Hello,
We have a Customer Insights implementation with 6 Business Units and are using Access Teams for access control in Dataverse today.
Current Dataverse access model (works as intended)
- Users can be members of multiple Access Teams.
- Access Teams are aligned to what we conceptually treat as sub‑BUs (for example C, D, E).
- Access is group‑managed via Azure AD.
- Resulting behavior:
- If a user is a member of Access Teams for C, D, and E, they can see all data belonging to C, D, and E.
- They cannot see data belonging to A or B.
- If a user is only a member of A, they can only see A.
- This works well across Dataverse entities using standard security + Access Teams.
The challenge in Customer Insights – Journeys
The issue appears specifically in Customer Insights – Journeys, especially for:
- journeys
- emails
- marketing interactions
- real‑time marketing assets
In CIJ, data access seems to be evaluated based on the user’s primary Business Unit rather than:
- Access Teams
- team membership
- cross‑BU collaboration pattern
This creates a problem for our hybrid access model:
- We need Business Unit A to be fully isolated
- Other units (C, D, E, etc.) must collaborate and share CIJ assets and data
- Users already have the correct access via Access Teams, but CIJ does not appear to respect this model
Questions
- Is this behavior expected in Customer Insights – Journeys (BU‑based access only)?
- Does CIJ currently ignore Access Team membership when determining visibility of journeys, emails, and interactions?
- Is there a supported way to implement a hybrid model where:
- One BU is isolated
- Other BUs collaborate
- Access Teams (rather than primary BU) drive visibility
- If not supported, what is the recommended Microsoft architecture for this scenario?
- Separate environments?
- Separate CIJ instances?
- Different BU structure?
- Other patterns?
Any clarification on supported patterns, limitations, or roadmap considerations would be greatly appreciated.
Thanks in advance!

Report
All responses (
Answers (