{"id":32628,"date":"2022-09-19T12:34:23","date_gmt":"2022-09-19T07:04:23","guid":{"rendered":"https:\/\/www.inogic.com\/blog\/?p=32628"},"modified":"2025-05-05T14:29:24","modified_gmt":"2025-05-05T08:59:24","slug":"record-ownership-across-business-units-preview","status":"publish","type":"post","link":"https:\/\/www.inogic.com\/blog\/2022\/09\/record-ownership-across-business-units-preview\/","title":{"rendered":"Record ownership across business units (PREVIEW)"},"content":{"rendered":"<p>Microsoft is continuously working on providing a richer and seamless experience while setting up the security model. In the Microsoft Dataverse environments, you can implement the security model with even more ease, you can refer to this <a href=\"https:\/\/docs.microsoft.com\/en-us\/power-platform\/admin\/wp-security-cds#to-enable-this-matrix-data-access-structure-preview\" target=\"_blank\" rel=\"noopener\">doc<\/a> for more details.<\/p>\n<p>In our previous <a href=\"https:\/\/www.inogic.com\/blog\/2021\/11\/2021-release-wave-2-updates-to-business-units-security-roles-and-users-in-dynamics-365-crm-and-dataverse\/\" target=\"_blank\" rel=\"noopener\">blog<\/a>, we have already explained the enhancements available while setting up the security model in Microsoft Dataverse. While exploring, then, the UI setting was not available for displaying security roles across business units.<\/p>\n<p>There is a setting available named \u201c<strong>Record ownership across business units (Preview)\u201d<\/strong> in the <a href=\"https:\/\/admin.powerplatform.microsoft.com\/\" target=\"_blank\" rel=\"noopener\">Power Platform Admin Center<\/a> which is in PREVIEW for a long time.<\/p>\n<p><strong>Need:<\/strong><\/p>\n<p>With this new feature, you can add security roles from other business units to a user besides the user&#8217;s standard business unit. The result is that users have privileges from their security roles in their business unit as well as privileges from the other security roles from the other business units.<\/p>\n<p><strong>Configuration:<\/strong><\/p>\n<p>Sign in to the\u202f <a href=\"https:\/\/admin.powerplatform.microsoft.com\/\" target=\"_blank\" rel=\"noopener\">Power Platform Admin Center<\/a> select the\u202fEnvironments\u202ftab, and then choose the environment that you want to enable this feature.<\/p>\n<p>Select\u00a0Settings\u00a0&gt;\u00a0Product\u00a0&gt;\u00a0Features &gt; Record ownership across business units (Preview) &gt; Turn on the toggle as shown:<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-32635\" style=\"border: 1px solid #0a0a0a; padding: 1px; margin: 1px;\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/1Record-ownership-across-business-units.jpeg\" alt=\"Record ownership across business units\" width=\"1429\" height=\"485\" srcset=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/1Record-ownership-across-business-units.jpeg 1429w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/1Record-ownership-across-business-units-300x102.jpeg 300w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/1Record-ownership-across-business-units-1024x348.jpeg 1024w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/1Record-ownership-across-business-units-768x261.jpeg 768w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/1Record-ownership-across-business-units-660x224.jpeg 660w\" sizes=\"(max-width: 1429px) 100vw, 1429px\" \/><\/p>\n<p><strong>NOTE:<\/strong><\/p>\n<ul>\n<li>By default this feature is disabled and needs to turn on manually.<\/li>\n<\/ul>\n<p>This feature changes the way we were managing the security roles till now. If you are thinking to implement the \u201c<a href=\"https:\/\/docs.microsoft.com\/en-us\/dynamics365\/customerengagement\/on-premises\/admin\/security-roles-privileges?view=op-9-1#BKMK_privileges\" target=\"_blank\" rel=\"noopener\">Role-based security model<\/a>\u201d then if you remember the security roles were created at the root level and these security roles were inherited by the child business units.<\/p>\n<p>But with this feature, you are now allowed to create a security role at individual BU as well. You can either create a new role from scratch or copy the existing role in the child BU itself, independent of the parent BU.<\/p>\n<p><strong>Use Case:<\/strong><\/p>\n<p>Let\u2019s say you have two different business units (BU1, and BU2) with different groups of users.<\/p>\n<p><img decoding=\"async\" class=\"wp-image-32636 aligncenter\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/Record.png\" alt=\"\" width=\"372\" height=\"82\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Let\u2019s say \u201cPaulina\u201d belongs to \u201cBU1\u201d and has BU level access as shown below, If she needs access to data created in \u201cBU2\u201d then below are the possibilities:<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-32634\" style=\"border: 1px solid #0a0a0a; padding: 1px; margin: 1px;\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/3Record-ownership-across-business-units.jpeg\" alt=\"Record ownership across business units\" width=\"949\" height=\"142\" srcset=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/3Record-ownership-across-business-units.jpeg 949w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/3Record-ownership-across-business-units-300x45.jpeg 300w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/3Record-ownership-across-business-units-768x115.jpeg 768w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/3Record-ownership-across-business-units-660x99.jpeg 660w\" sizes=\"(max-width: 949px) 100vw, 949px\" \/><\/p>\n<p><strong>NOTE:<\/strong><\/p>\n<ul>\n<li>BU1 and BU2 are child BU\u2019s of another BU \u201cInnosight\u201d and they are independent of each other.<\/li>\n<li>If BU1 and BU2 were child BUs of each other then providing parent-child BU access level would have provided the access across the BUs (through Business units hierarchy).<\/li>\n<\/ul>\n<p>There are a lot of possibilities around to achieve this in Dynamics 365. For example, record sharing, hierarchy security, business unit hierarchy, and team ownership.<\/p>\n<p>Out of all these possibilities, the new modernized business unit structure brings a more enhanced and easy way of doing it.