52
In Business Central on-prem we can manage user permissions based on Azure AD security groups, but in the SaaS version this is not an option. If a tenant has many users it is a very time consuming task to add permissions to each user. The current process is to add a BC license to users then update users from O365 in BC and then add/modify user groups. The preferred process would be to create new users in Azure AD/O365 portal and add relevant security groups and licenses. As today a users with a valid BC license logging into https://businesscentral.dynamics.com/ will be created automatically in BC and based on a mapping between AD security groups and BC user groups they should get the relevant user groups assigned including company limitations
STATUS DETAILS
Needs Votes
Ideas Administrator

Thank you for your feedback. Currently this is not in our roadmap; however, we are tracking it and if we get more feedback and votes, we may consider it in the future. 

 

Sincerely, 

Dmitry Chadayev

PM, Microsoft 


Comments

K

@kenneth, have you tried AAD Security Group teams or AAD Office Group teams in the SaaS version (D365)? I created AAD Security Group teams in D365 and linked them to security group's Object IDs in AAD. Then I assigned security roles to each AAD Security Group team in D365. Then I add users to appropriate security group in AAD. When they log into D365 for the first time, security roles are automatically assigned to them based on their membership of the D365 team via AAD security group. I hope this makes sense to you.

I'm waiting to upgrade our AAD to P1 level so I can assign D365 license to security groups in AAD so that license is automatically assigned to everyone in the security groups.

Category: Tenant Administration