web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

No record found.

Community site session details

Community site session details

Session Id :
Microsoft Dynamics CRM (Archived)

Restricting access to activities from the owner of the parent record

(0) ShareShare
ReportReport
Posted on by

We are implementing a Dynamics CRM 2016 solution for a company which has very specific security requirements.

All of the Organisation records (or Accounts) have organization-wide (or global) read, append and append to rights. We then have Business Unit (local) read access on the child Contact records. This has been achievable using the security roles and works as expected.

Our stumbling block has come in the form of Activities. The business requirements are that a user in a higher business unit (CEO's Office) can add an activity regarding a contact record which is owned by a user in a lower business unit (Sales Department) which is NOT then visible to the owner of the contact record.

I’ve come across this article http://garethtuckercrm.com/2013/04/24/implicit-shares-in-microsoft-crm-2011/ which explains there is a background process which uses the 'Reparent' cascade option whenever an activity is set regarding a parent record (on creating the activity record) to essentially give the owner of the parent record access to the child record regardless of their security role.

From my understanding there is no way to configure the cascade options on activity records as they are an 'out of the box' solution. Please let me know if this is not the case!

I have seen this post https://community.dynamics.com/crm/f/117/t/162833 which has similar requirements to ours and was wondering if there were other scenarios people have come across and the work-arounds people have used.

*This post is locked for comments

I have the same question (0)
  • Areti Iles Profile Picture
    User Group Leader on at

    Hi Lynda, I might be misunderstanding what you need here, but wouldn't it work if you edited the security role of the Sales Department so that the 'Activity' entity was set to Business Unit level? Any records created by the CEO would be against his/her business unit (or at Organisation level one would assume) so the Sales Department users wouldn't be able to see them?

  • Community Member Profile Picture
    on at

    Hi Areti, thanks for your reply. Yes we thought that would work too - but even when the user only has access to just the activity records they own, they still get cascaded rights to any activities added to the contact record they are the owner of.

  • Verified answer
    Community Member Profile Picture
    on at

    Just as an update on the above - we have found that we can change the relationship type of Contact:Phone Call/Email/Task/Letter etc. (1:N) from being parental to configurable cascade.

    Has anyone got any advice or warnings we should be aware of about taking this approach?

  • Areti Iles Profile Picture
    User Group Leader on at

    Hi Lynda,

    I think from memory (but could be wrong - hopefully someone will correct me if so), you can change the relationship type but it only applies from that moment on for new records that are created, i.e. historic/existing records will not be updated automatically so the 'old' settings will apply and the records will be visible based on those.

    Worth doing a quick check if you've changed it to see what has happened to old records...

  • Community Member Profile Picture
    on at

    Hi Areti, thanks for the reply. Yes we have found that changing the relationship type to 'Configurable Cascade' has solved our problem. Thankfully we are developing a fresh system so this won't effect live data - phew!

    Thanks for the help.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Neeraj Kumar – Community Spotlight

We are honored to recognize Neeraj Kumar as our Community Spotlight honoree for…

Leaderboard > 🔒一 Microsoft Dynamics CRM (Archived)

#1
SA-08121319-0 Profile Picture

SA-08121319-0 4

#1
Calum MacFarlane Profile Picture

Calum MacFarlane 4

#3
Alex Fun Wei Jie Profile Picture

Alex Fun Wei Jie 2

Last 30 days Overall leaderboard

Featured topics

Product updates

Dynamics 365 release plans