Business Central Permissions and Prerequisites

Modified on Mon, 28 Sep at 1:36 PM

On this page

Who this article is for

This article is for the Business Central administrator or Microsoft 365 administrator who prepares Microsoft Dynamics 365 Business Central so a Benji Pays user can connect it. If you are the person connecting, share this page with your administrator and then follow Connect Microsoft Dynamics 365 Business Central.

NOTE  This feature is currently in beta and is subject to change.

What Benji Pays reads and writes in Business Central

Benji Pays uses the standard Business Central API (version 2.0) and the Finance reports API. It does not install an extension in your company.

Business Central dataReadWriteWhy
Customers and customer contactsYesNoCustomer list, names, addresses and contact email addresses in Benji Pays
Sales invoices and posted sales invoicesYesNoOpen balances, due dates and invoice PDFs; determines which invoices are posted
Sales credit memosYesNoRefunds against approved credit memos
Cash receipt journals (customer payment journals) and journal linesYesYes (create lines, create journal, post)Recording payments, refunds and reversals
Customer ledger entries (Finance reports API)YesNoChecking whether a posted payment is applied before a void or refund
G/L accounts and bank accountsYesYes (create a clearing account if you ask Benji Pays to)Clearing, deposit, refund, surcharge and settlement account mapping in gateway settings
Payment terms, payment methods, currencies and exchange ratesYesNoInvoice skip rules and multi-currency conversions
Company informationYesNoCompany name and home currency
Webhook subscriptionsYesYesNear real-time sync of the entities above

Requirements for the Microsoft account that connects

The default connection is made by a signed-in user (delegated permissions). The account used to connect must:

  • Have a Business Central licence that allows posting journals (Essentials or Premium). A Team Member licence cannot post cash receipt journals.
  • Be a user in the Business Central company you want to connect, in the environment you want to connect.
  • Hold permission sets that allow reading the data above and creating and posting cash receipt journals. D365 BUS FULL ACCESS covers this. If your organisation prefers least privilege, create a custom permission set that includes read access to Customers, Contacts, Sales Invoices, Posted Sales Invoices, Sales Credit Memos, G/L Accounts, Bank Accounts, Payment Terms, Payment Methods, Currencies and Currency Exchange Rates, plus insert, modify, delete and post on Gen. Journal Batches and Gen. Journal Lines, and insert on Webhook Subscriptions.

When the user signs in, Microsoft asks them to grant Benji Pays the Dynamics 365 Business Central delegated permissions Financials.ReadWrite.All and user_impersonation, plus offline access so the connection stays active.

IMPORTANT  If your tenant blocks users from consenting to applications, a Global Administrator or Application Administrator must grant admin consent to Benji Pays first. Otherwise the connecting user sees "Approval required" or "Need admin approval" on the Microsoft sign-in page and the connection fails with "Error connecting to Business Central. Please try again."

If the connecting user leaves your organisation or their password changes, the connection stops working and Benji Pays shows a reconnect banner. Consider connecting with a dedicated integration user, or use the service-to-service option below.

Install the API Reports - Finance extension

Benji Pays reads Customer Ledger Entries to find out whether a posted payment has already been applied to invoices before it voids or refunds that payment. Business Central only exposes customer ledger entries through the API Reports - Finance extension, published by Microsoft.

  1. Open the Business Central admin center for your tenant.
  2. Select Environments, open the environment you will connect, then select Apps > Manage.
  3. Find API Reports - Finance (publisher Microsoft) and install it.
  4. In the Business Central web client, search for Extension Management, open API Reports - Finance, select Configure and turn on Allow HttpClient Requests


Without this extension, voids and refunds from Benji Pays show "Benji could not confirm the payment state in Business Central" and ask you to verify the payment manually.

Foreign currency invoices

If you invoice customers in a currency other than your company's local currency, add an exchange rate for each foreign currency under Currencies > Exchange Rates in Business Central. The rate must be stated against your local currency. Benji Pays reads these rates when it records a payment and stops with a clear error if no rate is in effect on the posting date. Details are in Multi-Currency Payments with Business Central.

Production and sandbox environments

Benji Pays lists every environment your account can access and shows the type next to the name, for example Production or Sandbox. A Benji Pays account connects to exactly one company in one environment. To test with a sandbox first, connect a separate Benji Pays account to the sandbox company; do not connect your live Benji Pays account to a sandbox and expect to switch it later.

Optional: service-to-service (application) connection

Choose this when the connection must not depend on a named user. Your Microsoft 365 administrator registers an application, and Benji Pays connects with its credentials.

Step 1: Register an application in Microsoft Entra ID

  1. Sign in to the Microsoft Entra admin center and go to Applications > App registrations > New registration.
  2. Name it, for example Benji Pays integration. For supported account types choose Accounts in this organizational directory only. No redirect URI is needed. Select Register.
  3. On the Overview page copy the Application (client) ID and the Directory (tenant) ID.
  4. Go to Certificates & secrets > New client secret, choose an expiry and copy the secret value immediately. It is shown only once.
  5. Go to API permissions > Add a permission > Dynamics 365 Business Central > Application permissions and add API.ReadWrite.All and Automation.ReadWrite.All.
  6. Select Grant admin consent for [your tenant].

Step 2: Register the application in Business Central

Azure permissions alone are not enough; Business Central must also trust the application.

  1. In Business Central, search for Microsoft Entra applications and select New.
  2. Enter the Client ID from Step 1 and a description, and set State to Enabled.
  3. Under User Permission Sets, add D365 AUTOMATION or EXTEN. MGT. - ADMIN, or a custom permission set that includes the objects listed earlier in this article. Applications cannot be assigned SUPER.
  4. Select Grant Consent if you did not grant admin consent in the Entra admin center


Step 3: Connect in Benji Pays

  1. On the Benji Pays accounting system page, select Use Service-to-Service authentication instead.
  2. On Business Central S2S Setup, enter the Tenant ID, Client ID and Client Secret, then select Connect.
  3. Choose the Environment and the Business Central company, then select Continue.
IMPORTANT  Client secrets expire. Note the expiry date you chose in Step 1. When the secret expires, payments stop recording and Benji Pays shows the reconnect banner; create a new secret and reconnect using the service-to-service option again.

If you see "Invalid Business Central credentials. Please check your Tenant ID, Client ID, and Client Secret.", confirm the three values, that admin consent was granted, and that the application is enabled with permission sets on the Microsoft Entra applications page in Business Central.

Checklist for your administrator

  • Business Central user (or application) with access to the target company and permission to create and post cash receipt journals.
  • Admin consent granted to Benji Pays if your tenant requires it.
  • API Reports - Finance extension installed with Allow HttpClient Requests enabled.
  • Exchange rates entered for every foreign currency you invoice in.
  • The correct environment (Production or Sandbox) identified before connecting.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article