Skip to content

SAP Licensing, Indirect Access and the Internet of Things

In 2016 the UK & Ireland SAP User Group asked SAP to define what indirect usage actually means once machines start talking to the ERP. SAP answered in 2018, and the answer changed the maths.

Indirect access is one of the oldest arguments in enterprise licensing, and SAP is where it bites hardest. The definition is simple enough to state: indirect access is a non-SAP application reading from or writing to SAP data, typically through a single technical user account. The difficulty has never been the definition. It has been working out what it costs.

How does indirect access affect SAP licensing?

Philip Adams, then chairman of the UK & Ireland SAP User Group, raised this directly in his keynote at the 2016 user group conference, and framed it around the Internet of Things.

I think we really do need clarity in this area. We need to understand and clearly define, what does indirect usage mean in our organisations?

His concern was concrete rather than theoretical. Teams inside organisations were designing new applications and new business processes that touched SAP, without anyone assessing what that did to the licence position — and the arrival of cheap connected devices was about to make that far more common. The user group asked the obvious follow-up: if a sensor talks to the back-end system, who is consuming the data, and where is it being consumed? The question did not get a satisfactory answer at the time. Source: diginomica, November 2016

What is the Internet of Things?

The Internet of Things means devices connected over the internet, able to communicate with us, with applications and with each other. The household example is the smart thermostat that can be turned up or down remotely, and that can switch the heating off when it notices your phone has left the house.

In business the interesting cases are less domestic. Sensors on production lines, telemetry from vehicles, connected medical equipment, building systems, logistics scanners. All of them generate data, and the value of that data comes from feeding it into the systems that already run the business. For a great many organisations, that system is SAP.

How does the IoT change the indirect access problem?

Indirect access rules were notoriously vague, and vague rules scale badly. A handful of integrations is a manageable ambiguity. Thousands of low-cost devices generating transactions is not.

There is a security dimension too. IoT hardware is frequently difficult to lock down, often cannot be brought under conventional device management, and sometimes cannot have its credentials changed at all. A device you cannot govern is a device whose access to your systems you cannot govern either — much the same exposure an organisation carries when it allows personal devices onto the network without a policy covering them.

Editor’s note, July 2026. This is the section the years have overtaken, and the news is good. SAP answered the question. Following the 2017 SAP v Diageo judgment in the English High Court, which exposed how arbitrary it was to licence third-party users as named SAP users, SAP announced a new Indirect/Digital Access policy in April 2018. Indirect access to the digital core is now licensed on documents rather than users: SAP defines a set of core document types, and licensing is driven by how many of them third-party access creates. The ambiguity Adams asked SAP to remove was largely removed. What replaced it is a counting problem — you now need to know which systems touch SAP and what they generate — which is a better problem to have, but still a problem you have to be able to measure.

Measuring and controlling indirect access

Whichever model applies to your agreement, the two underlying requirements have not changed since 2016:

  • You need to be able to detect every device on your network, IoT or conventional.
  • You need to know which of those devices are reaching your licence-controlled datacentre software.

The first is an IT asset management question. The second is a software asset management question. They are usually owned by different people, which is a large part of why indirect access surprises organisations.

What CerteroX does here

Finding the devices. CerteroX ITAM sweeps a class-C subnet in under five seconds using NetBIOS, SNMP and ICMP, and interrogates devices over SNMP rather than merely noting that something answered. That is where the old line about knowing how much ink is left in a printer cartridge comes from — consumables and page counts are genuinely part of what is read back, alongside switch port assignments and routing tables. Ten discovery methods land in one schema, so agentless and network-discovered devices sit in the same record as agent-managed ones.

Measuring the usage. AppsMonitor performs file-based usage metering with first-used and last-used tracking, and a % Used utilisation figure over a rolling 90-day window. Terminal Server and RDS remote usage is tracked per device. That is the evidence layer for arguments about who is actually consuming what.

The SAP position itself. CerteroX SAM includes a dedicated SAP licence engine, not a generic install count. A non-invasive ABAP connector — it does not require changes to production — reads named users de-duplicated across systems, along with roles, role groups, engines and authorisation definitions. Priority-ordered Analysis Rules then propose the licence type each user should hold, so you can see the current position, the suggested position and the optimal position side by side. For most organisations the named user optimisation is where the recoverable money is, and it is also the baseline you need before any conversation about digital access is worth having.

A caveat worth stating plainly, because this post is about not being surprised by licensing: the SAP engine described above measures named users, roles and engine usage. Document-level Digital Access counting is a separate exercise, and if your agreement has moved to that model you should treat the two as complementary rather than assume one covers the other.

The 2016 argument was that indirect access needed defining. It was defined. The work that remains is knowing what is connected to your systems and what it does when it gets there — and that has only become more worth doing.

To see an SAP licence position with named-user types and indirect access accounted for, book a demo.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.