web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Small and medium business | Business Central, N...
Suggested Answer

Permissions to limit edit access on dimension values from one dimension and read access to the rest

(5) ShareShare
ReportReport
Posted on by 28

I'm trying to configure Business Central SAAS to allow selected users to edit only one Dimension (e.g., Department) while keeping all other Dimensions view-only.


I currently have one permission set with three additional permission sets embedded into it:
  1. Base Permission Set: Verified with the only users have no access to dimenions or dimension values tables
  2. Read-Only Permission Set: This permission set gives read access to all users to dimension and dimension values tables
  3. Permission Set (with Security Filter) to allow R/I/M/D on Dept Dimension Values:
    • Read/Insert/Modify/Delete access on table 349
    • Security filter applied on the Department dimension  (Dimension Code = DEPT)
The result is that users can edit dimension values from all dimensions.  It appears to ignore the security filter to allow editing on only the Dept dimension values.
 
Any suggestions on what I'm missing would be appreciated.
I have the same question (0)
  • Suggested answer
    YUN ZHU Profile Picture
    101,995 Super User 2026 Season 1 on at
    It appears that the other permission sets include the permissions you've disabled.
    Try using Permission Exclusion.
    More details: Dynamics 365 Business Central: Permission Exclusion (Exclude in Permission Set)
    Thanks.
    ZHU
  • Suggested answer
    OussamaSabbouh Profile Picture
    17,676 Super User 2026 Season 1 on at
    Hello ,
     
    This isn’t a setup mistake, it’s a BC permission model limitation: permission sets are additive, and security filters don’t restrict write access if another permission set already grants access to the same table. Since users also have read access to Dimension Value (Table 349) without a filter, BC effectively ignores the filtered R/I/M/D set and allows editing all dimensions. You can’t achieve “edit only one dimension, read-only others” with permission sets alone; the practical solutions are to remove direct Dimension Value access and control changes via custom code/pages, or block changes using event subscribers unless Dimension Code = 'DEPT'. This has to be handled in code or process, not permissions.
     
    Regards,
    Oussama Sabbouh
  • Suggested answer
    Dhiren Nagar Profile Picture
    2,890 Super User 2026 Season 1 on at
    Hi,
     
    The issue is with the 2nd permission set, which is basically overriding your 3rd permission set.
    So business central always reads the permission which is giving highest level of permission. Even if you use Exclude and that exclude is in different permission set it will override. Exclude only works when used in single permission set.
     
    Regards,
    Dhiren.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Launch!

Jump in, show your community spirit, and win prizes!

Women in Power Builds Momentum

Expanding mentorship, skilling, and AI innovation

Congratulations to the May Top 10 Community Leaders

These are the community rock stars!

Leaderboard > Small and medium business | Business Central, NAV, RMS

#1
OussamaSabbouh Profile Picture

OussamaSabbouh 2,050 Super User 2026 Season 1

#2
YUN ZHU Profile Picture

YUN ZHU 1,351 Super User 2026 Season 1

#3
Grigorios Mavrogeorgis Profile Picture

Grigorios Mavrogeorgis 1,200 Super User 2026 Season 1

Last 30 days Overall leaderboard

Featured topics

Microsoft Training Manuals

Product updates

Dynamics 365 release plans