Skip to content

Setting Up Access Control

With access control, it is possible to restrict parts of Document Central to a defined group. Access control can be configured in various areas and for different functions by using groups in Document Central. This allows for restricting access to document areas or preventing the use of specific content types, for example.

Access control for documents is divided into the following four levels:

  1. Document Library: Control access to the entire document library within Document Central.
  2. Content Types: Restrict the use and access to specific content types.
  3. Content Types in a Document Library: Restrict the use and access to specific content types in a document library.
  4. Metadata: Define access permissions for individual metadata within Document Central.

Important

Please note that you must have completed the creation of the document library, content types, metadata, and user groups, depending on which access control you want to define, to proceed.

To enable access control, follow these steps:

  1. Navigate through the Document Central - Administrator role center.
  2. Click on Compliance in the menu bar and perform the action Compliance Setup.
  3. Check the box Enable Access Control.
  4. Access control is now enabled.

Creating User Groups

With user groups, you can specifically restrict access to content types and document libraries in Document Central. To do this, create a group and assign the desired users to it.

To create user groups, follow these steps:

  1. Navigate to the Document Central – Administrator role center.
  2. Select Compliance in the menu bar and then Access Control Groups.
  3. Select the action Create User Group.
  4. The wizard for creating an access control group will open. Select Start.
  5. Choose Only Document Central Group.
  6. On the next page, enter a name for the access control group. Optionally, you can also provide a code and a description. Then select Next.
  7. If necessary, add users to the newly created group. Use the dropdown menu in the Access Control Group Members section for this.
  8. Select Next after adding the desired members, and complete the wizard on the following page.

Document Central Group

A Document Central Group restricts access exclusively to the documents available in Document Central. The group is not synchronized with SharePoint or Azure and has no effect there.

Creating Security Groups

Security groups link the permissions in Document Central with the permissions of the connected SharePoint. Therefore, before creating an Azure security group, enable access control and SharePoint permission synchronization in the compliance setup.

Info

Before setting up security groups, an active SharePoint must be configured. Then, enable the options Enable Access Control and Enable SharePoint Permission Synchronization in the Compliance Setup.

To create the base permissions, you need SUPER permissions in Business Central.

Creating Base Permissions for Azure Security Groups

With the Create Base Permission (Preview) feature, you set up the foundation for permission control between Document Central, Azure, Business Central, and the connected SharePoint. The process creates the necessary security groups and SharePoint permission levels so that access to document libraries can be managed uniformly.

  1. Navigate to the Document Central – Administrator role center.
  2. Open the compliance setup.
  3. Enable the toggle for Enable Access Control.
  4. Enable the toggle for Enable SharePoint Permission Synchronization.
  5. Open Access Control Groups through Compliance.
  6. Click on the action Security Groups and perform the action Create Base Permissions.

    • When creating the base permissions, the necessary security groups are created in Azure and Business Central. This includes the group for Document Central users.
    • In the connected SharePoint, the permission levels DMS Read, DMS Read Write, and DMS Read Write Delete are created.
    • The permission levels control which actions users are allowed to perform in a document library:
      • DMS Read: Read documents.
      • DMS Read Write: Read and edit or create documents.
      • DMS Read Write Delete: Read, edit or create, and delete documents.

Creating Azure Security Group

  1. Navigate to the Document Central – Administrator role center.
  2. Select Compliance in the menu bar and then Access Control Groups.
  3. In the menu bar, select the action Create User Group.
  4. The wizard for creating a user group will open. Select Start.
  5. Choose Azure Security Group.
  6. Choose whether to create a new group or select an existing group from Business Central. Then click Next.
  7. Enter a name for the security group. Optionally, you can also provide a code and a description. Then select Next.
  8. Add users. Use the dropdown menu in the Code section for this.
  9. Select Next after adding all desired members, and complete the wizard on the following page.

Important Information

  • The main group Doc Central Users cannot be removed.
  • If a security group is removed from a document library and no access control is set up, Document Central automatically adds the group Document Central Users in SharePoint. This keeps access to the document library for Document Central users intact.
  • To create security groups, you need SUPER permissions in Business Central.

Removing Access Control Groups

Access control groups can be removed if they are no longer needed.

Follow these steps to remove an access control group:

  1. Navigate to the Document Central – Administrator role center.
  2. Click on Compliance in the menu bar and perform the action Access Control Groups.
  3. Select the access control group you want to remove.
  4. In the Access Control Groups section, perform the action Delete to remove the group.
  5. The access control group will be deleted after performing the action.

