, and license structures across the central systems is critical – provided this is covered by the applicable contractual terms. This allows potential license risks to be identified early and managed proactively.
With the Xiting Security Platform (XSP), SAP S/4HANA systems and clients can be analyzed centrally and – where a consolidated view has been agreed contractually – evaluated together. This creates cross-system transparency across users, roles, authorizations, and license types within the connected S/4HANA landscape.
Especially in hybrid scenarios with multiple systems, this centralized approach provides the foundation for assessing license and authorization structures consistently and detecting cross-system discrepancies early.
This transforms a fragmented system view into a consolidated governance perspective – critical for both license optimization and compliance and audit requirements.
The SAP license analysis is only the starting point into a broader optimization topic.
What matters most are the steps that follow:
With XAMS and XSP, a seamless end-to-end approach emerges for sustainably reducing SAP license costs and optimizing the SAP authorization concept over the long term.
Historically grown role models, over-authorized users, and incorrectly classified SAP Named Users are typically the main causes of unnecessarily high license costs.
Modern SAP license metrics primarily evaluate the authorizations that are present, not solely the actual usage of functions.
SAP USMM measures users within individual systems, while SAP LAW consolidates the results across systems.
New technologies such as SAP Fiori and the underlying OData services, as well as hybrid system landscapes, significantly change the requirements for roles and license classifications.
XAMS analyzes users, roles, and authorizations based on current SAP license rule sets and makes license-relevant changes immediately visible. In addition, the PFCG Integration enables continuous monitoring of license types after each role adjustment.
SAP Digital Access is an SAP licensing model for capturing indirect system access. Unlike classic Named User licensing, the focus is not on the individual user but on the business documents generated in SAP by external systems.
Currently, the Xiting Security Platform’s license analysis focuses on SAP S/4HANA landscapes. XSP provides a central, consolidated view of users, roles, authorizations, and license types across the connected S/4HANA systems. Other SAP solutions are not currently part of the analysis, though an expansion of supported systems is planned for the future.
You are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from YouTube. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from hCaptcha to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from Turnstile to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Hubspot Embedded Content. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Hubspot Meetings. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information