The Dynamics West G/L Security extension enhances security around User access to G/L Balances, G/L Entries and G/L Reporting so that only permitted data can be accessed on Business Central Pages and Reports. This fills a gap where the user may be able to drill down into the G/L detail or run reports through the read access permission. This provides a quick and easy way to prevent scenarios such as that where selection of G/L Accounts in Sales and Purchasing documents can be used to access G/L Balances and Entries and mistakenly find or purposefully explore for access if security is not well tested.

Restricting G/L Access

The G/L Security app adds a field in User Setup, “Restrict G/L Access”. This field is only visible and editable to a user with SUPER permission.

  • The default is “No Access”. The list of pages and reports restricted is below.  These do not include custom pages or reports.This is meant to be a comprehensive list keeping the user from accessing G/L Balances and Entries through any method including look up and drill-down. The Balance fields will be hidden on list pages and user cannot set them as visible or try to add them back to the page. If the user tries to access this data they will get the message “G/L Access Restricted”.

  • The “Select Accounts” option only allows the user to look up G/L Accounts for data entry on Sales and Purchase documents and Journals.
  • The “Balances Only” option allows pages to be displayed with balance amounts but no access to G/L Entries.
  • The “Reports and Balances” option also allows the user to run any of the reports.
  • The “No Restriction” option allows full access to G/L Balances, Entries and Reporting.

This does not affect Power BI. Any such restriction must be done through the Business Central Permissions.

Pages restricted

  • 17 G/L Account Card
  • 20 General Ledger Entries
  • 39 General Journal
  • 108 Financial Reports
  • 113 Budget
  • 154 G/L Account Balance/Budget
  • 253 Sales Journal
  • 254 Purchase Journal
  • 255 Cash Receipt Journal
  • 256 Payment Journal
  • 408 G/L Balance by Dimension
  • 414 G/L Balance
  • 415 G/L Account Balance
  • 422 G/L Balance/Budget
  • 554 Analysis by Dimensions
  • 570 Chart of Accounts (G/L)
  • 634 Chart of Accounts Overview

Reports Restricted

  • 4 Detail Trial Balance
  • 7 Trial Balance/Previous Year
  • 9 Trial Balance/Budget
  • 36 Fiscal Year Balance
  • 37 Balance Comp. – Prev. Year
  • 38 Trial Balance by Period
  • 94 Close Income Statement
  • 151 Balance Sheet
  • 154 Income Statement
  • 10002 Chart of Accounts
  • 10003 Closing Trial Balance
  • 10007 Consolidated Trial Balance
  • 10008 Consolidated Trial Balance (4)
  • 10019 G/L Register
  • 10021 Trial Balance Detail/Summary
  • 10022 Trial Balance
  • 10023 Trial Balance, per Global Dim.
  • 10025 Trial Balance, Spread G. Dim.
  • 10026 Trial Balance, Spread Periods

Exceptions

This does not affect Power BI, API endpoints, OData/page web services, and query object. Any such restriction must be done through the Business Central Permissions.

Custom Pages and Reports

There are five functions added to User Setup that can be used in custom extensions. These allow access based on the User Setup “Restrict G/L Access” field. They will throw the “G/L Access Restricted” error if the user is NOT set to any of the noted option(s):

  • AllowGLSelect()
    Test for anything other than “No Access”. Any other option is allowed to view G/L Accounts. The “Select Account” option allows viewing the list of G/L Accounts only. Return value indicates if permission granted.
  • CheckGLSelect()
    Test for anything other than “No Access”. A negative test – any selection other than “No Access” can view G/L Accounts. The “Select Account” option allows viewing the list of G/L Accounts only. Throws error if not allowed.
  • CheckGLBalances()
    Test for “No Restriction, “Balances” or “Reports and Balances”.
    Use for Pages showing Balances. Provided for clarity as reports also show balances.
  • CheckGLReport()
    Test for “”No Restriction” or “Reports and Balances”. This would be used for Reports.  This could be used for Pages showing Balances but is provided for clarity, the idea being that reports show balances. Throws error if not allowed..
  • CheckGLEdit()
    Test for “No Restriction”. This would be used for Pages for editing G/L Accounts. Throws error if not allowed.

Permission Grid

This grid breaks down the G/L Access options.

  Actions allowed
Permission G/L Lookup Display Pages Run Reports Edit G/L Accounts
Select Accounts Yes
G/L Balances Yes Yes
G/L Balances and Reports Yes Yes Yes
No Restriction Yes Yes Yes Yes

 

End User License Agreement

Press enter or esc to cancel