Keeping User Access Reviews (UAR) efficient, accurate, and auditable is one of the biggest challenges for SAP GRC administrators. While many organizations continue using the standard UAR functionality, SAP has delivered several powerful enhancements over the last few Support Packages that significantly improve reviewer productivity, administrative efficiency, and integration with SAP Cloud Identity Access Governance (IAG).
SAP GRC User Access Review (UAR) also known as SAP Access Certification, is one of the most important controls for maintaining compliant user access across SAP systems. Organizations performing SOX, ISO 27001, GDPR, or internal compliance reviews depend on SAP GRC Access Control to certify user access, remove excessive authorizations, and demonstrate audit readiness. Recent SAP Support Packages have introduced several enhancements that improve reviewer productivity, simplify administration, and strengthen integration with SAP Cloud Identity Access Governance (SAP IAG).
In this article, we'll explore five must-have User Access Review (UAR) enhancements that every SAP GRC Access Control customer should evaluate and implement.
- Mass cancel thousands of UAR requests using report GRAC_REQUEST_MASS_CANCEL.
- Review indirect HR organizational access during certification.
- Support SAP IAG Business Roles in User Access Reviews.
- Automatically remind reviewers about pending draft requests.
- Simplify SAP IAG Bridge reviews using wildcard (*) User IDs.
Who Should Read This?
This article is intended for:
- SAP Security Administrators
- SAP GRC Consultants
- SAP Access Control Administrators
- SAP Auditors
- Internal Audit Teams
- SAP Basis Teams supporting GRC
- Identity & Access Governance Professionals
Prerequisites:
Before implementing these enhancements, verify that your SAP system is updated to the latest ABAP/BASIS SP levels:
- Latest Support Package level
- SAP Notes implementation status
- Background jobs
- SAP IAG connectivity (if applicable)
- Transport strategy
Verifying these prerequisites before implementation helps ensure the SAP Notes can be deployed successfully and minimizes issues during User Access Review campaign generation.
1. Mass Cancellation of UAR & SoD Requests
SAP Note: 2921243 – Report for UAR and SOD Request Mass Cancellation in Admin Review
The Challenge
In large enterprises, User Access Review and SoD review campaigns can generate thousands of review requests. Sometimes these requests must be cancelled because:
- Incorrect review criteria were selected
- Wrong connector or landscape was chosen
- Organizational restructuring occurred
- New review cycle needs to be generated
- Reviewer assignment errors were discovered
Prior to this enhancement, administrators had to cancel requests individually through Admin Review, which was extremely time-consuming and could even lead to system timeouts during mass operations.
What's New?
SAP introduced a dedicated program - GRAC_REQUEST_MASS_CANCEL. This program allows administrators to:
- Mass cancel UAR requests
- Mass cancel SoD review requests
- Cancel requests for regeneration
- Select requests using request numbers and request types
Business Benefits
- Saves hours of administrative effort
- Eliminates manual cancellation of hundreds or thousands of requests
- Reduces database locks and timeout issues
- Enables rapid restart of review campaigns after configuration changes
- Improves operational efficiency during quarterly and yearly certification campaigns
Why It Matters
Organizations running quarterly SOX reviews often generate several thousand UAR requests. If a scheduling mistake occurs, this enhancement allows administrators to recover within minutes instead of spending days cancelling requests manually.
2. Include HR Organizational Assignments in User Access Review
SAP Note: 3031693 – UAR Jobs Can Be Scheduled for HR Organizational Assignments
The Challenge
Traditional User Access Reviews focus primarily on direct role assignments. However, many SAP landscapes assign authorizations indirectly through:
- Positions
- Jobs
- Organizational Units
- HR Organizational Management
These indirect assignments are often invisible during standard reviews, creating a compliance gap because reviewers cannot see the complete access granted to an employee.
What's New?
SAP has introduced a new scheduling option that enables administrators to include HR organizational assignments, such as roles inherited through positions, jobs, or organizational units, when generating UAR requests. This enhancement provides reviewers with a more comprehensive view of user access by incorporating both direct and indirect role assignments.
