Navigating Security, Permissions, and User Groups in Dynamics 365 Business Central

by | August 2, 2018 | Dynamics 365 Business Central

As a Business Central Administrator, one of your roles is to manage permissions for users & groups of users within your organization. You may be a Finance or Operations manager, an IT manager, an Office Manager, or the Business Central Administrator for your organization.  This blog was written with you in mind!  Whether you are going through a Business Central implementation, or have already implemented Business Central and are looking to align security & permissions to the roles & responsibilities of users within your organization, we have geared this content for you.

User Groups

User Groups in Dynamics 365 Business Central are an easy way to group together permissions that will be common among multiple users.

Let’s say you have a customer service group that you would like to grant access to Business Central, but you want to limit their access to Customers and Sales Orders only. You can create a new User Group and assign the appropriate permission sets to that group.

Navigating D365BC

When you’re creating the group, you can also assign the group a “Default Profile” – or role center the user will see when they log in.

Navigating D365BC

Once the User Group is created, you can assign permission sets to that User Group

Navigating D365 BC

Navigating D365 BC

You can quickly view the permission sets associated with each User Group in the “Permission Sets” Fact Box on the right side of the User Group Window.

Navigating D365BC


If you’d like to know more about what is defined in each permission set assigned to your User Groups, you can view this data by viewing the “Permission Set by User Group” matrix.

In this view, the permission sets are listed in the left-hand rows, while the User Groups are listed as columns at the top. If I select a row for the permission set I’m curious about, I can see in each column whether the User Group in question includes that permission set.

Navigating D365 BC

With the permission set highlighted, you can see the permissions to Table Data and other objects in the right-hand Fact Box for Permissions.

Navigating D365 BC

Alternatively, if you drill down into “Permissions” link in the top left corner, you can see a full matrix of the associated permissions, including whether the permission is read/ write/ modify/delete, and direct/indirect.

Navigating D365 BC


Assigning Permissions to Users

Users can be assigned permission either through User Groups, through direct permission set assignment, or both.

In the User Card, there are tabs for both User Groups and User Permission Sets. You can see the full list of User Groups assigned to that user.

The User Permission Sets tab of the user card will automatically inherit the permission sets associated with the User Groups assigned.

As an example, in my Cronus environment, user MATTS has recently been assigned the new “BC NEW CS” User Group we created earlier. When this User Group was assigned, each permission set that was added to the User Group is automatically added to the User.

Navigating D365 BC

Let’s say that in addition to the permissions in the Customer Service Group, I also want Matt to be able to view items. If this is a permission that I want to give Matt, but I don’t want to give to the entire Customer Service Group, I can add that permission on top of the permissions from his User Group.

In this way, I can “build on” to the User Groups by adding an individual permission for this user.

Navigating D365 BC

Assigning Permissions by Company

Another feature of the User Card is that you can assign User Groups and Permission Sets to Users by company. This will only apply if you have multiple companies in Business Central, but if you do (and you have different users in each company) this feature is very helpful.

When assigning the User Group or the User Permission Set, there is a field for “Company.” If the User needs to work in only one company, you can define the company at the time the groups or permissions are assigned. If the user needs permission in more than one company, you can leave the field blank to assign to “all” companies.

Taking our previous example, let’s say that I want to assign the Customer Service User Group to Matt for all companies, but I only want him to be able to view items in CRONUS. Here is what that set up would look like:

Navigating D365 BC

If you are interested in learning more about navigating security, permissions, and user groups in Dynamics 365 Business Central, here are additional resources:


For upcoming releases in Dynamics 365 Business Central Security, see the Business Application release notes:


Related Posts


Submit a Comment

Your email address will not be published. Required fields are marked *

Upcoming Events


07oct12:00 pm1:00 pmThe Three Paths to Business Central from Dynamics GP

08oct11:00 am12:00 pmConfab with Stoneridge - Livestream - The Vision and Strategy of Microsoft Business Systems

14oct10:00 am10:30 amThe Modern Manufacturer - Managing Complex Cost Modeling

14oct12:00 pm12:30 pmGenerating Custom Inspection or Process Forms

19octAll Day22Stoneridge Connect Fall 2020

22oct11:00 am12:00 pmConfab with Stoneridge - Livestream - Stoneridge Connect Recap

28oct10:00 am10:30 amThe Modern Manufacturer - Engineering Change Management: Introduction of NEW Functionality for Manufacturers Using Dynamics 365


11nov10:00 am10:30 amThe Modern Manufacturer - Tears and Trauma of MRP

About Stoneridge
Stoneridge Software is a unique Microsoft Gold Partner, with emphasis on partner. With specialties in Microsoft Dynamics 365, Microsoft Dynamics AX, Microsoft Dynamics NAV, Microsoft Dynamics GP and Microsoft Dynamics CRM, we focus on attracting the most knowledgeable experts in the field to our team, and prioritize delivering stellar solutions with maximum impact for your business. At Stoneridge, we are deeply committed to your results. Each engagement is met with a dedicated team, ready to provide thorough, tailored, and expert service. Based in Minnesota, we intentionally “step into your shoes,” wherever you are. We focus on what you care about, and develop trusting, long-term relationships with our clients.

Subscribe To Our Blog

Sign up to get periodic updates on the latest posts.

Thank you for subscribing!