web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Microsoft Dynamics 365 | Integration, Dataverse...
Unanswered

Best Practices: Assigning Security Roles & privileges

(2) ShareShare
ReportReport
Posted on by 659

Hi,

we are right now redefining our Security Roles structure and I wondered what is the best practice to assign roles to users.

Our organization works with the following job descriptions:

Sales:

- Sales Manager

- Sales Clerk

Customer Service:

- Support Manager

- Support Clerk

Finance:

- Quote Backoffice

- Order Management

- Invoice Management

My idea now was to create a Team for each job description.

So e.g. there is one team: "Sales Clerks" and I assign the team all necessary security roles. And assign the members to that team. 

- Do I need to use the Team-based "Security Roles" or "Direct User" access levels for this to work?

- Is this a good idea? What are your solutions?

- It is certainly easier to just assign a new employee to a Team  than setting up security roles individually

- Should we use Azure AD Groups in any way?

- Any resources regarding this topic that I should read?

Thanks.

I have the same question (0)
  • Ana Pereira Profile Picture
    on at

    Hi, 

    I think this documentation will assist you on your questions

    https://docs.microsoft.com/en-us/power-platform/admin/security-roles-privileges#team-members-privilege-inheritance

    Teresa

  • SA-30061402-0 Profile Picture
    37 on at
    You may find this excellent series of blog posts useful, from Guowei Xu
     
     
    Particularly the section on security roles
     
    Key takeaways from his post are:
     
    1. To control data access, you must set up an organizational structure that both protects sensitive data and enables collaboration.
    2. To ensure that users can view and access all areas of the web application, such as entity forms, the nav bar, or the command bar, all security roles in the organization must include the Read privilege on the Web Resource
     

    Not Recommended

    1. Creating a new security role from scratch will cause a lot of problems.
    2. Don’t Rename an existing security role.
    3. Don’t change the default roles. There is no reason to do that.
     
    Some of the ways we can achieve best practice in assigning and utilising RBAC are:
     

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Congratulations to our 2025 Community Spotlights

Thanks to all of our 2025 Community Spotlight stars!

Leaderboard > Microsoft Dynamics 365 | Integration, Dataverse, and general topics

#1
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 72 Super User 2026 Season 1

#2
BillurSamdancioglu Profile Picture

BillurSamdancioglu 64 Most Valuable Professional

#3
Abhilash Warrier Profile Picture

Abhilash Warrier 55 Super User 2026 Season 1

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans