Business Central Permissions and Prerequisites
Modified on Mon, 28 Sep at 1:36 PM
Who this article is for
This article is for the Business Central administrator or Microsoft 365 administrator who prepares Microsoft Dynamics 365 Business Central so a Benji Pays user can connect it. If you are the person connecting, share this page with your administrator and then follow Connect Microsoft Dynamics 365 Business Central.
What Benji Pays reads and writes in Business Central
Benji Pays uses the standard Business Central API (version 2.0) and the Finance reports API. It does not install an extension in your company.
| Business Central data | Read | Write | Why |
|---|---|---|---|
| Customers and customer contacts | Yes | No | Customer list, names, addresses and contact email addresses in Benji Pays |
| Sales invoices and posted sales invoices | Yes | No | Open balances, due dates and invoice PDFs; determines which invoices are posted |
| Sales credit memos | Yes | No | Refunds against approved credit memos |
| Cash receipt journals (customer payment journals) and journal lines | Yes | Yes (create lines, create journal, post) | Recording payments, refunds and reversals |
| Customer ledger entries (Finance reports API) | Yes | No | Checking whether a posted payment is applied before a void or refund |
| G/L accounts and bank accounts | Yes | Yes (create a clearing account if you ask Benji Pays to) | Clearing, deposit, refund, surcharge and settlement account mapping in gateway settings |
| Payment terms, payment methods, currencies and exchange rates | Yes | No | Invoice skip rules and multi-currency conversions |
| Company information | Yes | No | Company name and home currency |
| Webhook subscriptions | Yes | Yes | Near real-time sync of the entities above |
Requirements for the Microsoft account that connects
The default connection is made by a signed-in user (delegated permissions). The account used to connect must:
- Have a Business Central licence that allows posting journals (Essentials or Premium). A Team Member licence cannot post cash receipt journals.
- Be a user in the Business Central company you want to connect, in the environment you want to connect.
- Hold permission sets that allow reading the data above and creating and posting cash receipt journals. D365 BUS FULL ACCESS covers this. If your organisation prefers least privilege, create a custom permission set that includes read access to Customers, Contacts, Sales Invoices, Posted Sales Invoices, Sales Credit Memos, G/L Accounts, Bank Accounts, Payment Terms, Payment Methods, Currencies and Currency Exchange Rates, plus insert, modify, delete and post on Gen. Journal Batches and Gen. Journal Lines, and insert on Webhook Subscriptions.
When the user signs in, Microsoft asks them to grant Benji Pays the Dynamics 365 Business Central delegated permissions Financials.ReadWrite.All and user_impersonation, plus offline access so the connection stays active.
If the connecting user leaves your organisation or their password changes, the connection stops working and Benji Pays shows a reconnect banner. Consider connecting with a dedicated integration user, or use the service-to-service option below.
Install the API Reports - Finance extension
Benji Pays reads Customer Ledger Entries to find out whether a posted payment has already been applied to invoices before it voids or refunds that payment. Business Central only exposes customer ledger entries through the API Reports - Finance extension, published by Microsoft.
- Open the Business Central admin center for your tenant.
- Select Environments, open the environment you will connect, then select Apps > Manage.
- Find API Reports - Finance (publisher Microsoft) and install it.
- In the Business Central web client, search for Extension Management, open API Reports - Finance, select Configure and turn on Allow HttpClient Requests
Without this extension, voids and refunds from Benji Pays show "Benji could not confirm the payment state in Business Central" and ask you to verify the payment manually.
Foreign currency invoices
If you invoice customers in a currency other than your company's local currency, add an exchange rate for each foreign currency under Currencies > Exchange Rates in Business Central. The rate must be stated against your local currency. Benji Pays reads these rates when it records a payment and stops with a clear error if no rate is in effect on the posting date. Details are in Multi-Currency Payments with Business Central.
Production and sandbox environments
Benji Pays lists every environment your account can access and shows the type next to the name, for example Production or Sandbox. A Benji Pays account connects to exactly one company in one environment. To test with a sandbox first, connect a separate Benji Pays account to the sandbox company; do not connect your live Benji Pays account to a sandbox and expect to switch it later.
Optional: service-to-service (application) connection
Choose this when the connection must not depend on a named user. Your Microsoft 365 administrator registers an application, and Benji Pays connects with its credentials.
Step 1: Register an application in Microsoft Entra ID
- Sign in to the Microsoft Entra admin center and go to Applications > App registrations > New registration.
- Name it, for example Benji Pays integration. For supported account types choose Accounts in this organizational directory only. No redirect URI is needed. Select Register.
- On the Overview page copy the Application (client) ID and the Directory (tenant) ID.
- Go to Certificates & secrets > New client secret, choose an expiry and copy the secret value immediately. It is shown only once.
- Go to API permissions > Add a permission > Dynamics 365 Business Central > Application permissions and add API.ReadWrite.All and Automation.ReadWrite.All.
- Select Grant admin consent for [your tenant].
Step 2: Register the application in Business Central
Azure permissions alone are not enough; Business Central must also trust the application.
- In Business Central, search for Microsoft Entra applications and select New.
- Enter the Client ID from Step 1 and a description, and set State to Enabled.
- Under User Permission Sets, add D365 AUTOMATION or EXTEN. MGT. - ADMIN, or a custom permission set that includes the objects listed earlier in this article. Applications cannot be assigned SUPER.
- Select Grant Consent if you did not grant admin consent in the Entra admin center
Step 3: Connect in Benji Pays
- On the Benji Pays accounting system page, select Use Service-to-Service authentication instead.
- On Business Central S2S Setup, enter the Tenant ID, Client ID and Client Secret, then select Connect.
- Choose the Environment and the Business Central company, then select Continue.
If you see "Invalid Business Central credentials. Please check your Tenant ID, Client ID, and Client Secret.", confirm the three values, that admin consent was granted, and that the application is enabled with permission sets on the Microsoft Entra applications page in Business Central.
Checklist for your administrator
- Business Central user (or application) with access to the target company and permission to create and post cash receipt journals.
- Admin consent granted to Benji Pays if your tenant requires it.
- API Reports - Finance extension installed with Allow HttpClient Requests enabled.
- Exchange rates entered for every foreign currency you invoice in.
- The correct environment (Production or Sandbox) identified before connecting.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article