D365ConsultantDivision of Sataware
D365ConsultantDivision of Sataware
Access control

Permissions and security roles in Business Central, explained for controllers and admins.

Permissions and security roles in Business Central decide what each person can see, create, change and post. Getting them right protects segregation of duties and makes auditors comfortable. Getting them wrong means everyone has SUPER, or people hit permission errors in the middle of month end. This guide covers the building blocks and how you assign access in current versions. It also covers the limits a licence places on top, and a practical way to design roles.

Permission sets
the building block of all access
Licence first
no permission can exceed what the licence allows
Profiles
shape the home page, not what a user may do
Padlocks locked onto a railing in black and white

Building blocks of permissions and security roles in Business Central

A permission grants a type of access to an object such as a table, page, report or codeunit. Table data has four access types: read, insert, modify and delete. Code objects use execute. You can grant each one directly or indirectly. Indirect means the user can touch the data only through a specific permitted object, such as a posting routine that writes to ledger entry tables.

Permission sets bundle those permissions into a named collection. Microsoft ships many system permission sets, and extensions from Microsoft and AppSource publishers add their own. Administrators can also create user-defined permission sets. A permission set can include other sets, which keeps design tidy. For example, you can build a purchasing clerk role from several smaller sets.

Current versions also let you exclude permissions or whole sets within a composed set. So you can start from a broad set and remove specific access. Use that carefully and document it. Exclusions are harder to read at a glance than a set that only adds.

Who controls what: licence, permissions and profile

Layer
What it decides
Where it is managed
Licence
The ceiling: which areas a user may use at all, such as Essentials, Premium or Team Member
Microsoft 365 admin center, reflected in Business Central
Permission sets
What the user can read, insert, modify, delete or execute within that ceiling
Permission Sets and user cards in Business Central
Security groups
Assignment of permission sets to many users at once through a Microsoft Entra group
Security Groups page in Business Central, groups in Microsoft Entra
Security filters
Which records within a table a user may see, based on field values
Filters on permissions within a permission set
Profile (role)
Which role center and page layout the user sees
Profiles and user settings; it grants no access

Assigning security roles and permissions in current Business Central

Older versions used user groups to hand the same permission sets to several people. Microsoft replaced user groups with security groups and permission set assignment. So check which version you run before you follow older instructions online. A security group in Business Central links to a Microsoft Entra security group. Every member of that group then receives the permission sets you give the group.

You can also assign permission sets directly on a user card. Each assignment can cover one company. Leave the company blank, and it applies to every company in the environment. That field matters in multi-company setups. A clerk who posts in one entity should not automatically post in all of them.

For new users, an administrator can use the License Configuration page. It sets the default permission sets for each licence type. That way people start with sensible access, not whatever the standard defaults happen to be.

Facts that trip up administrators

  • โœ“SUPER gives full access to data, but a Team Member licence still limits what that user can do.
  • โœ“Changing a profile or role center changes what a user sees, not what they may do.
  • โœ“Features that require Premium, such as manufacturing, are not available to Essentials users through permissions.
  • โœ“A user needs SECURITY or equivalent rights to manage other users' permissions without being SUPER.
  • โœ“Partner accounts signed in through delegated administration cannot perform every task an internal admin can.
  • โœ“Extensions add their own permission sets, and an administrator must assign them before users can work with the new features.

Designing Business Central security roles that survive an audit

  1. 1

    List job roles, not people

    Write down the roles in the business and the tasks each one performs. Examples are AP clerk, AR clerk, buyer, warehouse receiver and controller. People change; roles are stable.

  2. 2

    Mark the conflicts

    Identify combinations that should not sit with one person. Creating vendors and approving payments is one such pair. Posting journals and approving them is another. These drive segregation of duties.

  3. 3

    Compose permission sets per role

    Build each role from system permission sets plus small user-defined ones. Use the permission recorder to capture exactly what a task needs when a standard set is too broad.

  4. 4

    Assign through groups

    Put users in Microsoft Entra security groups that map to roles. Then assign permission sets to those groups in Business Central, scoped to the right companies. That keeps permissions and security roles in Business Central tied to real jobs.

  5. 5

    Check effective permissions

    Use the Effective Permissions view to confirm what a user can really do once licence limits and all assignments combine. Then test with a real login in a sandbox.

  6. 6

    Review on a schedule

    Review who holds SUPER and other sensitive sets at least at each year end. Also review whenever someone changes role or leaves the company.

Permissions and security roles in Business Central: controller questions

Should anyone other than administrators have SUPER?

No, ideally only a small number of administrators hold SUPER, and not for day-to-day finance work. Giving SUPER to solve permission errors is common and removes the controls auditors look for. The better fix is to find the missing permission, often with the permission recorder. Then add it to the right role. It takes a little longer once and saves repeated audit findings.

Can we restrict a user to certain customers or departments?

Yes, security filters can limit which records a user sees. They work on field values, such as a salesperson code or a dimension. They work, but they add complexity and can affect performance on large tables. Use them where the business truly needs record-level restriction, and test reports carefully afterwards.

More questions on Business Central security and permissions

What happened to user groups?

Microsoft replaced user groups with security groups and direct permission set assignment in newer versions. Security groups link to Microsoft Entra groups, so IT manages membership where it already manages accounts. Upgrading from an older version? Plan how user group assignments move into the new model, and test it.

Why does a user with the right permissions still get an error?

Usually the licence does not allow the action, or the permission set applies to a different company. An extension's permission set may also be missing. Indirect permissions can also be the cause when a custom object touches a table directly. The Effective Permissions page shows where access comes from. That usually points straight at the gap.

Do permissions carry into Power BI or Excel exports?

Only partly. Excel exports from a page contain only what the user could see there. So Business Central permissions apply at export time. A published Power BI report reads data as the account that set up its refresh. Each viewer's own Business Central permissions do not limit what they see. Secure those reports with row-level security in Power BI.

Talk to us about your project.

Tell us what you run today and what has to change. A senior consultant replies with a written next step.

Get started

Start with a scoping conversation.

Thirty minutes with a senior consultant - not a sales call. We look at how you run today, tell you plainly whether Business Central is the right fit, and give you an honest sense of scope, cost and timeline before you commit to anything.

What happens next
1
We review your enquiry
A consultant reads it before the call - no discovery questionnaire to fill in.
2
30-minute scoping call
Your processes, your current systems, and the gaps that matter most.
3
Written summary & estimate
Indicative phases, licence counts and a cost range, in writing within three days.
Reply within one business day
NDA signed before discovery on request
No obligation, no cost for the scoping call
Microsoft-certified consultants only
Request your scoping call
Four fields. A consultant replies within one business day.
No cost
Your details stay with our consulting team - never shared, never added to a mailing list.