Indirect access is one of the oldest arguments in enterprise licensing, and SAP
is where it bites hardest. The definition is simple enough to state: indirect
access is a non-SAP application reading from or writing to SAP data, typically
through a single technical user account. The difficulty has never been the
definition. It has been working out what it costs.
How does indirect access affect SAP licensing?
Philip Adams, then chairman of the UK & Ireland SAP User Group, raised this
directly in his keynote at the 2016 user group conference, and framed it around
the Internet of Things.
I think we really do need clarity in this area. We need to understand and
clearly define, what does indirect usage mean in our organisations?
His concern was concrete rather than theoretical. Teams inside organisations were
designing new applications and new business processes that touched SAP, without
anyone assessing what that did to the licence position — and the arrival of
cheap connected devices was about to make that far more common. The user group
asked the obvious follow-up: if a sensor talks to the back-end system, who is
consuming the data, and where is it being consumed? The question did not get a
satisfactory answer at the time. Source: diginomica, November
2016
What is the Internet of Things?
The Internet of Things means devices connected over the internet, able to
communicate with us, with applications and with each other. The household
example is the smart thermostat that can be turned up or down remotely, and that
can switch the heating off when it notices your phone has left the house.
In business the interesting cases are less domestic. Sensors on production
lines, telemetry from vehicles, connected medical equipment, building systems,
logistics scanners. All of them generate data, and the value of that data comes
from feeding it into the systems that already run the business. For a great many
organisations, that system is SAP.
How does the IoT change the indirect access problem?
Indirect access rules were notoriously vague, and vague rules scale badly. A
handful of integrations is a manageable ambiguity. Thousands of low-cost devices
generating transactions is not.
There is a security dimension too. IoT hardware is frequently difficult to lock
down, often cannot be brought under conventional device management, and
sometimes cannot have its credentials changed at all. A device you cannot govern
is a device whose access to your systems you cannot govern either — much the
same exposure an organisation carries when it allows personal devices onto the
network without a policy covering them.
Editor’s note, July 2026. This is the section the years have overtaken, and
the news is good. SAP answered the question. Following the 2017 SAP v Diageo
judgment in the English High Court, which exposed how arbitrary it was to
licence third-party users as named SAP users, SAP announced a new
Indirect/Digital Access policy in April 2018. Indirect access to the digital
core is now licensed on documents rather than users: SAP defines a set of core
document types, and licensing is driven by how many of them third-party access
creates. The ambiguity Adams asked SAP to remove was largely removed. What
replaced it is a counting problem — you now need to know which systems touch
SAP and what they generate — which is a better problem to have, but still a
problem you have to be able to measure.
Measuring and controlling indirect access
Whichever model applies to your agreement, the two underlying requirements have
not changed since 2016:
- You need to be able to detect every device on your network, IoT or
conventional.
- You need to know which of those devices are reaching your licence-controlled
datacentre software.
The first is an IT asset management question. The second is a software asset
management question. They are usually owned by different people, which is a
large part of why indirect access surprises organisations.
What CerteroX does here
Finding the devices. CerteroX ITAM sweeps a class-C subnet in under five
seconds using NetBIOS, SNMP and ICMP, and interrogates devices over SNMP rather
than merely noting that something answered. That is where the old line about
knowing how much ink is left in a printer cartridge comes from — consumables and
page counts are genuinely part of what is read back, alongside switch port
assignments and routing tables. Ten discovery methods land in one schema, so
agentless and network-discovered devices sit in the same record as agent-managed
ones.
Measuring the usage. AppsMonitor performs file-based usage metering with
first-used and last-used tracking, and a % Used utilisation figure over a rolling
90-day window. Terminal Server and RDS remote usage is tracked per device. That
is the evidence layer for arguments about who is actually consuming what.
The SAP position itself. CerteroX SAM includes a dedicated SAP licence
engine, not a generic install count. A non-invasive ABAP connector — it does not
require changes to production — reads named users de-duplicated across systems,
along with roles, role groups, engines and authorisation definitions.
Priority-ordered Analysis Rules then propose the licence type each user should
hold, so you can see the current position, the suggested position and the
optimal position side by side. For most organisations the named user
optimisation is where the recoverable money is, and it is also the baseline you
need before any conversation about digital access is worth having.
A caveat worth stating plainly, because this post is about not being surprised by
licensing: the SAP engine described above measures named users, roles and engine
usage. Document-level Digital Access counting is a separate exercise, and if
your agreement has moved to that model you should treat the two as complementary
rather than assume one covers the other.
The 2016 argument was that indirect access needed defining. It was defined. The
work that remains is knowing what is connected to your systems and what it does
when it gets there — and that has only become more worth doing.
To see an SAP licence position with named-user types and indirect access accounted for, book a demo.