Hi All
I have gone head-first into the Security and Business structures and mechanisms of the Power Apps/D365 platform and all but gone mad. Its time to ask the gods again. 🙂
This is my first time working with it so there has been a lot to take in and my understanding is probably not perfect so please correct me if I look like I have taken the wrong approach. I am very close to having what I want, but I am facing some real sticking points at the bottom of the business structure and I cant see any posts with a similar use case so I am reaching out for some pointers. This project is not in production yet so I have nothing and nobody to bother by changing things.
Very abbreviated background:
- Canvas App for Client access.
- Dataverse backend.
- Client access is literally a client of the business. Not internal staff. (this is where my use case seems to differ from others)
- Model-driven app (Admins only - out of scope of the question)
- multiple points of business separation (Big Bosses/Regions/Clients)
After a significant amount of reading and brainstorming the requirements, I came up with the concept of the following structure:
4tier Business Unit set-up - each one below being a child:
- Root
- The Brass
- Regional Manager
- Client
The Brass and Regional Manager layers are, from all I can gather an easy implementation in this layout. The challenge for me at stage is the Client level.
For the Client Level, there would be Multiple individual clients in the single Client Business Unit. From my reading, having too many Business Units can both complicate and slow down the system. So my intention to avoid this was to have all Clients within a single Business Unit and isolate their data security and permissions via individual AAD Security Group Teams. From what I was reading, this would work, and it would allow the multiple users of each 'client' to work on the same data.
Implementation has not proven this to be the case though... I have set up an AAD Security Group Team and assigned it to the Client Business Unit. I have observed 2 issues so far which leave me thinking I have either totally misunderstood the material I've been reading, OR there is some kind of bug in my environment:
1. When one of the client users in the team creates something, the other member is unable to see the record.
2. Virtually anywhere that I am supposed to be able to 'assign' records to a Team, these AAD Security Group Teams are NOT visible. ONLY the Business Unit Teams. I am unable to change ownership of records to the Team. (This is as the Global Admin. So its not a permissions issue from here... I dont think!?)
3. It appears that when a user in this team creates a record, that USER is the owner of the record. Not the Team. (which explains point 1 really.
If it adds anything to the scenario - The ONLY location I have seen these teams show up when using the 'reassign records' function within the Classic D365 Security Admin Portal. THIS option allows me to select teams other than the Business Unit teams. But this is only useful for moving all records from a user to the team. Not specific records.
So I suppose my overall question is two-fold:
1. Why are these AAD Security Group Teams not showing up when I go to change ownership of records? (I think the answer to this will answer a lot of my underlying questions about implementation)
2. Am I wasting my time and making a mistake setting up my Clients in Teams rather than individual Business Units given they are for all intents and purposes 'external users' that need to have very limited access permissions? From what I can tell, getting this to work becomes real easy if I just use Business Units for each Client... But if the answer to this is yes, what happens if there ends up being thousands of clients and thus thousands of Business Units?
To all who made it to the bottom, thank you and I appreciate your time. Hoping someone out there can help me out.
Solved! Go to Solution.
Hi @Sheikx800,
Before I go further, have you evaluated Power Apps Portals for allowing your external clients access into the system? It uses Account (Organization) or Contact (Individual) as its primary ways of securing data.
The Azure AD group teams approach works and as you pointed out, is more flexible especially if many teams could be added or removed over time. But if you need a team per client and there are thousands of clients, managing this over time is unrealistic and you are better suited using portals and securing the data by the Account.
With regards to the issues you are experiencing:
#1 - This is likely due to Team Members Privilege Inheritence settings and how you assigned security roles. You'd want Team level privileges so that the members only have access to records owned by the team, and whenever they create records its auto assigned to the Team and not their individual accounts. You want to ensure you only assign the security role to the Team and not the individual, otherwise the record gets assigned to the individual by default and other team members won't have access.
#2 - the default Lookup views for Teams doesn't show AAD teams in the list. You'll need to select the view specifically for group teams, which is annoying because of the extra clicks.
#3 - see #1.
---
Please click Accept as Solution if my post answered your question. This will help others find solutions to similar questions. If you like my post and/or find it helpful, please consider giving it a Thumbs Up.
Hi @Sheikx800,
Before I go further, have you evaluated Power Apps Portals for allowing your external clients access into the system? It uses Account (Organization) or Contact (Individual) as its primary ways of securing data.
The Azure AD group teams approach works and as you pointed out, is more flexible especially if many teams could be added or removed over time. But if you need a team per client and there are thousands of clients, managing this over time is unrealistic and you are better suited using portals and securing the data by the Account.
With regards to the issues you are experiencing:
#1 - This is likely due to Team Members Privilege Inheritence settings and how you assigned security roles. You'd want Team level privileges so that the members only have access to records owned by the team, and whenever they create records its auto assigned to the Team and not their individual accounts. You want to ensure you only assign the security role to the Team and not the individual, otherwise the record gets assigned to the individual by default and other team members won't have access.
#2 - the default Lookup views for Teams doesn't show AAD teams in the list. You'll need to select the view specifically for group teams, which is annoying because of the extra clicks.
#3 - see #1.
---
Please click Accept as Solution if my post answered your question. This will help others find solutions to similar questions. If you like my post and/or find it helpful, please consider giving it a Thumbs Up.
Hi @ChrisPiasecki - Thank you for your response! Thank you for your comment on Portals. It confirms a direction I would like to go once this project hits market and develops some financial traction. Unfortunately, with the cost of Portal implementation, its not feasible until we are more established. I did a cost analysis on the 'tipping' point for this early in the project and it is highly beneficial once we have an established client base, but it would have us hemorrhaging money in the short-term. So it will be internal users and licensing for the beginning of the journey.
Thank you for your comments on Member Privilege Inheritance. The possibility that I have assigned privs to both the user and the group crossed my mind while I was staring at the ceiling in bad last night. I will check that later today and hopefully its the problem.
As for #2 - I cant believe I missed that... I had been into the advanced lookup window a dozen times but somehow missed the drop-down in the teams section to let you select the other teams... Thanks so much.
Will adjust privileges and re-assign some records later today and post back with outcome.
@ChrisPiasecki I have had another good play with this a and had a good read of this page as well:
Security roles and privileges - Power Platform | Microsoft Docs
Using advanced lookup and not having a 'man look' I was able to assign my records correctly to my teams. I can now observe each individual team in the same BU is seeing their own records. This is great.
I still seem to be missing or mis-understanding something with the Team privileges... It claims on that page that "For team members who do not have user privileges of their own, they can only create records with the team as the owner and they have access to records owned by the Team when Basic access level for Create and Read were given." If I dont give them any USER rights to create within the table they are working on, it should create within the Team right??
When one of my users goes to create a new record within the canvas app, the app errors and states they need create privileges, even though they should be getting that from the Teams security role and, I would then assume, it would create the record with the Team as the owner. I cant even find a gallery field that works nicely to change the owner of a new blank record and I didn't suspect it'd be possible. I was hoping that when these users created records this way they could straight away become owned by the Team. Am I wrong in this thinking? I see a few forum posts of people asking similar questions and getting responses with ideas such as having an instant flow monitoring the table and re-assigning records as users put them in... seems very work-aroundy to me???
I realise I am bending the rules a bit here by asking follow-up questions in the same thread.. but its very closely related so I am hoping it'll help others to have the response in the same place if you happen to have a solution. 🙂
I have opened up another post to cover this specific point @ChrisPiasecki - If you can answer the question by all means do but I figure it deserves extra points. 🙂
Creating records with Team as owner - Canvas App
Thought I would come back and post on my resolution to all of this in case anyone else with my struggle stumbles across this post.
Given time restraints and not being able to find a real solution to this issue, I changed my security structure to be dependent on Business Units rather than Teams. This is going to result in a lot of Business Units over time, but if our project gets to a point where the number of Business Units are causing problems in the Organisation (apparently around 1000 units), we will be in a very good place and be quite happy to fix it then. 🙂
So to summarise, I am no longer using AAD Security Group teams for segmenting/assigning record ownership. I have changed to using Business Unit Owner Teams and also User ownership to allow users to Create records (which they couldn't do when they had Teams only permissions). I have adjusted the security role to allow access to all permissions at a BUSINESS UNIT level rather than a user level as I was originally hoping. So now users can create records, and see other users' records that are within the team.