Adding Users to a Group

Users can be added to existing groups.

To add users to a group, follow these steps:

  1. Navigate to the Document Central – Administrator role center.
  2. Click on Compliance in the menu bar and perform the action Access Control Groups.
  3. Select the group to which users should be added and click on Edit.
  4. Add users to the list in the Members section.
  5. The users are now members of the group.

Removing Users from a Group

Users can be removed from an existing group.

To remove users from a group, follow these steps:

  1. Navigate to the Document Central – Administrator role center.
  2. Click on Compliance in the menu bar and perform the action Access Control Groups.
  3. Select the group from which you want to remove a user and click on Edit.
  4. Navigate to the Members section.
  5. Select the user or member you want to remove.
  6. Click on Delete Row in the Members section to remove the user.
  7. The user has now been removed from the group.

Setting Up Access Control for a Document Library

To enable access control for document libraries, follow these steps:

  1. Navigate through the Document Central - Administrator role center.
  2. Click on Repository in the menu bar and perform the action Document Libraries.
  3. Click on the document library code Code that is to be configured with access control.
  4. Perform the action Access Controls in the menu bar.
  5. Enter the group code in the User Group Code field.
  6. Define the values for the group's access control in the Read, Write, and Delete fields.
  7. Access control is now enabled for the defined user group.

Explanation

  • Read: The read permission determines whether users can see the documents archived in the document library. If a user does not have read permission for a document library, they cannot use Document Central to view the documents in that library.
  • Write: The write permission determines whether users can archive documents in the document library. If a user has read permission but no write permission for the document library, they can see the documents archived in the document library but cannot add new documents.
  • Delete: The delete permission determines whether users can delete the documents archived in the document library. If a user does not have delete permission for a document library, they cannot delete documents archived in that library.
  • Edit Retention Label: The permission to edit the retention label determines whether users can edit the retention label for documents archived in the document library. If a user does not have permission to edit the retention label for a document library, they cannot edit the retention label for any document archived in that library.

For documents displayed through a relationship or an additional search, the access controls of the source document apply. This means that if a user has read permission for a document library and the document is displayed through a relationship in another document library without read permission, the document will still be displayed.

Setting Up Access Control for Content Types

To enable access control for content types, follow these steps:

  1. Navigate through the Document Central - Administrator role center.
  2. Click on Repository in the menu bar and perform the action Content Types.
  3. Click on the content type name Name that is to be configured with access control.
  4. Perform the action Access Controls in the menu bar.
  5. Enter the group code in the User Group Code field.
  6. Define the values for the group's access control in the Read, Write, and Delete fields.
  7. Access control is now enabled for the defined user group.

Important

Access control at the content type level overrides the access control defined at the document library level.

Setting Up Access Control for Content Types in a Specific Document Library

To enable access controls for a content type in a specific document library, follow these steps:

  1. Navigate through the Document Central - Administrator role center.
  2. Click on Repository in the menu bar and perform the action Document Libraries.
  3. Click on the document library code Code that is to be configured with access control.
  4. Navigate to the Content Types section.
  5. Select the content type for which access controls are to be enabled and perform the action Access Controls.
  6. Enter the group code in the User Group Code field.
  7. Define the values for the group's access control in the Read, Write, and Delete fields.
  8. Access control is now enabled for the defined user group.

Important

Access control at the content type level in a document library overrides the access control defined at the document library and content type levels.

Explanation

  • Read: The read permission determines whether users can see documents archived with the content type. If a user does not have read permission for a content type, they cannot see the documents archived with that content type.
  • Write: The write permission determines whether users can archive documents with the content type. If a user has read permission but no write permission for a content type, they can see the documents archived with that content type but cannot select that content type for new documents they want to archive.
  • Delete: The delete permission determines whether users can delete documents archived with the content type. If a user does not have delete permission for a content type, they cannot delete documents archived with that content type.
  • Edit Retention Label: The permission to edit the retention label determines whether users can edit the retention label for documents archived with the content type. If a user does not have permission to edit the retention label for a content type, they cannot edit the retention label for any document archived with that content type.

If a user has no access controls for a document library but has access controls for a content type defined in the document library or generally, they can view, write, or delete documents with that content type based on the configured access controls.