MB-800 · Question #138
Drag and Drop Question A company uses Dynamics 365 Business Central. You grant the financial bookkeeper the D365 ACCOUNTANTS permission set. An auditor plans to perform an annual accounting audit…
The correct answer is Open Permission Groups page select the D365 ACCOUNTANTS code.; Use the Copy Permission Sets function.; Copy the permissions from the D365 ACCOUNTANTS permission set.; Assign a New Permission Set name to AUDIT.; Set the Insert, Modify, and Delete permissions to No for all permission lines.; Edit the permissions for Permission Set AUDIT. Dynamics 365 Business Central - Creating a View-Only Permission Set The Goal You need to create an AUDIT permission set that mirrors D365 ACCOUNTANTS exactly, but strips out all write access (Insert, Modify, Delete = No). Rather than rebuilding from scratch, you copy the…
Question
Exhibit
Answer Area
Drag items
Correct arrangement
- Open Permission Groups page select the D365 ACCOUNTANTS code.
- Use the Copy Permission Sets function.
- Copy the permissions from the D365 ACCOUNTANTS permission set.
- Assign a New Permission Set name to AUDIT.
- Set the Insert, Modify, and Delete permissions to No for all permission lines.
- Edit the permissions for Permission Set AUDIT.
Explanation
Dynamics 365 Business Central - Creating a View-Only Permission Set
The Goal
You need to create an AUDIT permission set that mirrors D365 ACCOUNTANTS exactly, but strips out all write access (Insert, Modify, Delete = No). Rather than rebuilding from scratch, you copy the existing set and then restrict it.
Step-by-Step Breakdown
Step 1: Open Permission Groups page, select the D365 ACCOUNTANTS code.
You must first navigate to the source permission set before any copy action is available. The Copy function is context-sensitive - it operates on whichever record is currently selected. Without selecting D365 ACCOUNTANTS first, you have no source to copy from.
Common mistake: Going to a blank Permission Sets page and trying to create new - you'd have to re-enter hundreds of permissions manually.
Step 2: Use the Copy Permission Sets function.
With D365 ACCOUNTANTS selected, you invoke the Copy Permission Sets action (available in the ribbon/action bar). This opens the copy dialog/wizard. You cannot reach this wizard without first selecting a source record (Step 1).
Common mistake: Trying to manually duplicate permission lines one-by-one - the Copy function exists precisely to avoid this.
Step 3: Copy the permissions from the D365 ACCOUNTANTS permission set.
Inside the copy wizard, you confirm the source is D365 ACCOUNTANTS. This is a distinct confirmation step - the wizard may allow you to change the source, so you explicitly verify you're copying the right set.
Common mistake: Assuming the source is auto-filled and skipping this confirmation, potentially copying from the wrong permission set.
Step 4: Assign a New Permission Set name to AUDIT.
Still inside the copy wizard, you define the destination name: AUDIT. This must happen before the copy completes - the system needs a unique code for the new permission set before it can write the records.
Common mistake: Accepting a default name or leaving it blank, then having to rename afterward, which is an extra step and can cause confusion.
Step 5: Set the Insert, Modify, and Delete permissions to No for all permission lines.
After the copy creates the AUDIT permission set, you bulk-modify all permission lines to remove write access. This is the core of the auditor's requirement - read-only. Doing this as a bulk operation (rather than line-by-line) is efficient when D365 ACCOUNTANTS has many object permissions.
Common mistake: Only setting permissions to No on some lines, or forgetting to check every object type (tables, pages, reports, etc.).
Step 6: Edit the permissions for Permission Set AUDIT.
This final step represents reviewing and saving the AUDIT permission set - confirming the result is correct, verifying no Read permissions were accidentally removed, and finalizing the record. In BC's UI, you formally exit edit mode or save the set.
Note on Step 5 vs. Step 6 ordering: The exam presents bulk-restricting permissions (5) before the explicit "edit" action (6). Interpret this as: the bulk No-setting happens within the editing session, and Step 6 represents the final review/save of that session. Both occur in the same edit context - Step 5 is the key action, Step 6 is the confirmation.
Common mistake: Skipping the final review - it's easy to assume the bulk action was perfect, but auditing the result catches edge cases (e.g., a permission line that needed Read = Yes but got set to No inadvertently).
Summary Table
| Step | Action | Why Here |
|---|---|---|
| 1 | Select D365 ACCOUNTANTS | Establishes source before Copy is available |
| 2 | Use Copy Permission Sets | Invokes the wizard from the selected source |
| 3 | Confirm source is D365 ACCOUNTANTS | Validates correct source inside the wizard |
| 4 | Name the new set AUDIT | Sets destination before copy executes |
| 5 | Set Insert/Modify/Delete to No | Restricts write access on the copied set |
| 6 | Edit/review AUDIT permission set | Finalizes and confirms the result |
The key conceptual point: copy first, restrict second - never build from scratch when a nearly-identical permission set already exists.
Topics
Community Discussion
No community discussion yet for this question.
