web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Customer experience | Sales, Customer Insights,...
Suggested Answer

Best way to restrict users to see lead's (other entities) records using Security Role

(0) ShareShare
ReportReport
Posted on by 147

Hello Guys,

Here i am trying to find a best way to restrict users to see lead's (other entities) records using Security Role without creating any other child Business unit.

Here is my example....

There are two teams as Team A and Team B. Each team has their own leader as Team Lead_A and Team Lead_B. Every team has two-two users as mentioned in screenshot. So what i want is that if any user of team creates any lead then it should be visible to him and team leader only other team member or team leader from different team should not be able to see this record. Admin is able to see all records.

I have created users, Roles and Teams but not able to get this done.

I don't want to create multiple child business unit or restrict it on views. So i just want to know that is it possible using Security Role only or what is the best possible way to achieve this.

pastedimage1571294136838v1.png

I have the same question (0)
  • Suggested answer
    Saad Kabarousse Profile Picture
    734 on at

    Hello,

    This won't be possible using Security roles Only, you'll have to create BU for each team member.

    Other Solution : Register a Plugin OnPost RetrieveMultiple message of the appropriate entity.

    The Inputparameters collection of the IPluginExecutionContext object contains a property named "Query" That holds the Original QueryExpression. You can examine this query and add your filter to just retrive (My own records if i am not a leader)  or  (My records + My Other siblings's im i am a team leader ).

    Hope This helps :)

  • David L. Carr Profile Picture
    75 on at

    It looks like there is a new feature that might help (in v9.0 online, anyway).   On the Security Roles Details page is a new setting: "When role is assigned to team".  There is a help link there, that links to this page:

    docs.microsoft.com/.../manage-teams

    I suspect the answer may be to create a role that has only "Owner" CRUD permissions for leads, and then assign that role to the teams. (And of course eliminate any access to leads from the user's security roles.)   You could then (code, workflow) ensure that the team owned the lead.  

    Hope this helps,

    Dave

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Winners!

Congratulations to our community stars!

Women in Power Builds Momentum

Expanding mentorship, skilling, and AI innovation

Congratulations to the July Top 10 Community Leaders

These are the community rock stars!

Leaderboard > Customer experience | Sales, Customer Insights, CRM

#1
11manish Profile Picture

11manish 85 Super User 2026 Season 2

#2
Daniyal Khaleel Profile Picture

Daniyal Khaleel 64 Most Valuable Professional

#3
ParthPatel249 Profile Picture

ParthPatel249 43

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans