IT CanvassTalk to an advisor
SAP administration · LessonReviewed by Arjun, SAP Solution Architect · Updated · Published · SAP S/4HANA 2023 · all levels

SAP Profiles

An authorization profile is the generated set of authorizations that actually gets assigned to a user, produced from a role in the Profile Generator (PFCG). Understanding profiles clarifies how role design becomes real access.

Quick answer

In SAP you design a role in PFCG and generating it produces the authorisation profile that is actually stored against the user and checked at runtime. Change a role and forget to regenerate the profile, and the change never reaches anyone. SAP_ALL grants everything and belongs only to controlled emergency access; manual profiles from SU02 are the legacy exception.

Key takeaways
  • Understanding profiles clarifies how role design becomes real access.
  • Watch out: Forgetting to regenerate the profile after role changes.

Profiles vs roles

You design a role in PFCG (menu + authorization objects and values); when you generate it, SAP produces an authorization profile containing those authorizations. The profile (not the role directly) is what is stored against the user and checked at runtime. In practice you always work through roles, and the profile is generated for you.

Generated vs manual profiles

Modern SAP uses generated profiles from PFCG (the Profile Generator). Older or special cases used manually-created profiles (SU02), but generated profiles from roles are the standard, they keep the menu, authorizations and profile in sync.

The importance of regeneration

A common pitfall: you change a role’s authorizations but forget to regenerate the profile, so the change never reaches users. After any authorization change, regenerate and confirm users are updated (a user-master comparison may be needed).

SAP_ALL and SAP_NEW

SAP_ALL is the all-powerful profile granting everything, appropriate only for tightly-controlled emergency/firefighter use, never for normal users. Recognising and controlling such powerful profiles is a key security responsibility.

Common pitfalls

  • Forgetting to regenerate the profile after role changes.
  • Assigning SAP_ALL to normal users.
  • Mixing manual and generated profiles confusingly.
Already working on SAP and stuck on a live ticket?Get an expert SAP developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support