web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

No record found.

Community site session details

Community site session details

Session Id :
Customer experience | Sales, Customer Insights,...
Unanswered

Give user access to a record even if his security role does not have ability to read records of that entity

(0) ShareShare
ReportReport
Posted on by

Let's say that a user does not have access to records of some specific entity (Lets say Invoices).

Is there some way that we allow the user to be able to see one record of that entity, one specific Invoice, without giving him permissions to see Invoice entity records on his security role?


I have the same question (0)
  • Guido Preite Profile Picture
    54,086 Moderator on at

    did you try to share the record?

  • Community Member Profile Picture
    on at

    Hello Guido,

    I thought about it also but I found this statement in official documentation:

    When you share a record with another user, indicate what access rights (Read, Write, Delete, Append, Assign, and Share) you want to grant to the other user. Access rights on a shared record can be different for each user with whom the record is shared. However, you cannot give a user any rights that he or she would not have for that type of entity, based on the role assigned to that user. For example, if a user does not have Read privileges on accounts and you share an account with that user, the user will be unable to see that account.

  • Guido Preite Profile Picture
    54,086 Moderator on at

    inside the user security role, you can just add a "Read" to that entity at "User" level (meaning the user can read only its own records by default) and without the create permission can't create new records of that type. In this way the user should be able to access the shared record.

  • Community Member Profile Picture
    on at

    Hello Guido,

    Yes, but you remember that I said that the user should not have any permission to access to particular entity on his own profile.

    I think that solution for this scenario is using Access Teams. I have never used this before.

  • Guido Preite Profile Picture
    54,086 Moderator on at

    give no access to an entity and give access to just "Read" with "User" level with no records is in the end the same.

    But if a user may be shared a record in the future having the possibility to find that record by the app menu or by advanced find is the minimum (in my opinion)

    I didn't check with access teams but probably you will need to grant a minimum security permission also there as well.

  • Community Member Profile Picture
    on at

    Yes, read permission on user level for particular entity was needed. Even if user gets permissions on behalf of his access team. Without that user do not see entity inside advanced find.

    Without that read permission I couldn't set it.

  • Hari Narayanan Profile Picture
    589 on at

    Not possible, unless user has minimum user level read access to record. Share or access team also wouldn't work

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Neeraj Kumar – Community Spotlight

We are honored to recognize Neeraj Kumar as our Community Spotlight honoree for…

Leaderboard > Customer experience | Sales, Customer Insights, CRM

#1
Tom_Gioielli Profile Picture

Tom_Gioielli 81 Super User 2025 Season 2

#2
Gerardo Rentería García Profile Picture

Gerardo Rentería Ga... 49 Most Valuable Professional

#3
#ManoVerse Profile Picture

#ManoVerse 40

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans