Skip to Content
avatar image
Former Member

Difference between Role & Profile

Hi

I created users through SU01 and assigned the profiles e.g SAP_ALL, SAP_NEW etc.

When i created profile using profile generator and assign, it assign to Role & Profile .

Can you please clearify for me the concept beteen Role & Profile

Thanks

Add comment
10|10000 characters needed characters exceeded

  • Get RSS Feed

5 Answers

  • avatar image
    Former Member
    Jul 21, 2006 at 09:27 PM
    Add comment
    10|10000 characters needed characters exceeded

  • avatar image
    Former Member
    Jul 23, 2006 at 09:27 AM

    Access (values for auth fields of objects) is in both cases granted via profiles (key fields of usrbf2).

    The roles of PFCG are just a tool ontop of profiles which generate them and associate them to the role. When you assign a user to a role, PFCG will technically assign the generated profiles to the user, not the role.

    Add comment
    10|10000 characters needed characters exceeded

  • avatar image
    Former Member
    Apr 14, 2009 at 01:27 PM

    Hi Juan,

    The Simple answer is :

    Roles and profiles are literally same.The only difference is using profile we canu2019t restrict a user up to activity level whereas we can do so using roles.

    Add comment
    10|10000 characters needed characters exceeded

    • Former Member Former Member

      Lovely old thread...

      As Wolfgang already indicated way back when... profiles are destined for potential obsoleteness.

      SAP has long been advocating not to use profiles (except the generated ones). UME's pointing to ABAP systems don't use it either for some time now.

      Since release 46C the new buffering method already supports authorizations only, or permissions...

      All it needs is a tool ontop of it for creating them, administrating it and assigning them in the various component systems => e.g. centrally in an IdM...

      I think the importance of meaningfull role naming conventions and the S_USER_OBJ, VAL, TCD will play a more meaningfull "role" as well, also for security admins.

      SAP seems to have been conceptually lining up for this in the ABAP stack, as it will no doubt play an important role as the user store for the component systems.

      > It may be simple but it is completely incorrect.

      Perhaps even completely obsolete.

      I have also noticed some of the technical settings changing in the USR* tables, in addition to their fields and their keys, in the latest releases.

      Cheers,

      Julius

  • avatar image
    Former Member
    Jun 11, 2013 at 04:22 AM

    This message was moderated.

    Add comment
    10|10000 characters needed characters exceeded

  • Dec 22, 2013 at 06:43 PM

    This message was moderated.

    Add comment
    10|10000 characters needed characters exceeded