Migrate all underlying system privileges of a compatibility role to a user-defined role.
Compatibility roles are immutable, but they can be migrated in their entirety to a new user-defined role. Once migrated, the compatibility role is automatically dropped. This process is systematically equivalent to individually granting each underlying system privilege to a user-defined role, then manually dropping the compatibility role.
During migration:
When migrating a compatibility role, the new role name cannot already exist, or begin with the prefix SYS_ and end with the suffix _ROLE.
| Compatibility Role | Statement | 
|---|---|
| SYS_AUTH_DBA_ROLE | ALTER ROLE SYS_AUTH_DBA_ROLE MIGRATE TO new_dba_role_name, new_sa_role_name, new_sso_role_name | 
| Any other compatibility role | ALTER ROLE compatibility_sys_role_name MIGRATE TO new_role_name | 
ALTER ROLE SYS_AUTH_DBA_ROLE MIGRATE TO Custom_DBA_Role, Custom_SA_Role, Custom_SSO_Role
ALTER ROLE SYS_AUTH_OPERATOR_ROLE MIGRATE TO Custom_Operator_Role
In both examples, all users, underlying system privileges, and roles granted to the original roles are automatically migrated to the new roles, then SYS_AUTH_DBA_ROLE, SYS_AUTH_SA_ROLE, SYS_AUTH_SSO_ROLE and SYS_AUTH_OPERATOR_ROLE are dropped.