We are trying to set up a user group able to operate only with sales and purchasing and not able to read or visualize any financial related data as balance sheet , bank statement or edit any critical parameter on system configuration. Apparently this is not straight forward and all default profile for sales and purchasing are giving extra permit we don't need.
We ask our consultant and they say we need to ''try and error'' and remove from a default user with default permit all unnecessary rights.
Is this the only way?
is there any default user setup available for specific roles as purchasing and sales that exclude all financial data visualization?
Thanks a lot
Hi, you can consider using the following two ways. One is to record the minimum permissions for operations, and the other is to exclude permissions you don't need.
How to create or modify permissions by recording your actions (Record Permissions)
Permission Exclusion (Exclude in Permission Set)
Hope this helps.
Thanks.
ZHU
hi
It is possible to create a user group with limited permissions for sales and purchasing in Microsoft Dynamics 365 Business Central. One approach is to create a custom security role that only grants the necessary permissions for sales and purchasing and excludes access to financial data.
To create a custom security role, you can use the "Permission Sets" and "Roles" pages in Business Central. Start by creating a new permission set for sales and purchasing that includes only the necessary permissions. Then, create a new role that is based on the "Basic User" role, but with the custom permission set assigned instead of the default permission set. Finally, assign the new role to the users who need access to sales and purchasing but not financial data.
You can also consider using the "Permission Sets" page to customize the permissions of the default sales and purchasing permission sets. To do this, you can remove the permissions related to financial data and save the modified permission set with a new name. Then, create a new role based on the "Basic User" role and assign the modified permission set to the role. This approach may be faster than creating a custom permission set from scratch, but it may be less flexible in the long term.
Overall, the "try and error" approach suggested by your consultant may be necessary to fine-tune the permissions of the custom role or permission set. It's important to thoroughly test the permissions to ensure that users have the necessary access to perform their job duties without accessing sensitive financial data.
DAniele
You basically have to create your own permission sets for this.
All the standard permission sets are built with more general access to the system.
Also remember that roles are not the same as permissions.
Maybe this can be of help.
Hi Bitu,
In standard Business central that is the Only way achieve your desired user access.
You have to do a lot of testing.
You can try the Recording Permission Sets Option. It will somewhat reduce the time.
But still You have to do the testing and all. Or you can subscribe anyone of the Application from the AppSource.
Stay up to date on forum activity by subscribing. You can also customize your in-app and email Notification settings across all subscriptions.
André Arnaud de Cal... 291,134 Super User 2024 Season 2
Martin Dráb 229,928 Most Valuable Professional
nmaenpaa 101,156