Transitioning to SAP S/4HANA is a major milestone, yet licensing is often overlooked. With the shift from Named User to Full Use Equivalent (FUE) licensing — especially in RISE with SAP contracts — licensing is no longer tied to user identity but to the authorizations granted. FUE licensing, which prices access based on assigned authorizations (not actual usage), can be 50–150% more expensive than usage-based models. Without strategic preparation, costs can spiral out of control.

We present a real-world case study of a large chemical manufacturing company that conducted a structured FUE analysis before migrating to S/4HANA. The outcome: a double-digit reduction in projected FUE consumption, measurable savings, and a stronger position in licensing negotiations with SAP.

1. Initial Situation

The client is a large chemical manufacturing company operating across several European countries. Their SAP ERP system, based on ECC, had been in place for over a decade. Over that time, user roles had been created and modified organically — often through copying, expanding, or assigning authorizations "just in case." By the time the company started planning their migration to SAP S/4HANA, their environment included:

The organization knew they would be forced to adopt the FUE model under RISE with SAP. What they didn't know was how many FUEs they actually needed — or how their current role design would translate into this new cost model.

2. First Attempt: Why the SLIM Report Failed

The customer's initial approach was to use the standard SAP simulation report from SAP Note 3113382 (SLIM_USER_CLF_HELP) — designed to estimate FUE needs based on current ECC authorizations. While it seemed like a reasonable starting point, it quickly revealed its limitations.

❌ A. Not designed for strategic decisions. The report assumes the current state of role assignments is correct and reflects actual business needs. In reality, years of overprovisioning mean this assumption is often invalid — leading to overestimated FUE counts.

❌ B. Complex and rigid. The tool relies on 700+ authorization objects and over 2,000 value-based conditions. Even one mistakenly included object (e.g. M_RECH_BUK with create rights) can upgrade a user from Core to Advanced — regardless of actual usage.

❌ C. No simulation capability. You cannot ask "what if I remove this object?" or "what if I split this role into display and edit variants?" — making it impossible to model cost improvements before implementation.

❌ D. No usage data integration. The report treats all authorizations equally regardless of whether they're ever used. Combining license-driving objects with actual usage data would transform it from a theoretical tool into a practical decision aid.

Even SAP acknowledges the limitation. SAP's own documentation for Note 3113382 explicitly recommends supplementing it with their STAR (Trusted Authorization Review) expert service — indicating the tool alone is insufficient for licensing strategy.

3. Revised Approach: GRC and Business-Led Optimization

Recognizing the limitations, the client pivoted to leverage their existing SAP GRC Access Control solution — specifically the Access Risk Analysis (ARA) and Business Role Management (BRM) modules. The adoption of GRC tooling brought measurable improvements through:

The Real Game-Changer: Business Stakeholder Workshops

The most impactful shift came not from the tool itself, but from involving the right people. A series of joint workshops brought together SAP Security consultants (technical role design), Functional consultants (which transactions support which processes), and Business stakeholders — key users, department heads, process managers — who knew actual operational needs.

These workshops enabled informed decisions by answering: Does this role really need change access, or is display sufficient? Can the role be split into two personas to reduce the license tier? Is this transaction still relevant? Can a user group move to Self-Service if the process is streamlined?

4. Measurable Results

>15%
Reduction in projected FUE consumption
12+
Months of unused role assignments flagged for removal
Many
Advanced users reclassified to Core or Self-Service
Data
Stronger SAP contract negotiation position

✅ Double-digit FUE reduction — Through simulation, cleanup, and role redesign, the company reduced projected FUE consumption by over 15%, without compromising operational needs or user experience.

Roles and transactions assigned to users but unused for 12+ months were flagged for removal. These included technical/test roles, inherited admin authorizations, copied roles with no valid business justification, and access no longer valid due to organizational changes.

High-cost roles were redesigned into distinct variants (e.g., "display-only" vs "editor"). Many users were reclassified from Advanced to Core or Self-Service, drastically reducing cost per user. A particularly valuable insight: in many cases, it was just one role that pushed a user into a higher FUE tier — and users rarely used any transactions from that role. Removing the unnecessary assignment delivered immediate FUE reduction with zero operational impact.

5. Key Takeaways

FUE is not just a metric — it's a new operating model. Organizations that treat it like a contract checkbox will lock in unnecessary costs. Those that approach it as a design and governance decision will unlock long-term value.