{"id":3935,"date":"2016-11-24T17:31:06","date_gmt":"2016-11-24T12:01:06","guid":{"rendered":"https:\/\/www.inogic.com\/blog\/?p=3935"},"modified":"2021-12-15T16:13:41","modified_gmt":"2021-12-15T10:43:41","slug":"minimum-privileges-required-to-login-microsoft-dynamics-365","status":"publish","type":"post","link":"https:\/\/www.inogic.com\/blog\/2016\/11\/minimum-privileges-required-to-login-microsoft-dynamics-365\/","title":{"rendered":"Minimum Privileges required to Login Microsoft Dynamics 365"},"content":{"rendered":"<p><strong>Introduction<\/strong>:<\/p>\n<p>We have been working a lot with security roles recently. Earlier we had the issue with insufficient permissions and then a few days later we had a request to fix a new security role created by a power user.<\/p>\n<p>Defining a Security Role has always been a daunting task. One needs to be very careful while selecting privileges for the Security Role creator.<\/p>\n<p>Dynamics CRM ships with few of the most commonly used Security Role Profiles like Salesperson, Sales Manager, etc. However, not all businesses revolve around these profiles or roles.<\/p>\n<p>Most of the businesses have their own set of Roles, which do tend to differ from the predefined Security Role Profiles.<\/p>\n<p>For a start, the predefined Security Role Profiles could come handy where your task would be to just turn on or off the privileges for a few of the entities, from say Salesperson profile and there you have the Security Profile that you are trying to create.<\/p>\n<p>But, there could be a scenario where you are trying to create a Security Role Profile, that is completely different from any of the predefined Security Role Profiles. With this case, it might be better to start from the scratch and add the privileges rather than pick one of the existing and start modifying it.<\/p>\n<p><strong>Login Security Role<\/strong><\/p>\n<p>Create a Security Role, with bare minimum privileges. Sounds Good!<\/p>\n<p>But, what could be the bare minimum privileges for a user to at least log-in into the Dynamics CRM?<\/p>\n<p>This blog post will drive you through it!<\/p>\n<p>Let\u2019s create a new Security Role by the name \u201cLog-In\u201d.<\/p>\n<p>This Security Role would hold only those privileges that allow a user to login into Dynamics CRM or to phrase it in another way, without these privileges, you would receive the error \u201cYou do not have permission to access these records. Contact your Microsoft Dynamics 365 administrator.\u201d<\/p>\n<p><a href=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/Insufficient-Permissions-error.jpg\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-3939\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/Insufficient-Permissions-error.jpg\" alt=\"Insufficient Permissions error\" width=\"462\" height=\"142\" \/><\/a><\/p>\n<p>Now, the next step is to assign those Golden Privileges that grants you Bare Minimum Privileges required to access Dynamics CRM.<\/p>\n<p>Navigate to Business Management Tab,<\/p>\n<ul>\n<li>Grant Read (Organization Level) Privilege for the Organization entity.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/Read-Privilege-for-Organization-Entity.jpg\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-3945\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/Read-Privilege-for-Organization-Entity.jpg\" alt=\"Read Privilege for Organization Entity\" width=\"571\" height=\"24\" \/><\/a><\/p>\n<ul>\n<li>Grant Read (Business Unit Level) Privilege for the User entity.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/Read-Privilege-for-User-Entity.jpg\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-3946\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/Read-Privilege-for-User-Entity.jpg\" alt=\"Read Privilege for User Entity\" width=\"497\" height=\"31\" \/><\/a><\/p>\n<ul>\n<li>Grant Read (Organization Level), Append (Organization Level), Append To (Organization Level) Privilege for the Currency entity.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/Multiple-Privileges-for-Currency-entity.jpg\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-3941\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/Multiple-Privileges-for-Currency-entity.jpg\" alt=\"Multiple Privileges for Currency entity\" width=\"607\" height=\"19\" \/><\/a><\/p>\n<p>This is it for the Business Management Tab.<\/p>\n<p>Next, navigate to Core Records Tab,<\/p>\n<ul>\n<li>Grant Create (Organization Level), Read (Organization Level), Append (Organization Level), Append To (Organization Level) Privilege for the Post Entity.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/privileges-for-post-entity.jpg\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-3944\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/privileges-for-post-entity.jpg\" alt=\"privileges for post entity\" width=\"613\" height=\"30\" \/><\/a><\/p>\n<ul>\n<li>Grant Create (User Level), Read (User Level) Privilege for the User Entity UI Settings<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/User-Entity-UI-Settings.jpg\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-3947\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/User-Entity-UI-Settings.jpg\" alt=\"User Entity UI Settings\" width=\"336\" height=\"19\" \/><\/a><\/p>\n<p>Next, navigate to Customization Tab,<\/p>\n<p>Grant the Privileges as per the below screenshot.<\/p>\n<p><a href=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/Grant-Privileges.jpg\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-3938\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/Grant-Privileges.jpg\" alt=\"Grant Privileges\" width=\"940\" height=\"940\" \/><\/a><\/p>\n<p>This is it for the Log-In Role.