Knowledge Base - Smart Flows

Minimal User Permissions in Dynamics 365 CE

Overview

To create a connection between Smart Flows and Microsoft Dynamics 365 CE, a user account with sufficient permissions is required to establish the initial handshake between the two applications.

This topic outlines the minimum set of privileges required for that connector user within your Microsoft Dynamics 365 CE environment.

Required Privileges

If you want to create a dedicated security role for configuring and maintaining the Smart Flows connector, add the following privileges to that role:

Privilege

Scope / Level

Why it is required

Organization - Read

Organization

Required during connector setup to retrieve organizational properties such as OrganizationId, UniqueName, UrlName, FriendlyName, OrganizationVersion, and languagecode.

Solution - Read

Organization

Required during connector setup to check whether the Experlogix Smart Flows managed solution is installed.

Entity - Read

Attribute - Read

Relationship Entity - Read

Organization

Required during connector setup and data set design to retrieve metadata about all Dynamics 365 CE entities, along with their attributes and relationships.

User - Read

Security Role - Read

Team - Read

Organization

Required during connector setup to verify that the Smart Flows Administrator security role is assigned. Also required for retrieving users and security roles during user provisioning and user synchronization.

Entity Data Permissions

In addition to the metadata privileges listed above, the connector user requires read and write access to the specific business entities (such as Account, Contact, or Opportunity) that your flows interact with during document generation and data collection.

These entity data privileges are only necessary for the connector user in the following cases:

  • Individual user authentications are switched off: All flow executions access Dynamics 365 CE data using the connector user credentials.

  • Individual user authentications are switched on with a fallback pattern: The connector user credentials are used as a fallback for non-interactive flow executions (such as automated or batch runs) when individual user credentials are not available.

When individual user authentications are enabled and flows are executed interactively, operations on business entities run under each user's own Dynamics 365 CE security role and permissions rather than the connector user's permissions.