web
You’re offline. This is a read only version of the page.
close
Skip to main content
Community site session details

Community site session details

Session Id :
Finance | Project Operations, Human Resources, ...
Suggested answer

How to add security while exposing ServicesGroup to third party.

(2) ShareShare
ReportReport
Posted on by 62

Hello Experts,

I have created a new ServiceGroup that includes 5 services under it. I now need to provide authorization details, such as the client ID and client secret, so that third party application users can access my API to insert customers from their customer portal and other data in my application D365 F&o.

Currently, all my APIs are exposed, even though users may not know the names of the other services. However, this still leaves my data vulnerable. Can someone please guide me on how to restrict access so that users can only use the specific Service Group and the 5 APIs within it?

Thank you!

I have the same question (0)
  • André Arnaud de Calavon Profile Picture
    297,200 Super User 2025 Season 2 on at
    How to add security while exposing ServicesGroup to third party.
    Hi Arabic Translation,

    In this case, I do assume the integration is done with a service account. As you mentioned that the users don't have direct access to F&O, they will not be able to call these services outside of your app unless they have credentials of the service account.
  • Arabic Translation with item Profile Picture
    62 on at
    How to add security while exposing ServicesGroup to third party.
    @André Arnaud de Calavon I have created 5 services grouped under a single service group in D365 F&O. My company uses a Customer Portal for retail purposes, and the requirement is that whenever a user creates a new customer in the customer portal, the portal should call my API to send the customer data to D365 F&O. The users of the Customer Portal are not D365 F&O users.
  • André Arnaud de Calavon Profile Picture
    297,200 Super User 2025 Season 2 on at
    How to add security while exposing ServicesGroup to third party.
    Hi Arabic Translation.
     
    How are the services used? Are the users using another application for data entry?
    Note that services are not accessible unless access is provided to a user via a F&O security role. If these 5 services are grouped in one security role, you can assign this to the integration user or individual users. The service permissions can be maintained on the Service operations node on security privileges.
     
    For other APIs you can develop or configure different security roles.
  • Suggested answer
    NikolajSorensen Profile Picture
    1,780 on at
    How to add security while exposing ServicesGroup to third party.
    You should create a new privilege/security role which grant access only to the data entities/service operations/tables that are used to facilitate the communication and workload.
     
    This role should then be assigned to the account in D365FO used.
     
    BR
    Nikolaj 

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Mansi Soni – Community Spotlight

We are honored to recognize Mansi Soni as our August 2025 Community…

Congratulations to the July Top 10 Community Leaders!

These are the community rock stars!

Leaderboard > Finance | Project Operations, Human Resources, AX, GP, SL

#1
Sohaib Cheema Profile Picture

Sohaib Cheema 665 User Group Leader

#2
Martin Dráb Profile Picture

Martin Dráb 595 Most Valuable Professional

#3
Yng Lih Profile Picture

Yng Lih 558

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans