This post is part of the New Functionality In Microsoft Dynamics 365 Business Central 2024 Wave 1 series in which I am taking a look at the new functionality introduced in Microsoft Dynamics 365 Business Central 2024 Wave 1.
The 8th of the new functionality in the Governance and administration section is Control partner access per environment.
Business Central customers with multiple environments are often working with many partners to support each environment. With this feature, customer administrators can now easily and efficiently control partner access to environments. This feature simplifies partner management by allowing administrators to assign partner tenants to each environment.
Enabled for: Admins, makers, marketers, or analysts, automatically
Public Preview: –
General Availability: Apr 2024
Feature Details
In 2024 release wave 1, Microsoft are introducing new environment settings in the Business Central admin center that enable internal administrators to control which environments delegated users and multitenant apps from partner tenants can access and administer. Internal administrators can specify the tenant IDs of partners that should be able to access each environment. Delegated users and multitenant apps accessing or administering the environment must belong to an allowlisted tenant. This feature is optional, and if no tenants are allowlisted for an environment, delegated users and multitenant apps will be able to access and administer the environment as they did before. This feature only affects the use of the admin center API by multitenant apps that have been authorized within the admin center
My Opinion
This sounds like a double edged sword; good for users to have the ability to restrict access to environments, but also too easy for something to be set incorrectly and deprive necessary access. However, the same can be said of any security on a system, so I’d say this is a good enhancement. Some of the clients I’ve worked with in the past have had very locked down systems, so they’d like this for witholding access to production while giving access to dev, QA and UAT environments. It could also be useful for companies operating in multiple countries by allowing only the partner for a specific country to access an environment.