Access with Microsoft 365 Licenses FAQ

Note

Azure Active Directory is now Microsoft Entra ID. Learn more

Security groups are new to Business Central in 2023 release wave 1. They're similar to the user groups that this article mentions. Like user groups, administrators assign the permissions to the security group that its members need to do their jobs.

User groups will no longer be available in a future release. You can continue using user groups to manage permissions until then. To learn more about security groups, go to Control Access to Business Central Using Security Groups.

Users can access Business Central data in Microsoft Teams using their Microsoft 365 license. This article answers frequently asked questions from administrators, consultants and others. Developers should refer to the Developer FAQ. For questions about integrating Business Central with Microsoft Teams, go to Teams FAQ.

Can I proactively configure different starting permissions for different groups of users?

Not at this time. Business Central only allows configuring one group of permissions that are assigned to all Microsoft 365 users when they sign into Business Central for the first time.

Can I proactively configure permissions, profiles, and settings for individual users before they sign in?

Yes. It can be achieved through security groups. By applying a security group to an environment, you define the total set of users that have access to that environment. This security group can include users with a Business Central license and users with a Microsoft 365 license. When you next update users from Microsoft 365 in the Users list, the Microsoft 365 user records will be created. You can then assign user groups, permissions, profiles, and other settings before they've signed in.

After a user signs in, can I change which objects they have access to?

Yes. After a user has signed in for the first time and their user record has been provisioned, administrators manage those users just like any other Business Central user. For example, they can add or remove permissions to different objects. If you change the permission sets assigned to the Microsoft 365 license in the License Configuration page, the change will only affect the next users that sign in for the first time.

How do I prevent access to sensitive tables?

Business Central offers a powerful and flexible permission model where administrators can define permission sets that grant access to specific objects, business processes or entire roles. To prevent access to sensitive tables, you can create custom permission sets that exclude permission to sensitive objects. For more information about exclude permissions, see Create a permission set.

Instead of customizing the License Configuration, can I customize a user group?

Yes. Adding permission sets to the Microsoft Teams Internal Users user group in Business Central, has the same net effect as adding permission sets to the Microsoft 365 license, as long as the Microsoft 365 license continues to map to this user group. This approach has the added benefit that permission sets are always synchronized with members of the group whenever you modify the user group.

When a Business Central user shares a record in Teams, do they grant new permissions?

No. This action isn't the same as sharing a link to a SharePoint document where the person sharing the document can choose to grant permission to others. In Business Central, only administrators can configure and assign permissions. When compared to sharing SharePoint documents, it's the equivalent of choosing the option to “Share to people with existing access”.

Does this feature support row-level security?

Yes. Even though a person accessing a record in Teams with their Microsoft 365 license may have the correct table and page object permissions, row-level permissions will be enforced if it' been implemented for that table.

If I configure permissions that include write access, will users be able to write in Teams?

If you configure Business Central to assign a permission set that includes insert, modify, or delete access to one or more objects, users with that permission set will still not be able to write in Teams when they only have a Microsoft 365 license. The Business Central service enforces read-only access no matter what insert, modify, or delete permission you assign.

Even though Business Central provides this level of protection, we still recommend that you avoid permission sets with write access. Doing so prevents issues further downstream when users change role or acquire new licenses.

See also

Overview of Business Central Access with Microsoft 365 licenses
Set Up Access with Microsoft 365 Licenses