
If your environment uses Azure AD security groups to control user access:
Verify that the user is a member of the Azure AD group assigned to Business Central.
Go to Microsoft Entra admin center → Groups → [BC access group] → Members and ensure the user is included.