web
You’re offline. This is a read only version of the page.
close
Skip to main content
Community site session details

Community site session details

Session Id :
Customer experience | Sales, Customer Insights,...
Suggested answer

Security Role vs Direct Share Impact On Related Record Access

(2) ShareShare
ReportReport
Posted on by 81
Hello,
 
I have 2 Sales Users in BU 3 and 1 Customer Service User in BU 1.  BU 1 is the parent of BU 2 and BU 2 is the parent of BU 3.  Both Sales Users are in a security role that allows parent child create, read, update, append, append to, and assign.  When a Case is created it is owned by the Customer Service User and the Account on the Case is set to an Account owned by Sales User 1.  Sales User 1 can read the Case associated with their Account.  Sales User 2 can access the Account but cannot see the related Case.
 
If the Account owned by User 1 is Shared with User 2, User 2 can then read the Case.  I understand that it is because of the cascade share in the Account/Case relationship however, I don't think setting up a process to share/unshare Accounts is the best solution.
 
Is there a way to provide this through the Security Role?  Meaning, if I give the Users in BU 3 the privilege to read all of the Accounts in BU 3, I want them to be able to access the records associated with the Accounts in BU 3 as well, even if the related records are owned by someone in a higher BU.
 
Thank you,
 
Jim
I have the same question (0)
  • Vahid Ghafarpour Profile Picture
    11,974 Super User 2025 Season 2 on at
    Security Role vs Direct Share Impact On Related Record Access
  • Suggested answer
    Amit Katariya007 Profile Picture
    10,409 Super User 2025 Season 2 on at
    Security Role vs Direct Share Impact On Related Record Access
    Hello User,
     
    If both Sales Users are in the same Business Unit (BU 3) and have Parent: Child access levels, they should have the same access to records owned by other users in BU 3 or higher BUs. If there is a discrepancy, it is likely due to one of the following reasons:
     
    Steps to Diagnose and Resolve the Issue
     
    A. Perform a Check Access Audit on the Case Record
    Use the Check Access feature in Dynamics 365 to verify what permissions Sales User 2 has on the Case record.
     
    1. Open the Case record that Sales User 2 cannot access.
    2. Navigate to ribbon -> click on Check Access (available on the ribbon).
    3. Search for Sales User 2.
    4. Review the results:
     
    If it says No access, note which privileges are missing, by doing a search with Sales User 1.
     
    At least it will show you, using what roles Sales User 2 inheriting case permissions.
     
    B. Compare Security Roles of Both Sales Users
    Ensure that both Sales User 1 and Sales User 2 have identical security roles. Specifically:
    1. Go to Settings > Security > Users.
    2. Open the user profiles for Sales User 1 and Sales User 2.
    3. Compare the Security Roles assigned to each user.
     
    If Sales User 1 has additional roles, identify and examine them for privileges on the Case entity.
     
    Key Privileges to Check:
    Case: Read privilege (must be Parent: Child Business Units).
    Account: Read privilege (if cascading permissions are involved).
    Any custom security roles or team-level permissions.
     
    C. Inspect Team Membership
    If team-based security is in use:
    1. Check if Sales User 1 is part of any team(s) with access to the Case record.
    2. Go to Settings > Security > Teams.
    3. Look for any Owner Teams or Access Teams that might be granting additional access.
     
    Ensure Sales User 2 is part of the same teams if needed.
     
     
     
    Thank you,
    Amit Katariya
  • jim.corriveau@chesterton.com Profile Picture
    81 on at
    Security Role vs Direct Share Impact On Related Record Access
    Amit/VaHiX - Thank you for the responses.
     
    Amit,
     
    Both Sales Users are in the same security roles, on the same teams, and in the same BU.  I checked the access levels, the Sales User 1 that owns the Account has the same privileges to the related Case as they do to their Account.
     
    The Sales User 2 that gets read privileges to the Account through the security role because the role is Account/Read/Parent:Child.  Sales User 2 does not get any access to the related Cases.  I understand that Sales User 1 gets access to the related Cases because the Account is shared with them when they become the owner and the Account/Case relationship is set to cascade share.
     
    What I don't understand is why, if the Read privilege is granted to Sales User 2 through a security role to Sales User 1's Accounts why isn't the Read privilege inherited by Sales User 2 to the related Cases of those Accounts?
     
    Thank you,
     
    Jim
     
     

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Abhilash Warrier – Community Spotlight

We are honored to recognize Abhilash Warrier as our Community Spotlight honoree for…

Leaderboard > Customer experience | Sales, Customer Insights, CRM

#1
Rishabh Kanaskar Profile Picture

Rishabh Kanaskar 241

#2
Tom_Gioielli Profile Picture

Tom_Gioielli 164 Super User 2025 Season 2

#3
MVP-Daniyal Khaleel Profile Picture

MVP-Daniyal Khaleel 153

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans