web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

No record found.

Community site session details

Community site session details

Session Id :
Finance | Project Operations, Human Resources, ...
Suggested Answer

What is permission required for Application user used for API calls

(0) ShareShare
ReportReport
Posted on by 162

Hi Community,

I wanted to ask a question regarding the Application user/ Service Account setup in the FnO. I wanted to create a user which can be used in the Scribe Integration but I don't want to provide the System admin to that principle user due to security protocol. Can anyone suggest the best practices for the same and Microsoft document for reference?

Also, Wanted to check whether System Admin is minimum requirement to access the API from external system if not, what is minimum security roles that we can provide.

I have the same question (0)
  • Suggested answer
    nunomaia Profile Picture
    25 Moderator on at

    You don't need an admin role.

    You can create a limited role for integration purposes. 
    For example, if you are using odata, you can have permissions for each entity for read / write.
    You can assign permissions to a user to smilate permissions and then map to azure application  
  • Mariano Gracia Profile Picture
    on at

    As Nuno says, you can define a role to access to specific entities, also to assign system user role is mandatory

  • Amit Prajapati Profile Picture
    162 on at

     What role we need to give to user for custom API and Odata Method which our third party application is calling

  • Mariano Gracia Profile Picture
    on at

    We cannot answer you as long as we don't know which api is calling that third party application, and because it's a custom api it is your responsibility to create the appropriate security objects: Security roles and privileges - Power Platform | Microsoft Learn

  • Barretao Profile Picture
    80 on at

    learn.microsoft.com/.../services-home-page

    "As a better practice, you should provision a dedicated service account that has the correct permissions for the operations that must be performed."

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Neeraj Kumar – Community Spotlight

We are honored to recognize Neeraj Kumar as our Community Spotlight honoree for…

Leaderboard > Finance | Project Operations, Human Resources, AX, GP, SL

#1
Martin Dráb Profile Picture

Martin Dráb 565 Most Valuable Professional

#2
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 450 Super User 2025 Season 2

#3
Sohaib Cheema Profile Picture

Sohaib Cheema 250 User Group Leader

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans