web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

No record found.

News and Announcements icon
Community site session details

Community site session details

Session Id :
Microsoft Dynamics CRM (Archived)

I have a very odd permissioning issue going on.

(0) ShareShare
ReportReport
Posted on by

I have three environments.  A development, testing, and production environment.

After last porting a solution from dev to testing, users with a specific custom security role no longer had access to view Accounts of any kind.  When looking at a list of accounts, all the user sees is a message stating "You do not have permission to access these records.  Please contact your Dynamics CRM Administrator."

This failure does not occur with this security role in my dev or production environments.  The security role grants organization-wide read privileges on Accounts.

What could be the problem?

*This post is locked for comments

  • Andre Margono Profile Picture
    2,602 on at

    Have you got the security role included in the solution?

    Do you have anything else like introducing a field level security on fields that are on a view?

  • RaviKashyap Profile Picture
    55,410 Moderator on at

    Hi,

    Can you download the log file and share the details. It is possible that is is missing some other permission in prod. Log file may give you the exact details.

    Hope this hleps.

  • bpoindexter Profile Picture
    on at

    Andre,

    Yes to having the role in the solution.

    There is some field level security involved with the people who have the custom security role assigned.  For the Account entity, only two out of box fields, Open Deals and Open Revenue, are subject to FLS.  The FLS profile does restrict the users using the custom security role from seeing those two fields.

    What is odd is the way that it's not affecting the production environment, and as far as I have been able to determine to this point, they're the same.

    FYI, I assign a different role to one of the affected users in my testing environment and it allowed them to view Account records.

  • bpoindexter Profile Picture
    on at

    Ravi,

    Unfortunately, when opening a list of Accounts, there is no window pop up with the error message of the type that allows you to download a log file.  What happens is the error message I posted in my original post appears in place of the grid you would expect to see.  There is otherwise no error pop up windows with a link to download log files.

  • Verified answer
    ashlega Profile Picture
    34,477 on at

    Hi,

     could you confirm a few things:

    - Whether your security role is, actually, configured correctly in production

    - If the users have been assigned that security role

    - If you have any plugins running on retrieve multiple  of the account entity?

    PS. Since you seem to be using CRM on-prem, you might also try tracing:

    support.microsoft.com/.../how-to-enable-tracing-in-microsoft-dynamics-crm

    Thanks,

    Alex

  • bpoindexter Profile Picture
    on at

    Alex,

    The security role is configured correctly in production as far as I can tell.  They are not experiencing this issue in Production.

    The user has been assigned the security role in question.

    I do not have any plugins running in the background when I check the system jobs screen.

    I will try to use tracing, but historically that's only helped me when a pop up error message is being generated.

  • Verified answer
    bpoindexter Profile Picture
    on at

    I have resolved the immediate issue.

    I took Alex's advice and enabled tracing.  What I found was that the user having difficulty did not have read permission on the Process entity.  The trace log was throwing errors to this effect.  Granting read permission resolved the problem.

    This is mystifying, however, because the user does not have this permission in production and it's causing no issues there.  The only thing I can conclude is that the most recent plugin I built (not ported to production yet) creates some kind of condition where this permission is needed.  The same user also doesn't have this permission in development environment and is not having an issue there either, though my dev and test environment can't be compared; the security apparatus is different.  Testing environment's security arrangement mirrors production, where dev does not.

    It doesn't really make sense because that particular new plugin does not run directly against an account object...it only runs when a record of a custom entity (which has a many-to-one relationship with account) is created.  During its processing it does read a related account object, but again, the plugin isn't even running so it doesn't make sense.

    One interesting thing I did find is that, logged in as the user having problems, I could open an account record directly.  I got a lot of errors when I did, and our business process flows were not visible.  It has the appearance that the lack of the read permission being granted on Process disabled access to a business process flow.  Same as described though, it doesn't make sense since the user doesn't have that read permission in production.

    So, I don't know the cause, but I do have a solution.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Winners!

Congratulations to our community stars!

Women in Power Builds Momentum

Expanding mentorship, skilling, and AI innovation

Congratulations to the August Top 10 Community Leaders

These are the community rock stars!

Leaderboard > 🔒一 Microsoft Dynamics CRM (Archived)

#1
ScottDurow Profile Picture

ScottDurow 2

Last 30 days Overall leaderboard

Featured topics

Product updates

Dynamics 365 release plans