In UAR, SAP has introduced an option to include organizational assignments in UAR requests, allowing reviewers to certify both direct and indirect role assignments.
Business Benefits
- Complete visibility into all user access
- Eliminates hidden access inherited from HR structures
- Improves audit readiness
- Supports segregation of duties validation more accurately
Why It Matters
Without this enhancement, reviewers may incorrectly certify a user's access because they only see directly assigned roles while critical access inherited through organizational assignments remains hidden.
3. Business Role Support for SAP IAG Bridge Scenario
SAP Notes
- 3216764 – UAR Generation with Business Role IAG Bridge Scenario
- 3217842 – UAR Provision with Business Roles IAG Bridge Scenario
The Challenge
Organizations integrating SAP GRC Access Control with SAP Cloud Identity Access Governance (IAG) increasingly manage access using Business Roles rather than technical roles.
Earlier versions of UAR experienced several issues:
- Approved Business Role removals were not sent to SAP IAG.
- The system could not determine the correct connector because Business Roles themselves do not contain connector information.
- Provisioning validation failed during review completion, preventing removal actions from being executed.
What's New?
UAR now supports generating review requests for Business Roles in the SAP IAG Bridge scenario. Approved removal decisions are automatically forwarded to SAP IAG for provisioning. Additionally, enhanced connector and Master User ID validation ensure requests are routed to the correct target system, improving provisioning accuracy and reducing failures.
The enhancement validates:
- Connector mapping
- Master User ID mapping
- Related provisioning environment
SAP also resolved validation issues where Business Role provisioning was incorrectly skipped because technical role validity was not properly evaluated. Applying Note 3217842 ensures Business Role removals are correctly processed after UAR approval.
Business Benefits
- Enables seamless SAP GRC and IAG integration
- Supports cloud-first Identity Governance strategies
- Ensures approved removals reach SAP IAG
- Reduces provisioning failures
- Improves end-to-end governance automation
- Supports Business Role–based access management
Why It Matters
Organizations investing in SAP Cloud Identity Access Governance should not stop at synchronizing Business Roles. Extending UAR to generate, validate, and provision Business Role decisions through the IAG Bridge creates a unified governance process across on-premise and cloud environments.
4. Email Reminder Notifications for Saved Draft Requests
SAP Note: 3433530 – Email Reminder Notification for UAR and SoD Saved Requests
The Challenge
Reviewers often receive hundreds of access review items. Instead of completing everything in one session, they:
- Review some line items
- Save the request as Draft
- Return later
The problem?
Once saved, there was no reminder mechanism, causing draft requests to remain unattended until campaign deadlines approached.
What's New?
SAP introduced a new program - GRAC_SAVED_REQ_EMAIL_REMINDER. This report sends reminder emails for:
- UAR draft requests
- SoD review draft requests
Notifications are sent to the current approver, reminding them to complete pending review actions. The enhancement was introduced as part of a Customer Connect improvement request.
Business Benefits
- Prevents abandoned review requests
- Improves campaign completion rates
- Reduces manual follow-up by GRC administrators
- Improves SLA compliance
- Enhances reviewer accountability
- Supports timely audit completion
Why It Matters
Rather than relying on manual reminder emails from administrators, organizations can automate the reminder process and keep review campaigns moving without additional administrative effort.
5. User ID Wildcard (*) Support for SAP IAG Bridge
SAP Note: 3229980 – UAR Generation with Business Role and User ID IAG Bridge Scenario
The Challenge
When generating UAR requests for Business Roles in the SAP IAG Bridge scenario, administrators often left the User ID selection blank, expecting the system to include all users.
Instead, no requests were generated because the process required an explicit User ID range.
What's New?
SAP enhanced the UAR generation logic by allowing the use of the wildcard value (*) for the User ID range in Business Role scenarios.
