I have read a lot and wen't through the docs pages on data entities a few times. If I missed the relevant page - please let me know.
After using the open in excel as SysAdmin for a data entity that is created with a per company purpose (meaning the primary company context has been set), I can simply remove the "Company" filter:

This causes a problem for security. Scenario: Some data from some table is displayed on some form. The menu item for the form exists in a security privilege. The Data Enity for some table is also added to the privilege so that the user can also open in Excel. The privilege is assigned to a user, but the user is restricted to certain companies. The user can then bypass this restriction by removing the filter in excel. In other words he is restricted in AX, but not in Excel.
Is there a way to restrict this? Or does it come down to that giving a user access to a data entity means the user has access to data in all companies?
- I am not sure whether I am only capable of doing this because of my SysAdmin role - I tried to check with another (restricted) user, but I couldn't get the add-in to work without my SysAdmin role (I didn't try very hard).
- XDS will be a bit overkill in my opinion
- I noticed new properties Operational Domain and Subscriber Access Level (for a data entity). I could not find any documentation on what they do, so I tested it with a few combinations - I didn't notice any differences.
Please let me know if I am unclear
Thanks for reading