Narrowing of G/L permissions possible?

c.bakker
Member Posts: 13
Investigating the possibilities to narrow regular user permissions in Nav 5 I got a little bit a nasty feeling in my stomach.
Does anyone know wether it is right that users who must be able to post (for example) purchase orders must have at least Indirect Read permission for Table 17 G/L Entry?
I would very much like to avoid assigning Read permissions for Table 17 G/L Entry because this permission very quickly results in permission to see or estimate company financial figures and profitablity.
I am very curious how other people are approaching this nasty issue!
Does anyone know wether it is right that users who must be able to post (for example) purchase orders must have at least Indirect Read permission for Table 17 G/L Entry?
I would very much like to avoid assigning Read permissions for Table 17 G/L Entry because this permission very quickly results in permission to see or estimate company financial figures and profitablity.
I am very curious how other people are approaching this nasty issue!
Choose a job you love, and you will never have to work a day in your life.
Confucius 500 BC
Confucius 500 BC
0
Comments
-
Well, I always think that Navision is created in a very open approach, and the security system is not one of the best in the market.
Is posting referring to Post Receive or Invoice?
I'm quite sure if Post Invoice the Purchase Order, the permission should be there. You can try this download:
http://www.mibuso.com/dlinfo.asp?FileID=357
Rgds,
Jon.Rgds,
Jon.0 -
If you want to post, you need to have rights to read the G/L, else NAV will not be able to find out the last entry no. etc.
May be you can change the way you are posting and let NAS (Nav Application Server) post the documents. It means that user just check the document and mark it "for posting" somehow and the automatic process under NAS account will post it.0 -
You could define a role which contains rights for forms all users may use. Add this role to all users.
And next you define a role which contains rights for forms which can only be viewed by users who are allowed to see g/l entries.
Tino Ruijs
Microsoft Dynamics NAV specialist0 -
https://mbs.microsoft.com/knowledgebase/KBDisplay.aspx?WTNTZSMNWUKNTMMYMXTYYKSWTLKQNNOXVYVPYPTUTSTYSUONRNMXRWXTKVYZRRPZ
See article 857993 on PartnerSource. Look at item 8.There are no bugs - only undocumented features.0 -
hi everybody
creating or setting up roles is a hard work (...VERY HARD work ](*,) ](*,) ) because you must test each and every one of Navision options, buttons, menus... but you can set permissions to each and every one of Navision objects and get full control on what a user can and cannot view.
you can set read permissions on TableData 17 G/L Entry and on Table 17 G/L Entry and no execution permission on Form 20 General Ledger Entries. this configuration will allow to read data when posting but denies access to G/L Entries...
surely you will have to create new roles... be patient!!_______________
so far, so good0 -
Indirect permission to read the G/L entry should not be a problem. This does not allow the user access to the G/L Entry table except through objects (typically posting codeunits) that explicitly allow for read access.0
-
hi everybody out there, thanks for your valuable response!
Maybe not exactly the answers I hoped for but for sure they give usefull hints how to deal with the security issue.Choose a job you love, and you will never have to work a day in your life.
Confucius 500 BC0 -
In NAV 2013 R2 I still have issues with this. It seems for any 'posting' operation, including posting of Warehouse Shipments and Receipts, users need Read = "Yes" against tables 16 and 18 (G/L Account and G/L Entry). "Indirect" is not sufficient (I've tried again with recent rollup CU32).
For this reason, as a company, we feel the need to remove the Departments menu and ability to modify their own role centres from almost all users, which is of course both a shame and quite inconvenient.
I suspect many companies simply ignore this fact and hope(?) their users aren't too inquisitive, unless there is a solution of which I'm not aware.0
Categories
- All Categories
- 73 General
- 73 Announcements
- 66.6K Microsoft Dynamics NAV
- 18.7K NAV Three Tier
- 38.4K NAV/Navision Classic Client
- 3.6K Navision Attain
- 2.4K Navision Financials
- 116 Navision DOS
- 851 Navision e-Commerce
- 1K NAV Tips & Tricks
- 772 NAV Dutch speaking only
- 617 NAV Courses, Exams & Certification
- 2K Microsoft Dynamics-Other
- 1.5K Dynamics AX
- 320 Dynamics CRM
- 111 Dynamics GP
- 10 Dynamics SL
- 1.5K Other
- 990 SQL General
- 383 SQL Performance
- 34 SQL Tips & Tricks
- 35 Design Patterns (General & Best Practices)
- 1 Architectural Patterns
- 10 Design Patterns
- 5 Implementation Patterns
- 53 3rd Party Products, Services & Events
- 1.6K General
- 1.1K General Chat
- 1.6K Website
- 83 Testing
- 1.2K Download section
- 23 How Tos section
- 252 Feedback
- 12 NAV TechDays 2013 Sessions
- 13 NAV TechDays 2012 Sessions