When a new employee needs access to Microsoft Dynamics 365 Business Central, setting them up involves a little more than simply creating a username and password.
You need to consider how they access Business Central, what they should be able to see, what they should be able to do and which areas of the system are relevant to their role.
Getting those elements right is important.
Give somebody too little access and they may struggle to do their job. Give them more access than they need and you could expose information or functionality unnecessarily.
The good news is that Business Central gives you several ways to manage this through users, licences, Role Centres, permission sets and Security Groups.
In this guide, we'll explain what each of those means, how they fit together and what you need to think about when setting up a new Business Central user.
And if you're looking for the step-by-step process, we've also put together a Business Central Roles, Users and User Setup helpsheet that you can keep to hand.
How to Set Up Users in Business Central: Roles, Permissions and Security Groups Explained
When a new employee needs access to Microsoft Dynamics 365 Business Central, setting them up involves a little more than simply creating a username and password.
You need to consider how they access Business Central, what they should be able to see, what they should be able to do and which areas of the system are relevant to their role.
Getting those elements right is important.
Give somebody too little access and they may struggle to do their job. Give them more access than they need and you could expose information or functionality unnecessarily.
The good news is that Business Central gives you several ways to manage this through users, licences, Role Centres, permission sets and Security Groups.
In this guide, we'll explain what each of those means, how they fit together and what you need to think about when setting up a new Business Central user.
And if you're looking for the step-by-step process, we've also put together a Business Central Roles, Users and User Setup helpsheet that you can keep to hand.
What do you need to set up a new user in Business Central?
At a high level, there are several parts to getting somebody properly set up:
The user account identifies who is signing in.
The licence determines their entitlement to use Business Central.
Permission sets control which areas of Business Central they can access and what actions they are permitted to perform.
The Role Centre determines how Business Central is presented to them and which information is prioritised on their homepage.
Security Groups can make it easier to manage permissions consistently for groups of employees.
One of the most important things to understand is that these elements don't all do the same job.
In particular, a Role Centre and a permission set are not the same thing.
What's the difference between a Role and permissions in Business Central?
This is an easy distinction to miss.
A Role Centre, sometimes referred to as a Profile or Role, determines how Business Central looks for that user.
For example, Business Central includes Role Centres aimed at different types of users, including:
- Business Manager
- Accountant
- Sales Order Processor
- Purchasing Agent
- Warehouse Worker
- Team Member.
An accountant might therefore see finance-focused information, reports and activities when they sign in, while somebody working in sales might see customers, sales quotes and orders more prominently.
But their Role Centre does not determine what they have permission to do.
That is controlled separately by permission sets.
A user could therefore have a very limited-looking Role Centre while technically having extensive permissions behind the scenes — or the reverse. Changing someone's Role Centre does not automatically change their permissions.
A simple way to think about it is:
Role Centre = what their Business Central workspace looks like
Permissions = what Business Central actually lets them do
That distinction is particularly important when setting up new starters.
How do you add a new user to Business Central?
For Business Central Online, the process starts outside Business Central itself.
Your user is first created through Microsoft 365 / Microsoft Entra ID, where the appropriate account and licence are assigned. The user can then be synchronised into Business Central.
Microsoft's current documentation follows the same overall approach: users are created through Microsoft 365 and access within Business Central is then managed using licences and permissions.
At a simplified level, the process looks like this:
1. Create the user's account
Create the employee's account in Microsoft 365 / Microsoft Entra ID and assign the appropriate Business Central licence.
2. Bring the user into Business Central
Within Business Central, open the Users page and use the appropriate user update/synchronisation option to bring their details across.
The HBP helpsheet covers this process step-by-step, including the Update Users from Microsoft 365 action.
3. Configure their user details
Once the user is available in Business Central, review their User Card and make sure the relevant details have been populated and saved.
4. Give them the right permissions
Next, decide what this person actually needs to be able to do.
This is where permission sets become important.
5. Choose the appropriate Role Centre
Consider which Business Central Role Centre best reflects their day-to-day job and gives them the most useful starting point when they sign in.
