Skip to main content

Notifications

Announcements

No record found.

Dynamics 365 Community / Forums / Sales forum / D365 Position Hierarch...
Sales forum
Suggested answer

D365 Position Hierarchy - Read Only Access Changes?

Posted on by 5
Hi.
 
I'm investigating implementing some extra security using the position hierarchy model.
I had looked into this several months ago & having done some research it seemed as if users would only have full write level access to data if the user the data was shared with was no more than one level below them in the hierarchy model.
Any further down the model and the records were read-only access only.
My testing at this time seemed to indicate that this was the case.
 
I did a few tests today now (months later) and I'm finding that the records now all seem to be writeable. Has the way Microsoft implement this type of security changed recently?
Or maybe there is another explanation for the fact that I am able to edit the records?
 
Below is a sample of how I have setup the position hierarchy...
I share a particular contact record with User Z, who is part of the Sub Branch D hierarchy (the lowest one).
I log into CRM as User X, who is part of the Main Branch hierarchy.
I have full write access to the contact record (all my security roles are set to have user level read and write access only - so it isn't the case that these roles supercede the position hierarchy).
Should I not have read-only access to this contact record, given that it is that many levels deep down the hierarchy?
 
Hierarchy 1: Main Branch
Hierarchy 2:  Sub Branch A (parent hierarchy is Main Branch)
Hierarchy 3:  Sub Branch B (parent hierarchy is Sub Branch A)
Hierarchy 4:  Sub Branch C (parent hierarchy is Sub Branch B)
Hierarchy 5:  Sub Branch D (parent hierarchy is Sub Branch C)
 
Thanks
Categories:
  • Suggested answer
    Haig Liu Profile Picture
    Haig Liu Microsoft Employee on at
    D365 Position Hierarchy - Read Only Access Changes?
    Hi,
     
    The related explains in the document.
    The direct higher positions have Read, Write, Append, AppendTo access to the lower positions’ data in the direct ancestor path. The non-direct higher positions, have read-only access to the lower positions’ data in the direct ancestor path.
    matches the results of your last test.
     
    As for why it can be edited in this test, I think it's possible that it's the permissions given by the shared record.
     
    Finally,
    While the hierarchy security model provides a certain level of access to data, additional access can be obtained by using other forms of security, such as security roles.
     
    I hope this helps, but please let me know if you need anything else or if you have any other questions.
    thanks,
    Haig Liu

Helpful resources

Quick Links

Dynamics 365 Community Update – Sep 9th

Welcome to the next edition of the Community Platform Update. This is a weekly…

Announcing Our 2024 Season 2 Super Users!

A new season of Super Users has arrived, and we are so grateful for the daily…

Leaderboard

#1
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 290,277 Super User 2024 Season 2

#2
Martin Dráb Profile Picture

Martin Dráb 228,126 Most Valuable Professional

#3
nmaenpaa Profile Picture

nmaenpaa 101,148

Leaderboard

Featured topics

Product updates

Dynamics 365 release plans