SAP Security and IAM determine costs and compliance in cloud transformation. Discover the Clean Architecture Blueprint for RISE with SAP now.
SAP Security and IAM determine costs and compliance in cloud transformation. Discover the Clean Architecture Blueprint for RISE with SAP now.
RISE with SAP and native cloud scenarios are considered by many companies to be purely IT migration projects. However, those who only think of the transformation in technical terms overlook the factor that disproportionately determines costs, compliance, and implementation speed: SAP Security in the form of clean Identity & Access Governance (IAM). This is precisely the difference between an SAP cloud migration that creates added value and one that burns money from the outset.
Many responsible parties assume that with the switch to a SaaS or PaaS environment, responsibility for access security also transfers to the cloud provider. The SAP Shared Responsibility Model states otherwise: SAP and the hyperscalers secure the infrastructure, i.e., the building with stable walls and functioning locking systems. Who gets a key within these walls, which doors are open, and who has access to the vault with business data is still solely decided by the company. In an emergency, an auditor, a supervisory authority, or an auditor within the framework of ISO 27001 or BAIT will therefore not ask the hyperscaler, but the management for proof of proper access controls. This is precisely where the biggest blind spots in SAP migration projects arise.
In addition to the compliance risk, inadequate identity governance directly impacts license costs. RISE with SAP does not bill based on actual usage, but on the assigned authorization profile, the so-called Full Usage Equivalent (FUE). If authorization profiles that have grown over years and become overloaded are uncritically adopted into the cloud, SAP automatically classifies even simple clerks into the most expensive license category. The cloud bill thus increases before any initial added value has been generated in the project. According to DSAG surveys, up to 35 percent of license costs arise solely from inactive accounts, outdated authorization clusters, and missing single sign-on. SAPinsider even assumes that 64 percent of SAP users fall into artificial over-licensing during cloud migrations.
In addition, there is a third risk that is easily underestimated: As long as role concepts and approvals continue to be managed manually via Excel and email, the authorization system slows down every transformation project. Not only the migration itself is delayed, but also every subsequent system expansion and every planned AI rollout, because new accesses first have to be laboriously approved manually.
Instead of viewing Identity & Access Management as an isolated security silo, SAP IAM can be built as the foundation of the entire transformation roadmap along a three-stage lifecycle.
In the Start Clean phase, the target vision is paramount before the actual migration: a central Identity Provider with Single Sign-On and enforced multi-factor authentication across all on-premises and cloud systems, supplemented by a standardized role design based on hybrid RBAC/ABAC models that maps future system expansions without new sprawl.
In the Get Clean phase, cleanup takes place during the migration itself. Systematic role mining identifies and eliminates unused authorizations, orphaned users, and critical segregation of duties conflicts. In parallel, classic GRC auditing shifts from manual, snapshot-based controls to digital, system-supported workflows.
The Stay Clean phase focuses on continuous governance in ongoing operations. An automated hire-to-retire process adjusts access rights in real time upon entry, department change, or exit, without manual intervention. Business owners from the departments confirm access rights at regular, automated recertification intervals via intuitive interfaces. And proactive risk monitoring integrates IAM logs into SIEM systems to immediately detect anomalous access patterns on core APIs.
| Pain Point | Conventional Approach | Clean Architecture Blueprint | Economic Added Value |
|---|---|---|---|
| Unclear Responsibilities | Assumption that the cloud provider fully assumes access security | Anchoring the Shared Responsibility Model in operations | Liability minimization, protection against audit penalties |
| Authorization Legacy Debt | Historical roles and orphaned accounts are migrated uncritically | Get Clean: systematic cleanup before go-live | Direct license savings potential through FUE optimization |
| Fragmented Approvals | Manual media discontinuities via Excel and email | Start Clean: central IdP, automated SSO | Reduced time-to-value for onboarding and rollouts |
| Creeping Loss of Control | Architecture reverts to sprawl after go-live | Stay Clean: Hire-to-Retire, Recertification, Monitoring | Sustainable TCO reduction |
A clean SAP authorization concept thus not only solves the operational dilemma between security and agility. It transforms identity governance from an administrative cost block into a direct driver for TCO reduction, license optimization, and platform agility.
A successful SAP cloud transformation requires a shift from reactive ad-hoc measures to structured, target-driven governance. The Shared Responsibility Model obliges companies to actively exercise sovereignty over their identities and data access. The Clean Architecture Blueprint transforms this not into a rigid restriction, but into a lean, cost-efficient, and elastic SAP landscape that ensures scalability, continuous innovation, and future AI scenarios.
Read more about the Clean Architecture Blueprint and how you can use Identity & Access Governance as a cost lever for your SAP cloud transformation in Manage Now’s complete whitepaper, or learn more in a personal conversation with our experts!
It describes the division of security responsibility between SAP or the hyperscaler and the customer. The provider secures the cloud infrastructure; the company remains fully responsible for identities, authorizations, and access within the cloud.
The FUE is the billing unit for RISE with SAP. Users are classified into license categories not by actual activity, but by assigned authorization profile. Overloaded profiles automatically lead to higher license costs.
According to DSAG surveys, up to 35 percent of licensing costs in historically grown SAP systems arise from inactive accounts, outdated authorization clusters, and missing single sign-on. These costs can be avoided through a clean authorization concept.
Ideally, already in the Start Clean phase, i.e., before the actual migration. This prevents authorization legacy debt from being uncritically adopted into the cloud, eliminating the need for later rework.
For CIOs, CFOs, enterprise architects, and IT managers of medium-sized companies who are planning or already implementing an SAP cloud transformation like RISE with SAP and want to keep an eye on costs, compliance, and implementation speed.
Subscribe to our newsletter to receive regular updates, invitations to our events, and exclusive IT insights.