Skip to main content

Notifications

Announcements

No record found.

Community site session details

Community site session details

Session Id :
Small and medium business | Business Central, N...
Suggested answer

Security Groups based on Entra with onPrem installation

(5) ShareShare
ReportReport
Posted on by 10
Hi all,
 
is it possible to create security-groups based on Entra (AAD) with a BC365 25.3 onPrem installation. The used instance is based on AccessControlService. Trying it I get always the answer 
 
It's interessing to see, that "normal" AD-Windows groups could also not be found (only with a indows-authetication).

KR GW
  • Suggested answer
    Jainam M. Kothari Profile Picture
    6,643 on at
  • Suggested answer
    YUN ZHU Profile Picture
    81,857 Super User 2025 Season 1 on at
    Security Groups based on Entra with onPrem installation
  • Suggested answer
    Khushbu Rajvi. Profile Picture
    15,085 Super User 2025 Season 1 on at
  • Suggested answer
    Holly Huffman Profile Picture
    5,919 on at
    Security Groups based on Entra with onPrem installation
    Hi there! Good morning, evening, or afternoon - depending on where you are :)
    Hope you are well today! 
     
    here are some thoughts / suggestions & apologies if you've tried these already! 
     
    •  Entra (AAD) Security Groups with On-Premises BC
      • Compatibility: Business Central on-premises installations typically rely on Windows Authentication or Access Control Service (ACS) for user authentication. However, Entra (AAD) integration is more common in cloud-based deployments.
      • Limitation: Directly using Entra (AAD) security groups in an on-premises setup may not be supported out of the box, especially if ACS is being used instead of Azure AD Authentication.
    •  Why "Normal" AD-Windows Groups Are Not Found
      • If you're unable to find Windows AD groups, it could be due to:
        • Authentication Mode: Ensure that the instance is configured to use Windows Authentication for group recognition.
        • Domain Trust Issues: Verify that the Business Central server is properly joined to the domain and can access the Active Directory.
    •  Possible Workarounds
      • Hybrid Identity Setup:
        • Use Azure AD Connect to synchronize on-premises Active Directory groups with Entra (AAD). This allows you to manage groups in AD while making them available in Entra.
        • Ensure that the synchronized groups are accessible in your Business Central environment.
      • Switch to Azure AD Authentication:
        • If feasible, consider switching from ACS to Azure AD Authentication for your Business Central instance. This would enable better integration with Entra (AAD) security groups.
      • Custom Development:
        • If neither of the above options works, you may need to explore custom development to bridge the gap between Entra (AAD) and your on-premises Business Central installation.
    • Next Steps
      • Verify your current authentication setup in Business Central Administration.
      • Check if Azure AD Connect is configured for your environment.
      • Consider consulting with your partner or Microsoft Support to explore hybrid identity solutions.
     

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

🌸 Community Spring Festival 2025 Challenge 🌸

WIN Power Platform Community Conference 2025 tickets!

Jonas ”Jones” Melgaard – Community Spotlight

We are honored to recognize Jonas "Jones" Melgaard as our April 2025…

Kudos to the March Top 10 Community Stars!

Thanks for all your good work in the Community!

Leaderboard

#1
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 294,303 Super User 2025 Season 1

#2
Martin Dráb Profile Picture

Martin Dráb 233,025 Most Valuable Professional

#3
nmaenpaa Profile Picture

nmaenpaa 101,158 Moderator

Leaderboard

Featured topics

Product updates

Dynamics 365 release plans