Proceed as follows:
Use a profile name which DOES NOT begin with T.
Using user administration, you can restrict the authorization to particular user groups.
Using profile administration, you can exclude further authorization objects , for example, for HR data. If you want your generated authorization profiles to begin with a letter other than T, you should inform your profile administrator.
How the Three Administrators Work Together
The authorization data administrator creates an activity group, chooses transactions and maintains authorization data. In the Profile Generator, authorization data administrators merely save the data since they are not authorized to generate the profile, and accepts the default profile name T_....
The authorization profile administrator calls Transaction SUPC and sets the following parameters on the next screen: the administrator flags All activity groups and restricts the selection by entering the ID of the activity group to be processed. On the following screen, the administrator selects Display profile to check the data. If the data is correct, the administrator generates the authorization profile.
Finally, the user administrator assigns the activity group to a user (using User maintenance). The authorization profile is added to the user master record.

No authorization profile beginning with T may contain critical (S_USER* objects) authorization objects.