SAP License Audits Contact Us
Home/Journal/Named User Licensing/Article
Named User Licensing

The dormant user problem, and the five-step cleanup that survives audit.

Every customer has them. They cost twice — once in unused licences, once in distorted audit findings. The workflow that fixes both.

May 2026 9 min read Editorial Desk · SAPLicenseAudits
Procurement analysts reviewing dormant user account extracts on a large dashboard display
— Procurement analysts reviewing dormant user account extracts on a large dashboard display

Dormant SAP users are the most under-managed line item in the licensed estate. Every customer we work with has them. The pattern is the same: an account created during go-live, a project that ended three years ago, a contractor whose engagement closed, an internal mover whose old role was never reclaimed. The user has not logged on in months. Their last transaction history is dated. But the licence is still allocated, and on the next USMM submission it will count.

The financial drag from dormant users sits in the seven- to eight-figure range for most mid-sized estates. The audit risk from dormant users is even larger, because SAP's measurement tools do not care whether a user is active. An assigned Professional licence on a locked account is still a Professional licence in the count. This article sets out the practical mechanics of identifying, classifying, and decommissioning dormant accounts before they distort the next measurement.

How SAP defines — and counts — a dormant user

The SAP commercial framework does not have a contractual definition of "dormant." The contractual definition is binary: a user account exists and has a licence assignment, or it does not. The measurement extract pulled by the USMM transaction reports on assignment, not on activity. Inactivity is purely a customer-side concept. That asymmetry is the source of the entire problem: SAP charges for assignments, the customer often manages by activity, and the gap between the two converts directly to cost.

Most procurement teams adopt a practical inactivity threshold — ninety days, six months, or twelve months without a logon — and treat any user beyond that threshold as a dormancy candidate. Whatever threshold is chosen, it needs to be written down, applied consistently, and reviewed at least twice a year ahead of the measurement window.

The four populations hidden inside the dormant pool

1. Departed employees with active accounts

The largest single category in most estates. HR notifies IT of a departure, IT triggers the joiner-mover-leaver workflow, but the SAP user account is one step removed and gets missed when the workflow has gaps. Every customer should reconcile the active SAP user list against the HR active-employee feed at least quarterly. The variance is almost always larger than expected.

2. Contractors whose engagements have ended

Contractor accounts are the most expensive form of dormancy because they are typically created with broad authorisations and Professional-tier classification, then forgotten when the project closes. We routinely see contractor accounts active three years after the contractor's last invoice. See our analysis of contractor classification under named-user rules for the audit implications.

3. Test, training, and temporary accounts

The accounts created during implementation and training that were never decommissioned. The naming convention often gives them away — TEST_BUYER01, TRG_FI_USER — but they sit in the production licence count exactly the same way as live accounts.

4. Internal-mover legacy assignments

Employees who moved between business units or roles, whose old authorisations were not removed and whose old account remains active alongside a new one. The same human is double-counted, often at the highest tier from either of the two assignments.

Field note — the consolidated landscape problem A dormant user in a single system is a single licence. A dormant user that exists in ECC, S/4HANA, BW, and Solution Manager is counted four times in the LAW consolidation if the user IDs are not properly linked. Cleanup needs to address the consolidated identity, not the individual system entries.

Why dormancy hits the audit bill twice

Dormant accounts cost the customer in two distinct ways. The first is the obvious one: licences that are paid for but unused. The second, less obvious cost is that dormant accounts distort the classification picture. An auditor examining the active user population pulls a much cleaner signal than one examining a population polluted with three-year-old contractor accounts that have inflated Professional assignments.

When the dormant pool is large, the auditor's typical position is to assume the entire population reflects the customer's actual licensing position, and to price findings accordingly. A cleaned-up active population, by contrast, lets the customer's negotiator argue that the active user mix is what the business actually needs — a much more defensible position in any reclassification dispute. The relationship between dormancy hygiene and audit outcomes is direct, and it is one of the few areas where customer-side preparation moves the eventual settlement by a meaningful margin.

