!
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Field Level Security in Microsoft Dynamic CRM 2013


Introduction to field level security

Field level security  is a security feature available in Microsoft Dynamics CRM 2013 using which administrators can configure individual fields in Dynamics CRM web application so that user will have restricted access to those fields.

In Microsoft Dynamics CRM 2013 and Online you can use field level security to configure security roles that control user and team access rights to specific fields and entities.

One important point to remember when enabling field security is that it can be implemented only for custom fields, and not for system fields.

Benefits of field security in Dynamics CRM 2013

Using field security users can be given Create, Read, Update to individual fields in Dynamics Web forms based on the security profiles.

A Security profile determines the following:
  • Permissions to the secure fields
  • Users and Teams
A Security Profile can be configured to grant the following permissions at the field level to the added users or teams:
  • Read (read-only access to the field’s data)
  • Create (users or teams in this profile can add data to this field when creating a record)
  • Update (users or teams in this profile can update the field’s data after it has been created)
A combination of these three permissions can be configured to determine the user privileges for a specific data field.


Enabling Field security for a field on an entity form

In order to restrict access to individual form fields, field security should be enabled first and which includes the following two high level steps:
1.     Mark the field as a secure field (enable it to be secure); and
2.     Configure Security Profiles

1. Mark the field as a secure field (enable it to be secure)
Figure -1: Enable field security for a field by selecting ‘enabled’ option

This can be done by enabling the field security option on the form definition window and selecting ‘Enabled’ option as shown below.
Settings-> Customizations -> Customize the system -> Entities -> Entity Name -> Field Name.





2. Create field security profiles



Once the field(s) is enabled for field security, then we can create or use existing field security profiles to configure security to users belong to that profiles. These security profiles are similar to security roles in Dynamics CRM.


Security profiles are nothing but the means to configure field security to users by adding them to these profiles.


Field level security profiles can be created in  the following Settings section: Settings -> Administration -> Fiel Level Security Profiles.




Figure -2: Existing security profiles in the system



Figure -3: Details of a security profile


Add users or team to the profile

Once a security profile is created Dynamics CRM users can be added to the profile to whom field security need to be enabled.

Figure -4 : Adding uses to a security profile


Edit field permissions

Clicking on ‘Field Permissions’ navigation link on left side to to view the fields for which field   level security is enabled. 

Click on ‘Edit’ button on top to open the field permissions window for the particular field selected in the Field permission window.  You can select yes to to give ‘Read’, Update and Create permissions to the selected field level security profile.

Field permissions window can also be opened by double clicking on the field selected.

Figure -5: Setting Read, Update, Create permissions for  a security profile on a particular field.



Figure -6:  Edit field permissions for  a security profile on a particular field.


Microsoft Dynamics CRM 2011 Interview Questions- Security

Security is an important part of Microsoft Dyanmics CRM administrator day to day activities. Developers who customize and implement the Microsoft CRM also should have a good idea of security model. In any Microsoft CRM technical interview you can expect a couple of security questions. So I have compiled the most important security questions here.


Microsoft-Dynamics-CRM-2011-security-role-record-field-level-privilege-access-level

1. Difference between Role based and object based security.

2. What are the 3 different security levels in Microsoft CRM 2011


3. Define Role based, record based and field level security.


4. Define security roles and Field level security?

5. A user in Microsoft CRM have assigned Sales representative role and have Read access for accounts at user level. Later he assigned to a Sales manager role which has write access for accounts at organizations level. What would be the access he will have in effect?


6.  In a sales organization who implemented Microsoft CRM, sales manager wants the sales target and deadline fields disabled for sales executives from all the forms. How to achieve this?


7. Can a Microsoft CRM user apply field level security for a system entity field?


8. How to implement Field level security for a field in an entity form?


9. There exists two business units in an organization, BU1 and BU2. The admin need to give  user of BU1 access to some records that belongs to BU2. What is the best approach to configure the same?


10. Define privileges and access levels?

11. What are the five access level depths that are available for most privileges?


Also Read: Microsoft Dynamics CRM 2011 Interview Questions -1

Enjoy reading!! Feel free to add your comments below.