Using multiple Business Units in a parent-child relationship was a functional approach to this issue for our use case. I still believe that AAD Security Group Teams are a lot more flexible, but I couldn't find any resources or confirm why I was unable to create records directly on behalf of the Team from my Canvas app.
Our ongoing BACK TO BASICS: TUESDAY TIP series dedicated to helping both new members and seasoned veterans of our community learn and grow reached a milestone ten posts! We're excited to present this "one stop" post for each of our #TuesdayTips, making it easier to find what you're looking for and help you understand the community: from ranking and badges to profile avatars, from being a Super User to blogging in the community, and so much more. Thank you for your incredible support for this series--we are so glad it was able to help so many of you navigate your community experience. Back to Basics Tuesday Tip #1: All About Your Community Account Find out the basics of your community account. Whether it's changing your username, updating an email address, understanding GDPR, or customizing your profile, this is the place to begin. Community Links: ○ Power Apps ○ Power Automate ○ Power Pages ○ Copilot Studio Back to Basics Tuesday Tip #2: All About Community Ranks Have you ever wondered how your fellow community members earn the different ranks available? What is the difference between an Advocate and a Helper, a Solution Sage and a Community Champion? In this #TuesdayTip, we share the secrets and tips to help YOU keep your ranking growing--and why it's so important to our communities. Community Links: ○ Power Apps ○ Power Automate ○ Power Pages ○ Copilot Studio Back to Basics Tuesday Tip #3: Contributing to the Community If you need to understand how subscriptions or notifications work, how to use search to find the answers you're looking for, or editing your posts, this is the place to start. With these handy tips, you'll find what you're looking for, ask some great questions, and format your posts perfectly! Community Links: ○ Power Apps ○ Power Automate ○ Power Pages ○ Copilot Studio Back to Basics Tuesday Tip #4: What is a Super User? Have you ever been exploring the community and come across a user with this unique icon next to their name? It means you have found the actual, real-life superheroes of the Power Platform Community! Super Users are our heroes because of the way they are consistently helpful with everything from solutions to flagging spam, offering insight on the community, and so much more! Find out more in this #TuesdayTip. Community Links: ○ Power Apps ○ Power Automate ○ Power Pages ○ Copilot Studio Back to Basics Tuesday Tip #5: How to Become a Community Blog Author We want YOU to be part of the community blog! Sharing your knowledge of Power Platform is an essential part of our community! By sharing what you know and have learned with the community in the Power Platform in the community blog, you help us create a more engaged and informed community, better equipped to tackle complex challenges. To get started with blogging across the Power Platform communities, please visit the following links. Community Links: ○Power Apps ○ Power Automate ○ Power Pages ○ Copilot Studio Back to Basics Tuesday Tip #6 All About Community User Groups Being part of, starting, or leading a User Group can have many great benefits for our community members who want to learn, share, and connect with others who are interested in the Microsoft Power Platform and the low-code revolution. Don't wait. Get involved with (or maybe even start) a User Group today--just follow the tips below to get started. Community Links: ○ Power Apps ○ Power Automate ○ Power Pages ○ Copilot Studio Back to Basics Tuesday Tip #7: Resources for User Groups Once you've launched your Community User Group, we are excited to have many resources available that can help you lead, engage, and grow your User Group! Whether it's access to the Microsoft Community Tenant for User Groups, help with finding speakers for your User Group meetings (both local and virtual speakers), and even finding spaces to have your meetings in--check out this #TuesdayTip to get what you need! Community Links: ○ Power Apps ○ Power Automate ○ Power Pages ○ Copilot Studio Back to Basics Tuesday Tip #8: All About Subscriptions and Notifications Keeping track of what you want to know and how you want to find out about it may seem confusing. This #TuesdayTip is all about your community profile's subscriptions and notifications settings. Check out the links below for clear directions and how-to's. Community Links: ○ Power Apps ○ Power Automate ○ Power Pages ○ Copilot Studio Back to Basics Tuesday Tip #9: All About the Community Galleries Have you checked out the library of content in our galleries? Whether you're looking for the latest info on an upcoming event, a helpful webinar, or tips and tricks from some of our most experienced community members, our galleries are full of the latest and greatest video content for the Power Platform communities. Find out more by following the links below. Community Links: ○Power Apps ○ Power Automate ○ Power Pages ○ Copilot Studio Back to Basics Tuesday Tip #10: Community Support Whether you're a seasoned community veteran or just getting started, you may need a bit of help from time to time! If you need to share feedback with the Community Engagement team about the community or are looking for ways we can assist you with user groups, events, or something else, Community Support is the place to start. Community Support is part of every one of our communities, accessible to all our community members, so find out what it means for your community with our last #TuesdayTip. Community Links: ○ Power Apps ○ Power Automate ○ Power Pages ○ Copilot Studio Thank you for your support for our #TuesdayTip series. We look forward to bringing you more tips and tricks to help make your community experience the best it can be!
