Srini P,July 25, 2026 2
FREE – Anyone can read

Top 5 SAP GRC User Access Review (UAR) Enhancements for Better Compliance

Keeping User Access Reviews (UAR) efficient, accurate, and auditable is one of the biggest challenges for SAP GRC administrators. While many organizations continue using the standard UAR functionality, SAP has delivered several powerful enhancements over the last few Support Packages that significantly improve reviewer productivity, administrative efficiency, and integration with SAP Cloud Identity Access Governance (IAG).

SAP GRC User Access Review (UAR) also known as SAP Access Certification, is one of the most important controls for maintaining compliant user access across SAP systems. Organizations performing SOX, ISO 27001, GDPR, or internal compliance reviews depend on SAP GRC Access Control to certify user access, remove excessive authorizations, and demonstrate audit readiness. Recent SAP Support Packages have introduced several enhancements that improve reviewer productivity, simplify administration, and strengthen integration with SAP Cloud Identity Access Governance (SAP IAG).

📌 Key Takeaways

In this article, we'll explore five must-have User Access Review (UAR) enhancements that every SAP GRC Access Control customer should evaluate and implement.

  • Mass cancel thousands of UAR requests using report GRAC_REQUEST_MASS_CANCEL.
  • Review indirect HR organizational access during certification.
  • Support SAP IAG Business Roles in User Access Reviews.
  • Automatically remind reviewers about pending draft requests.
  • Simplify SAP IAG Bridge reviews using wildcard (*) User IDs.

Who Should Read This?

This article is intended for:

  • SAP Security Administrators
  • SAP GRC Consultants
  • SAP Access Control Administrators
  • SAP Auditors
  • Internal Audit Teams
  • SAP Basis Teams supporting GRC
  • Identity & Access Governance Professionals

Prerequisites:

Before implementing these enhancements, verify that your SAP system is updated to the latest ABAP/BASIS SP levels:

  • Latest Support Package level
  • SAP Notes implementation status
  • Background jobs
  • SAP IAG connectivity (if applicable)
  • Transport strategy

Verifying these prerequisites before implementation helps ensure the SAP Notes can be deployed successfully and minimizes issues during User Access Review campaign generation.

1. Mass Cancellation of UAR & SoD Requests

SAP Note: 2921243 – Report for UAR and SOD Request Mass Cancellation in Admin Review

The Challenge

In large enterprises, User Access Review and SoD review campaigns can generate thousands of review requests. Sometimes these requests must be cancelled because:

  • Incorrect review criteria were selected
  • Wrong connector or landscape was chosen
  • Organizational restructuring occurred
  • New review cycle needs to be generated
  • Reviewer assignment errors were discovered

Prior to this enhancement, administrators had to cancel requests individually through Admin Review, which was extremely time-consuming and could even lead to system timeouts during mass operations.

What's New?

SAP introduced a dedicated program - GRAC_REQUEST_MASS_CANCEL. This program allows administrators to:

  • Mass cancel UAR requests
  • Mass cancel SoD review requests
  • Cancel requests for regeneration
  • Select requests using request numbers and request types

Business Benefits

  • Saves hours of administrative effort
  • Eliminates manual cancellation of hundreds or thousands of requests
  • Reduces database locks and timeout issues
  • Enables rapid restart of review campaigns after configuration changes
  • Improves operational efficiency during quarterly and yearly certification campaigns

Why It Matters

Organizations running quarterly SOX reviews often generate several thousand UAR requests. If a scheduling mistake occurs, this enhancement allows administrators to recover within minutes instead of spending days cancelling requests manually.

2. Include HR Organizational Assignments in User Access Review

SAP Note: 3031693 – UAR Jobs Can Be Scheduled for HR Organizational Assignments

The Challenge

Traditional User Access Reviews focus primarily on direct role assignments. However, many SAP landscapes assign authorizations indirectly through:

  • Positions
  • Jobs
  • Organizational Units
  • HR Organizational Management

These indirect assignments are often invisible during standard reviews, creating a compliance gap because reviewers cannot see the complete access granted to an employee.

What's New?

SAP has introduced a new scheduling option that enables administrators to include HR organizational assignments, such as roles inherited through positions, jobs, or organizational units, when generating UAR requests. This enhancement provides reviewers with a more comprehensive view of user access by incorporating both direct and indirect role assignments.

In UAR, SAP has introduced an option to include organizational assignments in UAR requests, allowing reviewers to certify both direct and indirect role assignments.

Business Benefits

  • Complete visibility into all user access
  • Eliminates hidden access inherited from HR structures
  • Improves audit readiness
  • Supports segregation of duties validation more accurately

Why It Matters

Without this enhancement, reviewers may incorrectly certify a user's access because they only see directly assigned roles while critical access inherited through organizational assignments remains hidden.

3. Business Role Support for SAP IAG Bridge Scenario

SAP Notes

  • 3216764 – UAR Generation with Business Role IAG Bridge Scenario
  • 3217842 – UAR Provision with Business Roles IAG Bridge Scenario

The Challenge

Organizations integrating SAP GRC Access Control with SAP Cloud Identity Access Governance (IAG) increasingly manage access using Business Roles rather than technical roles.

Earlier versions of UAR experienced several issues:

  • Approved Business Role removals were not sent to SAP IAG.
  • The system could not determine the correct connector because Business Roles themselves do not contain connector information.
  • Provisioning validation failed during review completion, preventing removal actions from being executed.

What's New?

UAR now supports generating review requests for Business Roles in the SAP IAG Bridge scenario. Approved removal decisions are automatically forwarded to SAP IAG for provisioning. Additionally, enhanced connector and Master User ID validation ensure requests are routed to the correct target system, improving provisioning accuracy and reducing failures.

The enhancement validates:

  • Connector mapping
  • Master User ID mapping
  • Related provisioning environment

SAP also resolved validation issues where Business Role provisioning was incorrectly skipped because technical role validity was not properly evaluated. Applying Note 3217842 ensures Business Role removals are correctly processed after UAR approval.

Business Benefits

  • Enables seamless SAP GRC and IAG integration
  • Supports cloud-first Identity Governance strategies
  • Ensures approved removals reach SAP IAG
  • Reduces provisioning failures
  • Improves end-to-end governance automation
  • Supports Business Role–based access management

Why It Matters

Organizations investing in SAP Cloud Identity Access Governance should not stop at synchronizing Business Roles. Extending UAR to generate, validate, and provision Business Role decisions through the IAG Bridge creates a unified governance process across on-premise and cloud environments.

4. Email Reminder Notifications for Saved Draft Requests

SAP Note: 3433530 – Email Reminder Notification for UAR and SoD Saved Requests

The Challenge

Reviewers often receive hundreds of access review items. Instead of completing everything in one session, they:

  • Review some line items
  • Save the request as Draft
  • Return later

The problem?

Once saved, there was no reminder mechanism, causing draft requests to remain unattended until campaign deadlines approached.

What's New?

SAP introduced a new program - GRAC_SAVED_REQ_EMAIL_REMINDER. This report sends reminder emails for:

  • UAR draft requests
  • SoD review draft requests

Notifications are sent to the current approver, reminding them to complete pending review actions. The enhancement was introduced as part of a Customer Connect improvement request.

Business Benefits

  • Prevents abandoned review requests
  • Improves campaign completion rates
  • Reduces manual follow-up by GRC administrators
  • Improves SLA compliance
  • Enhances reviewer accountability
  • Supports timely audit completion

Why It Matters

Rather than relying on manual reminder emails from administrators, organizations can automate the reminder process and keep review campaigns moving without additional administrative effort.

5. User ID Wildcard (*) Support for SAP IAG Bridge

SAP Note: 3229980 – UAR Generation with Business Role and User ID IAG Bridge Scenario

The Challenge

When generating UAR requests for Business Roles in the SAP IAG Bridge scenario, administrators often left the User ID selection blank, expecting the system to include all users.

Instead, no requests were generated because the process required an explicit User ID range.

What's New?

