Bank access: company, personal and EBICS participant
This page describes how Business Central identifies itself to the bank: through the company bank access, personal bank access and EBICS participants in 365 business Banking.
An access belongs to the bank connection, not to a single bank account. You therefore set it up once per company. After that, you can connect every further bank account without setting up the access again.
| Company bank access | Personal bank access | EBICS participant | |
|---|---|---|---|
| For | PSD2/XS2A via finAPI and verification of payee | PSD2/XS2A via finAPI, when your bank issues personal credentials | EBICS |
| Number | exactly one per company | one per person | one per bank |
| Applies to | every bank account of the company | the accounts this person connected themselves | the accounts in this bank's EBICS contract |
| Location | Banking Setup > Company Bank Access | Personal Bank Accesses | EBICS Participants |
| Created | during setup | via Use With My Own Bank Login on the bank account card | by creating and initializing it |
Bank accounts that you keep via camt/pain files require no access, because Business Central does not communicate with a bank for them.
Company bank access (always required)
The company bank access is the identity that Business Central uses towards finAPI. There is one per company, and it applies to every bank account.
Set it up in every case
Verification of payee runs exclusively via finAPI and signs in with the company bank access. This also applies if you do not connect any account via finAPI but only via EBICS or by file. Without this access, no verification of payee takes place.
You do not need to enter a password. Business Central generates one and stores it securely. You only check the Email Address and Phone Number that finAPI uses to contact you when a bank requires renewed consent. The procedure is described under Banking setup.
Personal bank access
Some banks issue personal online banking credentials: every person has their own login and TAN method. In this case, the bank requires the credentials and TAN of the person who makes the payment.
For this purpose, each person creates a personal bank access with Use With My Own Bank Login. If they connect another bank account later, their existing access is reused. Towards finAPI, they are one user.
Not required with a shared company login
If your bank issues a shared login for the company, the company bank access is sufficient. Personal bank access is not relevant for EBICS and the file route.
How to create and remove a personal bank access is described in Use with my own bank login.
EBICS participant
An EBICS participant is your access to one bank. It consists of the bank URL, host ID, partner ID, user ID and a key pair that belongs exclusively to your company. If you have EBICS contracts with several banks, create one participant per bank.
A participant belongs to the company, not to a person. It signs payments with its key, without a TAN and also in the background. Only a participant with the status Ready can connect bank accounts. Because of the initialization letter, setup takes a few days. See Set up an EBICS participant.
Who reads, who pays
A bank account is read through exactly one access, usually the company bank access. In addition, any number of people can pay from it with their own access.
The access through which transactions are retrieved determines the numbers under which they arrive. If two accesses read the same account, every booking would arrive twice, under numbers that cannot be matched to each other.
On the bank account card, the Who Can Use This Account FactBox shows Reads Transactions and Can Pay for each access. It is only displayed if at least one personal bank access is assigned to the bank account.
Which access Business Central uses when
Business Central determines the following two points separately and without prompting you:
| Operation | Access used |
|---|---|
| Retrieving transactions | The account's single reading source, regardless of who starts the retrieval, on screen or in the job queue. |
| Payment | The signed-in person's own access, if they have one for this account. Otherwise, the company bank access. |
An assignment alone is not enough
A personal access is only used for an account once the person has connected the account themselves in their bank's web form. Until then, Assigned Bank Accounts shows the status Not connected yet, and the company bank access applies.
You cannot pay on behalf of another person, because Business Central never uses another person's credentials. If another person is to pay, that person carries out the payment themselves.
See also
- Banking setup
- Use with my own bank login
- Set up an EBICS participant
- One bank access for several companies
- Account information service and payment initiation service
