Skip to content

Latest commit

 

History

History
117 lines (81 loc) · 9.35 KB

tenant-admin-center.md

File metadata and controls

117 lines (81 loc) · 9.35 KB
title description author ms.topic ms.devlang ms.search.keywords ms.date ms.author
Business Central Admin Center| Microsoft Docs
Learn about how a VAR or an internal administrator can set update windows and other admin tasks.
jswymer
conceptual
al
administration, tenant, admin, environment, telemetry
04/01/2021
jswymer

The Business Central Administration Center

[!INCLUDEazure-ad-to-microsoft-entra-id]

The [!INCLUDEprodadmincenter] provides a portal for administrators to do administrative tasks for a [!INCLUDEprod_short] tenant. Here, administrators can:

[!div class="mx-imgBorder"] Business Central Admin Center.

Supported Microsoft Entra roles for access

Users with the following Microsoft Entra roles are authorized to access the [!INCLUDEprodadmincenter] and [!INCLUDE prod_short] environments:

Although the following roles aren't required to access the [!INCLUDEprodadmincenter] or its environments, they allow for administration of tools and resources that integrate with [!INCLUDE prod_short]:

Internal administrators

As the internal administrator, you can choose the link in the Settings menu when you're signed in to [!INCLUDE prod_short].

Alternatively, you can access the administration center from the URL, use the following pattern but replace [TENANT_ID] with the tenant ID of your [!INCLUDE prod_short]:

https://businesscentral.dynamics.com/[TENANT_ID]/admin

Tip

The tenant ID is shown in the Help and Support page in your [!INCLUDE prod_short].

Delegated administrators (Partner users)

Partner organizations can set up a (Granular Delegated Administration Privileges (GDAP))[/partner-center/gdap-introduction] relationship including at least one of the Microsoft Entra roles that grant access to the [!INCLUDEprodadmincenter] to access their customers' administration centers. Learn how to set up a GDAP relationship.

After the relationship is set up, users in the partner tenant can access the [!INCLUDEprodadmincenter] for the customer's tenant. However, the users must be in a security group assigned to at least one of the required roles in the active GDAP relationship, which is done by completing these steps:

  1. Sign in to the Partner Dashboard.
  2. Select the Customers link in the navigation pane.
  3. Select the customer tenant that you want to do administrative tasks for.
  4. Select Service Management.
  5. Under the Administer Services heading, select [!INCLUDEprod_long].

You can also get to the administration center by using the URL of a tenant, as described in the previous section.

Tip

Delegated administrators do not need a license assigned or be a guest user in the customer tenant to access and administer the customer's [!INCLUDE prod_short] environments.

In the [!INCLUDE prodadmincenter], you can specify support information, create and remove environments, and you can access your customer's [!INCLUDE prod_short] environments.

Note

As the partner, there are certain tasks that you cannot do in your customers' [!INCLUDE prod_short]. For more information, see Acting as a delegated administrator.

Cleaning up settings

If your organization decides to switch to another partner, you must make sure that some settings that your current partner made in your [!INCLUDE prodadmincenter] are removed. This task includes the following settings:

  • Support contact details

    1. In the [!INCLUDE prodadmincenter], choose the relevant environment, and then, in the Support menu, choose Manage Support Contact.
    2. Verify that the values in the Name, Email address, and the Website fields are still relevant; if not, then delete or modify the values.
  • Notification recipients

    1. In the [!INCLUDE prodadmincenter], on the left side, choose Notification recipients
    2. Verify that the list of email addresses are still relevant; if not, then delete or modify the values.
  • Application Insights key (if set up by the partner)

    1. In the [!INCLUDE prodadmincenter], choose the relevant environment, and then, in the top menu, choose Application Insights Key.
    2. Remove the value of the Instrumentation Key
  • Authorized Microsoft Entra apps (if set up by the partner)

    1. In the [!INCLUDE prodadmincenter], navigate to 'Authorized Microsoft Entra apps' and remove any apps authorized by the partner.
    2. Revoke consent granted to the Microsoft Entra app belonging to the partner from your Microsoft Entra tenant. For more information, see here.
    3. Removed apps might have extra permissions assigned to execute certain administration operations, such as the D365 BACKUP/RESTORE permission. Any apps set up with permissions in Business Central can be disabled from the Microsoft Entra applications page. For more information, Assign Permissions to Users and Groups.

When you establish a relationship with a new partner, they fill in these fields again.

See also

Production and Sandbox Environments
Managing Environments
Tenant Notifications
Environment Telemetry
Administration Center API
Managing Technical Support
Business Central Data Security
Introduction to automation APIs
Microsoft Partner Dashboard
Add a new customer in the Partner Center
Assign licenses to users in the Partner Center
Create new subscriptions in the Partner Center
Cloud Solution Provider program - selling in-demand cloud solutions