6. Test their access
Finally, don't assume that because everything looks correct in the setup, the user can do everything they need.
The HBP onboarding checklist recommends testing the sign-in and carrying out role-specific transactions to confirm their access works as expected.
How do permission sets work in Business Central?
Permission sets determine which parts of Business Central a user can access and what they can do with them.
That can include whether somebody can read, insert, modify or delete information across Business Central objects such as tables, pages and reports.
This allows access to be matched much more closely to somebody's responsibilities.
For example, a warehouse employee may need access to stock and warehouse functionality but have no reason to access detailed financial information.
Likewise, somebody processing sales orders may need to work extensively with customers and sales documents without requiring access to every finance or administration function.
The aim is therefore not simply to ask:
"Can this person access Business Central?"
but:
"Can they access the right parts of Business Central for their job?"
Microsoft also recommends using permissions and permission sets to fine-tune which functionality users can access.
Should you create your own Business Central permission sets?
Business Central includes built-in permission sets supplied and maintained by Microsoft, but businesses can also create their own user-defined permission sets.
One important recommendation in our helpsheet is to copy a Microsoft permission set and modify the copy, rather than directly editing the built-in version.
That's because Microsoft's built-in sets can change as Business Central is updated.
That gives you greater control over your own configuration while reducing the risk of future Microsoft updates affecting changes you've made.
What are Security Groups in Business Central?
If you're managing more than a handful of users, setting permissions individually every time somebody joins or changes role can become difficult to maintain.
That's where Security Groups can help.
A Security Group is created in Microsoft Entra ID and linked with Business Central. Rather than assigning the same permission sets individually to every employee, permissions can be assigned to the group.
Users who belong to that group then inherit those permissions.
For example, you could have groups such as:
BC Finance Users
BC Sales Users
BC Purchasing Users
When somebody joins your finance team, you add them to the relevant group rather than rebuilding their access from scratch.
Microsoft describes Security Groups as a way to make permissions easier to manage across multiple users, with permissions assigned to the group and then applied to its members.
Why use Security Groups rather than setting everybody up individually?
The bigger your Business Central user base becomes, the more valuable this approach can be.
Without Security Groups, every new employee can mean another collection of individual permission assignments.
Over time, that increases the risk of:
inconsistent access, missed permissions, unnecessary permissions and more administration whenever somebody joins, leaves or changes role.
With Security Groups, businesses can create a more repeatable approach.
Our Business Central helpsheet summarises the benefit particularly well: Security Groups can make onboarding faster, reduce errors and make access easier to audit.
It is also now an important part of Microsoft's current Business Central security model. Microsoft replaced the older User Groups approach with Security Groups beginning in Business Central version 22.
What should you check when setting up a new Business Central user?
A useful user onboarding process should go beyond simply checking whether the person can log in.
Before considering the setup complete, it is worth checking:
- the correct Microsoft account and licence have been assigned;
- the user has been brought into Business Central;
- their User Card contains the appropriate information;
- the correct permission sets or Security Group membership have been applied;
- their Role Centre makes sense for the work they do;
- they can successfully sign in;
- they can carry out the transactions and tasks their job requires; and
- the setup has been recorded appropriately for future access reviews.
These steps form the basis of the onboarding checklist included in our helpsheet.
Get the complete Business Central user setup helpsheet
There is a lot to consider when setting up Business Central users, particularly once you start looking at different roles, permissions and Security Groups.
That's why we've put the practical steps together in one place.
Our Microsoft Dynamics Business Central – Roles, Users and User Setup helpsheet covers setting up a user, assigning Role Centres and permission sets, creating and using Security Groups and a checklist to follow when onboarding somebody new.
Download the Business Central Roles, Users and User Setup Helpsheet >
If you're unsure about the access somebody needs or would like help reviewing the way users and permissions are currently managed within your Business Central environment, speak to the HBP Business Central team.
Posted by The HBP Group
Written by experts across the business, The HBP Group blog covers cybersecurity, IT best practice, Microsoft solutions, ERP systems, and technology strategy—helping organisations reduce risk, improve performance, and make smarter IT decisions.