Chapter 2 of 7Page 2 of 2

Install and activate

Assign permissions

Assign the two Universal Search permission sets: BAA SEARCH ADM for the people who set the app up, and BAA SEARCH for every user who searches.

updated: applies-to: 1.0.0.1

This page applies to version 1.0.0.1; the current product version is 1.0.0.0.

Universal Search ships two assignable permission sets, one for the people who administer the app and one for everyone who searches. Assigning them now means your administrators can start indexing without a SUPER account, and your users can open the search page as soon as the index is built.

The two permission sets

Permission set Caption Assign to
BAA SEARCH Universal Search - Use Every user who searches
BAA SEARCH ADM Universal Search - Admin Administrators, IT and partner consultants who set up and maintain the app
  • Universal Search - Use lets a user open the Universal Search page, read the index and setup, and run searches.
  • Universal Search - Admin includes everything in Universal Search - Use. It adds full access to the app's own tables, the setup, index configuration and activation pages, and the access that Start Indexing needs: read, insert, modify and delete on Job Queue Entry, plus read, insert and modify on Job Queue Category.
Permission Sets list filtered to BAA SEARCH and BAA SEARCH ADM with their Universal Search captions
The two permission sets Universal Search installs.

NOTE

Without BAA SEARCH ADM, an administrator who is not a SUPER user cannot schedule the background indexing job, so Start Indexing cannot complete. Assign it before anyone runs the setup.

Assign a permission set to a user

  1. In Tell Me, search for Users and open the user you want to give access to.
  2. In the user's permission sets, add BAA SEARCH ADM for an administrator, or BAA SEARCH for someone who only searches.
User card with the BAA SEARCH ADM permission set added in the user permission sets part
Step 2: add the permission set on the user card.
  1. Repeat for every user who needs Universal Search. A user who has BAA SEARCH ADM does not also need BAA SEARCH.

Permissions and search results

The permission sets control who can use Universal Search. They do not grant access to Business Central's business tables, although both include read access to the app's own index table, which stores the text of every indexed field. Results only include tables the searching user can read, and opening a result checks the read permission again.

WARNING

The read check is made per table, not per record, and Universal Search does not apply security filters to individual results. If you limit some users to part of a table with security filters, leave that table out of Search Index Configuration.

People who post documents but do not use Universal Search do not need either permission set. Universal Search records changes to indexed tables with its own built-in permissions, so their postings do not fail for lack of a Universal Search permission set.

For every grant in both sets, see the permission sets reference.

What's next

Register your environment for the free license: Activate the license.

// next step

Ready to try Universal Search?