web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

No record found.

Community site session details

Community site session details

Session Id :
Customer experience | Sales, Customer Insights,...
Suggested Answer

D365 Position Hierarchy - Read Only Access Changes?

(0) ShareShare
ReportReport
Posted on by 7
Hi.
 
I'm investigating implementing some extra security using the position hierarchy model.
I had looked into this several months ago & having done some research it seemed as if users would only have full write level access to data if the user the data was shared with was no more than one level below them in the hierarchy model.
Any further down the model and the records were read-only access only.
My testing at this time seemed to indicate that this was the case.
 
I did a few tests today now (months later) and I'm finding that the records now all seem to be writeable. Has the way Microsoft implement this type of security changed recently?
Or maybe there is another explanation for the fact that I am able to edit the records?
 
Below is a sample of how I have setup the position hierarchy...
I share a particular contact record with User Z, who is part of the Sub Branch D hierarchy (the lowest one).
I log into CRM as User X, who is part of the Main Branch hierarchy.
I have full write access to the contact record (all my security roles are set to have user level read and write access only - so it isn't the case that these roles supercede the position hierarchy).
Should I not have read-only access to this contact record, given that it is that many levels deep down the hierarchy?
 
Hierarchy 1: Main Branch
Hierarchy 2:  Sub Branch A (parent hierarchy is Main Branch)
Hierarchy 3:  Sub Branch B (parent hierarchy is Sub Branch A)
Hierarchy 4:  Sub Branch C (parent hierarchy is Sub Branch B)
Hierarchy 5:  Sub Branch D (parent hierarchy is Sub Branch C)
 
Thanks
I have the same question (0)
  • Suggested answer
    Haig Liu Profile Picture
    Microsoft Employee on at
    Hi,
     
    The related explains in the document.
    The direct higher positions have Read, Write, Append, AppendTo access to the lower positions’ data in the direct ancestor path. The non-direct higher positions, have read-only access to the lower positions’ data in the direct ancestor path.
    matches the results of your last test.
     
    As for why it can be edited in this test, I think it's possible that it's the permissions given by the shared record.
     
    Finally,
    While the hierarchy security model provides a certain level of access to data, additional access can be obtained by using other forms of security, such as security roles.
     
    I hope this helps, but please let me know if you need anything else or if you have any other questions.
    thanks,
    Haig Liu

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Neeraj Kumar – Community Spotlight

We are honored to recognize Neeraj Kumar as our Community Spotlight honoree for…

Leaderboard > Customer experience | Sales, Customer Insights, CRM

#1
Tom_Gioielli Profile Picture

Tom_Gioielli 83 Super User 2025 Season 2

#2
Gerardo Rentería García Profile Picture

Gerardo Rentería Ga... 49 Most Valuable Professional

#3
#ManoVerse Profile Picture

#ManoVerse 40

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans