
Quick Answer
Managing user roles and permissions in Microsoft Dynamics 365 Business Central involves adding users, assigning appropriate licenses, using permission sets and security groups to control access, and using Profiles (Roles) to tailor the workspace. In Business Central, profiles and roles primarily shape the user experience, while licenses and permission sets determine what data and functions a user is authorized to access. Applying least-privilege access helps protect sensitive data, reduce unnecessary permissions, support compliance, and ensure employees have the access required for their jobs.
Businesses can use Microsoft Dynamics 365 Business Central to connect and manage essential processes, from financial management and operations to customer service, within a unified ERP environment. Leveraging the application effectively requires properly setting up and managing users, roles, and permissions. This guide explains how to manage Business Central users, permission sets, security groups, profiles, company restrictions, security filters, and effective permissions.
What Are User Roles and Permissions in Business Central?
In Business Central, user roles and permissions serve different purposes. Profiles, shown as Profiles (Roles) in the interface, determine the workspace and Role Center a user sees. Permission sets determine which Business Central objects and actions the user can access. Administrators can assign permission sets directly to users or through security groups, subject to the user's license entitlements.
For example, a sales employee can use a sales-focused Role Center and receive permission to create and update sales orders. A finance employee can have a finance-focused workspace and permission to access financial reports or invoices. The Role Center organizes the user experience, while the assigned permissions control access to data and functions.
Why Are User Roles and Permissions Important in Business Central?
Business Central can contain sensitive employee, customer, operational, and financial data. Incorrect permission settings can give unauthorized users access to sensitive information, creating potential security risks. Following the principle of least privilege helps organizations limit access to the data and functions each user needs for their job.
Many companies also operate in industries with regulatory or audit requirements. Properly configured Business Central permissions, security groups, and access reviews can support an organization's access-control, accountability, and compliance practices.
How Do Permissions Work in Business Central?
Business Central uses multiple layers of access controls to define what users can access and which actions they can perform. A user's license establishes the functionality they are entitled to use, while permission sets, security groups, profiles, company restrictions, and security filters provide more specific control over their access.
Licenses and Entitlements
Licenses determine the functionality and Business Central objects a user is entitled to access. In Business Central online, entitlements are based on the user's Microsoft license or assigned Microsoft Entra role. Permissions can then further restrict access within those entitlements.
Permission Sets
Permission sets group related access permissions for specific Business Central objects, such as tables, pages, reports, and codeunits. They define what users can access within the system and which actions they can take, from viewing and adding data to changing, removing, or executing it. Administrators can use predefined permission sets or create customized permission sets to meet specific business requirements.
Security Groups
Security groups simplify permission management for multiple users. Administrators can assign permission sets to a security group, and those permissions apply to its members. This is useful when several employees require the same level of access.
Profiles and Role Centers
Profiles, which are referred to as Profiles (Roles) in the Business Central interface, define the workspace and Role Center presented to different types of users. They can be based on a user's business role or department and help tailor the user interface to their responsibilities. Profiles affect the user experience and navigation, while permissions determine what the user is actually authorized to access.
Company Restrictions
Permission sets can be configured to apply either to an individual company or across all companies. Leaving the Company field blank allows the permission set to apply across companies, while specifying a company limits its scope to that company.
Security Filters
Business Central security filters provide more granular, record-level control. They can restrict users to specific records within a table, such as allowing a salesperson to access only records associated with their assigned salesperson code. Security filters are configured within permission sets.
Effective Permissions
A user's effective permissions reflect the combined permissions granted directly and through security groups, while still being limited by the user's license entitlements. Reviewing the Effective Permissions page helps administrators understand a user's actual access, identify the source of a permission, review applied security filters, and spot permissions that may be broader than intended.
IES Tip: Review Effective Permissions after a user changes roles, joins or leaves a security group, or reports unexpected access. This can help quickly pinpoint the permissions responsible for allowing or blocking a specific user action.
Adding Users in Business Central
For Business Central online, users are typically created and assigned licenses in the Microsoft 365 admin center. Business Central can then create or update user records based on the Microsoft 365 users and their assigned licenses.
1. Navigate to Users > Active users, then choose Add a user.
2. Go to the Set up the basics pane and fill in the basic user information:
1. Name: First and last name, user name, and display name.
2. Domain: Add the domain for that user's account.
3. Password settings: Select either an auto-generated password or manually provide a strong password.
4. Choose whether to require a password change at the user’s initial sign-in.
3. Go to the Assign product licenses pane. Choose the appropriate license and location for that user.
4. Expand Apps and select or deselect the apps users have a license for, then click Next.
5. Go to the Optional settings pane and expand Roles if you need to make the user an administrator. You can also expand Profile info to add extra information about the user.
6. Click Next to review the settings and make any additional updates. Once you're done, click Finish adding and then Close.
The platform provides an option for adding users in bulk.
1. Navigate to Users > Active users and select Add multiple users.
2. When the Add list of users page appears, select the option to upload users via a spreadsheet or CSV file.
3. After selecting I'd like to upload a CSV with user information, download the sample CSV file. Confirm that your spreadsheet follows the specified column headings.
4. Once you've formatted your CSV file correctly, select Browse to choose the location of your file, then click Open.
5. Select Next to go to the Licenses page. Choose the location, licenses, and apps you want applied to the new users, then click Next.
6. Review all selections before selecting Add users.
Managing Permissions in Business Central
After adding users, you can apply the appropriate permissions for their job roles. You can create a permission set and assign it to multiple users simultaneously.
IES Tip: Assign permissions based on each user's responsibilities and avoid granting broader access than necessary.
1. Go to the search icon and enter Permission Sets. Click the applicable link.
2. Select New. Once a new line appears, add all necessary fields.
3. Select Permissions. Once the Permission Set page appears, go to the Type field to include or exclude permissions for the object.
4. You can define the access level for each permission using the following options:
1. Read Permission
2. Insert Permission
3. Modify Permission
4. Delete Permission
5. Execute Permission
The Permission Sets page allows administrators to view existing permission sets and create or modify custom ones. After a permission set is created, it can be assigned to individual users or security groups.
1. Go to the Search icon and enter Users to pull up the applicable link.
2. Choose the user you wish to add a permission set to.
3. Look in the Permission Sets FactBox to see any permissions already applied to the user.
4. Click Edit to open the User Card page.
5. Go to the User Permission Sets FastTab and enter all required fields on a new line.
You can add permission sets to multiple users using the following steps:
1. Select the Search icon and enter Users to pull up the applicable link.
2. Go to the Users page and select Permission Set by User.
3. Click the username checkbox on relevant permission set lines to assign them to the user. You can select the All Users checkbox to assign a permission set to all applicable users.
Using Security Groups to Manage Business Central Permissions
Security groups make it easier to manage permissions for multiple users. Administrators can apply permission sets to security groups, allowing all members to receive the assigned permissions. This is useful for teams with similar responsibilities, such as sales or purchasing.
For Business Central online, security groups are based on Microsoft Entra security groups. For on-premises deployments, Business Central can link to Windows Active Directory groups, depending on the authentication configuration.
To assign permissions to a security group:
1. Go to Search and enter Security Groups, then select the relevant page.
2. Select New and link the group to the appropriate Microsoft Entra or Windows group.
3. Select the security group and choose Permissions.
4. Assign one or more permission sets to the group.
5. If needed, specify a company to limit the permission set to that company. Leave the Company field blank to apply it across all companies.
Using security groups allows administrators to update permissions centrally. When a permission set assigned to a group changes, the updated permissions apply to the group's members.
IES Tip: Use security groups when multiple users need the same permissions. This makes access easier to manage as team members change roles. Review group membership regularly to ensure users have only the access they need.
Managing User Profiles and Role Centers
Profiles in Business Central determine how a user's workspace is organized based on their role or responsibilities. The Role Center in Business Central provides a role-specific workspace with relevant tasks, activities, and information. A profile controls the Role Center, navigation, available actions, and other elements of the user interface.
Administrators can assign profiles according to each user's job responsibilities. For example, a sales employee can use a sales-focused Role Center with relevant tasks and information, while an accountant can have a finance-oriented workspace.
Profiles determine the user's workspace and interface, whereas permissions determine what they can access and do. Those controls are managed through licenses, permission sets, and security groups.
IES Tip: Choose profiles that match users' job functions, but remember that profiles control the interface while permission sets control access. Review profiles regularly to ensure they continue to align with users' current responsibilities.
Best Practices for Managing Users and Permissions in Business Central
Before setting up access, perform a role analysis of your company's workflows, structure, and job responsibilities. This helps identify the data and functions each job requires and makes it easier to apply least-privilege access.
Key Business Central permission management best practices include:
- Use least privilege: Grant only the access a user needs to perform their job.
- Use security groups for shared access: When multiple users need the same permissions, manage them centrally through security groups where appropriate.
- Review Effective Permissions: Check actual access after job changes, permission-set changes, or security-group changes.
- Limit SUPER access: Because SUPER provides broad access within the scope of a user's license, reserve it for users who genuinely need that level of administrative access.
Internet eBusiness Solutions can help businesses design permission structures and custom roles that align with their business processes. Contact one of our representatives to learn more about our services.
Auditing and Monitoring Permission Changes
Regularly reviewing access helps administrators identify unnecessary or unexpected permissions. Administrators should periodically review direct permission assignments, security group membership, user-defined permission sets, company-specific assignments, and Effective Permissions to confirm that access still matches each user's responsibilities.
For Business Central online, Microsoft also provides audit and telemetry capabilities for reviewing permission-related changes. Organizations with formal security or compliance requirements should define a recurring access-review process rather than relying only on one-time permission setup.
FAQs


