Permissions and licenses
This page describes the permission sets of 365 business Banking, the Banking and EBICS Connection licenses and the Banking Metrics page.
As in Microsoft Dynamics 365 Business Central in general, user rights in 365 business Banking are granted through permission sets. Two licenses determine which features are available: Banking for everything except EBICS, and EBICS Connection for the connection via EBICS.
Standard functionality in Business Central
Permission sets grant users and user groups rights on tables, pages and reports. For more information, see Assign permissions on Microsoft Learn.
Permission sets
| Permission set | Purpose |
|---|---|
| Banking (Base) | All features for daily work with 365 business Banking: connecting, retrieving, applying, paying, direct debits and payment service providers. The setup pages (Banking Setup, bank accesses, EBICS Participants, the payment service providers' connection setups) can be read but not changed. Values that the processes themselves update there are still written. SEPA payment import and releasing bank accounts are not included. |
365 Banking - Setup (bdev.BNK SETUP) | For the person who sets up Banking. Includes Banking (Base) and Banking - Release Bank Accounts and permits changes to every setup. It also makes its holder a setup user, who sees the Technical details FastTab and every user's personal bank accesses on the bank access pages. |
Banking - Release Bank Accounts (bdev.BNK RELEASE) | Releasing customer and vendor bank accounts for payments, see Business partner bank accounts. Assign the set to people who check bank details without setting up Banking. |
| Banking SEPA Import (with recipient details) | Full access to SEPA payment import, including the lines with recipients and amounts. |
| Banking SEPA Import (no recipient details) | Import, validate, approve and carry out SEPA payment imports without seeing the recipients: count and total are visible, the lines are not. The line table can neither be opened, exported to Excel nor read via the API. Intended for payroll files. |
| Per-User Plan | Technical set for licensing through Microsoft's per-user plan. Do not assign it manually. |
The difference between the two SEPA import sets is explained in Who may see the recipients. The SEPA Payment Import action in the role center only appears for users with one of the two sets.
With licensing through Microsoft's per-user plan (Business Central online only), users with the plan automatically receive Banking (Base), Banking SEPA Import (with recipient details), Banking - Release Bank Accounts and Per-User Plan.
Whether a setup page can be edited depends on the actual write permission on its table, regardless of which permission set grants it. Users with SUPER or with a custom set that holds these rights can therefore also perform the setup.
What only setup users see
The Technical details FastTab on the Company Bank Access and on personal bank accesses (with password, bank access ID and the Enable Multi-Company Connection switch) is only visible to users with the SUPER permission set or with 365 Banking - Setup. The same applies to the full Personal Bank Accesses list. All other users only see their own access on the bank access pages. No message about missing permissions is shown.
SUPER is a security role rather than a functional one. If the person who sets up Banking does not hold SUPER (for example, with delegated administration), assign them 365 Banking - Setup, directly or through a security group, for the company or for all companies.
Payment service provider credentials
With Banking (Base), payment service provider credentials are readable
The API keys, client secrets and tokens of payment service providers are stored in the setup tables of 365 business Banking. On the connection setups they are masked. However, Banking (Base) grants direct read access to these tables; with this set, they can only be changed through the app's own processes. Any user with this set can therefore also read the values outside the page, for example via Open in Excel. The Amazon Pay private key is the exception: 365 business Banking stores it in isolated storage, not in the setup table. Therefore, use only restricted keys with the required rights for payment service providers, and assign Banking (Base) only to users who need it. For more information, see Security and data protection.
Storing the remaining credentials in isolated storage is planned for version 18.5.
Business Central version
365 business Banking runs on Business Central 25 and newer, online and on-premises. The features that require a newer version are listed under Get started: Requirements.
Licenses
| License | Covers | Licensing methods | Trial period |
|---|---|---|---|
| Banking | everything except EBICS: PSD2/XS2A via finAPI, camt/pain file, payment service providers, Universal, verification of payee, application, payments, direct debits, SEPA payment import | per user, per company, per tenant or on-premises environment; in Business Central online also via Microsoft's per-user plan | 30 days |
| EBICS Connection | the connection via EBICS: EBICS participants, statements and payments via EBICS | per company, per tenant or on-premises environment | 30 days |
Both licenses are registered at installation. You activate and manage them in Extension License Management (365 business development), see License management and License methods.
What is missing without a license
- Without a Banking license, the Connect Bank Account wizard offers no banking providers except SEPA Bank Account (EBICS) when the EBICS Connection license is active, and functions such as Carry Out Payment, verification of payee, fixed exchange rates, Required Approvers and the extended application paths are hidden or inactive.
- Without EBICS Connection, SEPA Bank Account (EBICS) is missing from the wizard. In Change Banking Services you can still choose it, but when you confirm with OK, Business Central reports: "… is not licensed. Open Extension License Management (365 business development) to activate it."
Microsoft's per-user plan
If you license Banking through Microsoft's per-user plan, 25 payment instructions per month are included per licensed user. Business Central rejects a payment that would exceed the monthly allowance. Payments are counted in the Banking Metrics.
Banking Metrics
The Banking Metrics page shows per day and bank account the number of operations that 365 business Banking has performed. You open it via the Metrics action on Banking Setup and on the Company Bank Access.
| Column | Meaning |
|---|---|
| Metric Type | Bank Transactions (retrieved transactions), Payment Instructions (payments carried out) or IBAN Name Check (verifications of payee) |
| Date | the day |
| Bank Account No. | the bank account |
| Quantity | the number of operations |
The page provides an overview of usage and cannot be edited.
