web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Apps / Security roles -- rest...
Power Apps
Answered

Security roles -- restict assignment scope to intra Business Unit

(0) ShareShare
ReportReport
Posted on by 22

Hi!  Does anyone know if it is possible to set up a security role so that users can assign ownership of records within their Businerolesss Unit, but cannot assign ownership to users in a different Business Unit?

 

I.e. a user in Business Unit A can assign ownership of a record to another user in Business Unit A, but cannot assign ownership to a user in Business Unit B?   

 

Or (possibly the same thing) make it so that they can update the Owning User for a record, but not the Owning Business Unit?

I have the same question (0)
  • Fubar Profile Picture
    8,483 Super User 2026 Season 1 on at

    Yes, as long as the Tables in question have been defined as User/Team Owned.  You just need to configure the Security Role Permissions for the Table in question (not full green)

  • matmeredith Profile Picture
    22 on at

    Thanks, but that's not what I'm seeing.  

    I have a record called "Job", and my user has a security role which sets the assign privilege for job to "Business Unit" -- I think that's what you're suggesting?

    But this user is now able to assign job records to users in a different business unit which is what I want to prevent.  It seems that setting the scope of the assign privilege to Business Unit means that they can only assign records owned by their Business Unit, but it doesn't stop them assigning them to any Business Unit.

  • Fubar Profile Picture
    8,483 Super User 2026 Season 1 on at

    a) make sure the users previous privileges have been removed, logout, close browser etc

    b) make sure the user does not have another security role that is giving them the permission either directly or inheriting it off a team they belong to. (privileges are additive, the user will get the highest privilege setting if multiple Security Roles with different privilege settings)

    c) you could also possibly try lowering the Append privilege on the Table that the owner is being changed on

     

  • matmeredith Profile Picture
    22 on at

    Thanks but I've done all of this and it very definitely doesn't work still.   I've also reduced their append to privileges for User / Team / Business Unit to be Business Unit scope, but they can still assign the record to users in a different BU 😞

  • Verified answer
    thomasfnorthrup Profile Picture
    252 on at

    Hi, Thanks for reaching out. Your experience is the correct functionality. The limit for Business Unit on a privilege limits the performance of the action, not the destination of the action. For assign, the user is limited to only be able to assign records owned by other users in their BU, but it does not limit who they can assign to. 

     

    You can try adjusting the Append To privilege to BU on the User table under Business Management tab in a security role. I would do a lot of testing to make sure this doesn't break any other table relationships.

     

    Please mark as a solution or give kudos if it helps. 

    Tom

  • Prakash4691 Profile Picture
    1,332 on at

    Hi @matmeredith,

    User entity read will always be in org level and append to can be set only to minimum of BU level. So your requirement is bit difficult to achieve using OOB security role configuration.

     

    You can try creating a sync workflow that executes when record is assigned. Check if owning user BU does not equal to entity: owning business unit (dynamic value) then stop the workflow with cancelled status and throw an error message. This works only when record created by the same BU user not via sharing or assign if record created by different BU user.

     

    Attached SS for your reference.

    image.png

     

    If it answers your question, kindly give kudo and accept it as solution.

     

    Regards,

    Prakash

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Introducing the 2026 Season 1 community Super Users

Congratulations to our 2026 Super Users!

Kudos to our 2025 Community Spotlight Honorees

Congratulations to our 2025 community superstars!

Leaderboard > Power Apps

#1
Haque Profile Picture

Haque 94

#2
WarrenBelz Profile Picture

WarrenBelz 82 Most Valuable Professional

#3
Kalathiya Profile Picture

Kalathiya 38 Super User 2026 Season 1

Last 30 days Overall leaderboard