Skip to main content

Notifications

Announcements

No record found.

Customer experience | Sales, Customer Insights,...
Suggested answer

D365 Position Hierarchy - Read Only Access Changes?

(0) ShareShare
ReportReport
Posted on by 5
Hi.
 
I'm investigating implementing some extra security using the position hierarchy model.
I had looked into this several months ago & having done some research it seemed as if users would only have full write level access to data if the user the data was shared with was no more than one level below them in the hierarchy model.
Any further down the model and the records were read-only access only.
My testing at this time seemed to indicate that this was the case.
 
I did a few tests today now (months later) and I'm finding that the records now all seem to be writeable. Has the way Microsoft implement this type of security changed recently?
Or maybe there is another explanation for the fact that I am able to edit the records?
 
Below is a sample of how I have setup the position hierarchy...
I share a particular contact record with User Z, who is part of the Sub Branch D hierarchy (the lowest one).
I log into CRM as User X, who is part of the Main Branch hierarchy.
I have full write access to the contact record (all my security roles are set to have user level read and write access only - so it isn't the case that these roles supercede the position hierarchy).
Should I not have read-only access to this contact record, given that it is that many levels deep down the hierarchy?
 
Hierarchy 1: Main Branch
Hierarchy 2:  Sub Branch A (parent hierarchy is Main Branch)
Hierarchy 3:  Sub Branch B (parent hierarchy is Sub Branch A)
Hierarchy 4:  Sub Branch C (parent hierarchy is Sub Branch B)
Hierarchy 5:  Sub Branch D (parent hierarchy is Sub Branch C)
 
Thanks
  • Suggested answer
    Haig Liu Profile Picture
    Haig Liu Microsoft Employee on at
    D365 Position Hierarchy - Read Only Access Changes?
    Hi,
     
    The related explains in the document.
    The direct higher positions have Read, Write, Append, AppendTo access to the lower positions’ data in the direct ancestor path. The non-direct higher positions, have read-only access to the lower positions’ data in the direct ancestor path.
    matches the results of your last test.
     
    As for why it can be edited in this test, I think it's possible that it's the permissions given by the shared record.
     
    Finally,
    While the hierarchy security model provides a certain level of access to data, additional access can be obtained by using other forms of security, such as security roles.
     
    I hope this helps, but please let me know if you need anything else or if you have any other questions.
    thanks,
    Haig Liu

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Congratulations 2024 Spotlight Honorees!

Kudos to all of our 2024 community stars! 🎉

Meet the Top 10 leaders for December!

Congratulations to our December super stars! 🥳

Get Started Blogging in the Community

Hosted or syndicated blogging is available! ✍️

Leaderboard

#1
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 291,642 Super User 2024 Season 2

#2
Martin Dráb Profile Picture

Martin Dráb 230,371 Most Valuable Professional

#3
nmaenpaa Profile Picture

nmaenpaa 101,156

Leaderboard

Featured topics

Product updates

Dynamics 365 release plans