<\/p>\n<p>With the above role assigned, a user would be able to login. But note that we have not yet provided the user with any privileges to the core records. You can now add the privileges for the operations allowed by this user.<\/p>\n<p><strong>Ability to record leads and activities against leads.<\/strong><\/p>\n<p>You can create a new role \u201cLead Access\u201d and provide the user level privileges for Read, Create, Write, Append, and Append To.<\/p>\n<p><a href=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/lead.jpg\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-3940\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/lead.jpg\" alt=\"lead\" width=\"797\" height=\"27\" \/><\/a><\/p>\n<p>To allow access to record activities against leads, user level privileges for Activity entity needs to be provided.<\/p>\n<p><a href=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/activity.png\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-3936\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/activity.png\" alt=\"activity\" width=\"928\" height=\"30\" \/><\/a><\/p>\n<p><strong>Dynamics CRM View<\/strong><\/p>\n<p>A user with the \u201cLog-in\u201d role and \u201cLead Access\u201d Role would be able to login to the web client and would see the following navigation options.<\/p>\n<p><a href=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/navigation-option.jpg\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-3942\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/navigation-option.jpg\" alt=\"navigation option\" width=\"965\" height=\"562\" \/><\/a><\/p>\n<p>The user will be able to create a new lead<\/p>\n<p><a href=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/new-lead.png\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-3943\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/new-lead.png\" alt=\"new lead\" width=\"318\" height=\"384\" \/><\/a><\/p>\n<p>And add an activity through the social pane<\/p>\n<p><a href=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/add-activity.jpg\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-3937\" src=\"https:\/\/www.inogic.com\/blog\/wp-content\/uploads\/2016\/11\/add-activity.jpg\" alt=\"add activity\" width=\"523\" height=\"164\" \/><\/a><\/p>\n<p><strong>Note: Using this role the user could perform the said operations on the web client. But depending on the use case at your end, you will have to tweak the privileges to match your specific needs.<\/strong><\/p>\n<p><strong>Conclusion<\/strong>:<\/p>\n<p>It is always advisable to use the OOB security roles and start tweaking them to match your requirements rather than start from a blank role as apart from the entity privileges there are other special privileges embedded within a security role that might hamper smooth functioning of the system and block user from performing certain operations.<\/p>\n<h2 style=\"text-align: left;\"><div class=\"su-heading su-heading-style-default su-heading-align-center\" id=\"\" style=\"font-size:15px;margin-bottom:5px\"><div class=\"su-heading-inner\">Cut short 90% of your manual work and repetitive data entry!<\/div><\/div><\/h2>\n<p style=\"text-align: left;\"><em>Get 1 Click apps and say goodbye to all repetitive data entry in CRM &#8211;<\/em><br \/>\n<em><strong><a href=\"https:\/\/bit.ly\/3oH7dYw\" target=\"_blank\" rel=\"noopener noreferrer\">Click2Clone<\/a> <\/strong>\u2013 Clone\/Copy Dynamics 365 CRM records in 1 Click<\/em><br \/>\n<em><strong><a href=\"https:\/\/bit.ly\/3EPjAYc\" target=\"_blank\" rel=\"noopener noreferrer\">Click2Export<\/a><\/strong> \u2013 Export Dynamics 365 CRM Report\/CRM Views\/Word\/Excel template in 1 Click<\/em><br \/>\n<em><strong><a href=\"https:\/\/bit.ly\/3EN8h2v\" target=\"_blank\" rel=\"noopener noreferrer\">Click2Undo<\/a><\/strong> \u2013 Undo &amp; Restore Dynamics 365 CRM data in 1 Click<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction: We have been working a lot with security roles recently. Earlier we had the issue with insufficient permissions and then a few days later we had a request to fix a new security role created by a power user. Defining a Security Role has always been a daunting task. One needs to be very\u2026 <span class=\"read-more\"><a href=\"https:\/\/www.inogic.com\/blog\/2016\/11\/minimum-privileges-required-to-login-microsoft-dynamics-365\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":13,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[16,24,51],"tags":[560,1181,1182,1183,1184],"class_list":["post-3935","post","type-post","status-publish","format-standard","hentry","category-dynamics-365","category-dynamics-crm-2016","category-security","tag-dynamics-365-insufficient-permissions-error","tag-minimum-dynamics-crm-permissions","tag-minimum-privileges-for-dynamics-365-login","tag-minimum-privileges-required-to-access-dynamics-crm","tag-minimum-security-permissions-in-dynamics-crm"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/posts\/3935","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/comments?post=3935"}],"version-history":[{"count":0,"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/posts\/3935\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/media?parent=3935"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/categories?post=3935"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.inogic.com\/blog\/wp-json\/wp\/v2\/tags?post=3935"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}