Hi. I am new to Dynamics and had to take control of our crm in a hurry. I know some things and watched some online courses in linkedIn learning and other resources but not quite well in the using and administering the system. this system had a previous admin and due to some managerial changes had to leave our company.
the point is I've asked to remove his security roles from the system. but when I remove his roles, some of automated taskes in process flow don't work due to lack of security privileges for the previous admin. he is not owner of any of the ques, business units, workflow processes and nothing. but still if he has no security roles, for example you won't be able to close a case. the error log is below.
help me understand what is the problem and how to solve it please. thanks
---the Error Detail----------------------------------------------------------
<s:Envelope xmlns:s=/http://schemas.xmlsoap.org/soap/envelope//><s:Body><s:Fault><faultcode>s:Client</faultcode><faultstring xml:lang=/en-US/>SecLib::CrmCheckPrivilege failed. Returned hr = -2147220943 on UserId: a7af3dba-e064-e911-80c5-0050569b7de7 and PrivilegeType: Read</faultstring><detail><OrganizationServiceFault xmlns=/http://schemas.microsoft.com/xrm/2011/Contracts/ xmlns:i=/http://www.w3.org/2001/XMLSchema-instance/><ActivityId>81240b22-0955-41a1-97e3-d833c5b1034c</ActivityId><ErrorCode>-2147220943</ErrorCode><ErrorDetails xmlns:a=/http://schemas.datacontract.org/2004/07/System.Collections.Generic//><Message>SecLib::CrmCheckPrivilege failed. Returned hr = -2147220943 on UserId: a7af3dba-e064-e911-80c5-0050569b7de7 and PrivilegeType: Read</Message><Timestamp>2023-12-03T07:00:48.4898036Z</Timestamp><ExceptionRetriable>false</ExceptionRetriable><ExceptionSource i:nil=/true//><InnerFault><ActivityId>81240b22-0955-41a1-97e3-d833c5b1034c</ActivityId><ErrorCode>-2147220943</ErrorCode><ErrorDetails xmlns:a=/http://schemas.datacontract.org/2004/07/System.Collections.Generic//><Message>SecLib::CrmCheckPrivilege failed. Returned hr = -2147220943 on UserId: a7af3dba-e064-e911-80c5-0050569b7de7 and PrivilegeType: Read</Message><Timestamp>2023-12-03T07:00:48.4898036Z</Timestamp><ExceptionRetriable>false</ExceptionRetriable><ExceptionSource i:nil=/true//><InnerFault><ActivityId>81240b22-0955-41a1-97e3-d833c5b1034c</ActivityId><ErrorCode>-2147220943</ErrorCode><ErrorDetails xmlns:a=/http://schemas.datacontract.org/2004/07/System.Collections.Generic//><Message>SecLib::CrmCheckPrivilege failed. Returned hr = -2147220943 on UserId: a7af3dba-e064-e911-80c5-0050569b7de7 and PrivilegeType: Read</Message><Timestamp>2023-12-03T07:00:48.4898036Z</Timestamp><ExceptionRetriable>false</ExceptionRetriable><ExceptionSource i:nil=/true//><InnerFault><ActivityId>81240b22-0955-41a1-97e3-d833c5b1034c</ActivityId><ErrorCode>-2147220943</ErrorCode><ErrorDetails xmlns:a=/http://schemas.datacontract.org/2004/07/System.Collections.Generic//><Message>SecLib::CrmCheckPrivilege failed. Returned hr = -2147220943 on UserId: a7af3dba-e064-e911-80c5-0050569b7de7 and PrivilegeType: Read</Message><Timestamp>2023-12-03T07:00:48.4898036Z</Timestamp><ExceptionRetriable>false</ExceptionRetriable><ExceptionSource i:nil=/true//><InnerFault><ActivityId>81240b22-0955-41a1-97e3-d833c5b1034c</ActivityId><ErrorCode>-2147220960</ErrorCode><ErrorDetails xmlns:a=/http://schemas.datacontract.org/2004/07/System.Collections.Generic//><Message>Principal user (Id=a7af3dba-e064-e911-80c5-0050569b7de7, type=8) is missing prvReadEntitlement privilege (Id=0925bd85-61f1-485c-b34f-240504216bd1)</Message><Timestamp>2023-12-03T07:00:48.4898036Z</Timestamp><ExceptionRetriable>false</ExceptionRetriable><ExceptionSource i:nil=/true//><InnerFault i:nil=/true//><OriginalException i:nil=/true//><TraceText i:nil=/true//></InnerFault><OriginalException i:nil=/true//><TraceText i:nil=/true//></InnerFault><OriginalException i:nil=/true//><TraceText i:nil=/true//></InnerFault><OriginalException i:nil=/true//><TraceText i:nil=/true//></InnerFault><OriginalException i:nil=/true//><TraceText>
[Microsoft.Crm.Service.ObjectModel: Microsoft.Crm.Service.ObjectModel.CasePostUpdatePlugin]
[4b723f64-b443-422b-a269-34ad739f19ee: CasePostUpdatePlugin]
</TraceText></OrganizationServiceFault></detail></s:Fault></s:Body></s:Envelope>
------------------------------------------------------------------------------------
UserId is the old admin after I remove security roles.
CasePostUpdatePlugin is this a plugin? I don't see any plugin by this name in my environment.
this is the most problem in my system right now and can't find the reason.