Skip to main content

Notifications

Community site session details

Community site session details

Session Id :
Small and medium business | Business Central, N...
Answered

BC on-premise user permission management through Azure AD Groups - can it be done?

(0) ShareShare
ReportReport
Posted on by 4,209 Super User 2025 Season 1

Hello,

I want to understand if this is actually manageable for on-premise environment, or this is intended only for the BC cloud/online option.

We have Windows groups that are synced with Azure AD groups. 
In BC we create a user card for the group with type Windows Group, and add permissions. 

On the user Card - there are no permissions. 

When user logs in through link that uses Windows authentication - all works great - the only downside is the additional credential entering at login.
When we add the Microsoft 365 e-mail in the user card, and he uses a link that uses O365 authentication - in the BC user card we see that the Status becomes Active - so the login was successful, but the user doesn't have any permissions. 


Is there a way that BC can read the users Azure AD group memberships and assign permissions to user based on Azure AD group? (in Azure the BC app has been given permissions to read users, group memberships etc.)

Thanks for Your time!

  • KasparsSemjonovs Profile Picture
    4,209 Super User 2025 Season 1 on at
    RE: BC on-premise user permission management through Azure AD Groups - can it be done?

    Thanks, Marco,

    so it seems this is not working yet like I want to :)

  • Verified answer
    Marco Mels Profile Picture
    on at
    RE: BC on-premise user permission management through Azure AD Groups - can it be done?

    Hello,

    This is on the ideas site and also under discussing within product group:

    experience.dynamics.com/.../

    Hope this clarifies.

  • KasparsSemjonovs Profile Picture
    4,209 Super User 2025 Season 1 on at
    RE: BC on-premise user permission management through Azure AD Groups - can it be done?

    Hi, Daniele,

    we tried this with BC 19.5 with no success.

    and also we tried this with latest BC21.2 : learn.microsoft.com/.../authenticating-users-with-azure-ad-openid-connect

    The results were the same as described in initial post.

    I cannot tell for sure - there is a possibility that we might have configured something wrongly - but tried this several times and the result is always the same. So looking if anyone has succeeded this for on-prem BC.

  • DAnny3211 Profile Picture
    9,276 Moderator on at
    RE: BC on-premise user permission management through Azure AD Groups - can it be done?

    hi

    look this

    learn.microsoft.com/.../authenticating-users-with-azure-active-directory

    DAniele

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Announcing the Engage with the Community forum!

This forum is your space to connect, share, and grow!

🌸 Community Spring Festival 2025 Challenge Winners! 🌸

Congratulations to all our community participants!

Adis Hodzic – Community Spotlight

We are honored to recognize Adis Hodzic as our May 2025 Community…

Leaderboard > Small and medium business | Business Central, NAV, RMS

#1
Sohail Ahmed Profile Picture

Sohail Ahmed 1,200

#2
YUN ZHU Profile Picture

YUN ZHU 1,006 Super User 2025 Season 1

#3
Mansi Soni Profile Picture

Mansi Soni 864

Overall leaderboard

Featured topics

Product updates

Dynamics 365 release plans