Skip to main content

Notifications

Community site session details

Community site session details

Session Id :
Small and medium business | Business Central, N...
Answered

Prevent access to default API Pages (via Postman or PowerBi) for specific users or security groups

(3) ShareShare
ReportReport
Posted on by 75
Hi all,
i was wondering how to prevent users from using default and customer made API calls and datasets eg. via Postman or PowerBi.
 
As i understand access rights are  the same as in in client, but is there an easier way to prevent API access completely?
 
Thks Frank
  • FJ-14031703-0 Profile Picture
    75 on at
    Prevent access to default API Pages (via Postman or PowerBi) for specific users or security groups
    Hi all,
     
    first of all, thanks for your fast and helpfull tips. 

    By now i figured out, that there is some kind of misunterstanding the exlusion permission.
    I had to add the permission set witch grants permission for being able to exlude special objects, like the api page objects.
     
    Right now i have to firgure out how to add this recently learned to my existing security groups and permission set combination.

     
    But the path is way clearer now for me. Thanks to you all.
     
     
  • Verified answer
    Jainam M. Kothari Profile Picture
    5,891 on at
    Prevent access to default API Pages (via Postman or PowerBi) for specific users or security groups
    Hello,
     
    To prevent users from accessing APIs in Business Central, you can use a combination of permission sets, security filters, and API management. By creating or modifying permission sets to exclude access to specific API objects, configuring security filters to limit data access, and disabling or restricting unwanted API endpoints, you can effectively control and prevent unauthorized API access. Additionally, assigning users to specific groups with restricted permissions ensures only authorized users have API access.
     
  • Verified answer
    YUN ZHU Profile Picture
    81,360 Super User 2025 Season 1 on at
    Prevent access to default API Pages (via Postman or PowerBi) for specific users or security groups
    If you want to set global read-only permissions, you can use the following method.
    More details:
    Dynamics 365 Business Central: Managing Database Access Intent (Managing write access to APIs from the client)
     
    If you want to restrict a user's API permissions, which are either pages or queries, you can create a permission set to exclude those permissions individually.
    Dynamics 365 Business Central: A simple way to view the list of all APIs
     
    Hope this helps.
    Thanks.
    ZHU
  • Verified answer
    Ramesh Kumar Profile Picture
    3,280 on at
    Prevent access to default API Pages (via Postman or PowerBi) for specific users or security groups
    There is no master switch — but you can use Permission Sets or disable Web Services for Specific Users or Azure AD authentication.
     
    Thanks!
    Ramesh
     
    If this was helpful, please check the "Does this answer your question?" box and mark it as verified.
  • Verified answer
    Khushbu Rajvi. Profile Picture
    14,415 Super User 2025 Season 1 on at
    Prevent access to default API Pages (via Postman or PowerBi) for specific users or security groups
    Yes, there is a way to block API access for specific users or security groups in Business Central. To prevent specific users from accessing Web Services in Business Central (e.g., via Power BI or Postman), remove their API-related permission sets (like API Read or D365 POWER BI), avoid assigning Web Service Access Keys, and optionally create a custom permission set that blocks access to API and OData objects—this way, they can still use the web client but won’t consume external connections or hit the 100-connection limit.
     

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

🌸 Community Spring Festival 2025 Challenge 🌸

WIN Power Platform Community Conference 2025 tickets!

Jonas ”Jones” Melgaard – Community Spotlight

We are honored to recognize Jonas "Jones" Melgaard as our April 2025…

Kudos to the March Top 10 Community Stars!

Thanks for all your good work in the Community!

Leaderboard

#1
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 294,095 Super User 2025 Season 1

#2
Martin Dráb Profile Picture

Martin Dráb 232,866 Most Valuable Professional

#3
nmaenpaa Profile Picture

nmaenpaa 101,158 Moderator

Leaderboard

Featured topics

Product updates

Dynamics 365 release plans