addverk
Contact us
← Articles / Administration

Security groups and users

Addverk · 3 min read

Assigning permission sets to each individual user takes time and creates errors when someone changes role or leaves. Security groups solve that by collecting users in groups that receive permissions. In Business Central online they are linked to Microsoft Entra groups. The article explains how it works and what you should check yourself in your tenant. There is a short checklist at the end.

Groups in Entra, permissions in Business Central

You create a group in Microsoft Entra, for example in the Microsoft 365 admin center. In Business Central you open the Security Groups page, create a new one and choose the Entra group in the Microsoft Entra Security Group field.

Then you assign permission sets to the group. All members get them. Microsoft Learn says that this way of managing permissions can also be reused across Dynamics 365 applications.

Users and groups per role

There is an important caveat. Members only appear on the group if they have also been created as users in Business Central. An Entra group therefore does not in itself give access without a user and a licence.

Licences are assigned in the Microsoft 365 admin center. Check on Microsoft Learn how users are created by licence and how they get their default permissions.

A practical model is to create one security group per job function and link one or more permission sets to each. When a colleague changes role, you change the group membership in Entra rather than fixing permissions from scratch.

You can specify a particular company when you assign, if the permissions should only apply there. If you leave the field empty, they apply to all companies.

Environment access and control

Security groups can also be used to control who may sign in to a specific environment. That is a different function from permission sets and is described on a separate Microsoft Learn page about access to environments. Check it if you want to restrict access to, for example, a sandbox with a copy of production.

Use the Security Groups page to see members and assigned permission sets. The action Permission Sets by Security Group shows more detail. On the user card you can see security group memberships and permission sets from groups. The Effective Permissions page shows whether a permission comes from a group.

  • Review group membership at every departure or role change.
  • Keep SUPER to very few people.
  • Test each group with a test user.
  • Note who owns each group.

Example of a model

This is an example, not a recommendation: Create the groups BC-Sales, BC-Purchasing, BC-Warehouse, BC-Accounting and BC-Admin in Entra. Link each to one or more user-defined permission sets in Business Central. Assign employees to groups in Entra, and let Business Central read the membership.

Keep only two or three people in BC-Admin, and do not give them SUPER if the role does not require it.

Departures and delegated administrators

Remove the employee from the groups, block or remove the user in Business Central, and remove the licence in the Microsoft 365 admin center. Check that the person does not own job queue entries or scheduled reports that will stop working.

Users from a partner can appear as delegated administrators. They are created automatically in Business Central when they sign in, and their actions can be traced in the change log. They appear with a pseudonym and not a name if the partner uses granular permissions.

Agree with the partner which permissions they should have, and review the list of users regularly.

External access

Partners can sign in as delegated administrators. They appear in the user list with a pseudonym, and their actions are logged. Check your agreement on what a partner may do, and review the list regularly.

Addverk is a new Business Central partner. See our services and prices if you want help tidying up users and permissions.

See services and prices
See services and prices
The newsletter about Business Central

Short, concrete e-mails about what customers most often ask us. We write when we have something worth reading.

Get a free licence review