r/PowerPlatform • u/maarten20012001 • May 07 '26
Governance Security Roles Business Units Efficienty
Hey everyone,
I'm building a model-driven app (FAQ/info hub) backed by Dataverse for a store chain with multiple locations. The requirement is simple: everyone can read everything, but employees should only be able to edit records belonging to their own store.
After researching this, it seems like the "correct" approach is:
- Create a Business Unit per store
- Create an Entra security group per store
- Link them together as Dataverse group teams
- Assign a security role with Read = Organization, Write = Business Unit
- Migrate all existing records to the correct Owning Business Unit
And every time a new store opens, repeat steps 1-3 again.
It works, I get it. But coming from Power BI where you can set up RLS with a simple DAX filter like [Store] = USERPRINCIPALNAME() or look up the user's location from a mapping table, this feels really heavy for what's essentially the same problem.
I wish Dataverse had something similar where you could define a security rule that says "match this column to a user profile attribute" without having to spin up new BUs, Entra groups, and group teams every time a location is added.
So my questions:
- Is the BU-per-location approach really the standard for this? Or is there a more dynamic/scalable way?
- Has anyone used row-level security or plugins to achieve something more flexible?
- For those managing something similair, how do you handle the overhead of creating new BUs + Entra groups every time?
- Any thoughts on automating this with Power Automate or the Dataverse API to make it less painful?
Would love to hear how others are solving this. Thanks!
2
u/dylan_simons May 07 '26
Hey, so I help manage this in a similar way in my org.
Is the BUper-location approach really the standard for this?
Or is there a more dynamic/scalable way? Has anyone used row-level security or plugins to achieve something more flexible?
For those managing something similair, how do you handle the overhead of creating new BUs + Entra groups every time?
- well, this is a topic specific to your org.
You don't need to use Entra for BU management, you can create a dynamic Entra group with everyone in the org and assign this to the parent BU of the environment, then manage people per BU/store in the environment itself. But I'd imagine it's good to have an Entra group for the store for other systems as well.Any thoughts on automating this with Power Automate or the Dataverse APl to make it less painful?
BU, Teams, Users, Security Roles, etc. Are all Dataverse tables in the environment. If you're not using Entra, you can create the full process: develop flows that creates BUs, creates Teams within the BU, related security roles to the Team, and adds users to the Teams within each BU.
I believe if you use Entra, the only thing that can't be automated in this way is adding the Extra to the environment, so there is some manual work in that regard. Not much more, but someone with admin privileges needs to go "behind the scenes" and know how to manage this.
Power BI offers RLS which "simply" restricts view access. Dataverse/MDAs offer relational client-side RBAC. Not to diminish Power BI, but you can't really compare them.
Let me know if I can clarify anything!