Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

security

Former Member
0 Kudos

What is the diff role and profile

1 ACCEPTED SOLUTION

Former Member
0 Kudos

HI Manohar,

Role is group of transactions,menu's,programs,reports and urls.

Profile is group of not more than 150 Authorization Objects.

<removed_by_moderator>

Thanks.

Raju.

Edited by: Julius Bussche on Feb 25, 2008 4:40 PM

4 REPLIES 4

Former Member
0 Kudos

Hi,

As mentioned by dimitri in ur other post,please use search forum.There r plenty of them over there.

U can also find some valuable info on :

[http://www.sapsecurityonline.com/index.htm]

Rgds,

Gadde.

Former Member
0 Kudos

HI Manohar,

Role is group of transactions,menu's,programs,reports and urls.

Profile is group of not more than 150 Authorization Objects.

<removed_by_moderator>

Thanks.

Raju.

Edited by: Julius Bussche on Feb 25, 2008 4:40 PM

0 Kudos

hello,

In the beginning there was the profile. The first time I was working with it was in SAP Release 2,2c. In the role you added the authorization objects with the values and that gives the authorizations. You then can add the role to the user (transaction su01). You even can nest profiles in profiles etc. It can give you quit a mess. SAP came in release 4.0 (also 3.3 i) with the profile generator. It gives you the possibility to create roles in describing way, with a menu function and more. After you create a role there is the authorization tab and on top the icon to generate profiles. SAP still uses the profiles to deal with the authorizations. So the profiles you do not have to worry about when using the transaction PFCG, it is a blessing. Keep in mind that if you made changes to a role that you always generate the profiles otherwise you have a mismatch with the roles and profiles and you do not now what the user is getting. Look into transaction su56 then you see how the authorization objects are connected to the user, you see the profiles and the roles.

Generated profiles can not be change by hand and if you add a role to the user the profiles are add automatically.

Look in su02 for profiles.

have fun and if you want to know more let me know.

Jan van Roest

WolfgangJanzen
Product and Topic Expert
Product and Topic Expert
0 Kudos

See: