Overview
To create a connection between Smart Flows and Microsoft Dynamics 365 CE, a user account with sufficient permissions is required to establish the initial handshake between the two applications.
This topic outlines the minimum set of privileges required for that connector user within your Microsoft Dynamics 365 CE environment.
Required Privileges
If you want to create a dedicated security role for configuring and maintaining the Smart Flows connector, add the following privileges to that role:
|
Privilege |
Scope / Level |
Why it is required |
|---|---|---|
|
Organization - Read |
Organization |
Required during connector setup to retrieve organizational properties such as |
|
Solution - Read |
Organization |
Required during connector setup to check whether the Experlogix Smart Flows managed solution is installed. |
|
Entity - Read Attribute - Read Relationship Entity - Read |
Organization |
Required during connector setup and data set design to retrieve metadata about all Dynamics 365 CE entities, along with their attributes and relationships. |
|
User - Read Security Role - Read Team - Read |
Organization |
Required during connector setup to verify that the Smart Flows Administrator security role is assigned. Also required for retrieving users and security roles during user provisioning and user synchronization. |
Entity Data Permissions
In addition to the metadata privileges listed above, the connector user requires read and write access to the specific business entities (such as Account, Contact, or Opportunity) that your flows interact with during document generation and data collection.
These entity data privileges are only necessary for the connector user in the following cases:
-
Individual user authentications are switched off: All flow executions access Dynamics 365 CE data using the connector user credentials.
-
Individual user authentications are switched on with a fallback pattern: The connector user credentials are used as a fallback for non-interactive flow executions (such as automated or batch runs) when individual user credentials are not available.
When individual user authentications are enabled and flows are executed interactively, operations on business entities run under each user's own Dynamics 365 CE security role and permissions rather than the connector user's permissions.