web
You’re offline. This is a read only version of the page.
close
Skip to main content
Community site session details

Community site session details

Session Id :
Microsoft Dynamics CRM (Archived)

Help configuring Security Roles (read permissions on activities)

(0) ShareShare
ReportReport
Posted on by

I need to configure CRM Online to fulfill the following requirements:

  1. Executive Team members to see all emails owned by all users regardless of business unit
  2. Non-Executive Team members to see all emails tracked to contacts they own (including emails tracked by members of Executive Team). i.e. they will not be able to see emails tracked to Contacts owned by Executive Team members. 

Any ideas?

 

*This post is locked for comments

I have the same question (0)
  • Community Member Profile Picture
    on at
    RE: Help configuring Security Roles (read permissions on activities)

    1. Activity Read privilege set to Organizations

    2. For these users, Activity Read privilege set to User - they won't see any emails but their own.

    Otherwise - will need to setup a hierarchy of your business units to reflect something as follows:

    Parent BU - houses all Executive Team members

    Child BU - all non-exec team members - Activity Read priviledge set to User, BU, or Parent/Child BU (not Organization level)

    If you have a complex BU hierarchy already - I suggest looking at using Positional/Managerial security available in CRM Online - www.powerobjects.com/.../hierarchical-security-model-dynamics-crm-2015-2

  • Community Member Profile Picture
    on at
    RE: Help configuring Security Roles (read permissions on activities)

    Thanks for the response Darren but I don't my requirements were clear enough.

    "Allow both Executive and Non-executive team members to view all emails but prevent Non-executive from seeing emails tracked to Contacts Owned by a member of the Executive team".

  • Verified answer
    Community Member Profile Picture
    on at
    RE: Help configuring Security Roles (read permissions on activities)

    Yep thats a difference maker.  Know in CRM ownership is determined at the record itself.  Security is based on these ownership fields.  

    When you apply privilege level for Activities in a security role - its only based on the context of who owns the Activity - NOT on the regarding record (or Party List members on the activity)

    I am not aware of way to achieve this exactly with Security Roles in CRM.  I still think the closest you could get would be if you use Managerial or Positional security function - however - because of the fact above - would have to get creative in other ways.

    The manual approach to acheive this would be to use Access Teams.  Non-exec members would be part of a given Access Team.  If that access team is added to a Contact, those members would gain access to activities on the Contact.

    www.powerobjects.com/.../access-teams-in-dynamics-crm-2013

    This can be managed manually through the UI - and may be too cumbersome for end users to manage.  You can get into coding/scripting to manage this automatically.  This kind of security customization can take a lot of effort. msdn.microsoft.com/.../dn481569.aspx

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Abhilash Warrier – Community Spotlight

We are honored to recognize Abhilash Warrier as our Community Spotlight honoree for…

Leaderboard > 🔒一 Microsoft Dynamics CRM (Archived)

#1
Community Member Profile Picture

Community Member 2

#1
UllrSki Profile Picture

UllrSki 2

#3
SC-08081331-0 Profile Picture

SC-08081331-0 1

Last 30 days Overall leaderboard

Featured topics

Product updates

Dynamics 365 release plans