Using Security Groups to Limit Users in Dynamics (Work 365)

Modified on Tue, Oct 21 at 11:02 AM

Applies To: Microsoft Dynamics 365 / Dataverse, Work 365
Audience: System Administrators, IT Governance Teams, Licensing Managers


Overview

In Work 365 environments on Microsoft Dynamics 365/Dataverse, you can restrict which licensed users are enabled in an environment by associating a Microsoft Entra ID (Azure AD) security group with that environment. Only users in the assigned security group get enabled in Dynamics. Work 365 license usage then counts only active, enabled users with read/write access.


When to Use This

  • Limit active Work 365 users to remain within your licensed tier.

  • Restrict access to specific teams (Billing, Support, Admin).

  • Separate access across environments (Production, Sandbox, Training).

Reference: Work 365 Support Portal – Security Group Configuration

Prerequisite: Global Administrator privileges in your Microsoft 365/Entra ID tenant.


Steps to Configure Access via Security Groups

Step 1: Create a Security Group in Microsoft 365/Entra

  1. Go to portal.office.com or the Microsoft 365 Admin Center.

  2. Navigate to Groups → Add a group.

  3. Choose Type = Security Group.

  4. Enter a Name and Description (e.g., Work365_Users).

  5. Add all users who should have access to the Work 365 environment.

  6. Save.

Tip (naming):

  • Work365-Prod-Users

  • Work365-Sandbox-Users

Step 2: Assign the Security Group to the Dynamics/Work 365 Environment

  1. Open the Power Platform Admin Center: admin.powerplatform.microsoft.com.

  2. Environments → select your target environment → Edit.

  3. Under Security group, select the group you created.

  4. Save.

Result: Only users in the group (with valid Dynamics licenses) are enabled in the environment.


Effect

ConditionResult
User is in the assigned security group and licensedEnabled in environment
User is licensed but not in the groupDisabled automatically
Admin user excluded from groupMay retain global admin access; add to group for consistency
Work 365 license countReflects enabled users only

More info: Microsoft Learn – Control user access to environments by using security groups


Impacts & Considerations

ScenarioImpact / Action
Assigning a group to an existing environment with many usersUsers not in the group are automatically disabled
System Admins not in the groupThey can still access as global admins, but should be added for visibility
Environment-level accessGroup controls who can access; Dynamics roles still define privileges
Work 365 license usageCounts enabled users only

Note: Using security groups simplifies governance—adding/removing users in the group updates access without manual user enable/disable in Dynamics.


Best Practices

  • Naming: Use environment-based names (Work365-Prod-Users, Work365-Dev-Users).

  • Layered Security: Combine group access (entry) with Dynamics roles (privileges).

  • Periodic Reviews: Audit group membership quarterly; remove inactive users.

  • Separate per Environment: Distinct groups for Prod, Sandbox, Training.

  • Document: Track group names, mapped environments, and admin contacts.


Troubleshooting

IssueCauseResolution
“You can’t access this environment.”User not in assigned security groupAdd the user to the correct group and retry
Users remain enabled after removalDirectory sync delay or cacheWait for sync or manually disable user in Dynamics
All users disabled after assignmentGroup missing required membersVerify membership; add admins/service accounts
License count not reducedOld users still marked enabledReview users and disable stale accounts

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article