Transitioning to SAP S/4HANA is a major milestone, yet licensing is often overlooked. With the shift from Named User to Full Use Equivalent (FUE) licensing — especially in RISE with SAP contracts — licensing is no longer tied to user identity but to the authorizations granted. FUE licensing, which prices access based on assigned authorizations (not actual usage), can be 50–150% more expensive than usage-based models. Without strategic preparation, costs can spiral out of control.
We present a real-world case study of a large chemical manufacturing company that conducted a structured FUE analysis before migrating to S/4HANA. The outcome: a double-digit reduction in projected FUE consumption, measurable savings, and a stronger position in licensing negotiations with SAP.
1. Initial Situation
The client is a large chemical manufacturing company operating across several European countries. Their SAP ERP system, based on ECC, had been in place for over a decade. Over that time, user roles had been created and modified organically — often through copying, expanding, or assigning authorizations "just in case." By the time the company started planning their migration to SAP S/4HANA, their environment included:
- Over 2,500 active SAP users
- Hundreds of roles — many overlapping or outdated
- Extensive authorizations with SoD risks in many business areas
- Numerous "power users" with broad access copied from admin or test environments
- A Named User license model with categories like Professional, Limited Professional, and Employee
The organization knew they would be forced to adopt the FUE model under RISE with SAP. What they didn't know was how many FUEs they actually needed — or how their current role design would translate into this new cost model.
2. First Attempt: Why the SLIM Report Failed
The customer's initial approach was to use the standard SAP simulation report from SAP Note 3113382 (SLIM_USER_CLF_HELP) — designed to estimate FUE needs based on current ECC authorizations. While it seemed like a reasonable starting point, it quickly revealed its limitations.
❌ A. Not designed for strategic decisions. The report assumes the current state of role assignments is correct and reflects actual business needs. In reality, years of overprovisioning mean this assumption is often invalid — leading to overestimated FUE counts.
❌ B. Complex and rigid. The tool relies on 700+ authorization objects and over 2,000 value-based conditions. Even one mistakenly included object (e.g. M_RECH_BUK with create rights) can upgrade a user from Core to Advanced — regardless of actual usage.
❌ C. No simulation capability. You cannot ask "what if I remove this object?" or "what if I split this role into display and edit variants?" — making it impossible to model cost improvements before implementation.
❌ D. No usage data integration. The report treats all authorizations equally regardless of whether they're ever used. Combining license-driving objects with actual usage data would transform it from a theoretical tool into a practical decision aid.
Even SAP acknowledges the limitation. SAP's own documentation for Note 3113382 explicitly recommends supplementing it with their STAR (Trusted Authorization Review) expert service — indicating the tool alone is insufficient for licensing strategy.
3. Revised Approach: GRC and Business-Led Optimization
Recognizing the limitations, the client pivoted to leverage their existing SAP GRC Access Control solution — specifically the Access Risk Analysis (ARA) and Business Role Management (BRM) modules. The adoption of GRC tooling brought measurable improvements through:
- License simulation — instantly testing how role or object changes would affect FUE classification
- Ruleset flexibility — quickly adapting classification logic as SAP criteria changed
- Usage integration — identifying unused transactions or roles over the past 6–12 months
- License visibility — directly linking required license types to roles, users, and access requests
The Real Game-Changer: Business Stakeholder Workshops
The most impactful shift came not from the tool itself, but from involving the right people. A series of joint workshops brought together SAP Security consultants (technical role design), Functional consultants (which transactions support which processes), and Business stakeholders — key users, department heads, process managers — who knew actual operational needs.
These workshops enabled informed decisions by answering: Does this role really need change access, or is display sufficient? Can the role be split into two personas to reduce the license tier? Is this transaction still relevant? Can a user group move to Self-Service if the process is streamlined?
4. Measurable Results
✅ Double-digit FUE reduction — Through simulation, cleanup, and role redesign, the company reduced projected FUE consumption by over 15%, without compromising operational needs or user experience.
Roles and transactions assigned to users but unused for 12+ months were flagged for removal. These included technical/test roles, inherited admin authorizations, copied roles with no valid business justification, and access no longer valid due to organizational changes.
High-cost roles were redesigned into distinct variants (e.g., "display-only" vs "editor"). Many users were reclassified from Advanced to Core or Self-Service, drastically reducing cost per user. A particularly valuable insight: in many cases, it was just one role that pushed a user into a higher FUE tier — and users rarely used any transactions from that role. Removing the unnecessary assignment delivered immediate FUE reduction with zero operational impact.
5. Key Takeaways
- Start early — licensing begins with role design. Decisions made before go-live have direct financial impact on FUE count for the life of the contract.
- Don't rely on raw reports alone — SAP Note 3113382 offers a starting point, but lacks simulation, clarity, and business context.
- Engage the business — the biggest lever for optimization wasn't the software; it was business engagement. Workshops brought real-world understanding that no tool alone can provide.
- Combine simulation + usage data — aligning FUE impact with actual usage enabled confident, data-driven cleanup.
- Make licensing part of access culture — embedding FUE awareness into daily provisioning creates continuous cost control, where every access request is a chance to validate cost vs. need.
FUE is not just a metric — it's a new operating model. Organizations that treat it like a contract checkbox will lock in unnecessary costs. Those that approach it as a design and governance decision will unlock long-term value.