<\/p>\n<p>Before turning on this functionality, if you observe the manage security role page then you will experience that changing\/selecting another BU is not allowed.<\/p>\n<p>Navigate to Environments &gt;\u00a0Select an appropriate environment \u00a0&gt;\u00a0Settings &gt; Users &gt; Select the user &gt; Manage Security roles. On this page you can observe changing the BU is not allowed:<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-32633\" style=\"border: 1px solid #0a0a0a; padding: 1px; margin: 1px;\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/4Record-ownership-across-business-units.jpeg\" alt=\"Record ownership across business units\" width=\"564\" height=\"496\" srcset=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/4Record-ownership-across-business-units.jpeg 564w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/4Record-ownership-across-business-units-300x264.jpeg 300w\" sizes=\"(max-width: 564px) 100vw, 564px\" \/><\/p>\n<p>After turning on this functionality you have the flexibility to change the BU and can assign the desired security role from the respective BU among the list.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-32632\" style=\"border: 1px solid #0a0a0a; padding: 1px; margin: 1px;\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/5Record-ownership-across-business-units.jpeg\" alt=\"Record ownership across business units\" width=\"560\" height=\"273\" srcset=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/5Record-ownership-across-business-units.jpeg 560w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/5Record-ownership-across-business-units-300x146.jpeg 300w\" sizes=\"(max-width: 560px) 100vw, 560px\" \/><\/p>\n<p>As shown below created the \u201cBU2 Salesperson\u201d role under \u201cBU2\u201d and assigned this to \u201cPaulina\u201d<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-32631\" style=\"border: 1px solid #0a0a0a; padding: 1px; margin: 1px;\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/6Record-ownership-across-business-units.jpeg\" alt=\"Record ownership across business units\" width=\"973\" height=\"129\" srcset=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/6Record-ownership-across-business-units.jpeg 973w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/6Record-ownership-across-business-units-300x40.jpeg 300w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/6Record-ownership-across-business-units-768x102.jpeg 768w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/6Record-ownership-across-business-units-660x88.jpeg 660w\" sizes=\"(max-width: 973px) 100vw, 973px\" \/><\/p>\n<p>\u201cPaulina\u201d can now access records from both BU1 and BU2 even though \u201cPaulina\u201d belong to BU1. This is because we have assigned security roles to the \u201cPaulina\u201d from BU2 as well.<\/p>\n<p>Though \u201cPaulina\u201d belongs to BU1, roles from other BU (i.e. BU2) can be assigned, Refer to the below screenshot:<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-32630\" style=\"border: 1px solid #0a0a0a; padding: 1px; margin: 1px;\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/7Record-ownership-across-business-units.jpeg\" alt=\"Record ownership across business units\" width=\"502\" height=\"756\" srcset=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/7Record-ownership-across-business-units.jpeg 502w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/7Record-ownership-across-business-units-199x300.jpeg 199w\" sizes=\"(max-width: 502px) 100vw, 502px\" \/><\/p>\n<p>As \u201cPaulina\u201d user have a security role from BU1 and BU2 which allows her to access both BUs data as shown:<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-32629\" style=\"border: 1px solid #0a0a0a; padding: 1px; margin: 1px;\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/8Record-ownership-across-business-units.jpeg\" alt=\"Record ownership across business units\" width=\"1252\" height=\"282\" srcset=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/8Record-ownership-across-business-units.jpeg 1252w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/8Record-ownership-across-business-units-300x68.jpeg 300w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/8Record-ownership-across-business-units-1024x231.jpeg 1024w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/8Record-ownership-across-business-units-768x173.jpeg 768w, https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2022\/09\/8Record-ownership-across-business-units-660x149.jpeg 660w\" sizes=\"(max-width: 1252px) 100vw, 1252px\" \/><\/p>\n<h2><strong>Conclusion<\/strong><\/h2>\n<p>By using this feature users can easily assign the security roles independent of BUs and can access the data from other BUs with little effort<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft is continuously working on providing a richer and seamless experience while setting up the security model. In the Microsoft Dataverse environments, you can implement the security model with even more ease, you can refer to this doc for more details. In our previous blog, we have already explained the enhancements available while setting up\u2026 <span class=\"read-more\"><a href=\"https:\/\/www.inogic.com\/blog\/2022\/09\/record-ownership-across-business-units-preview\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":13,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[18,1913,44],"tags":[2611,2629],"class_list":["post-32628","post","type-post","status-publish","format-standard","hentry","category-dynamics-365-v9-2","category-microsoft-power-platform-services","category-power-apps","tag-power-platform-admin-center","tag-record-ownership-across-business-units"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/posts\/32628","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/comments?post=32628"}],"version-history":[{"count":0,"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/posts\/32628\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/media?parent=32628"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/categories?post=32628"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/tags?post=32628"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}