SAP enhanced the UAR generation logic by allowing the use of the wildcard value (*) for the User ID range in Business Role scenarios.

The enhancement automatically handles cases where the User ID range is empty, ensuring all relevant users associated with Business Roles are included. It also complements earlier performance improvements and Business Role support delivered in related SAP Notes.

Business Benefits

  • Simplifies UAR scheduling
  • Eliminates confusion when reviewing all users
  • Prevents missing review requests
  • Improves Business Role review coverage
  • Reduces administrator errors during campaign generation

Why It Matters

For organizations managing thousands of users through SAP IAG Business Roles, this small enhancement removes unnecessary manual effort and ensures that review campaigns include the intended population without requiring explicit User ID ranges.

Common Mistakes During SAP GRC User Access Reviews (UAR)

Avoid these common mistakes to ensure your User Access Review process is accurate, efficient, and audit-ready:

  • Reviewing only direct roles: Reviewers may miss access inherited through composite roles or organizational structures, resulting in incomplete certifications.
  • Ignoring HR inherited access: Excluding roles inherited through positions, jobs, or organizational units can leave critical access unreviewed.
  • Not sending reminder emails: Without automated reminders, draft review requests may remain pending, delaying campaign completion.
  • Forgetting Business Role validation: In SAP IAG Bridge scenarios, incorrect connector or Business Role validation can cause provisioning failures after approval.
  • Running UAR before connector synchronization: Generating review requests before synchronizing connectors or repository data may result in outdated or incomplete access information.
✅ Best Practice

Before launching a User Access Review (UAR) campaign, ensure connectors are synchronized, repository data is up to date, HR organizational assignments are included where applicable, and automated reminder notifications are enabled. These steps help improve review accuracy, reduce administrative effort, and support audit readiness.

Final Thoughts

SAP continues to enhance User Access Review with features that go beyond bug fixes by addressing real operational challenges faced by security administrators and auditors. User Access Review is a cornerstone of SAP access governance, but its effectiveness depends on both functionality and usability. By implementing these SAP Notes, organizations can reduce administrative overhead, improve reviewer productivity, strengthen compliance, and enhance integration with SAP Cloud Identity Access Governance. Whether you're preparing for an audit, optimizing quarterly certifications, or modernizing your access governance strategy, these enhancements deliver measurable value and are well worth including in your SAP GRC roadmap. Implementing these five enhancements can significantly improve the efficiency and effectiveness of your UAR process:

SAP Note Enhancement Business Value Applicable Scenario

  • 2921243 - Mass Cancellation High Large review campaigns
  • 3031693 - HR Organizational Assignments High Indirect access
  • 3216764 - Business Roles Very High SAP IAG
  • 3433530 - Draft Reminder Medium Quarterly reviews
  • 3229980 - Wildcard User ID Medium Business Role campaigns

Organizations that have not reviewed their SAP GRC Access Control implementation in the last few years are likely missing several productivity improvements delivered through SAP Notes. Implementing these enhancements can reduce administrative effort, improve audit readiness, and provide a more complete view of user access across both on-premise SAP systems and SAP Cloud Identity Access Governance. Reviewing these enhancements as part of every SAP GRC upgrade or quarterly maintenance cycle helps ensure that User Access Reviews remain efficient, accurate, and aligned with evolving compliance requirements.

Our Recommendation

Organizations should review these SAP Notes during every SAP GRC Support Package upgrade or annual health check to ensure they are taking advantage of the latest User Access Review capabilities and productivity improvements:

  • SAP Note 2921243
  • SAP Note 3031693
  • SAP Note 3216764
  • SAP Note 3217842
  • SAP Note 3229980
  • SAP Note 3433530
⚠️ Disclaimer

This article is based on publicly available SAP Notes and practical implementation experience. SAP Notes may be updated, replaced, or superseded over time. Always verify the latest SAP documentation and test all changes in a non-production environment before implementation. SAP®, SAP GRC, SAP Access Control, SAP S/4HANA, SAP HANA, and SAP Cloud Identity Access Governance (SAP IAG) are trademarks or registered trademarks of SAP SE or its affiliates. SAP Security Expert is an independent community and is not affiliated with, endorsed by, or sponsored by SAP SE.

