Skip to main content

Notifications

Announcements

No record found.

Community site session details

Community site session details

Session Id :
Microsoft Dynamics 365 | Integration, Dataverse...
Unanswered

Azure AD Group integration for Business Unit / Teams and role based assignment in D365 CE... General Question

(0) ShareShare
ReportReport
Posted on by 5

Have a general question, I've come across a few D365 instances in my travels and just wondered why more people don't use Azure AD groups to manage users and security. I know the MS documentation on it is sparse at best, there are a few (quite old) blogs / posts )like this one Dynamics 365 and AD groups. Dynamics 365 has some security features… | by Ben "The Hosk" Hosking | Medium) about people who have used it (but without going to deep into their own use case / situation).

The general question / discussion I wanted to ask was "Why not - the feature has been around for ages? " - Is it just the lack of documentation around the feature or is there some giant gotcha involved in using it that a casual administrator (such as myself) would simply not have been exposed to. 

I'm mostly just curious at this point.. I have a situation where I believe it may benefit the administrative side of the organisation, but I don't want to be that guy that saves "Team A" a days work a week by giving "Team B" an extra days work a week and calling it a win. 

Any responses welcome. 

  • Community Member Profile Picture
    on at
    RE: Azure AD Group integration for Business Unit / Teams and role based assignment in D365 CE... General Question

    Hi Whatsamattr,

    Based on my guess, the Azure AD groups feature requires a trip to the Azure portal, which many people will find cumbersome and may run into permission issues when accessing the Azure portal!

  • PerezAguiar Profile Picture
    Microsoft Employee on at
    RE: Azure AD Group integration for Business Unit / Teams and role based assignment in D365 CE... General Question

    Hey!

    There might be several reasons to explain this:

    a) People not aware of the functionality.

    b) Separation of roles:  sometimes the Dynamics/PowerPlatform administrators don't have permissions over the AD (which is controlled by a different group of people) and companies don't want to provide such access.

    c) Confusion on how it works or how they could benefit from using security groups to restrict access to environments (Test environments or Production environments) as well as AAD Teams + Automatic Roles (which would be inherited).  

    d) For some small deployments where you have just a few sales persons + less sales managers, using this approach might require more initial work (despite being "cleaner" to maintain).  This approach (using security groups + AAD Teams + Inherited roles) is most commonly deployed when there are large Dynamics deployments (several environments or several different teams).

    Regards,

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Ramesh Kumar – Community Spotlight

We are honored to recognize Ramesh Kumar as our July 2025 Community…

Congratulations to the June Top 10 Community Leaders!

These are the community rock stars!

Announcing the Engage with the Community forum!

This forum is your space to connect, share, and grow!

Leaderboard > Microsoft Dynamics 365 | Integration, Dataverse, and general topics

#1
Adis Profile Picture

Adis 136 Super User 2025 Season 1

#2
Sohail Ahmed Profile Picture

Sohail Ahmed 81

#3
Jonas "Jones" Melgaard Profile Picture

Jonas "Jones" Melgaard 77 Super User 2025 Season 1

Product updates

Dynamics 365 release plans