Skip to content

Understanding SAP Licensing

SAP licenses on usage, then declines to define usage precisely. Named user types, package metrics measured on business volume, and the two things that have changed most since this was written — document-based Digital Access and the move to S/4HANA.

SAP licensing is widely accepted to be one of the most complex models any major publisher operates. The reason is structural rather than accidental. Unlike most vendors, SAP licenses on usage — and then does not always define usage explicitly or unambiguously. The gap between those two facts is where SAP customers lose money, in both directions.

The named user

The primary metric for SAP applications is the Named User. It is assigned to a person, not to a device or a session, and it is not shared. There are three principal types:

  • Professional user. Able to perform operational tasks such as system administration or system management roles that fall within the agreed licence metrics. This user also holds the rights specified for the SAP Application Limited Professional User.
  • Limited professional user. Performs limited operational roles as defined by the software licence.
  • Employee user. Performs tasks purely for their own use, not on behalf of anyone else, as set out by the software licence.

Two things follow from this that catch people out.

The first is that the type is determined by what a user is entitled to do, not what they actually did. A user with wide authorisations who logs in twice a year is still classified on their authorisations. This is why over-classification is so common: roles get granted generously during an implementation and are never narrowed afterwards.

The second is that a person with accounts on several SAP systems is one named user, not several — but only if the accounts are recognised as belonging to the same person. Where they are not de-duplicated, the same human being is counted and licensed repeatedly.

Packages

Beyond named users, SAP sells packages: additional software components bought separately, such as the SAP Payroll Package.

Packages use different metrics from the Named User, and those metrics are based on data created in the SAP system rather than on people. Many different types of measurement exist, developed by SAP in collaboration with customers so that the metric reflects a real business quantity: the number of orders processed, the number of contracts tracked, gross written premiums, and so on.

The licensed level of such a metric reflects the required capacity of the package. That is designed to be flexible — as the business grows and requirements change, licences can be adjusted. Be aware, though, that reductions are usually difficult to secure unless the right to reduce was negotiated into the agreement in the first place. Growth is easy to buy. Shrinkage is a contract clause you either have or do not.

Because package consumption is driven by business volume rather than by IT activity, it moves without anybody in IT touching anything. A good quarter in sales can push you past a licensed capacity level. Nobody involved will have done anything wrong, and nobody will necessarily notice.

What has changed since this was written

Two developments since 2016 have altered the shape of the problem enough that any current reading of SAP licensing has to account for them.

Digital Access. For years, indirect use of SAP — third-party systems reaching SAP through a service account — could only be licensed by counting the people behind the connection as named users. That made indirect access one of the most contested areas in enterprise licensing. In 2018 SAP introduced Digital Access, which licenses indirect use by the documents that indirect use creates in the system rather than by user. This changes the shape of the exposure; it does not remove it. You still have to know which integrations generate documents, of which types, at what volume, before you can tell whether the document-based model or named users is the better position for you. Both answers depend on measurement you have to produce yourself.

S/4HANA and the conversion question. Movement from ECC to S/4HANA, and to the bundled commercial models built around it, means many organisations are not simply renewing a licence position but converting one — with entitlement restated in Full Use Equivalent terms rather than in the named user categories they have tracked for a decade. A conversion is negotiated against your measured position. If the measured position is over-classified, you carry the over-classification into the new agreement and pay for it for years.

That is the practical reason to get user classification right before a conversion conversation, not during one.

Measurement is the whole game

SAP provides its own measurement — system measurement runs and the License Administration Workbench consolidating them — and you should run it. But it answers SAP’s question, which is what you appear to be consuming under the classifications you have already assigned. It does not answer yours, which is what you should have assigned.

The original version of this post advised setting up alerts against package metrics so that an organisation can see when it is approaching full consumption, because without them you can become non-compliant without ever knowing. That advice was right, and it is worth restating that consumption drift is silent by default. What has changed is that it no longer has to be a manual discipline somebody remembers to build.

What CerteroX SAM does with SAP

SAP is one of six publishers with a dedicated licence engine in CerteroX SAM, alongside Microsoft, Oracle, IBM, Adobe and Salesforce. The SAP-specific mechanics are these:

A non-invasive ABAP connector. It reads named users de-duplicated across systems, together with roles, role groups, engines and authorisation definitions. Nothing is installed into production to make that happen, which matters because the most common reason SAP measurement does not get done properly is that nobody will approve a change to the production system.

Priority-ordered Analysis Rules. Rather than reporting what each user is currently classified as, the rules propose the licence type each user should hold, based on their authorisations and behaviour. You get the current position, a suggested position and an optimal position side by side. That comparison is the deliverable: it is what turns “we hold 4,000 professional licences” into “we need this many, and here is the evidence for each reclassification.”

A continuously computed effective licence position. Purchased, used, available, required, variance and exposure, calculated continuously rather than reconciled the week a measurement is due. Overspend and additional-licence requirements are both surfaced, because the point is to find the over-licensed categories as well as the under-licensed ones.

Threshold alerts and trend charts over that position, so package consumption approaching a licensed capacity level raises a flag on the way up rather than in an annual declaration.

Entitlement held with the contract. Licences, transactions, agreements, maintenance, suppliers and publishers in one record, with subscription flags and expiry tracking. When a conversion negotiation starts, the entitlement history is already assembled.

The point

SAP licensing is complex, but the complexity is not evenly distributed. Almost all of it concentrates in two questions: which type each named user genuinely needs, and what business volume your packages are actually consuming. Answer those two continuously and most of the rest is administration.

Answer them once a year, under time pressure, from a system measurement run that reflects classifications nobody has reviewed since go-live, and you are negotiating against a number that was never yours.

Book a demo, or read more about CerteroX SAM.

Related reading

Other posts covering the same ground.

  • Oracle ULA – What are the dangers and how do you avoid them?

    An Oracle Unlimited Licence Agreement is only unlimited within its clauses. What certification actually asks of you, where toxic consumption creeps in, and why the measurement work has to start at the beginning of the term rather than the last six months.

    • SAM
    • Governance
    6 min
  • Microsoft Licensing Update – August 2025

    Microsoft's August 2025 Product Terms changes: Extended Term standardised across programmes, Exchange and Skype for Business Server Subscription Editions, the Exchange and Windows 10 ESU programmes, and the Dynamics 365 F&O enforcement dates.

    • SAM
    • Governance
    4 min
  • Oracle ULA: know your options. Exit with confidence.

    Renew, rescope or exit — an Oracle ULA gives you three routes and a narrow window to choose between them. The questions to settle first, and a six-point health check to see how ready you actually are.

    • SAM
    • Governance
    6 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.