The enhancement automatically handles cases where the User ID range is empty, ensuring all relevant users associated with Business Roles are included. It also complements earlier performance improvements and Business Role support delivered in related SAP Notes.
Business Benefits
- Simplifies UAR scheduling
- Eliminates confusion when reviewing all users
- Prevents missing review requests
- Improves Business Role review coverage
- Reduces administrator errors during campaign generation
Why It Matters
For organizations managing thousands of users through SAP IAG Business Roles, this small enhancement removes unnecessary manual effort and ensures that review campaigns include the intended population without requiring explicit User ID ranges.
Common Mistakes During SAP GRC User Access Reviews (UAR)
Avoid these common mistakes to ensure your User Access Review process is accurate, efficient, and audit-ready:
- Reviewing only direct roles: Reviewers may miss access inherited through composite roles or organizational structures, resulting in incomplete certifications.
- Ignoring HR inherited access: Excluding roles inherited through positions, jobs, or organizational units can leave critical access unreviewed.
- Not sending reminder emails: Without automated reminders, draft review requests may remain pending, delaying campaign completion.
- Forgetting Business Role validation: In SAP IAG Bridge scenarios, incorrect connector or Business Role validation can cause provisioning failures after approval.
- Running UAR before connector synchronization: Generating review requests before synchronizing connectors or repository data may result in outdated or incomplete access information.
Before launching a User Access Review (UAR) campaign, ensure connectors are synchronized, repository data is up to date, HR organizational assignments are included where applicable, and automated reminder notifications are enabled. These steps help improve review accuracy, reduce administrative effort, and support audit readiness.
Final Thoughts
SAP continues to enhance User Access Review with features that go beyond bug fixes by addressing real operational challenges faced by security administrators and auditors. User Access Review is a cornerstone of SAP access governance, but its effectiveness depends on both functionality and usability. By implementing these SAP Notes, organizations can reduce administrative overhead, improve reviewer productivity, strengthen compliance, and enhance integration with SAP Cloud Identity Access Governance. Whether you're preparing for an audit, optimizing quarterly certifications, or modernizing your access governance strategy, these enhancements deliver measurable value and are well worth including in your SAP GRC roadmap. Implementing these five enhancements can significantly improve the efficiency and effectiveness of your UAR process:
SAP Note Enhancement Business Value Applicable Scenario
- 2921243 - Mass Cancellation High Large review campaigns
- 3031693 - HR Organizational Assignments High Indirect access
- 3216764 - Business Roles Very High SAP IAG
- 3433530 - Draft Reminder Medium Quarterly reviews
- 3229980 - Wildcard User ID Medium Business Role campaigns
Organizations that have not reviewed their SAP GRC Access Control implementation in the last few years are likely missing several productivity improvements delivered through SAP Notes. Implementing these enhancements can reduce administrative effort, improve audit readiness, and provide a more complete view of user access across both on-premise SAP systems and SAP Cloud Identity Access Governance. Reviewing these enhancements as part of every SAP GRC upgrade or quarterly maintenance cycle helps ensure that User Access Reviews remain efficient, accurate, and aligned with evolving compliance requirements.
Our Recommendation
Organizations should review these SAP Notes during every SAP GRC Support Package upgrade or annual health check to ensure they are taking advantage of the latest User Access Review capabilities and productivity improvements:
- SAP Note 2921243
- SAP Note 3031693
- SAP Note 3216764
- SAP Note 3217842
- SAP Note 3229980
- SAP Note 3433530
This article is based on publicly available SAP Notes and practical implementation experience. SAP Notes may be updated, replaced, or superseded over time. Always verify the latest SAP documentation and test all changes in a non-production environment before implementation. SAP®, SAP GRC, SAP Access Control, SAP S/4HANA, SAP HANA, and SAP Cloud Identity Access Governance (SAP IAG) are trademarks or registered trademarks of SAP SE or its affiliates. SAP Security Expert is an independent community and is not affiliated with, endorsed by, or sponsored by SAP SE.

