Dynamics 365 Business Central User Onboarding: Give Staff Secure, Role-Based Access
Introduction
Business Central rarely belongs to one person. Accountants, chartered accountants, finance managers, and other staff may need access to the same ERP system. Each user needs the right identity, license, sign-in protection, and permissions before working with financial data.
Dynamics 365 Business Central user onboarding has two main paths. You can create an internal Microsoft 365 user for an employee, or invite an external person as a guest with a Gmail or other personal account. The correct choice depends on the person’s relationship with your organization.
Watch our step-by-step video to learn How to add users in Dynamics 365 Business Central, configure user setup, and assign permissions in just 5 minutes:
Choose the Right Dynamics 365 Business Central User Onboarding Method
Your onboarding method affects account control, licensing, and security. Internal employees usually need a company account managed through Microsoft 365. External users may need limited guest access for a defined business task.
Use Microsoft 365 accounts for employees and internal users
Microsoft 365 accounts suit employees who work for your company. This includes finance staff, accountants, managers, and other users who need regular access to Business Central.
You create the account in the Microsoft 365 admin center and assign a Business Central license. The account can then synchronize with Business Central, where an administrator reviews the user and assigns permission sets.
Invite external users as Business Central guests
External users may include outside accountants, consultants, auditors, or business partners. They can be invited with Gmail or another personal email address, depending on your Microsoft 365 and Business Central setup.
The transcript references guest access but does not show the complete invitation process. Before inviting an external user, check the available license rules and decide which Business Central data and actions the guest needs. Give external users limited access that matches their work.
Separate licensing from permissions
A license allows a user to access the Business Central service. Permission sets control what the user can view, create, change, or post inside the system.
These are separate parts of onboarding. An employee may have a valid license but still lack access to finance pages or transactions. Review the user’s duties before assigning permissions, and avoid broad admin access when a smaller role is enough.
Create a Microsoft 365 User for Dynamics 365 Business Central User Onboarding
The Microsoft 365 admin center is the starting point for onboarding an employee. The process creates the user’s identity and connects that identity to a Business Central subscription.
Add the employee in the Microsoft 365 admin center
Open admin.microsoft.com and select Add user. Enter the employee’s name and create a username that follows your organization’s account policy.
Set a strong temporary password. Avoid short, common, or predictable passwords, even if the user will change the password later. Share initial sign-in details through an approved secure channel.
Assign the Business Central subscription
Continue to the licensing screen after entering the user’s account details. Select the available Business Central product license. If several Microsoft subscriptions appear, review each option and choose the one approved for the employee’s role.
Finish the account setup after assigning the license. The employee can then sign in with the new Microsoft 365 email address and password.
Confirm the account is ready for sign-in
Record the new sign-in address in your access records. Tell the employee when to sign in and explain that Microsoft may require extra identity checks during the first login.
The account may still need to synchronize with Business Central. It also needs suitable permission sets before the employee can complete daily tasks.
Secure the First Business Central Sign-In with MFA
Business Central contains financial records, customer information, vendor details, and transaction data. Multifactor authentication adds another check beyond the password and helps protect the account if the password is exposed.
Sign in through the Business Central portal
Open businesscentral.dynamics.com in a browser. The new employee enters the Microsoft 365 email address and password created during account setup.
A successful login should lead to the Business Central homepage. This flow applies to an internal Microsoft 365 user. A guest user may follow a different authentication process based on the external account.
Register Microsoft Authenticator
Microsoft Authenticator may appear during the first sign-in. Install the app on the user’s mobile device, select Next, and scan the QR code shown on the screen.
The app may ask the user to approve a sign-in request or enter a number displayed in the browser. Complete that prompt in the Authenticator app to confirm the user’s identity.
Complete additional verification
Business Central or Microsoft 365 may also ask for a mobile number. Enter the number and complete the verification code process when prompted.
This second check helps reduce unauthorized access to financial systems. Require MFA for users who handle records, approvals, postings, or other sensitive Business Central work.
Synchronize Users and Assign Business Central Permissions
Creating a Microsoft 365 account does not always make the user appear in Business Central at once. Automatic synchronization may take time, or an administrator may need to start the update manually.
Update users from Microsoft 365 when synchronization is delayed
Open the Business Central administration area and search for Users. Look for the option named Update users from Microsoft 365.
Run the update if the new employee does not appear in the user list. Confirm that the process finishes successfully. In the demonstrated process, one user update was applied and then closed.
Verify the user appears in Business Central
Search for the employee by name or account email. Check that the displayed identity matches the Microsoft 365 account created earlier.
Confirm that the user is enabled and can reach the Business Central homepage. The administrator’s view may show settings and user controls that the employee will not see.
Review permission sets before granting access
Synchronization only imports the account. It does not decide what the employee can do in Business Central.
Review the employee’s job duties before assigning permission sets. Finance access may include customer records, vendors, posting, or transactions, so test the account with the intended role. Review access again when the employee changes jobs or leaves the company.
Validate Dynamics 365 Business Central User Onboarding
A user is not fully onboarded when the account exists. You should test the complete sign-in process and confirm that the employee sees the right Business Central functions.
Test the complete employee sign-in experience
Sign in through businesscentral.dynamics.com with the new account. Confirm that Microsoft Authenticator works and that the Business Central homepage loads.
Check the user’s access to pages, records, and actions. The employee should see the tools needed for the assigned role, without receiving unnecessary administrative rights.
Troubleshoot missing users and failed access
If the user cannot sign in, check that the Microsoft 365 account was created successfully and that a Business Central license was assigned. Then run Update users from Microsoft 365 and confirm that the account is enabled.
If login works but key functions are missing, review the permission sets. If the MFA prompt fails, confirm that Authenticator registration and phone verification are complete.
Use an onboarding checklist for repeatable administration
Use the following checklist for each new employee or guest:
- Create the Microsoft 365 account or begin the external guest process.
- Assign the correct Business Central license.
- Provide secure sign-in instructions.
- Register Microsoft Authenticator and complete MFA.
- Synchronize the account with Business Central.
- Assign and review permission sets.
- Test the final user experience.
- Record the approved access and responsible administrator.
Conclusion
Effective Dynamics 365 Business Central user onboarding connects five controls: identity, licensing, authentication, synchronization, and permissions. Internal employees usually receive Microsoft 365 accounts, while external users may receive guest invitations with limited access.
Assign the Business Central license, complete MFA, and confirm the account appears in Business Central. If synchronization fails, use Update users from Microsoft 365. Then test the user’s access from the employee’s point of view.
Use this process for every new user, document the approval, and review access whenever responsibilities change.










