web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Microsoft Dynamics 365 | Integration, Dataverse...
Answered

Project Accelerator + Planner: Auto Assignment Security Role Granting Unintended Access

(1) ShareShare
ReportReport
Posted on by 4

We’re facing a permission issue in Project Accelerator with Planner integration.

When Planner is used in Project Accelerator (by creating a plan and linking it to a Teams group), the Teams group is automatically added to Dataverse and assigned the “Project Team Member” managed security role from Project Accelerator.

This results in all users in that group getting access to the Project Accelerator app, which we want to avoid.

We tried removing the role, but:


  • It’s not scalable
  • Access becomes messy/inconsistent
  • When reused in another project, the role gets auto-assigned again

    We can handle Project Managers via a separate security role, but the issue remains for Planner-based users.

Requirement:

  • Users should work with Planner tasks assigned through Project Accelerator
  • But must NOT access the Project Accelerator app

    Reference:
    https://learn.microsoft.com/en-us/project-for-the-web/enhance-project-for-the-web-projects-use-accelerator

    Any suggestions to prevent this auto assignment or control access better? Thanks!
Project Accelerator Issue.png
I have the same question (0)
  • Verified answer
    sannavajjala87 Profile Picture
    50 on at
    This is expected behavior with the current Project Accelerator architecture.
     
    When a Planner plan is created and associated with a Microsoft Teams group, Project Accelerator creates (or reuses) the corresponding Microsoft Entra ID group team in Dataverse and automatically assigns the managed Project Team Member security role. This is required so team members can access the Dataverse records needed for Project Accelerator features.
     
    A few thoughts that may help:
     
    - The managed Project Team Member role should not be modified or removed. Since it's part of the managed solution, any updates or reprovisioning can reapply it, which is the behavior you're seeing.
     
    - There isn't a supported setting to disable this automatic role assignment. The Planner integration relies on the Dataverse team and its associated security role to function correctly.
     
    - Controlling app access separately from data access is generally the recommended approach. If users need Planner functionality but shouldn't use the Project Accelerator app, consider limiting app visibility using app sharing and security role assignments rather than trying to prevent the Dataverse team from receiving its managed role.
     
    - If appropriate for your scenario, you could also create a custom model-driven app that exposes only the required Planner/Project tables for specific users, while reserving the full Project Accelerator app for Project Managers and administrators.
     
    One question that would help identify the best approach:
     
    - When you say users "must not access the Project Accelerator app," do you mean:
      - They should not even see the app tile in the app launcher?
      - They can open the app but should have read-only or limited functionality?
      - Or they should only work in Microsoft Planner/Teams and never interact with the Project Accelerator model-driven app?
     
    The answer will determine whether this is primarily an app access problem or a Dataverse security problem, as those are managed independently.
  • PK-01071546-0 Profile Picture
    4 on at

    Thanks for the response.

    To answer your question, our requirement is that Planner users should ideally not see the Project Accelerator app at all, or at minimum they should be able to view project information but not edit project metadata fields.

    In our scenario, when a Teams group is associated with a Planner plan for a project, all members of that Teams group automatically receive access through the Project Team Member role. As a result, both Project Managers and Planner users within the same Teams group can edit project metadata fields in Project Accelerator, which is not the desired behavior.

    We attempted the following approach:

    • Created a custom security role by copying the Project Team Member role.
    • Removed write permissions on the Project table and changed access to read-only.
    • Assigned this custom role to the Dataverse team.
    • Granted full project management permissions to Project Managers through a separate user security role.

    With this configuration, the project metadata appears to be protected as expected, and Planner users are no longer able to edit project records.

    However, we encountered a new issue: Planner users can no longer update tasks in Microsoft Planner. The tasks become effectively read-only for them. We found that task editing only works when write access is granted back to the Project table, which seems to indicate a dependency between Planner task updates and write permissions on the Project entity.
     
    Have you come across this behavior before, or do you know which specific Project Accelerator/Dataverse tables require write access for Planner task updates? We are trying to understand whether there is a supported approach that allows Planner users to update Planner tasks while preventing them from modifying project metadata within Project Accelerator.
     
    Additionally, another challenge is with the out-of-the-box Planner notifications. When a task is assigned, Planner sends email notifications containing links that point directly to Project Accelerator records. As a result, Planner users may click these links and be taken into the Project Accelerator app. Since the Teams group contains both Project Managers and Planner users, the automatically assigned Project Team Member role provides access that we are trying to restrict.
  • Suggested answer
    11manish Profile Picture
    1,125 on at
    If your requirement is that users should only interact with Planner tasks and never access Project Accelerator, the cleanest approach is to keep those users working directly in Planner/Teams rather than making them project members through Project Accelerator. If they need full Project Accelerator integration, the automatic security role assignment is expected and currently cannot be disabled.

    If this behavior doesn't meet your organization's security model, it would be worth raising it through the Microsoft feedback channels or opening a support case to confirm whether any newer configuration options are available, as this is a common enterprise scenario.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Winners!

Congratulations to our community stars!

Women in Power Builds Momentum

Expanding mentorship, skilling, and AI innovation

Congratulations to the June Top 10 Community Leaders

These are the community rock stars!

Leaderboard > Microsoft Dynamics 365 | Integration, Dataverse, and general topics

#1
11manish Profile Picture

11manish 77

#2
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 45 Super User 2026 Season 1

#3
sannavajjala87 Profile Picture

sannavajjala87 29

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans