However, Firefighter access also introduces significant security and compliance risks because it allows users to temporarily bypass standard authorization controls and segregation of duties (SoD) restrictions. For this reason, organizations must ensure that emergency access is carefully governed, monitored, and audited.
Over the past few SAP releases, several enhancements have been introduced in SAP Access Control to improve the security, traceability, and governance of Firefighter sessions. Several additional improvements to Firefighter functionality were previously highlighted in an SAP Press article:
https://blog.sap-press.com/10-enhanced-eam-firefighter-features-in-sap-access-control-12.0
In this article, we focus on five additional enhancements that can further strengthen Emergency Access Management governance in SAP environments. Implementing these improvements helps organizations reduce privileged access risks while improving audit readiness.
As organizations move toward S/4HANA and modern SAP landscapes, strengthening Emergency Access Management becomes even more critical.
Key takeaway
Firefighter access is necessary for operational continuity, but without proper controls it can introduce significant privileged access risks. Implementing the latest SAP EAM enhancements helps organizations balance operational flexibility with strong security governance.
1. Replace S_ADMI_FCD (PADM) with S_SEC_SASS Authorization Object
One of the most significant security improvements introduced by SAP addresses the long-standing use of powerful administrative authorizations within Firefighter processes.
Historically, certain backend processes used by SAP GRC during the termination of a Firefighter session relied on SAP Basis functions that required the authorization object S_ADMI_FCD with the value PADM (Profile Administration). However, S_ADMI_FCD enables administration of authorization profiles, which ultimately determine user permissions in the SAP system.
From a governance perspective, S_ADMI_FCD with PADM is considered a highly sensitive authorization and is frequently highlighted in security audits due to its potential to bypass segregation of duties controls.
To address this risk, SAP introduced a new authorization object called S_SEC_SASS. Beginning with SAP S/4HANA 2025 and SAP_BASIS 8.16, the system now performs the authorization check using S_SEC_SASS with activity value 03. This authorization becomes the primary object used by the required BASIS processes.
For compatibility with older configurations, the system still performs a fallback check using S_ADMI_FCD with PADM if the new authorization object is not present. Support for this enhancement is delivered through SAP Note 3682044, which enables SAP GRC to utilize the new authorization mechanism.
Note: This authorization object requires the plugin component GRCPINW V1200_750 in the backend system with SAP_BASIS 8.16 or higher. Systems running earlier plugin versions or lower SAP_BASIS releases will continue to rely on the traditional S_ADMI_FCD - PADM authorization.
Important: SAP still recommends assigning S_ADMI_FCD to the dedicated RFC user used by GRC processes.
2. Enhanced Firefighter Audit and Change Log Collection
One of the common challenges organizations face with Firefighter access is the lack of detailed visibility into activities performed during emergency sessions. Historically, activity logs collected during emergency access sessions did not always provide sufficient information to clearly understand the sequence and context of system events.
SAP introduced a fix through SAP Note 3458033 that enables additional logging details such as Audit Class, Severity (Event Class), Message ID, and TABKEY information.
This enhancement significantly improves audit traceability and forensic analysis, making it easier to determine what actions were executed during emergency access and how they impacted the system.
SAP Note 3457932 provides further implementation guidance. The corrections must be applied in both backend and frontend systems to ensure the new logging information is captured properly.
3. New Firefighter Audit Report for End-to-End Visibility
Another useful improvement introduced by SAP is the Firefighter Audit Report, which provides a consolidated and end-to-end view of emergency access activity.
Previously, administrators and auditors often had to review multiple reports to understand the complete lifecycle of a Firefighter session.
The new report simplifies this process by presenting the entire emergency access lifecycle in a single view. From the creation of the access request to the execution of the Firefighter session and the subsequent controller review, all relevant information can be analyzed within one screen.
This report is available through NWBC (NetWeaver Business Client) and provides improved visibility into session usage, activity logs, and approval details. Because the report aggregates large volumes of session data, SAP recommends applying appropriate filter criteria when executing it to avoid performance issues or system dumps.
Organizations can enable this functionality either by upgrading to SAP Access Control 12.0 SP24 or by implementing SAP Note 3426290, which activates the enhanced reporting capability.
4. Disable Automatic Removal of Invalid Firefighter IDs
During repository synchronization, SAP GRC typically removes Firefighter IDs that no longer exist in the backend system. This automatic cleanup ensures that the GRC repository remains aligned with the backend landscape.
However, in some scenarios this behavior can remove valuable historical information related to Firefighter assignments and relationships. Such information may be required during security investigations or audit reviews.
To address this challenge, SAP introduced an enhancement that allows organizations to disable the automatic removal of invalid Firefighter IDs during repository synchronization. By retaining this information, organizations can maintain a complete historical record of emergency access assignments within the GRC system.
This improvement is particularly valuable for organizations that must maintain long-term audit trails and compliance documentation.
The enhancement can be implemented using SAP Note 3376846.
5. Email Notifications for Expiring Firefighter IDs
Proper lifecycle management of Firefighter IDs is essential to ensure that emergency access remains temporary and well controlled. In many organizations, Firefighter IDs remain active longer than necessary because expiration dates are not actively monitored.
SAP introduced a new report that automatically sends email notifications to Firefighter owners and controllers when a Firefighter ID is approaching its expiration date. By default, the notification is triggered fifteen days before the assignment expires.
The notification email includes a direct link to the Firefighter ID maintenance screen, allowing the owner or controller to review the assignment and extend the validity if required.
This proactive notification capability helps organizations prevent outdated emergency access assignments and ensures that privileged access remains properly governed.
This functionality can be implemented through SAP Note 3354809.
Together, these enhancements strengthen SAP Firefighter governance, privileged access monitoring, and overall SAP security posture.
Conclusion
As organizations adopt S/4HANA and modern SAP security architectures, strengthening Emergency Access Management becomes increasingly important. Firefighter access is a critical capability that allows organizations to resolve urgent production issues quickly. However, because it grants temporary privileged access, it must be managed with strong governance and monitoring.
Recent SAP enhancements significantly improve the security, transparency, and auditability of Emergency Access Management. By implementing these improvements and following best practices, organizations can reduce privileged access risks while maintaining operational flexibility.
Strengthening Firefighter governance ultimately improves SAP security posture, audit readiness, and overall privileged access management maturity.