A new month means it's time to celebrate and welcome the new user groups that have joined our community. We are excited to announce that we have more than 8 New Groups, which is no surprise after the amazing Microsoft Power Platform Conference. This month, we are breaking them out by the different community categories. If your group is listed here, give this post a kudo so we can celebrate with you! Don't forget to take a look at the many events happening near you or virtually! It's a great time of year to connect and engage with User Groups both locally and online. Please Welcome Our NEW User Groups Power Platform: PowerIT User Group: Nottingham Power Platform User Group: Bergen Power Platform User Group: Danmark Nashville Power Platform User Group Microsoft Ambassador Program y Mujer Latina Technolochicas NCWIT Community Copilot Studio: Copilot User Group Italia Dynamics365: Dynamics User Group AdriaticDynamic 365 Azerbaijan December User Group Events 01 Dec 2023 Aprendiendo Desarrollo web, creando mi primer power app y power page. 01 Dec 2023 Q4 Hybrid Philadelphia Dynamics 365 & Power Platform User Group Meeting05 Dec 2023APAC Dynamics 365 FastTrack Bootcamp - BI and Analytics07 Dec 2023Bay Area Power Platform Meetup: Learn, Share, and Connect07 Dec 2023Indiana D365/AX December User Group Meeting07 Dec 2023Dynamics User Group Meeting: Houston09 Dec 2023 December '23 - NEW Power Apps User Group Meeting - Online 12 Dec 2023December Cleveland Power Platform User Group Meeting12 Dec 2023 RW2 Data Stewardship Open Forum Discussion 13 Dec 2023 Black Country Power Platform User Group - December 2023 - West Midlands
Welcome to our November Newsletter, where we highlight the latest news, product releases, upcoming events, and the amazing work of our outstanding Community members. If you're new to the Community, please make sure to follow the latest News & Announcements and check out the Community on LinkedIn as well! It's the best way to stay up-to-date with all the news from across the Power Platform and beyond. This month's highlights:- - Our most active community members- Microsoft Power Up Program- Microsoft Community Days website - The latest blogs and more COMMUNITY HIGHLIGHTS Check out the most active community members of the last month. These hardworking members are posting regularly, answering questions, kudos, and providing top solutions in their communities. We are so thankful for each of you--keep up the great work! If you hope to see your name here next month, just get active! FLMikePstork1Nived_NambiarWarrenBelzSprongYeManishSolankiLaurensMwskinnermlcAgniusExpiscornovuscreativeopinion KatieAUinzil2kHaressh2728hafizsultan242douicmccaughanwoLucas001domliu Power Up Program Click the image below to discover more about the amazing Microsoft Power Up Program, as Reem Omar, Abbas Godhrawala, Chahine Atallah, Ruby Ruiz Brown, Juan Francisco Sánchez Enciso, Joscelyne Andrade Arévalo, Eric G. and Paulina Pałczyńska share how non-tech professionals can successfully advance into a new career path using Microsoft #PowerPlatform. To find out more about this amazing initiative, click here to apply for the program and reboot your journey into low-code app development today! Community Days - Event Website Have you checked out the Community Days website yet? Dedicated to the volunteer community organizers around the world, Community Days is the perfect place to find an event near you or add an event for wider exposure. Many thanks to Thomas Daly, Sharon Weaver, Sedat Tum, Jonathan Weaver, Manpreet Singh, David Leveille, Jason Rivera, Mike Maadarani, Rob Windsor and the team for all their hard work. Anyone can host a Community Day on any topic relevant to our industry, just click the image below to find out more. EVENT NEWS Power Platform French Summit - Paris/Virtual - 6-7th Dec It's not long now until the Power Platform French Summit, which takes place both virtually and in-person at the Microsoft France conference center in Paris on 6-7th December 2023. If you can't make it