The cleanup workflow that survives an audit

A defensible cleanup is documented, reproducible, and respects regulatory data-retention requirements. Five steps cover what is needed.

68%
Average claim reduction
$180M+
Saved across active matters
500+
Engagements closed since 2018

Step 1 — Pull the dormancy extract

Use SUIM or an equivalent role-mining tool to extract every active user account and the date of their last logon, last transaction execution, and last password change. Cross-reference with the HR feed and the contractor master.

Step 2 — Classify the dormant pool

Sort the dormant accounts into the four categories above. Departed employees and ended contractors are immediate lock-and-delete candidates. Test and training accounts need a documented review with the implementation team. Internal-mover legacies need an authorisation review.

Step 3 — Lock first, delete later

Locking removes the account from the active count without losing the audit trail. SAP retention requirements and customer-side regulatory obligations (financial-services audit trails, GDPR retention rules) frequently require the account record to persist even after the licence is released. A two-stage lock-then-delete approach satisfies both compliance and licence-optimisation requirements.

Step 4 — Re-run the USMM extract

The licence count needs to be re-pulled after the lock to confirm the dormant accounts have dropped out of the active assignment. If they have not, the USMM configuration may need tuning — locked accounts can remain in the extract under some configurations.

Step 5 — Document the workflow

The auditor will ask how the dormancy classification was made. A written workflow with timestamps, approver names, and the HR-feed reconciliation evidence is the defence against any subsequent challenge.

The reclassification opportunity inside the dormant pool

Beyond pure removal, the dormant-account review is also the moment to revisit user-type classifications across the active estate. Many customers find that the same authorisation patterns that flagged accounts as dormant also reveal active accounts that are misclassified upwards — users with Professional licences who only ever executed Limited Professional transactions over the entire measurement period.

A combined dormancy and reclassification exercise typically produces a twenty to forty per cent reduction in the active Professional user count without any change to actual business activity. See the deeper treatment in our SAP Audit Defence Playbook, which includes a chapter on the role-mining mechanics, and the case study covering a global retailer's named-user reclassification for an example of the financial impact.

The timing question — before or after the measurement

The cleanest answer is: well before the measurement window opens. SAP's USMM cycle is annual for most customers, with a fixed submission window. Any cleanup completed inside the window is valid for that year's measurement. Cleanup performed after submission affects the following year's count but cannot retroactively reduce the current submission.

A best-practice cadence is a quarterly dormancy sweep with a deeper cleanup running ninety days ahead of submission. This gives the customer enough lead time to handle any escalations — locked-account disputes from line managers, retention-policy reviews from legal — without sliding into the measurement window. Customers that attempt the cleanup in the final two weeks before submission almost always under-deliver because the approval friction is greater than expected.

Where dormancy interacts with RISE and S/4HANA migration

The migration to S/4HANA or to a RISE-managed estate is the single largest licence inflection point most SAP customers will encounter in the contract's life. Dormant accounts dragged across the migration carry forward into the new metric and frequently inflate the initial baseline used for the conversion pricing.

If a customer migrates with a polluted active-user population, the new S/4HANA Full Use Equivalent count or the RISE-equivalent licensing tier is set against an inflated baseline. Cleanup before migration converts directly into reduced conversion cost. See our S/4HANA topic page for the broader conversion mechanics, and the related engine-metric conversion analysis for how the same logic applies to the engine side of the contract.

What good looks like

A well-managed estate runs a quarterly dormancy reconciliation, maintains a written joiner-mover-leaver SLA between HR and IT, keeps the contractor master in sync with procurement, and re-classifies internal movers within thirty days of role change. The active Professional population matches the active business need. The USMM submission is a procedural confirmation of a position the customer already understands, not an annual fire drill.

Customers that hit this standard typically see audit cycles close in weeks rather than months, with findings in the low single digits rather than the seven- to eight-figure range. Dormancy hygiene is not glamorous, but the financial leverage is greater than any other single piece of licence administration.

— Subscribe

SAP Audit Alerts · The weekly briefing

Every Wednesday. Field reports from active matters, decoded SAP communications, and what to look for in the next audit cycle. Work email only.