Frequently Asked Questions

What is SAP GRC User Access Review (UAR)?

<p>SAP GRC User Access Review (UAR) is a governance process within SAP GRC Access Control that enables organizations to periodically review and certify user access to SAP systems. It helps managers and application owners verify that users have only the access required for their job responsibilities, supporting compliance with regulations such as SOX, GDPR, and internal security policies. UAR is a key control for maintaining the principle of least privilege and reducing the risk of unauthorized or excessive access.</p>

Which SAP Note enables mass cancellation of UAR requests?

<p>SAP Note <b>2921243</b> introduces the report <b>GRAC_REQUEST_MASS_CANCEL</b>, which allows administrators to mass cancel User Access Review (UAR) and Segregation of Duties (SoD) review requests. This enhancement significantly reduces the effort required to cancel large review campaigns and regenerate them when configuration or scheduling changes are needed.</p><p></p>

Can UAR review Business Roles in SAP IAG?

<p>Yes. SAP GRC supports reviewing Business Roles in SAP Cloud Identity Access Governance (SAP IAG) Bridge scenarios through <b>SAP Notes</b> <b>3216764 and 3217842</b>. These enhancements enable UAR to generate review requests for Business Roles, validate connector and Master User ID mappings, and automatically send approved role removal decisions to SAP IAG for provisioning.</p>

Does SAP GRC support reminder emails for draft UAR requests?

<p>Yes. SAP Note <b>3433530</b> introduces automated email reminders for User Access Review (UAR) and Segregation of Duties (SoD) requests that have been saved as drafts. Using the report GRAC_SAVED_REQ_EMAIL_REMINDER, administrators can notify reviewers about pending draft requests, helping improve review completion rates and ensuring certification campaigns stay on schedule.</p>

Can indirect HR roles be reviewed during User Access Reviews?

<p>Yes. SAP Note <b>3031693</b> allows User Access Review requests to include access inherited through HR Organizational Management, such as positions, jobs, and organizational units. This enhancement provides reviewers with a more complete view of a user's effective access, reducing the risk of certifying users without considering indirect role assignments.</p>

Which report is used to cancel UAR requests?

<p>The report <b>GRAC_REQUEST_MASS_CANCEL</b> is used to mass cancel User Access Review (UAR) and Segregation of Duties (SoD) review requests. Introduced through SAP Note <b>2921243</b>, it enables administrators to efficiently cancel large numbers of review requests and regenerate campaigns when necessary.</p>

Does the wildcard (*) work during Business Role reviews in SAP IAG Bridge?

<p>Yes. SAP Note <b>3229980</b> introduces support for the wildcard character (*) in the User ID selection field when generating UAR requests for Business Roles in SAP IAG Bridge scenarios. This allows administrators to include all eligible users without specifying individual User IDs or ranges, simplifying campaign generation and reducing administrative errors.</p>

Which SAP GRC versions support these enhancements?

<p>Most of these enhancements were introduced for SAP GRC Access Control 12.0 through SAP Notes and Support Packages. Some enhancements may also be available for SAP GRC Access Control 10.1, depending on the applied Support Package Stack and SAP Note availability. Organizations should review the prerequisites and applicability of each SAP Note in the SAP Support Portal and ensure they are running a supported SAP GRC release before implementation.</p>

Srini P

Srini P

SAP GRC Team Lead

Srini P is an experienced SAP Security & GRC Advisor and independent consultant with extensive expertise in designing, implementing, and optimizing SAP Security and Governance, Risk, and Compliance (GRC) solutions. He has helped organizations strengthen access governance, regulatory compliance, and security controls across complex SAP landscapes. With a practical, business-focused approach, Srini specializes in SAP authorization design, Segregation of Duties (SoD), user access governance, and security assessments. As a trusted advisor, he works closely with clients to deliver scalable, compliant, and risk-aware SAP security strategies that align with business objectives.

Top 5 SAP GRC User Access Review (UAR) Enhancements for Better Compliance | SAP Security Expert