in-person, all sessions will also be broadcast on virtual networks for better distribution and accessibility. There's a fantastic array of speakers, including Jérémy LAPLAINE, Amira Beldjilali, Rémi Chambard, Erika Beaumier, Makenson Frena, Assia Boutera, Elliott Pierret, Clothilde Facon, Gilles Pommier, Marie Aubert, Antoine Herbosa, Chloé Moreau, Raphaël Senis, Rym Ben Hamida, Loïc Cimon, Joséphine Salafia, David Zoonekyndt, Aïcha Charpentier, Henry Jammes, Milene Rochard, Mehdi EL YASSIR, and many more. Click the image below for more information. LATEST COMMUNITY BLOG ARTICLES Power Apps Community Blog Power Automate Community Blog Copilot Community Blog Power Pages Community Blog
In the bustling world of technology, two dynamic leaders, Geetha Sivasailam and Ben McMann, have been at the forefront, steering the ship of the Dallas Fort Worth Power Platform User Group since its inception in February 2019. As Practice Lead (Power Platform | Fusion Dev) at Lantern, Geetha brings a wealth of consulting experience, while Ben, a key member of the Studio Leadership team at Lantern, specializes in crafting strategies that leverage Microsoft digital technologies to transform business models. Empowering Through Community Leadership Geetha and Ben's journey as user group leaders began with a simple yet powerful goal: to create a space where individuals across the DFW area could connect, grow their skills, and add value to their businesses through the Power Platform. The platform, known for its versatility, allows users to achieve more with less code and foster creativity. The Power of Community Impact Reflecting on their experiences, Geetha and Ben emphasize the profound impact that community engagement has had on both their professional and personal lives. The Power Platform community, they note, is a wellspring of resources and opportunities, fostering continuous learning, skill enhancement, and networking with industry experts and peers. Favorite Moments and Words of Wisdom The duo's favorite aspect of leading the user group lies in witnessing the transformative projects and innovations community members create with the Power Platform. Their advice to aspiring user group leaders? "Encourage diverse perspectives, maintain an open space for idea-sharing, stay curious, and, most importantly, have fun building a vibrant community." Building Bridges, Breaking Barriers Geetha and Ben encourage others to step into the realm of user group leadership, citing the rewarding experience of creating and nurturing a community of like-minded individuals. They highlight the chance to influence, impact, and positively guide others, fostering connections that extend beyond mere technology discussions. Joining a User Group: A Gateway to Growth The leaders stress the importance of joining a user group, emphasizing exposure to diverse perspectives, solutions, and career growth opportunities within the Power Platform community. "Being part of such a group provides a supportive environment for seeking advice, sharing experiences, and navigating challenges." A Year of Milestones Looking back at the past year, Geetha and Ben express pride in the group's growth and global participation. They recount the enriching experience of meeting members in person at the Microsoft Power Platform conference, showcasing the diverse range of perspectives and guest speakers that enriched the community's overall experience. Continuous Learning on the Leadership Journey As user group leaders, Geetha and Ben recognize the continuous learning curve, blending interpersonal skills, adaptability, and dedication to foster a vibrant community. They highlight the importance of patience, persistence, and flexibility in achieving group goals, noting the significance of listening to the needs and suggestions of group members.They invite all tech enthusiasts to join the Dallas Fort Worth Power Platform User Group, a thriving hub where the power of community propels individuals to new heights in the dynamic realm of technology.
