How to Create & Copy user role in SAP system
A role is you assign to your users the user menu that is displayed after they log on to the SAP system. Roles also contain the authorizations that users can use to access the transactions, reports, Web-based applications, and so on that are contained in the menu.
Roles should be created in Y & Z Only. From A to X. These are by default used for SAP.
Overview of Role
- Menu
- Profile
- Authorization / Authorization Objects
- Organization level /Field and field values.
- Users
Menu
In the menu, one can add SAP Transaction codes (Standard or custom), Reports, Web-based applications and etc.
Profile
Profiles are the objects that actually store the authorization data.
Authorization / Authorization Objects
An entry in the user master record as part of an authorization profile. Authorization consists of full or generic values for the authorization fields in an authorization object. The combination determines which activities a user can use to access certain data.
Authorization Objects
Combinations of authorization fields, which represent data and activities, are used to grant and check authorizations. Authorization objects are grouped together in authorization object classes.
Organization level
This defines actually the organizational elements in SAP for example Company Code, Plant, Planning Plant, Purchase organization, Sales organization, Work Centers, etc.
Field and field values
In order to restrict the access one can control the values in the respective Authorization Objects. (For example Authorization object F_BKPF_BUK: Accounting Document: Authorization for Company Codes, contains the relation between fields: BUKRS = Company Code and ACTVT = Activity).
Users
One should assign the role to a specific user with user comparison so they can access the particular T-code and authorization.
Types of Roles in SAP
- Individual / Common Role.
- Master and Derived Role.
- Composite Role.
Individual / Common Role
Base role with the desired Authorizations as per the purpose of the role; with the organizational levels as Company Code, Plant, Sales Organization, Profit Center and etc.
Master and Derived Role
Master Roles
With Transactions, Authorization Objects, and with all organizational level management.
Derived Roles
With organizational level management and Transactions and Authorization Object copied from Master Role.
Composite Role
It’s a collection of many derived roles or single roles.
How to create a role in the SAP system?
Solution
Execute T-code PFCG
![create a role in SAP system 1](https://www.esds.co.in/kb/wp-content/uploads/2022/02/1-1.png)
Create a role with starting Y or Z. As shown below.
Then click on sing role.
![create a role in SAP system 2](https://www.esds.co.in/kb/wp-content/uploads/2022/02/2.png)
Add the Description and save.
Go to the Menu tab click on transaction add the T-code.
![create a role in SAP system 3](https://www.esds.co.in/kb/wp-content/uploads/2022/02/3.png)
Enter the T-code and click on Assign Transactions.
![create a role in SAP system 4](https://www.esds.co.in/kb/wp-content/uploads/2022/02/4.png)
Go on Authorizations Tab and click on Propose profile names.
Then Click on Change Authorization Data
![create a role in SAP system 5](https://www.esds.co.in/kb/wp-content/uploads/2022/02/5.png)
Click on Yes
![create a role in SAP system 6](https://www.esds.co.in/kb/wp-content/uploads/2022/02/6.png)
Click on Continue.
![create a role in SAP system 7](https://www.esds.co.in/kb/wp-content/uploads/2022/02/7.png)
Click on generate.
![create a role in SAP system 8](https://www.esds.co.in/kb/wp-content/uploads/2022/02/8.png)
Go on the Users Tab and add the users.
![create a role in SAP system 9](https://www.esds.co.in/kb/wp-content/uploads/2022/02/9.png)
Click on User Comparision and click on YES and Full Comparssion.
![create a role in SAP system 10](https://www.esds.co.in/kb/wp-content/uploads/2022/02/10.png)
How to copy role in SAP system
Execute T-code PFCG
![create a role in SAP system 11](https://www.esds.co.in/kb/wp-content/uploads/2022/02/11.png)
Mention Role which wants to copy
And tap on the copy role option (or) GoTO Role and Copy (Shift+F11)
![create a role in SAP system 12](https://www.esds.co.in/kb/wp-content/uploads/2022/02/12.png)
Select a new role name and click on Copy all
![create a role in SAP system 13](https://www.esds.co.in/kb/wp-content/uploads/2022/02/13-1024x453.png)
New Role Copied and then click on Change
GoTo Authorizations tab and click on Edit authorization data
Generate Profile Name
![create a role in SAP system 14](https://www.esds.co.in/kb/wp-content/uploads/2022/02/14.png)
Click on change
![create a role in SAP system 15](https://www.esds.co.in/kb/wp-content/uploads/2022/02/15.png)
Tap Generate profile
![create a role in SAP system 16](https://www.esds.co.in/kb/wp-content/uploads/2022/02/16.png)
Click on generate
![create a role in SAP system 17](https://www.esds.co.in/kb/wp-content/uploads/2022/02/17.png)
Once a profile has been generated
GoTo User tab Maintained user ID and click on User Comparison
![create a role in SAP system 18](https://www.esds.co.in/kb/wp-content/uploads/2022/02/18.png)
Click on yes
![create a role in SAP system 19](https://www.esds.co.in/kb/wp-content/uploads/2022/02/19.png)
Click on Full Comparison
![create a role in SAP system 20](https://www.esds.co.in/kb/wp-content/uploads/2022/02/20.png)
Role Copied and assign to user
![](https://www.esds.co.in/kb/wp-content/uploads/2022/02/21.png)