
Dataverse Security - Simply Explained
Get every episode summarized
Each time M365.FM - Modern work, security, and productivity with Microsoft 365 publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
THE THREE LAYERS OF DATAVERSE SECURITY
Dataverse security is built around three distinct layers that work together. The first layer controls what actions users can perform. The second layer determines which records users are allowed to access. The third layer protects individual fields inside those records. Rather than relying on a single permission model, Dataverse combines these layers to provide highly granular security suitable for enterprise environments. Understanding how they interact is the key to designing secure Power Platform solutions.
SECURITY ROLES – WHO CAN DO WHAT
Everything starts with Security Roles. Every Dataverse user must have at least one security role before they can access any data. Security roles define privileges such as:
- Create
- Read
- Write
- Delete
- Append
- Assign
- Share
- Basic User
- System Customizer
- Environment Maker
- System Administrator
ACCESS LEVELS – HOW MUCH DATA?
Granting permission to read data isn't enough. Dataverse also defines how much data a user may access through Access Levels. The four primary scopes are:
- User
- Business Unit
- Parent: Child Business Units
- Organization
BUSINESS UNITS – ORGANIZING ACCESS
Business Units provide organizational separation. They typically represent departments such as:
- Sales
- Marketing
- Finance
- HR
- Customer Support
TEAMS – SHARED OWNERSHIP
While Business Units organize departments, Teams simplify collaboration. Dataverse supports two primary team types. Owning Teams Owning Teams own records collectively. Instead of assigning ownership to a single employee, an entire team becomes responsible for the record. This works particularly well for sales teams, service desks, and project groups where multiple people collaborate continuously. Access Teams Access Teams don't own records. Instead, they provide temporary or scenario-specific access without transferring ownership. Microsoft also integrates Teams with Microsoft Entra ID security groups, allowing administrators to manage membership centrally while Dataverse automatically synchronizes permissions. This significantly reduces administrative effort in larger organizations.
FIELD-LEVEL SECURITY
Sometimes protecting an entire record isn't enough. Sensitive information may exist in only one or two fields. Examples include:
- Salary
- Tax IDs
- Credit card numbers
- Social security numbers
- Banking details
- Read
- Update
- Create
MASKING AND BEST PRACTICES
Recent Dataverse enhancements introduced column masking, allowing organizations to partially display sensitive information. Instead of revealing an entire credit card number, users may only see the final four digits. Masking occurs on the server, ensuring consistent protection across forms, APIs, reports, and applications. Additional protections include:
- App Access Control
- Offline security
- Server-side enforcement
- Secure mobile synchronization
- Security Roles
- Business Units and Teams
- Field-Level Security only where necessary
COMMON TROUBLESHOOTING SCENARIOS
Many Dataverse security issues follow familiar patterns. A common mistake is creating a custom security role while forgetting to assign the Basic User role, preventing users from accessing the environment. Another frequent misunderstanding involves additive permissions. Assigning another security role never removes existing permissions—it only grants additional access. Administrators should also verify:
- Business Unit ownership
- Team ownership
- Access Levels
- Field Security Profiles
Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-a-microsoft-mvp-podcast-by-mirko-peters--6704921/support.
Get every episode summarized
Each time M365.FM - Modern work, security, and productivity with Microsoft 365 publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from M365.FM - Modern work, security, and productivity with Microsoft 365

Constraint-Based Scheduling: The Architecture That Makes Production Plans Real
M365.FM - Modern work, security, and productivity with Microsoft 365

A Machine Goes Down. How Should Your Production Plan React?
M365.FM - Modern work, security, and productivity with Microsoft 365

Can Value Stream Mapping Become a Live Data Model?
M365.FM - Modern work, security, and productivity with Microsoft 365

How Finite Capacity Scheduling Actually Works in Manufacturing
M365.FM - Modern work, security, and productivity with Microsoft 365