When using legacy User Groups to assign permissions to users, it's possible to define for which companies the user should have the different user groups, and therefor permissions. This allows for a limited number of User Groups.
When using Security Groups, it looks like we must create several security groups in order to achieve the same result. Example with a company with 5 “roles” where there are 5 companies:
Before with User Groups with mapping og Companies per User:
CUSTOM BASIC
CUSTOM FINANCE
CUSTOM PROJECT
CUSTOM SALES
CUSTOM ADMIN
Now with Security Groups:
CUSTOM BASIC CUSTOMERX Company1
CUSTOM BASIC CUSTOMERX Company2
CUSTOM BASIC CUSTOMERX Company3
CUSTOM BASIC CUSTOMERX Company4
CUSTOM BASIC CUSTOMERX Company5
CUSTOM FINANCE CUSTOMERX Company1
CUSTOM FINANCE CUSTOMERX Company2
CUSTOM FINANCE CUSTOMERX Company3
CUSTOM FINANCE CUSTOMERX Company4
CUSTOM FINANCE CUSTOMERX Company5
CUSTOM PROJECT CUSTOMERX Company1
CUSTOM PROJECT CUSTOMERX Company2
CUSTOM PROJECT CUSTOMERX Company3
CUSTOM PROJECT CUSTOMERX Company4
CUSTOM PROJECT CUSTOMERX Company5
CUSTOM SALES CUSTOMERX Company1
CUSTOM SALES CUSTOMERX Company2
CUSTOM SALES CUSTOMERX Company3
CUSTOM SALES CUSTOMERX Company4
CUSTOM SALES CUSTOMERX Company5
CUSTOM ADMIN CUSTOMERX Company1
CUSTOM ADMIN CUSTOMERX Company2
CUSTOM ADMIN CUSTOMERX Company3
CUSTOM ADMIN CUSTOMERX Company4
CUSTOM ADMIN CUSTOMERX Company5
I hope we’re missing something here, and that there is already a solution for this. If not, there should be a way to map companies when assigning Security Groups, or an option to map the companies in Business Central once the user is imported. If the user comes into Business Central with access to all companies, we need an "activate" function to trigger when the company mapping is completed to make sure the user doesn't get too much access when first imported.
Comments
Actually, an extension to the permission sets assigned to a security group could solve this, as it would allow specifying the security group users who should only have the permission in specific companies, while the rest inherit the default
Category: General
We are also looking for a solution to this using Security groups.Customers with hundreds of companies where employees need to access different companies, is gonna flood with different Security groups..Make it work like User Groups where we can choose which company the specific employee gets permissions in.Before this is possible, our customers with 100+ companies NEED to continue using user groups and not security groups
Category: General
Business Central Team (administrator)
Thank you for this suggestion! Currently this is not on our roadmap. We are tracking this idea and if it gathers more votes and comments we will consider it in the future. Best regards, Business Central Team