SAP TCodes · LessonBy Anitha M, SAP Trainer, 13 yrs · Published · SAP S/4HANA 2023 · all levels
PFCG
PFCG is the SAP transaction code for Role Maintenance (Profile Generator) (Basis/Security). It maintains authorization roles, the menu and authorization objects, and generates the profiles assigned to users, the heart of SAP authorization design.
Quick answer
PFCG maintains authorization roles, the menu and authorization objects, and generates the profiles assigned to users, the heart of SAP authorization design.
Key takeaways
- Role name (single/composite).
- Menu tab (transactions/apps in the role).
- Authorizations tab (objects and field values).
- Watch out: Using the wrong variant (create vs change vs display).
Purpose
It maintains authorization roles, the menu and authorization objects, and generates the profiles assigned to users, the heart of SAP authorization design.
Key fields and screen
- Role name (single/composite).
- Menu tab (transactions/apps in the role).
- Authorizations tab (objects and field values).
- Generate profile; user assignment tab.
Tips
- Add transactions to the menu, then maintain the pulled-in authorization objects.
- Regenerate the profile after any authorization change.
- Use SU24 defaults to reduce manual authorization work.
Common errors
- Forgetting to regenerate the profile (changes not effective).
- Over-broad authorizations (*) instead of least privilege.
- Missing objects causing SU53 authorization failures.
Common pitfalls
- Using the wrong variant (create vs change vs display).
- Missing prerequisite master data or authorization.
- Not checking the resulting document/log.
Practice challenge
+0 XPStreak ×0
Question 1 of 2
Which statement is true of PFCG?
Frequently asked questions
What does PFCG stand for in SAP?
PFCG is the SAP transaction code for Role Maintenance (Profile Generator) (Basis/Security). It maintains authorization roles, the menu and authorization objects, and generates the profiles assigned to users, the heart of SAP authorization design.
How is access to PFCG controlled?
Role name (single/composite). Menu tab (transactions/apps in the role). Authorizations tab (objects and field values).
Which related transactions work alongside PFCG?
Add transactions to the menu, then maintain the pulled-in authorization objects. Regenerate the profile after any authorization change. Use SU24 defaults to reduce manual authorization work.
What tends to go wrong with PFCG?
Using the wrong variant (create vs change vs display). Missing prerequisite master data or authorization. Not checking the resulting document/log.