SAP FUE and User Management: A Practical Guide to Optimizing Licenses and Access

Posted by Massimo Manara on Sep 30, 2026, 8:15:00 AM

SAP licenses represent a significant cost item for any organization running SAP S/4HANA. The FUE (Full Use Equivalent) model has introduced a new measurement logic compared to the traditional Named User License (NUL) used in SAP ECC — and with it, new complexities: how do you correctly calculate the number of FUEs required? Where do you start? And what are the most common mistakes?

Read More

Topics: sap license auditing, sap fue

SAP Critical Authorization Objects

Posted by Massimo Manara on Sep 23, 2026, 8:15:01 AM

What are the critical authorization objects in SAP? Is there an official list of which ones they are and how they should be managed?

Read More

Managing External Users in SAP: How to Do It?

Posted by Massimo Manara on Sep 16, 2026, 8:15:00 AM

External user management in SAP comes up frequently in consulting engagements — and for good reason. Some organizations deal with high volumes of external staff rotating in and out of the system; others have more stable external populations. Either way, the question is the same: who are these users, and how should their SAP accounts be managed?

Read More

SE16 in SAP: What It Is and Why It Is a Security Risk

Posted by Massimo Manara on Aug 5, 2026, 8:15:00 AM

For some, SE16 is an unfamiliar transaction code. For SAP administrators, it is part of daily life — and often, unfortunately, for others too. This article covers what SE16 does, how many variants exist, and why access to it needs to be carefully controlled.

Read More

Topics: se16, audit

Does SAP Log Everything?

Posted by Massimo Manara on Jul 29, 2026, 8:15:00 AM

"SAP logs everything" — it's a statement heard frequently. But is it actually true? Can you always trace who did what in the system? And are there ways to bypass or delete those logs? This article addresses all of these questions.

Read More

Topics: SAP LOG

SAP Vulnerabilities: Code Red

Posted by Massimo Manara on Jun 17, 2026, 8:15:00 AM

Who decided there is a problem? What criteria make a given SAP vulnerability critical and what happens when the red findings become too many to handle? Are they all genuine?

Read More

Topics: sap vulnerability

SAP User Trace

Posted by Marta Ortona on Nov 8, 2024, 8:15:00 AM

From SAP_BASIS 7.40 SP16 SAP has been release a new tool for trace user authorization "long-term" trace.

What is it and how works? 

Read More

Topics: authorization concept, Trace autorizzazioni SAP

SAP CVA what is it?

Posted by Klea Duro on Oct 18, 2024, 8:15:00 AM

What can be done to check whether programs developed in SAP comply with security standards?

Read More

Topics: Secure programming

How many and which workflows to define in SAP GRC Access Control?

Posted by Klea Duro on Oct 4, 2024, 8:15:00 AM

There are several workflows that this tool provides.

 

 

Some of these are standard and cannot be changed, while others leave ample room for customization.

 

What are the points of attention when deciding which steps and how many to include in various workflows?

 

We will discuss about them in this article.

Read More

Topics: SAP GRC

HOW TO PERFORM A RISK ANALYSIS WITH GRC ACCESS CONTROL?

Posted by Klea Duro on Sep 20, 2024, 8:15:00 AM

In order to perform a risk analysis in SAP and even non-SAP systems, you can use the SAP GRC Access Control tool.

 

 

Through the Access Risk Analysis module.

Read More

Topics: SAP GRC

Yes Subscribe!

Blog Aglea, what you could find out?

Every Friday a new post, interview or content related to SAP Security.

  • Tips on how to design SAP Security
  • How to
  • Checklist
  • Common error and pitfall on security SAP
  • Interview with experts
  • Who we are and Aglea vision on SAP Security

Recent Posts

Post By Topic

See all