How to: Create the External Application Account in LS Central
There are two ways to create the external application account in LS Central: manually or automatically from code.
In both cases, the app needs to be granted consent manually, but the option to create the record from code is much more convenient for end-users.
Create the Microsoft Entra Application Record Manually
- In LS Central, click the
icon, and enter Microsoft Entra Applications (formerly Azure Active Directory Application), and select the relevant link. - Click the New action to add a new record.
- In the Microsoft Entra Applications card, fill in the Client ID that you copied in the setup or an ID that you received from the organization that owns the external application. The curly brackets are added automatically.

- Enter a description.
- Assign the proper permission sets to the user.
To assign a permission set
The application must have sufficient permissions to perform its integration tasks. Follow the principle of least privilege and grant only the permissions required by the integration.
Important:
Do not create or assign a permission set based on SUPER. Service-to-service (S2S) integrations should be granted only the permissions required to execute their intended functionality.
Recommended Permissions
For LS Central integrations, the permission set should include only the permissions required by the integration.
D365 BASIC
Assign D365 BASIC as a baseline permission set.
- Provides the minimum access required for standard application functionality.
- Acts as a prerequisite for opening pages and accessing standard application objects.
- Does not grant write access to business data.
Execute Permissions
Grant Execute permission only to the LS Central objects used by the integration.
Examples include:
- LSCRetailWebServices
- LSCRetailMSGGetActiveListXML
- Replication XMLports used by the LS Central integration
- Other codeunits and XMLports required by the specific integration scenario
Table Permissions
Grant RIMD (Read, Insert, Modify, Delete) permissions only to the tables that the integration actually reads from or writes to.
Avoid granting access to tables that are not required by the integration.
Extension Management
Assign EXTEN. MGT. - ADMIN only if the application needs to install, manage, or administer extensions.
Automation APIs
Assign D365 AUTOMATION only if the integration uses Business Central Automation APIs, such as:
- Company management
- User management
- Session management
Do not use this permission set as a general substitute for business-data permissions.
Permissions to Exclude
Do not assign:
- Permissions & Licenses - Edit
- Any permission set derived from SUPER
- Any additional permissions that are not explicitly required by the integration
Determine the Required Permissions
Business Central provides tools that can help identify the exact permissions required by an integration.
Use Permission Recording
Permission Recording can be used to determine which objects the integration accesses.
- Create a test environment.
- Open the Permission Set card and start permission recording.
- Execute the integration workflow.
- Stop the recording and review the resulting permission set.
- Use the recorded permissions as the basis for a dedicated integration permission set.
Use the Effective Permissions Page
The Effective Permissions page can be used to identify missing permissions for a user or application account.
If an operation fails due to insufficient permissions, review the Effective Permissions page to determine which objects require additional access.
Best Practice
The preferred approach is to create a dedicated permission set that contains only the permissions required by the LS Central.
Review and maintain this permission set as the integration evolves. Using Permission Recording and Effective Permissions ensures that the application receives only the access it requires while helping maintain a secure least-privilege configuration.
Future versions of LS Central may provide a dedicated integration permission set. Until then, Permission Recording and Effective Permissions are the recommended methods for determining the minimum required access.
See also
Video Tutorial: S2S Authentication - Step 2
Microsoft Learn - Set up the Microsoft Entra application in Business Central