This is the TENTH post in our ongoing series dedicated to helping the amazing members of our community--both new members and seasoned veterans--learn and grow in how to best engage in the community! Each Tuesday, we feature new content that will help you best understand the community--from ranking and badges to profile avatars, from Super Users to blogging in the community. Our hope is that this information will help each of our community members grow in their experience with Power Platform, with the community, and with each other! This Week: All About Community Support Whether you're a seasoned community veteran or just getting started, you may need a bit of help from time to time! If you need to share feedback with the Community Engagement team about the community or are looking for ways we can assist you with user groups, events, or something else, Community Support is the place to start. Community Support is part of every one of our communities, accessible to all our community members. Power Apps: https://powerusers.microsoft.com/t5/Community-Support/ct-p/pa_community_support Power Automate: https://powerusers.microsoft.com/t5/Community-Support/ct-p/mpa_community_support Power Pages: https://powerusers.microsoft.com/t5/Community-Support/ct-p/mpp_community_support Copilot Studio: https://powerusers.microsoft.com/t5/Community-Support/ct-p/pva_community-support Within each community's Community Support page, you'll find three distinct areas, each with a different focus to help you when you need support from us most. Community Accounts & Registration is the go-to source for any and all information related to your account here in the community. It's full of great knowledge base articles that will help you manage your community account and know what steps to take if you wish to close your account. ● Power Apps ● Power Automate ● Power Pages, ● Copilot Studio Using the Community is your source for assistance with everything from Community User Groups to FAQ's and more. If you want to know what kudos are, how badges work, how to level up your User Group or something else, you will probably find the answers here. ● Power Apps ● Power Automate ● Power Pages ● Copilot Studio Community Feedback is where you can share opportunities, concerns, or get information from the Community Engagement team. It's your best place to post a question about an issue you're having in the community, a general question you need answered. Whatever it is, visit Community Feedback to get the answers you need right away. Our team is honored to partner with you and can't wait to help you! ● Power Apps ● Power Automate ● Power Pages ● Copilot Studio
What an amazing event we had this year, as Microsoft showcased the latest advancements in how AI has the potential to reshape how customers, partners and developers strategize the future of work. Check out below some of our handpicked videos and Ignite announcements to see how Microsoft is driving real change for users and businesses across the globe. Video Highlights Click the image below to check out a selection of Ignite 2023 videos, including the "Microsoft Cloud in the era of AI" keynote from Scott Guthrie, Charles Lamanna, Arun Ulag, Sarah Bird, Rani Borkar, Eric Boyd, Erin Chapple, Ali Ghodsi, and Seth Juarez. There's also a great breakdown of the amazing Microsoft Copilot Studio with Omar Aftab, Gary Pretty, and Kendra Springer, plus exciting sessions from Rajesh Jha, Jared Spataro, Ryan Jones, Zohar Raz, and many more. Blog Announcements Microsoft Copilot presents an opportunity to reimagine the way we work—turning natural language into the most powerful productivity tool on the planet. With AI, organizations can unearth value in data across productivity tools like business applications and Microsoft 365. Click the link below to find out more. Check out the latest features in Microsoft Power Apps that will help developers create AI-infused apps faster, give administrators more control over managing thousands of Microsoft Power Platform makers at scale, and deliver better experiences to users around the world. Click the image below to find out more. Click below to discover new ways to orchestrate business processes across your organization with Copilot in Power Automate. With its user-friendly interface that offers hundreds of prebuilt drag-and-drop actions, more customers have been able to benefit from the power of automation. Discover how Microsoft Power Platform and Microsoft Dataverse are activating the strength of your enterprise data using AI, the announcement of “plugins for Microsoft Copilot for Microsoft 365”, plus two new Power Apps creator experiences using Excel and natural language. Click below to find out more about the general availability of Microsoft Fabric and the public preview of Copilot in Microsoft Fabric. With the launch of these next-generation analytics tools, you can empower your data teams to easily scale the demand on your growing business. And for the rest of all the good stuff, click the link below to visit the Microsoft Ignite 2023 "Book of News", with over ONE HUNDRED announcements across infrastructure, data, security, new tools, AI, and everything else in-between!
User | Count |
---|---|
4 | |
4 | |
2 | |
1 | |
1 |