addverk
Contact us
← Articles / Administration

Permission sets in Business Central

Addverk · 3 min read

Permission sets decide what a user may read, insert, modify, delete and run in Business Central. If everyone gets the same large set, it is easy, but also risky. The article explains how permission sets are built, how you make your own from the standard sets and how you can record what a role actually needs. There is also a short list of what you should check every year.

Licence, permission sets and structure

A user's access is decided by two things. The licence gives an overall frame, and the permission sets you assign give the detailed permissions. According to Microsoft Learn, all users must have at least one permission set before they can get into Business Central.

The permission set SUPER gives access to everything the licence allows. It is practical during setup, but should only be given to very few people.

A permission set consists of permissions to objects such as table data, pages and codeunits. For each one you can specify read, insert, modify, delete and execute permissions. The value Indirect means that the user may only use the object through another object, such as posting, and not directly themselves.

A set can also include other permission sets. You can then exclude individual permissions. If a permission is both included and excluded, the exclusion wins.

Make your own sets

Standard sets from Microsoft cannot be edited, but you can copy them into user-defined sets. When copying, you choose whether to copy as a reference, as a flat list or as a clone. Reference gives a set that follows Microsoft's changes. You can also turn on a notification if the original set changes.

Create sets based on job functions, for example sales, purchasing, warehouse and accounting, and assign them to security groups rather than to individual users.

Record and check permissions

It can be hard to guess which objects a task requires. Business Central can record your actions. Open a new permission set, choose Permissions and start recording. Carry out the task, stop the recording and add the recorded permissions to the set.

Review the list afterwards. The recording includes everything you touch, and you have to decide yourself whether the user may insert, modify or delete.

The Effective Permissions page on the user card shows which permissions a user has and where they come from. You need the permission set SECURITY or SUPER to see other users' effective permissions.

You can export sets to an XML file and import them into another tenant, and you can remove obsolete permissions from all sets. Changes to permissions can also be sent to telemetry.

Companies and annual review

When you assign a permission set to a user or a security group, you can specify a particular company. If you leave the field empty, the permissions apply to all companies. If the set should apply to several companies but not all, you have to add it for each company.

This is useful if you have subsidiaries where an employee may only work in one of them.

Once a year, review who has SUPER, which user-defined sets exist and whether permissions fit the roles. Use the permissions overview page to see which sets and users are connected to a given page or table.

Indirect permissions

Use the value Indirect where possible. A user can, for example, post sales documents without having full permission to modify the sales line table directly. Posting uses the permission, but the user cannot use it for anything else.

This gives better protection than giving direct permission to the whole table, but it requires testing for each role, so that you discover if a task is missing a permission.

Next steps

Addverk is a new Business Central partner. See our services and prices if you want help designing permission sets by role.

See services and prices
See services and prices
The newsletter about Business Central

Short, concrete e-mails about what customers most often ask us. We write when we have something worth reading.

Get a free licence review